Discussion summary
Bramble is a local-first password manager with custom sync engine, emphasizing resource efficiency and security. The developer plans to add more crypto options and is focused on careful planning and testing.
What the discussion says
- The sync engine is custom-built for encryption, not using common libraries.
- Focus on resource efficiency for password management.
- Plans to expand crypto options beyond Monero.
- No iOS release yet, which may limit adoption.
“Bramble's sync is built around its own encrypted vault.”
“I like Monero, but will add more options soon.”
Join the discussion
Write your take first — we'll ask for email only when you're ready to publish.
- Hacker News
- Really clean concept. Keeping everything entirely on-disk instead of relying on a third-party cloud is something I've been wanting to see more of.by mune2gu-chan
- It’s nice to always have more options but I don’t want it to be local, I lose the centralized system and having multiple devices syncing the pass database, or a turned off device, or an attack/ransom that took all your files including your passowrds, or your lost your device while traveling.. It’s better to have them secured somewhere safe and only accessible remotely, and there are plenty of self hosting options out there.by tamimio
- I think you are going to run into a lot of anxiety about data loss. I did find the recovery code and peer to peer sync notes, which help.
Most people are not going to think through where to store an encrypted folder on a share so that there is a backup. If you are targeting just tech forward users that's probably okay, but for larger usage, you might think about full disaster recovery case where a computer and phone are both lost, as well as how to make it easy on where a copy is always stored or sync'd so users don't have to worry.
by Aaron_NW - > TL;DR: I dislike private-equity and venture funded companies messing with our security, so I created my own Password Manager which is local-first, free, open source and as transparent as it gets.
I do too! And I appreciate your transparency about the vibe coding. But nowhere in the repository that I've found so far do you say who is writing this. For something like a password manager, I kind of need to know who's responsible for it, and who's reviewing the LLM source code, what they've done before, what their business model is, etc.
Can you share?
- This looks like something I've been looking for! Excited to give it a try! I don't even use a password manager because of the things you've seemed to work around here. It's been painful.
Honestly, though, I'm most intrigued by your P2P solution. I've built a couple of web apps as custom html elements that use indexedDB for storage and I've been trying to figure out the sweet spot for syncing the data between apps. I think this nostr relay hits the mark as something people can feel comfortable not self hosting, while power users can host their own solution. Seems like a great solution, to me! Any advice as to some footguns with the approach? I'm very interested in giving it a try myself[0], so any notes you think would prevent some re-work would be really appreciated!
[0] as a public domain/oss-licensed module, if there's a reasonable method of packaging it as a standalone library
by catapart - i think this is a great Idea but it doesnt beat any of the other free password managers like keepass.. I support this Idea tho and ill check on it to see where youve gotten! i usually just use keepassDX on my phone and keepassXC on my pc to create a local encrypted database file that i sync through MEGA sync which creates another level of encryption and i have 3 ways to get my password back if i lost them ( the database also gets saved in the phone) , the problem im seeing with youur product is just that is your browser is compromised your password is visible. compared to the keepass encrypted database its lacking security.by HN-user2345
- What does this offer over other local-first password managers? For example, there are a fair few Android/iOS apps based on KeePass (I currently use https://www.keepassdx.com on my Android phone).by ZenoArrow
- I think local-first password managers are the way forward. Big tech companies already have way too much power and having them mediate our most important data is a bad precedent to set.
I like that you made this P2P, I designed one that sits on top of sqlite and is 100% local first but is not P2P, take a look if you are interested in some prior art in this space:
I decided to go with native apps all the way, Rust backend and Flutter front-end but kind of regret it now with how the Play/App stores are such a hassle to work with.
by tmpfs