Cloaker


Cloaker
Download on the AppStore Click here to request a review of this app

  • App Store Info

Description

Much better than a password safe - this app gives you access to your passwords from any iOS device without the need for synchronisation between devices or cloud storage.

Rather than store data (which can then be hacked), passwords and other security related data like answers to "security questions" are created and re-created only when you need them based on a PIN code combined with other easy to remember information.

The idea is to keep all your accounts as safe as possible by using random security data that is different for every account and that can't easily be reverse-engineered back to your easy-to-remember information.

We humans prefer to use the same easy-to-remember convention when creating passwords for many different online accounts. For example, we may create passwords like Phone123, Netflix123, eBay123 etc etc.

The problem with this is that hackers fully understand our human tendencies and using a convention like this will put all of your accounts at risk if just one is compromised.

Wouldn't it be great if you could keep using this kind of approach but be absolutely certain you are secure, no matter what happens with one individual account?

Cloaker solves this problem by allowing you to use simple information as the basis for generating passwords and data for security questions etc. Cloaker even allows everyone to use the same simple information and still creates vastly different security data for each by combining the information with your secret PIN.

The PIN and simple information are used to generate the unique security data using an industry standard, one-way hashing algorithm. A change to even one letter in your simple information from say, A to B, results in a vastly different output for which reverse-engineering back to the original PIN or text is extremely difficult.

All you do is enter your PIN and then you can enter any text you want:

For example: entering a PIN of 11112 and the simple text "PHONE" yields the following security data in 12 sections that can be used for passwords or security questions etc.

q@x< k967 Qf4* 4Hq&
6937 7415 5489 3879
XUH PHA CZS UZF

You can then tap on the sections you want to use for your password or security question answers.

Another advantage of this approach is that you can generate the same security information on any iOS device that has this app loaded. You don't need to manage copying around a password file that may or may not be up-to-date. The generated security data relies only on something you know : Your PIN and simple information, and something you have: This app running on any iOS device.

The sections you tap on are highlighted for future reference. This doesn't mean any of the generated security data is being stored - it's not - only one-way hashed reference numbers are stored in your phone - these numbers, like the security data, the stored numbers cannot be decrypted back to the original data.

Of course, this last feature will only be available on the iOS device it was entered on.

You can also enter some additional text alongside the main text. This allows you to generate many variations of security data under one main text ‘heading’.
For example, if the main simple text is “PHONE”, you can then entire extra text like “FOOD” to generate a new set of security data. You can then take, for example, one of the 4 digit numbers and use it for the answer to the security question “What is your favourite food?”.

Word of advice - never add real answers to security questions like, what’s your mothers maiden name. That kind of private information should be kept private because if it ever gets hacked you will have lost it forever. Instead, use this app and only give out the random data it generates and the inevitable data breaches that occur regularly in the cyber-world won't concern you :-)

DISCLAIMER: No responsibility will be accepted for any loss or injury arising from the use of this app.

What's New in Version 1.3

- Removed confirmation and storage of PIN hash for enhanced security.
- Removed assumptions about weak PINs, any PIN can now be used even a PIN with just one digit (risk of using easily guessed PINs is owned by the user).
- Now clears the password screen when the app goes into background for enhanced security.

Screenshots

Screenshot 1 of 10 Screenshot 2 of 10 Screenshot 3 of 10 Screenshot 4 of 10 Screenshot 5 of 10 Screenshot 6 of 10 Screenshot 7 of 10 Screenshot 8 of 10 Screenshot 9 of 10 Screenshot 10 of 10