Offline-Password-Manager

Offline Password Manager/Autofill | AI Keyboard

PolyCast5 as a Offline Password Manager

PolyCast5 is an excellent password manager due to its native capability to auto-fill text without an internet connection as the go-between. This essentially allows it to function as an offline password manager, keeping your passwords secure on device while any typing is done with encrypted Bluetooth LE.


Additionally, this makes it perfectly cross-platform since it'll work for anything with Bluetooth while still being super fast and convienent.Β 

Here's how it works:

  • One time setup (discussed later)
  • Then, simply say "password" followed by a description of what it is for (e.g. "Discord")
  • AI matches your description to the password namesΒ available (never the password itself, so it's secure)
  • AI returns an index to the chosen name then the firmware safely extracts the actual password to stream over Bluetooth LE
  • You're logged in!

It's as easy as that. So let's go over how to get this working on your PolyCast5.



One-Time Setup

To get this working, all you need to do is create an Auto Keyboard category named "Passwords" and then save any passwords that you want to be searchable to that category.


Just go to Bluetooth > Auto Keyboard > Add/Edit Script, then connect to the advertised network with your phone or PC. Once you're connected, you'll see the script editor in your browser. From here, create a new category with the "Add New" button and name it exactly "Passwords", then click save. You should then see it appear below in "Existing Categories".


While you're here, you can also create one named "Custom" to set up custom commands. ButΒ more on that here.

Of course, you can also create other categories and name them whatever you want, but only these two are built-in to be AI searchable.


Next, scroll down to "Existing Scripts" and select the category "Passwords" you just created. From here you can click on any existing scripts to edit them or just click "+ Add New" to add a new one.

After clicking, you'll be brought to the "Edit Script" option and prompted to enter a name. This is the name of the specific password that you/the AI will use to identify which password entry auto-fills which password.


This said, give it a clear, descriptive name that you'll easily remember when speaking. I want to also point out that the beauty of AI here is that you don't have to say exactly the name of the password. AI simply picks theΒ closest one.Β This said, of course the AI never sees your actual password, ONLYΒ the name in which it picks and the secure firmware handles the rest.

So if the password name is "Autodesk Fusion360 Pro Account" for example, but you just say "Fusion360" the AI would likely pick "Autodesk Fusion360 Pro Account" to auto-fill assuming no other similar names. So feel free to add a few easy-to-remember keywords.


After putting in the name, put the password as the payload and hit save. Depending on the platform, you may also want to put <enter> at the end so it automatically presses the enter key after it's done typing, but that is up to you.

I'm at index 10 because I already saved 9 other passwords.

I also want to point out that at the bottom it tells you what tokens are allowed to be interpreted in case you want to get creative.

For example, to auto-fill both my username and password in one go I could type the username and password as one string and then have it <shift+left> back over the password part and then <ctrl+x>. This makes it so the username is fully typed out and the password is copied to the clipboard to easily paste into the password section after.


You can also reverse this process and type the password first in the password area then paste the username as a safer security practice.


Example:

usernamePASSWORD123!<shift+left><shift+left><shift+left><shift+left><shift+left><shift+left><shift+left><shift+left><shift+left><shift+left><shift+left><shift+left><ctrl+x>

Future me here! A new command has been added to make this much easier. Use the <select_prior> command to select all text typed before it. With this, you can avoid counting out each <shift+left>. Example:

username<select_prior><ctrl+x>PASSWORD123!

I also want to point out that you may see this when opening the Bluetooth (BT) portal in your browser:

A browser will say anything using HTTP instead of HTTPS is insecure, but this is not the case. PolyCast5 uses a SoftAP with WPA2-PSK encryption that provides transport layer security. This encrypts all traffic between the client and PolyCast5 access point, so as long as you don't give out the randomly generated portal password you'll be just fine. Additionally, the Bluetooth LE used to type the actual payloads is encrypted with AES-128-CCM, uses ECDH P-256 for key exchange, frequency hops, and has enabled MITM protection.



Tips and Best Practices

To get the most out of your PolyCast5 password manager, keep these tips in mind:

  • Keep a secure paper backup! If you ever lose your PolyCast5, you don't want to also lose all of your passwords.
  • Set a PIN. Go to settings and set an unlock PIN to protect others from getting into your device. PolyCast5 uses incremental lockout like a phone, making it impossible to brute-force.
  • Lock it down. By default, PolyCast5 units come with development mode flash encryption, but this isn't enough to secure your device from a sophisticated physical access attack. Enable secure boot and release mode flash encryption to make sure that no one can steal your info should you ever lose your PolyCast5.
  • Use unique, descriptive names.Β When naming your password entries, choose names that are distinct and easy to say. Avoid similar-sounding names for different accounts, as this makes it easier for the AI to match the right one on the first try.
  • Use strong, complex passwords. Since you never have to type or remember your passwords manually, take advantage of this by using long, randomized passwords for each account. PolyCast5 handles the hard part of typing them out for you.
  • Keep your Passwords category organized. If you have a lot of accounts, consider using clear naming conventions. For example, prefix work accounts with "work" (e.g., "Work Email", "Work Slack") and personal accounts with "personal" if needed.

Another very important security aspect is that the PolyCast5 firmware is open-source (if you're reading this pre-launch, it will be released after first units are shipped). If you worry something is malicous, simply inspect the code for yourself and then rebuild it on your own local machine and re-upload to your PolyCast5. EZPZ!

PolyCast5 offers a simple and secure approach to password management combining voice-activated AI with local storage. Whether you're tired of cloud-based services, need a cross-platform solution that works with any Bluetooth device, or simply want a faster way to log in, give the PolyCast5 password manager a try to never manually type a password again!


Happy casting!

*Please note that RoboticWorx is not responsible for compromised passwords. Be secure in your password management and always follow best security practices.*

Back to blog