Drop dead gorgeous and very functional
For Mooltipass Mini Offline Password Keeper
On the Tindie service.
Delivery was from China although tindie order looks like it will ship from Switzerland easy mistake but product page is clear. Caveat emptor.
Very slow shipping. Extraordinarily slow including more than a week in the UK. One whole week spent processing customs.
I had to pay customs handling fees which were over twice the actual customs due!
On the device itself
It is drop dead gorgeous the OLED is beautiful crisp, clear, bright (even at 10%). The blue is just so vibrant. The animations as you scroll are oddly satisfying as is using the scroll wheel with lets you intuitively navigate the devices firmware. More on the scroll wheel later.
Due to issues with purchasing a Mooltipass (slow delivery, customs issues, expensive) some degree of vendor lock in. Requires you to buy another device (admittedly the cheapest compatible card readers seem to be about £15) to read the mooltipass cards to extract keys to decrypt your back up. Another issue is while the smart cards appear to be cut down from the normal credit card form factor, I can’t find any of these AT888SC102 in smart card form factor at quantities less than 100 units. That means I have to pay shipping to get hold of these otherwise normal cards from China (and presumably wait 3 weeks). I’ve not idea of the reason these particular cards were selected, there might be very good reason for it for all I know.
The wheel is intuitive to use but snap risk and seems to be the most likely point of failure for the device. Would 3 buttons be so awful? Or even 2 buttons like a ledger or even 3 buttons, it would make confirm and cancel more intuitive in my opinion.
The browser integration for the most part works very well. There are intolerable nag screens whenever a page is loaded without the mooltipass connected. Look to your OS settings to supress these notifications but those only seem to have been a temporary fix for me. The app does not allow you to make this change.
Using the device unaided works well.
It seems passwords are generated computer side before transfer to the device. This has pros and cons. A pro being increased entropy compared to on device alone. A con is that I trust the device more than I trust the computer. Overall though it doesn’t seem to make a security difference because passwords must be on the computer at some point to be useful (or you can’t log in!).
There are no on device password management features. To add a password you either have to do so through the desktop app like Moolticute (more on that later) or the browser plugs (more on that later too).
The 31 character password limit is unfortunate (for me) as all my pre-existing passwords are 32 characters long! I’ll have to be very sure of the Mooltipass before I move over passwords that I could not afford to lose. My Github password is 64. This was of course in hindsight overkill, but overkill without a draw back when my password manager allowed it!
I did accidently lock myself out of an account in the first day I had the Mooltipass (generated a password and forgot to save it!). So make sure you do some trial runs, maybe using new accounts to get the hang of the process.
The browser plugins are very helpful in reducing clicks on the device, however the notification with pop up noise every time the device isn’t plugged in it soul destroying, as is the notifications that the password is too long (even if you don’t want to save it to the device).
The password generate is clunky; you must go into settings to change characteristics and it does not ensure at least one character per category included so you might tick include numbers if the site requires it and it might not actually include a number (by random). Finally, as I said I did lock myself out more than once and that’s mostly my fault of course but why would I want to generate a new password and NOT save it?
Overall, I am very pleased with this device, it’s not perfect, far from it, but it works well and is head and shoulders ahead of the others. Did I mention just how gorgeous this device is? I like that it will work with any device unlike other hardware password managers and allows easy navigation of logins on the device. I do think improving the plugin will be low hanging fruit and this would improve the experience immensely.
Response from Stephan Electronics | March 15, 2019
Hello Ali,
Wow, thanks a lot for the time you took to write this great review!
We'll answer some of the points you brought up:
- You may actually purchase standard cards from us in single quantity, on tindie
- We actually tried a 3 button interface, but that made the scrolling experience disastrous
- In theory notifications should only appear once if your device is not connected
- Password are actually generated using the device onboard RNG
- On device password management: we actually didn't implement it because of the display low resolution
- We'll add an option to disable all notifications in moolticute in our next release
Thanks again for your great review!
Mathieu