Countermail's Safebox is a password manager, a secure place where you can store all your usernames and passwords. All data in the Safebox is protected with one master password. The Safebox does not use any public/private keys, it's using pure OpenPGP symmetrical encryption. This means that the Safebox encryption is separated from your account keys and password, so you can use a different password for the Safebox. As usual, all encryption/decryption is done on your local computer, inside the Java-applet in your web browser. No Safebox-data will leave your computer in unencrypted form.
Warning! If you forget your password your data will be inaccessible! We do not have any "Forgot password" function, since such functions may weaken the "chain" of security.
Go to your Safebox by clicking on the Safebox-folder in the left menu:
When your Safebox is empty, you must first select a Safebox password:
The next time you login to your Safebox, you will be asked to enter the Safebox password:
Functionality inside the Safebox:
- Listbox with all your stored pages, sorted alphabetically using the Short Description.
Click on a line to View / Change / Delete a page
- Short description, enter a title for the page
- URL/Address, enter the URL to the page
- Username, the login name on that page
- Password, you can use all types of characters here, internally it's converted to Base64 to allow all characters for all languages
- Notes, you can enter any additional info here
- Visit URL, click here to open a new window that will redirect you to the page
- Show Pass / Hide Pass, click here to show the password
- Add page / Save page, click Add Page to add a new page, when this button says "Save page" it will update the currently selected record
- Delete page, delete the currently selected record and all info that belongs to this page
- Clear fields, empty all fields so you can to add new pages, the button on #9 will change to "Add page" after clicking "Clear fields"
- Automatic logout, after you logged in the password will be cached for a while, it will be automatically logged out if it's been idle for this amount of minutes
- Change password, click to change the Safebox master password
- Close Safebox, but don't clear the password cache
- Logout, close Safebox and clear the password cache
The Safebox master password is converted to a AES-256 key using OpenPGP's Iterated and Salted S2K, the iteration code is set to 192, which equals to approx. 4 MB of data to hash (password+salt iterated through SHA-1). This makes the password very slow to bruteforce.
An Intel Core-i7 CPU @ 3.2 GHZ can test approx 30 passwords per CPU-core, per second.
Example, if you have a 10-letter password using a charset of 62 (a-z, A-Z, 0-9), it will take more than 400 years to bruteforce, using a super-computer with one million i7 CPU-cores:
62^10 / (30000000*3600*24*365) = 887 years (whole keyspace), and 443.5 years for half the keyspace.
Read more about OpenPGP S2K here:
Read more about OpenPGP symmetrical encryption here:
Sep 3, 2015
Security upgrade on servers. 15 minutes downtime.
Added VCARD-Export and VCARD-Import for Contacts
Added PGP-packet analyzer on our Tools-page
Changed Trial accounts restrictions, read more.
New SSL/TLS certificate, fingerprints.
More storage space for members with 12 or 24 months subscriptions.
Updated our Tools-page.
We are working to open up the webmail for our Two Factor Auth-mobile app. We will send an email to our users when it's ready
Improved spam blocking
Added FAQ: How do I create good passwords?
Changed spam flag to minimize false Spam classifications. Read more
Updated CounterMailPortable. Read more
Bugfixes and Updated Offline Login and more. Read more
Updated our Tools page. Read more
Added Quota warnings. Read more
Changed new public keysize to 4096 bits.
New USB routine. Read more
Changed Trial account period to 7 days
Opened up our XMPP chat server.
Added new Support-system and a new FAQ
Updated Java info page
Added MacOS support for our USB-key
Added Countermail Portable for Windows
Added Safebox feature
Scheduled Maintenance - August 30, 13:00 GMT. Servers will be down for approx. 2-3 hours.
Added subfolder creation.
Applet and Certificate update
Added Wire transfer payment
Third party IMAP-clients need to clean their cache. Read here.
Added Domain Panel for all domain administrators
Added quick search
Added default Compose-alias
Added new session option for TOR/VPN/Proxy-surfing. Settings/Personal info - Lock IP-address
Added iPhone information
Added message filters
Updated alias function
Added new white theme
Added email notification
Added more server-side SPAM protection
New Compose window
Added instructions for Android phones
Added new feature:
Opened up for all !
Open website for Beta-testers
Installed our primary login and database servers
Comodo Usertrust certified our company for Java applet code signing
Domain name registration. Official start of the project.