Unicode Password Generator & File Protector
UNIGEN
Cross-platform Rust desktop app (egui/eframe) for generating cryptographically strong, high-entropy Unicode passwords, running a hardened local password vault, and protecting sensitive files with authenticated AES-256-GCM encryption.
Rust
egui / eframe GUI
613 Unique Chars
AES-256-GCM
Argon2id / PBKDF2
Secure Shred
Clipboard Exclusion
Password Vault
v2.1.2
Overview
UNIGEN is a Rust desktop application (built on egui/eframe) that combines a high-entropy Unicode password generator, a full password vault, and a file encryption/decryption toolkit. Single static binary — cargo build --release and run — on Windows, Linux, and macOS.
Four tabs cover the workflow: Password Generator for creating up to 10,000 cryptographically secure passwords from a 613-character Unicode pool; Vault, a local password manager with an envelope key hierarchy, in-memory encryption of secrets, and KeePassXC CSV import; and File Protector for AES-256-GCM authenticated encryption with a per-file configurable Argon2id or PBKDF2-HMAC-SHA256 key derivation. Includes platform-native clipboard exclusion, auto-clear timers, cross-platform process hardening, and multi-pass secure file shredding with no external tool dependencies.
Password Generator
∞
613 unique Unicode character pool
Eight distinct sets: Latin Standard & Extended, Cyrillic, CJK & Kana, Simplified Chinese, Greek, Math/Symbols & Currency, Dingbats & Misc — plus a live "Source Code" set built from every unique character in the script itself.
1–10k
Batch generation
Generate 1 to 10,000 passwords at once, 8–128 characters each. Uses Python's secrets module for cryptographically secure random selection.
📊
Pattern-aware entropy feedback
Pool size, entropy (bits), and strength rating update live as you toggle character sets and adjust length — discounted for common passwords, keyboard walks, and repeated/sequential runs instead of scoring on character-class variety alone.
🔐
Encrypt & Shred
Save your password list, encrypt it with a passphrase, verify the round-trip, then securely shred the plaintext — all in one click.
📋
Clipboard security
Platform-native clipboard exclusion prevents password-history tools from capturing copied passwords. Auto-clear timer with 5–300s delay.
File Protector
🔒
AES-256-GCM authenticated encryption
Confidentiality + integrity via the aes-gcm crate's AEAD primitive. Tampered ciphertext, or a file with bytes appended after the real ending, is rejected rather than silently decrypted.
🔑
Argon2id or PBKDF2-HMAC-SHA256
KDF choice plus its parameters (memory/time/lanes or iteration count) are stored in the file header and authenticated as AAD — tampering with them fails decryption instead of silently taking effect. Unique salt and nonce per file.
🧹
Pure Rust secure shredding
3 random-data passes + 1 zero pass, fsync'd between each, followed by deletion. No dependency on the Unix shred binary. Verify-before-shred streams a byte-for-byte comparison so a corrupted or truncated file is never mistaken for a good one.
📁
General file encryption
Encrypt or decrypt any file — not just password lists. Optional "verify then shred" checkbox for one-click secure archival.
🌑
Dark theme
A single, permanent dark theme with a Clearlooks/GTK-inspired visual language and restrained rounding — no light-mode toggle.
Password Vault
Envelope key hierarchy
🗝
Master → KEK → vault key → per-entry key
The master password derives a key-encryption key (KEK) that only wraps a random 32-byte vault key; each entry's AES-256-GCM key is then derived from the vault key via a per-entry HKDF expand, so no two entries ever share a key and a leaked entry key can't reveal the vault key.
♻
Fast password change
Changing the master password re-wraps the vault key in O(1) — it doesn't re-encrypt every entry — while a full re-encrypt with a fresh vault key remains available if a key compromise is suspected.
⇄
Backward compatible
Older single-key vault files still open transparently and are upgraded to the envelope format on next save.
In-memory protection
🧬
RAM-at-rest obfuscation
Vault passwords are kept as ChaCha20-sealed LockedSecrets, not plaintext, for the entire time the vault is unlocked — decrypted only for the moment a field is shown, copied, or edited.
✎
Leak-resistant text fields
Password, username/URL, and Notes fields all use custom widgets that never push plaintext snapshots into egui's undo/redo history — the gap plain TextEdit leaves behind.
🔒
mlock / VirtualLock status
A live indicator shows whether secret memory is actually locked out of swap on this platform, not just whether the option is checked.
⭳
KeePassXC CSV import
Imports KeePassXC exports, correctly handling multi-line Notes fields instead of splitting them into orphaned rows.
Remember session: on Windows, an opt-in DPAPI-backed cache can survive auto-lock (Until app exits) or an app restart (Until logout) without ever storing the master password as plaintext at rest — off by default (Never), and cleared on manual lock, password change, or switching vault files.
Installation
Rust toolchain (stable, edition 2021+). Build the GUI binary with Cargo — no separate runtime to install.
# Debian / Ubuntu — GTK3 file-dialog backend
sudo apt install libgtk-3-dev
# Clone and build
git clone https://github.com/A113L/unigen
cd unigen
cargo build --release
# Run
./target/release/unigen
Character Sets
Latin (Standard) — a-z A-Z 0-9 !"#$%&'()*+,-./:;<=>?@[\]^_`{|}~
Latin (Extended) — ąćęłńóśźż äöüß èéêë īįì ôöòó œøãåáàâæçñ
Cyrillic — абвгдеёжзийклмнопрстуфхцчшщъыьэюя
Asian (CJK + Kana) — 漢字日本語中文 あいうえお アイウエオ
Simplified Chinese — 你好世界中国语言文字系统安全密码保护
Greek — ΑΒΓΔΕΖΗΘΙΚΛΜΝΞΟΠΡΣΤΥΦΧΨΩ αβγδελμνξοπρςστυφχψω
Math/Symbols — ∞±≠∑∏√∫∂∆πµΩ≈≡≤≥∇ ¢£¥€₩₪₹₽฿₫₴₦₲
Dingbats & Misc — ★☆☀☁☂☃☄☠☢☣♠♣♥♦♪♫✔✖✳❄‼
All sets are combined into one deduplicated pool. Toggle individual sets to control entropy and character composition. The "Source Code" set is built live from every unique character in the script itself.
Security Architecture
Encryption
A
AES-256-GCM
Authenticated encryption — confidentiality plus integrity verification. Tampered ciphertext, or KDF parameters altered in the header, is rejected.
K
Argon2id / PBKDF2-HMAC-SHA256
KDF parameters are stored in the header and bound into the AAD per file, with a random salt. Keys are never reused across encryptions.
N
12-byte nonce
Fresh nonce per encryption operation prevents IV reuse attacks.
S
Serialize-safe secrets
SecretString/LockedSecret deliberately don't implement generic serde::Serialize — code elsewhere in the app can't accidentally leak a secret via a stray serde_json::to_string or debug log; it fails to compile instead.
Shredding
1
Pass 1–3: Random data
Three passes of cryptographically secure random bytes overwrite the file contents.
2
Pass 4: Zero fill
Final pass overwrites with zeros. fsync called between every pass to flush to disk.
3
Delete & report
File is unlinked. Status indicates "secure" if overwrite was verified, "fallback" if only deletion could be confirmed.
SSD / CoW caveat: On SSDs, copy-on-write filesystems (Btrfs, ZFS, APFS), or filesystems with snapshots/journaling, overwritten data can persist elsewhere on the device. Treat shredding as strong best-effort — use full-disk encryption (BitLocker, FileVault, LUKS) as your baseline.
Password Generator Workflow
Step 1
Configure parameters
Set length (8–128) and count (1–10,000) with sliders or spinboxes. Toggle character sets — entropy updates live.
Step 2
Generate passwords
Click Generate Passwords. Review the list. For batches >25, a summary view appears with download option.
Step 3
Copy, save, or encrypt
Copy All with clipboard-manager exclusion. Save to File as plaintext. Encrypt & Shred for one-click secure archival.
Step 4
Clear clipboard
Click Clear Clipboard or enable Auto-clear (5–300s) to wipe the system clipboard when done.
File Protector Workflow
Encrypt
Browse to any file, enter passphrase (min 8 chars)
Optionally check "verify, then securely shred the original after encryption". Output is a portable .enc container.
Decrypt
Browse to .enc file, enter passphrase
Click Decrypt & Save to restore original bytes to a location you choose. Streaming decrypt rejects anything tampered with or truncated.
Shred
Manual secure destruction
Browse to any file and permanently destroy it with the same multi-pass overwrite, independent of encryption.
Vault Workflow
Step 1
Open or create a vault
Pick a vault file and set a master password. New vaults save directly in the envelope key-hierarchy format.
Step 2
Add or import entries
Enter title, username, password, URL, and notes by hand, or import a KeePassXC CSV export in one step.
Step 3
Unlock, copy, auto-lock
Copy a password or a selected line of Notes to the clipboard with auto-clear; auto-lock hides entries after inactivity, with an optional DPAPI-backed "remember session" on Windows.
Step 4
Save, verified
Every save decrypts its own output — in memory and again from disk — before publishing over the real vault file, so a failed write never corrupts the last good vault.