Muhammad Afiq Haikal Ahmad Tarmizi, Muhammad Anwar Mohd Asri, Norlia Md Yusof
The rapid growth of online services has significantly increased the number of credentials users must manage, leading to widespread password reuse and weak authentication practices. This issue is particularly severe on mobile devices, where usability constraints often conflict with secure password management. Existing password managers commonly rely on cloud-based storage and subscription models, which introduce privacy concerns and increase exposure to centralized attacks. This paper presents Sack Key, a privacy-centric mobile password manager designed with an offline-first architecture to enhance security and user control. Sack Key securely stores credentials locally using AES-256 encryption and eliminates dependency on cloud infrastructure. The system incorporates multi-layer security mechanisms, including master password, Two-Factor Authentication (2FA), automatic session locking and privacy-preserving features such as manual encryption and decryption. Additionally, Sack Key supports secure peer-to-peer password sharing over local networks without internet connectivity. The results of functional, security and user testing indicate that Sack Key provides reliable password protection, strong user trust in offline security and intuitive user experience. The findings demonstrate that an offline-first password manager can effectively balance usability, security and privacy in mobile environments.