Case 02 / 個人プロジェクトPersonal project

Enigmaa

パラメータを自分で決められ、記録がなくても同じパスワードを再計算できる、パスワード生成ツール。A password generator where you set the parameters yourself and can recalculate the same password without any record.

PDFをダウンロードDownload PDF
期間When2026年9月〜From Sep 2026
対応環境PlatformsMac・iPhone
担当My part要件とルールの設計、取捨Requirements, rules, trade-offs

01背景と目標Background and goal

背景Background

多くのサービスが定期的なパスワード変更を求める。ランダムな文字列は覚えられず、自分で考えた組み合わせは新しいものが作れなくなり、何に変えたかも分からなくなる。Many services ask you to change your password regularly. Random strings cannot be remembered, and the combinations I made up myself ran out, and I lost track of what I had changed to.

課題感Problem

記録に頼ると、記録をなくしたときに困る。かといって、算式が全員共通だと公開できず、守りはパラメータの秘密だけになる。Relying on records is a problem when the records are lost. But if the formula is the same for everyone, it cannot be made public and the only protection is keeping the parameters secret.

目標Goal

管理ツールではなく、パラメータを自分で操作できる生成ツール。同じ条件なら記録がなくても同じパスワードを再計算でき、算式そのものが利用者ごとに違う。Not a password manager, but a generator whose parameters you control. The same conditions give the same password with no record, and the formula itself differs for each user.

02開発の流れProcess

  1. 1
    ルールを決めるDefine the rules
    9/15
    日単位、パラメータは追加可、順序で結果が変わるDaily, extra parameters, order changes the result
  2. 2
    Mac版を作るBuild the Mac app
    9/15
    その日のうちに最初の版A first version the same day
    SwiftUI
  3. 3
    算式を見直すRework the formula
    9/19
    算式そのものが利用者ごとに違う形にSo the formula itself differs per user
  4. 4
    iPhone版iPhone app
    9月中旬Mid Sep
    同じコードを共有Shared codebase
    SwiftUI
  5. 5
    安全性の審査と2言語化Security review, two languages
    10/3
    3つの観点でレビュー、12字ルール、中・英Review from 3 angles, 12-character rule, ZH and EN
  6. 6
    公開準備Getting ready to release
    10/3〜
    App Store提出。名称は Enigma が使用済みのため Enigmaa にApp Store submission. Named Enigmaa because Enigma was taken
    App Store Connect

03考え方The idea

「保存する」のではなく「再計算する」Recalculate, not store

保存する方式Store it一般的な考え方The usual idea
パスワードを作るMake a password
→
保存するSave it
→
必要なときに取り出すRetrieve it when needed
Enigmaa再計算する方式Recalculate it
パラメータを入れるEnter the parameters
→
日付を選ぶPick a date
→
同じ結果が出るThe same result comes out

記録は「答え」ではなく「条件」What is kept is the conditions, not the answer. 記録が消えても、同じ条件から同じパスワードを取り戻せる。If the record is lost, the same conditions bring back the same password.

04いちばん難しかった点The hardest part

算式が、本当に利用者ごとに変わることMaking the formula really differ for each user

最初の設計First design9/15
パラメータParameters
+
日付Date
→
全員共通の算式One formula for everyone
→
守りはパラメータの秘密だけProtection rests on keeping the parameters secret
見直し後After the rework9/19〜
パラメータParameters
+
日付Date
+
最初に設定した主パスワードThe first master password
→
人ごとに違う算式A formula that differs per person
→
算式が公開されても、パラメータだけでは再現できないEven with the formula public, the parameters alone cannot reproduce it

役割Who did what 「算式まで利用者ごとに変わること」を求めたのは私。算式の設計と実装はClaude。I asked for the formula itself to differ per user. Claude designed and built the formula.

代償:機種を変えるときは、最初に設定した主パスワードの入力が必要になる。The cost: when you change device, you need the master password you first set.

05取捨Trade-offs

選ばなかった案と、承知の上の代償What I did not choose, and the costs I accepted

✕サービス名もパラメータに入れる(複雑になりすぎる)Put the service name in the parameters (too complex)
✕算式専用の合言葉を別に作る(面倒)A separate passphrase for the formula (too much hassle)
✓パラメータ+日付+最初の主パスワードだけで再計算Recalculate from parameters, date and the first master password only

代償(承知の上で選んだ)Costs (chosen knowingly)

  • 半年に一度まとめて換える運用なので、その間は全サービスが同じ組になる。Passwords are changed all at once about every six months, so every service shares one set in between.
  • 機種変更のとき、最初の主パスワードが必要。A device change needs the first master password.
  • 最初の主パスワードは、あとから変えられない。The first master password cannot be changed later.

06課題と対応Problems and fixes

4つの重要な判断Four key calls

課題PROBLEM
私の対応WHAT I DID
持ち帰った原則PRINCIPLE
算式がアプリの中で全員共通で、守りがパラメータの秘密だけだったThe formula was the same in every copy of the app, so protection rested only on keeping the parameters secret
→
最初に設定した主パスワードから作った鍵を算式に混ぜたMixed a key made from the first master password into the formula
→
算式が公開されても守れる作りにするBuild it so it stays safe even if the formula is public
日本語・中国語が入力できない(標準の伏せ字欄)Chinese and Japanese could not be typed (the standard secure field)
→
パラメータ欄は自作の伏せ字欄にした(主パスワードだけ標準のまま)Built a custom masked field for parameters; only the master password keeps the standard one
→
部品の制約は、作る前に確かめるCheck a component's limits before building on it
審査で、弱い主パスワードは総当たりに弱いと指摘されたThe review found that a weak master password can be brute-forced
→
12字以上のルールにし、設定画面で「一生使う根っこのパスワード」と明記したRequired 12+ characters and said plainly in Settings that it is the permanent root password
→
弱点は隠さず、画面の言葉でも伝えるDo not hide a weakness; say it on screen too
入れなくなる不安を減らしたい。でも日常の操作は難しくしたくないReduce the fear of being locked out, without making daily use harder
→
解除手段を複数用意(主パスワード、生体認証、復旧キー、ヒントの答え)。ヒントの答えは任意で、空欄を勧めるSeveral ways in (master password, biometrics, recovery key, hint answer). The hint answer is optional and leaving it blank is encouraged
→
入口は複数に、日常の操作は簡単にSeveral ways in, and an easy daily routine

07役割分担Working split

要件と取捨は私、算式の設計と実装はAII set requirements and trade-offs; AI designed and built the formula

私の役割MY ROLE要件定義Requirementsルール設計Rule design取捨Trade-offs公開作業Release
01
私ME困りごとと使い方のルールを決めるSet the problem and the rules
02
AI最初の版を実装Build the first version
03
私ME「算式まで利用者ごとに変わる」を要件にするRequire that the formula itself differs per user
AI算式の方式を設計Design the formula
04
私ME四つの図形をカテゴリにする案Idea: four shapes as categories
05
AI3つの観点でレビューReview from three angles
私ME使いやすさとの兼ね合いで取捨Weigh each finding against ease of use
06
私ME審査提出、実機の操作動画Submission, a device walkthrough video
AI提出資料と文面の準備Prepare submission material

08成果Results

2
対応環境
Mac・iPhone
Platforms
Mac, iPhone
2
言語
繁体字中国語・英語
Languages
Traditional Chinese, English
53
自動検証の項目
(10/5時点)
Automated checks
(as of 5 Oct)
3
並行レビューの観点
暗号・App Store・データ
Review angles
crypto, App Store, data
1.0
iPhone版をApp Storeで公開iPhone version released
on the App Store

09Claudeの講評Claude's view

共同作業者の見方で、筆者が書いたものではありません。The collaborator's opinion, not written by the author.

Claudeの講評Claude's view共同作業者の見方Collaborator's opinion

良かった点Worked well

  • 「管理ツールではなく生成ツール」という定義を最後まで守り、保存ではなく再計算に絞った。Kept the definition "a generator, not a manager" to the end, and stayed with recalculation rather than storage.
  • 弱点(主パスワードの強度)を隠さず、画面の言葉でも伝える形にした。Did not hide the weak point (master password strength) and said it on screen too.
  • 強制する所と任意にする所を、使いやすさを基準に分けた。Split what is required from what is optional, using ease of use as the test.

改善できる点Could be better

  • 算式の安全性は私たち自身の審査のみで、第三者の暗号レビューは受けていない。The formula was reviewed only by us; no third-party cryptography review.
  • 公開から日が浅く、他の人が使った記録はまだない。Released only recently, so there is no record of other people using it yet.
  • 最初の主パスワードが変えられない点は、代償として残っている。That the first master password cannot be changed remains a cost.
筆者AUTHOR日常の使いやすさを基準に考えるJudges by everyday ease of useなぜ必要かを自分の言葉で言えるCan say why it is needed in their own words面倒な機能は足さないDoes not add fussy features