Materials for journalists, bloggers and media.
Geslar is a Croatian password security ecosystem — a passphrase generator, password manager, and TOTP authenticator. Free, no registration, no cloud. Built by Daniel Legin, a CISO who needed a tool he could recommend to the users he protects every day.
Source: CERT.hr, 2025 annual report.
Download a real Geslar vault encrypted with the same cryptography used by the Geslar password manager. Try to decrypt it — inside is a message with reward instructions.
Did you crack it? Email info@geslar.app with the decrypted contents.
Zagreb, April 2026.
Daniel Legin, Head of System Integration and CISO, has released Geslar — a password security ecosystem that differs from everything on the market by requiring no user account, using no cloud servers, and collecting no user data.
"I protect IT systems and users professionally. Every day I see the same thing: people using the same password across twenty sites. I looked for a tool I could give them — free, in Croatian, no registration, secure to the standards I apply in enterprise systems. It doesn't exist. So I built it," says Legin.
Geslar consists of three tools: geslar.app — the first passphrase generator using Croatian dictionaries (5,700+ words, 8 dialects); Vault — a password manager browser extension with AES-256-GCM encryption, autofill, TOTP, biometrics, and import from 13 sources; and Authenticator — a standalone TOTP app for iOS and Android.
In the context of growing cyber threats — 1,513 cybersecurity incidents in Croatia in 2025, a 35.9% increase according to CERT.hr, of which 32% are phishing attacks directly targeting passwords — Geslar offers the opposite approach to the industry: instead of a centralized server as a target, there is no server.
"When LastPass was hacked in 2022, 30 million encrypted vaults ended up in the hands of attackers. That cannot happen to Geslar — because there is no server to hack. The same crypto model I apply to protect enterprise systems, I built into a tool anyone can use — for free," explains Legin.