🎯 Background & Problem
When working remotely (WFH) or conducting cross-environment debugging, developers frequently connect to enterprise VPNs (e.g., Cisco AnyConnect / OpenConnect) authenticated with “Static Passwords + Google Authenticator Dynamic 2FA OTPs”.
Everyday Friction:
- Repetitive Manual Reconnection: Dynamic OTPs change every 30 seconds; reconnecting requires manually checking a smartphone app multiple times a day.
- Mobile Debugging Roadblocks: Connecting an iOS device directly to a VPN often breaks local proxy inspection tools (Charles/Proxyman).
- Router LuCI Incompatibility with 2FA: Standard OpenWrt router interfaces only store static passwords and cannot reconnect to 2FA-protected corporate gateways.
Blinq (QuickOpen) was engineered under the slogan: “Blink and you’re in.” — Instant TOTP calculation, local AES-256 encrypted credential management, and one-click connection with OpenWrt split-tunneling.
🚀 Key Features & Architecture
- ⚡ Sub-Second Auto-Authentication: Generates RFC 6238 TOTP codes on the fly and streams credentials directly into OpenConnect processes without manual intervention.
- 🔒 AES-256-GCM On-Device Encryption: Secures user credentials and TOTP seeds locally with AES-256-GCM. Zero telemetry or external credential leakage.
- 🌐 Transparent Router Split-Tunneling: Integrates seamlessly with OpenWrt routers via
tun0virtual interfaces anddnsmasqrule engines, allowing all LAN devices (including test iPhones and TVs) to access internal enterprise resources transparently. - 💻 Cross-Platform & Zero Dependencies: Single binary written in pure Go, supporting macOS (Apple Silicon & Intel), Linux, and Windows.
🖼️ Interface Showcase

🏗️ System Topology
| |
🛠️ Engineering Highlights
- Hardened Local Credential Vault: Combines machine-derived keys and user passphrases to encrypt configuration blobs with AES-256-GCM.
- Smart DNS & Split Routing: Custom
vpnc-scripthooks anddnsmasqrules prevent DNS pollution while preserving Gigabit-speed public browsing.
📈 Shipping & Deliverables
- Cross-platform CLI binaries and automated build packaging
- OpenWrt daemon script and transparent split-tunneling setup
- Dedicated product landing page live at https://getblinq.app
🔗 Links
- Product Website: https://getblinq.app