Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
HOSTSPICA RESEARCH
Engineering write-ups, R&D notes and guides for HostSpica Authenticator, Passkey and Identity. Every claim comes with a way to check it, and every page says what the product does not protect against.
LATEST
An Android app needs the INTERNET permission to reach the network. Here is how to confirm an app does not declare it, what that does and does not guarantee, and what we found in HostSpica Identity 1.0.0.
ReadA step-by-step walk through RFC 6238 time-based one-time passwords, the exact algorithm HostSpica Authenticator runs on your phone, the test vectors you can check it against, and where TOTP stops protecting you.
ReadWhat is inside the otpauth-migration QR code that Google Authenticator shows when you export accounts, how HostSpica Authenticator reads and writes it, and why exports are split into pages of at most 10 accounts.
ReadThe exact format of HostSpica backup files, how your password becomes an encryption key (PBKDF2 with 600,000 rounds, then AES-256-GCM), what happens on a wrong password or a tampered file, and the limits you should plan around.
ReadEvery key HostSpica Authenticator, Passkey and Identity use, where it is stored, what it protects, what is not encrypted, and what Keystore protection does and does not stop.
ReadA plain explanation of how passkeys and WebAuthn work: the key pair, the challenge, why a fake site cannot use your passkey, the difference between synced and device-bound passkeys, and what you lose if you lose the phone.
ReadWhat happens inside HostSpica Passkey when a site asks to create or use a passkey on Android: the Credential Manager hand-offs, the authenticator data we build, Android key attestation, the bugs we hit, and what we do not support yet.
ReadHow an Android Autofill service sees a login form, how HostSpica Vault matches entries to sites, why the password is released only after a biometric check, and the limits of Autofill, including a lookalike-domain flaw we found and fixed before release.
ReadA plain threat model for HostSpica Authenticator, Passkey and Identity: who might attack, what each protection stops, what it does not, and which risks remain. Written by us, not independently audited.
ReadHOW WE WRITE