<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>HostSpica Research</title>
    <link>https://hostspica.com/research</link>
    <description>Engineering write-ups, R&amp;D notes and guides on how HostSpica apps are built and secured.</description>
    <language>en</language>
    <atom:link href="https://hostspica.com/research/feed.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>How to check that an Android app has no internet permission (and how we check ours)</title>
      <link>https://hostspica.com/research/check-android-app-has-no-internet-permission</link>
      <guid isPermaLink="true">https://hostspica.com/research/check-android-app-has-no-internet-permission</guid>
      <description>An Android app needs the INTERNET permission to reach the network. Here is how to confirm an app does not declare it, what that does and does not guarantee, and what we found in HostSpica Identity 1.0.0.</description>
      <pubDate>Sat, 03 Oct 2026 03:30:00 GMT</pubDate>
      <author>contact@hostspica.com (Rohan Kumar)</author>
    </item>
    <item>
      <title>How TOTP works, and how HostSpica Authenticator implements it</title>
      <link>https://hostspica.com/research/how-totp-works-and-how-hostspica-authenticator-implements-it</link>
      <guid isPermaLink="true">https://hostspica.com/research/how-totp-works-and-how-hostspica-authenticator-implements-it</guid>
      <description>A step-by-step walk through RFC 6238 time-based one-time passwords, the exact algorithm HostSpica Authenticator runs on your phone, the test vectors you can check it against, and where TOTP stops protecting you.</description>
      <pubDate>Sat, 03 Oct 2026 03:30:00 GMT</pubDate>
      <author>contact@hostspica.com (Rohan Kumar)</author>
    </item>
    <item>
      <title>Inside Google Authenticator's export QR code, and why we cap a page at 10 accounts</title>
      <link>https://hostspica.com/research/inside-google-authenticator-export-qr-otpauth-migration</link>
      <guid isPermaLink="true">https://hostspica.com/research/inside-google-authenticator-export-qr-otpauth-migration</guid>
      <description>What is inside the otpauth-migration QR code that Google Authenticator shows when you export accounts, how HostSpica Authenticator reads and writes it, and why exports are split into pages of at most 10 accounts.</description>
      <pubDate>Sat, 03 Oct 2026 03:30:00 GMT</pubDate>
      <author>contact@hostspica.com (Rohan Kumar)</author>
    </item>
    <item>
      <title>How HostSpica backups are encrypted: file formats, key derivation and limits</title>
      <link>https://hostspica.com/research/how-hostspica-backups-are-encrypted-formats-and-limits</link>
      <guid isPermaLink="true">https://hostspica.com/research/how-hostspica-backups-are-encrypted-formats-and-limits</guid>
      <description>The exact format of HostSpica backup files, how your password becomes an encryption key (PBKDF2 with 600,000 rounds, then AES-256-GCM), what happens on a wrong password or a tampered file, and the limits you should plan around.</description>
      <pubDate>Sat, 03 Oct 2026 03:30:00 GMT</pubDate>
      <author>contact@hostspica.com (Rohan Kumar)</author>
    </item>
    <item>
      <title>Where every HostSpica secret lives: the Android Keystore key hierarchy</title>
      <link>https://hostspica.com/research/where-every-hostspica-secret-lives-keystore-key-hierarchy</link>
      <guid isPermaLink="true">https://hostspica.com/research/where-every-hostspica-secret-lives-keystore-key-hierarchy</guid>
      <description>Every key HostSpica Authenticator, Passkey and Identity use, where it is stored, what it protects, what is not encrypted, and what Keystore protection does and does not stop.</description>
      <pubDate>Sat, 03 Oct 2026 03:30:00 GMT</pubDate>
      <author>contact@hostspica.com (Rohan Kumar)</author>
    </item>
    <item>
      <title>Passkeys from first principles: what happens when you sign in without a password</title>
      <link>https://hostspica.com/research/passkeys-from-first-principles</link>
      <guid isPermaLink="true">https://hostspica.com/research/passkeys-from-first-principles</guid>
      <description>A plain explanation of how passkeys and WebAuthn work: the key pair, the challenge, why a fake site cannot use your passkey, the difference between synced and device-bound passkeys, and what you lose if you lose the phone.</description>
      <pubDate>Sat, 03 Oct 2026 03:30:00 GMT</pubDate>
      <author>contact@hostspica.com (Rohan Kumar)</author>
    </item>
    <item>
      <title>How an Android passkey provider works: Credential Manager, step by step</title>
      <link>https://hostspica.com/research/how-an-android-passkey-provider-works-credential-manager</link>
      <guid isPermaLink="true">https://hostspica.com/research/how-an-android-passkey-provider-works-credential-manager</guid>
      <description>What happens inside HostSpica Passkey when a site asks to create or use a passkey on Android: the Credential Manager hand-offs, the authenticator data we build, Android key attestation, the bugs we hit, and what we do not support yet.</description>
      <pubDate>Sat, 03 Oct 2026 03:30:00 GMT</pubDate>
      <author>contact@hostspica.com (Rohan Kumar)</author>
    </item>
    <item>
      <title>How Android Autofill works, and how HostSpica Vault gates every fill</title>
      <link>https://hostspica.com/research/how-android-autofill-and-hostspica-vault-protect-each-fill</link>
      <guid isPermaLink="true">https://hostspica.com/research/how-android-autofill-and-hostspica-vault-protect-each-fill</guid>
      <description>How an Android Autofill service sees a login form, how HostSpica Vault matches entries to sites, why the password is released only after a biometric check, and the limits of Autofill, including a lookalike-domain flaw we found and fixed before release.</description>
      <pubDate>Sat, 03 Oct 2026 03:30:00 GMT</pubDate>
      <author>contact@hostspica.com (Rohan Kumar)</author>
    </item>
    <item>
      <title>Threat model: what a local-only authenticator, passkey and vault app protects, and what it cannot</title>
      <link>https://hostspica.com/research/threat-model-local-only-authenticator-passkeys-and-vault</link>
      <guid isPermaLink="true">https://hostspica.com/research/threat-model-local-only-authenticator-passkeys-and-vault</guid>
      <description>A plain threat model for HostSpica Authenticator, Passkey and Identity: who might attack, what each protection stops, what it does not, and which risks remain. Written by us, not independently audited.</description>
      <pubDate>Sat, 03 Oct 2026 03:30:00 GMT</pubDate>
      <author>contact@hostspica.com (Rohan Kumar)</author>
    </item>
  </channel>
</rss>