How HostSpica backups are encrypted: file formats, key derivation and limits
SHORT ANSWER
How are HostSpica backup files encrypted?
Your backup password is stretched into a 256-bit key with PBKDF2-HMAC-SHA256 using 600,000 rounds and a random 16-byte salt. The data is then encrypted with AES-256-GCM, which also detects tampering. HostSpica never sees the password, so a lost password means a lost backup.
Key takeaways
- A backup is only as strong as its password. The file is designed so that guessing the password is slow, not impossible.
- A wrong password or a changed file fails closed: you get an error, never partly restored data.
- Passkeys are never part of a backup. Their keys cannot leave the phone's secure hardware.
- We cannot recover a lost backup password, because we never have it or the key.
What a backup contains
- Authenticator backup: your 2FA accounts, including their secrets, labels, issuers, algorithm, digits, period and counter.
- Vault backup: your Vault entries, including passwords and notes.
- HostSpica Identity backup: both of the above in one file, made from Settings, then Back up everything.
- Never included: passkeys. Their private keys live in the phone's Keystore or StrongBox and cannot be exported, so a file that claimed to contain them would be a security hole.
From password to key
Encryption keys must be long and random, and a password is neither. A key derivation function bridges that gap by making each password guess expensive. We use PBKDF2 with HMAC-SHA-256, 600,000 iterations, a random 16-byte salt for every export, and a 256-bit output. 600,000 rounds is the current OWASP minimum for this combination. We chose PBKDF2 over Argon2id because Android has PBKDF2 built in, and Argon2 would need a native library; Argon2id is the stronger design and could replace it in a later format version.
The derived key then encrypts the data with AES-256-GCM using a fresh random nonce. GCM is authenticated encryption: decrypting checks a 128-bit tag, so any change to the ciphertext, salt or nonce makes the whole operation fail instead of returning altered data.
The file formats
| Backup | Layout |
|---|---|
| Authenticator, `.hspb` | 4 bytes `HSPB`, 1 byte version (1), 4 bytes iteration count, 1 byte salt length, salt, 1 byte nonce length, nonce, then the ciphertext with its GCM tag. Inside, one account per line with 9 fields separated by `|`; label and issuer are base64, the secret is Base32. |
| Vault, `.hsvb` | A JSON object: `hsvb` (version 1), `iter`, and base64 `salt`, `nonce` and `ct`. The decrypted text is JSON with the entries. |
| Identity, `.hsib` | A JSON container: `hsib` (version 1), plus the Authenticator part and the Vault part, each base64 and each already encrypted. Both use your password but with their own random salt and nonce. |
The files are therefore recognisable as HostSpica backups, and their size reveals roughly how many entries they hold. They do not reveal what is in them.
Wrong password, damaged file
Restore derives a key from the password you type and tries to decrypt. If the password is wrong, or any byte of the file was changed, GCM's check fails and the restore stops with an error before anything is imported. Our tests cover a correct round trip, a wrong password, a tampered ciphertext, and the fact that every export uses a new salt and nonce.
When a restore succeeds, entries that are already on the phone are skipped, so restoring the same file twice does not create duplicates.
Limits you should plan around
Frequently asked questions
Why 600,000 iterations?
It matches the current OWASP guidance for PBKDF2-HMAC-SHA256. More rounds slow an attacker and also slow you on a phone, so the number is a balance. The count is stored in the file, so a future version can raise it.
Can HostSpica open my backup if I forget the password?
No. We never receive the file or the password, and the key exists only while you type the password.
Are backups the same as Android's own cloud backup?
No. Android's automatic app backup is turned off for HostSpica Identity. Backups only exist when you make one.
References
Review status
Last technical self-review by the author on 3 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED