Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
Local-only TOTP and HOTP two-factor codes for Android.
Guide
An Android app needs the INTERNET permission to reach the network. Here is how to confirm an app does not declare it, what that does and does not guarantee, and what we found in HostSpica Identity 1.0.0.
Engineering write-up
A step-by-step walk through RFC 6238 time-based one-time passwords, the exact algorithm HostSpica Authenticator runs on your phone, the test vectors you can check it against, and where TOTP stops protecting you.
R&D note
What is inside the otpauth-migration QR code that Google Authenticator shows when you export accounts, how HostSpica Authenticator reads and writes it, and why exports are split into pages of at most 10 accounts.
Engineering write-up
The exact format of HostSpica backup files, how your password becomes an encryption key (PBKDF2 with 600,000 rounds, then AES-256-GCM), what happens on a wrong password or a tampered file, and the limits you should plan around.
Engineering write-up
Every key HostSpica Authenticator, Passkey and Identity use, where it is stored, what it protects, what is not encrypted, and what Keystore protection does and does not stop.
Technical report
A plain threat model for HostSpica Authenticator, Passkey and Identity: who might attack, what each protection stops, what it does not, and which risks remain. Written by us, not independently audited.