Threat model: what a local-only authenticator, passkey and vault app protects, and what it cannot
SHORT ANSWER
What threats do HostSpica apps defend against?
They defend against data leaving the phone over the network, someone finding your locked phone, other apps reading your data, lookalike-site phishing of passkeys, and a stolen backup file with a strong password. They do not defend against a rooted or compromised phone, someone who knows your phone PIN and holds the phone, or you losing both the phone and the backup.
Key takeaways
- This model is our own analysis. It has not been reviewed by an independent party.
- The strongest guarantees are structural: no internet permission, hardware-held keys, and sign-in checks done by the operating system.
- The weakest points are the phone itself being compromised, and anyone who knows your screen-lock PIN.
- Recovery is on you: we cannot recover a lost phone, backup password or passkey.
Scope and assumptions
This covers HostSpica Authenticator, HostSpica Passkey and HostSpica Identity for Android, as built in October 2026. We assume Android is genuine, up to date and not rooted, and that the Google Play build is unmodified. We have not had an independent audit, so each row below is our reasoning, not a third party's finding.
What we protect
- 2FA secrets and Vault passwords and notes (confidentiality).
- Passkey private keys (confidentiality and non-exportability).
- The act of signing in: that only you can approve a passkey sign-in or fill a password.
- Backup files (confidentiality, tamper detection).
Attackers and outcomes
| Attacker | What stops them | What does not |
|---|---|---|
| Network attacker or data collector | The apps declare no internet permission, so they cannot send or receive anything. No analytics or ad code exists. See [how to check](/research/check-android-app-has-no-internet-permission). | Anything you choose to share through other apps, such as a backup you put in a synced folder. |
| Someone finds your locked phone | Phone lock, plus Keystore keys held in secure hardware, plus the app asking for biometric or device credential on open. | Nothing relevant remains once the phone is locked; a weak phone PIN weakens it. |
| Someone holds your unlocked phone | The app re-locks after the time you set (immediately by default, up to 15 minutes). Passkey signing needs your biometric every time and does not accept a PIN. | Within the unlock window they can open the app. If they know your phone PIN, they can unlock the app, and fill Vault passwords, because those prompts accept the PIN. |
| Another app on your phone (not rooted) | Android's app sandbox: other apps cannot read our private data or use our Keystore keys. Screenshots and recordings are blocked. Copied passwords are marked sensitive and cleared after 30 seconds. | Accessibility services or keyboards you have granted can see what is on screen or typed. Android decides what other apps may read from the clipboard while a copied value is there. |
| Malware with root, or a compromised Android | Nothing reliable. Keys cannot be copied out of hardware, but code running as the app can ask Keystore to use them, and can read what the app displays. | All of it. We show a warning on rooted phones but do not block. |
| Phishing site | Passkeys: the browser signs for the real site only. Vault Autofill: offered only on the exact registered domain. | TOTP codes can be phished in real time. Copying a password by hand and pasting it into a fake page defeats everything. |
| Someone steals a backup file | AES-256-GCM with a key from PBKDF2 (600,000 rounds). See [backups](/research/how-hostspica-backups-are-encrypted-formats-and-limits). | A weak or reused password can be guessed offline. |
| Nearby attacker on Bluetooth | Our experimental cross-device sign-in is designed to be single-use and to expire after 60 seconds. | It is our own protocol, not a FIDO standard transport, and it has not been independently reviewed. |
| A malicious HostSpica update | Google Play signing and our release key. | You trust us. A malicious update could add the internet permission or change the code. Check permissions after updates. |
Risks that remain
What we plan
- Publish file formats and test vectors so others can check our crypto.
- Seek an independent review and say so on this page when it happens.
- Re-run this model with every release that changes a protection, and record changes in the security changelog.
Frequently asked questions
Is this an audit?
No. It is our own threat model. An audit means an independent party tested the apps; we have not had one.
What is the single most important thing I can do?
Use a strong screen-lock PIN or password that nobody else knows, make a backup with a long passphrase, and store the passphrase separately from the file.
Why do you not block rooted phones?
Detection can be wrong, and blocking hurts legitimate users. We warn instead, and say plainly that protections are weaker there.
References
Review status
Last technical self-review by the author on 3 October 2026. No independent reviewer yet. If you spot an error, write to [email protected] and we will correct it and note the change.
Rohan builds HostSpica's Android apps — Authenticator, Passkey and Identity — and writes up how they work, including the mistakes along the way.
ABOUT THE PRODUCTS
RELATED