Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
HOSTSPICA RESEARCH
Engineering write-ups, R&D notes and guides for HostSpica Authenticator, Passkey and Identity. Every claim comes with a way to check it, and every page says what the product does not protect against.
LATEST · PAGE 4 OF 4
The exact format of HostSpica backup files, how your password becomes an encryption key (PBKDF2 with 600,000 rounds, then AES-256-GCM), what happens on a wrong password or a tampered file, and the limits you should plan around.
ReadEvery key HostSpica Authenticator, Passkey and Identity use, where it is stored, what it protects, what is not encrypted, and what Keystore protection does and does not stop.
ReadA plain explanation of how passkeys and WebAuthn work: the key pair, the challenge, why a fake site cannot use your passkey, the difference between synced and device-bound passkeys, and what you lose if you lose the phone.
ReadWhat happens inside HostSpica Passkey when a site asks to create or use a passkey on Android: the Credential Manager hand-offs, the authenticator data we build, Android key attestation, the bugs we hit, and what we do not support yet.
ReadHow an Android Autofill service sees a login form, how HostSpica Vault matches entries to sites, why the password is released only after a biometric check, and the limits of Autofill, including a lookalike-domain flaw we found and fixed before release.
ReadA plain threat model for HostSpica Authenticator, Passkey and Identity: who might attack, what each protection stops, what it does not, and which risks remain. Written by us, not independently audited.
ReadWhat a WebAuthn authenticator or passkey provider has to get right at registration and sign-in, item by item, with an honest status for HostSpica Passkey and a test plan you can run on any provider.
ReadHOW WE WRITE