Join 5,000+ subscribers getting weekly tips on web development, mobile apps, and AI solutions.
A passkey provider for Android with hardware-backed keys.
Guide
An Android app needs the INTERNET permission to reach the network. Here is how to confirm an app does not declare it, what that does and does not guarantee, and what we found in HostSpica Identity 1.0.0.
Engineering write-up
Every key HostSpica Authenticator, Passkey and Identity use, where it is stored, what it protects, what is not encrypted, and what Keystore protection does and does not stop.
Guide
A plain explanation of how passkeys and WebAuthn work: the key pair, the challenge, why a fake site cannot use your passkey, the difference between synced and device-bound passkeys, and what you lose if you lose the phone.
Engineering write-up
What happens inside HostSpica Passkey when a site asks to create or use a passkey on Android: the Credential Manager hand-offs, the authenticator data we build, Android key attestation, the bugs we hit, and what we do not support yet.
Technical report
A plain threat model for HostSpica Authenticator, Passkey and Identity: who might attack, what each protection stops, what it does not, and which risks remain. Written by us, not independently audited.