OneMoreSecret
com.onemoresecret
Zapstore _@zapstore.dev Republished from GitHub / F-Droid by the Zapstore main account.
OneMoreSecret is a decentralized secrets manager that leverages your smartphone's hardware keystore and biometric authentication to protect your passwords. Instead of relying on a cloud database, your sensitive data (e.g. passwords, TOTP tokens, files, and Bitcoin private keys are encrypted into QR codes or text payloads that can be safely embedded anywhere — even on a public wiki or plain text file. When you need to use a secret, you simply scan the code or tap the link with your phone, authenticate with your fingerprint to decrypt it locally, and the app acts as a virtual Bluetooth keyboard to instantly "auto-type" the password into your computer. This creates a seamless, air-gapped bridge that keeps your private keys entirely offline, protecting your credentials from keyloggers and cloud breaches while making cross-device authentication completely effortless. See https://github.com/stud0709/OneMoreSecret#readme for detailed introduction and tutorial.
First release: Nov 4, 2025, 4 total releases.
Most recent release: Sep 17, 2026.
Appears in 4 app stacks.
10 sats / 1 zaps received in the past year.
Sats Received
Underlying data available via MCP: app_zaps, app_releases.
Zap Count
Underlying data available via MCP: app_zaps, app_releases.
Releases
- Sep 17, 2026 1.0# Release Notes ## 🚀 Nostr Remote Transport & Pairing Replaced the legacy local Wi-Fi TCP socket listener (`WiFiComm`) with a modern, firewall-resilient **Nostr Relay Transport** layer (reusing Application ID `10` and Kind `25000` ephemeral events) for remote communication between desktop/web clients and OneMoreSecret: * **End-to-End Authenticated Encryption (AES-256-GCM)**: All Nostr message payloads are authenticated and encrypted using 256-bit Pre-Shared Keys (PSK) with AES-256-GCM (`NostrPskCrypto`). * **Master RSA-Encrypted Pairing QR Codes**: Added support for encrypting the pairing payload inside a Master RSA-AES generic envelope (`APPLICATION_RSA_AES_GENERIC`), ensuring pairing credentials (topic, PSK, relays) can only be read by authorized OneMoreSecret devices. * **Persistent & Durable Pairing Sessions**: * Pairing sessions persist across app backgrounding, screen locks, and device sleeps, reconnecting automatically upon resuming the app (`NostrConnectionManager`). * Enforced a **24-hour expiration TTL** on pairing sessions to prevent stale connections from remaining open indefinitely.
More…
* Instant session purge on entering the Panic PIN or tapping the dedicated Clear button. * **Camera Overlay & UI Integration**: * Added a non-intrusive **Nostr Pairing Status Card** at the bottom of `QRScreen` displaying the active topic prefix and a quick **Clear** button. * Cleaned up redundant menu actions from the top-level QR scanner dropdown. * Simplified pairing acceptance flow to automatically return to the previous screen immediately upon confirmation (`MsgPluginNostrPairing`). --- ## 🛡️ Protocol Hardening & Reliability * **Replay Protection & Event Deduplication**: * Implemented a persistent LRU event cache (`processedEventIds`) and timestamp floor (`minCreatedAt`) to eliminate duplicate event processing across reconnections and app restarts (`NostrClient`). * **Message TTL & Queue Management**: * Enforced a **60-second TTL** on incoming and queued Nostr messages to reject expired or delayed relay events. * Incoming messages received while navigating outside `QRScreen` or inside `MessageScreen` are safely queued and dispatched smoothly upon resume. * **Request Correlation & Echo Suppression**: * Added `reply_to` tag correlation on response events to associate answers directly with client request IDs. * Added self-event filtering to ignore relayed echo events and prevent event feedback loops. * **Protocol Cleanup**: Enforced canonical `disconnect` event handling and retired legacy `bye` synonyms and unused Wi-Fi socket listeners. --- ## 🐛 Bug Fixes & Stability (PR [#35](https://github.com/stud0709/OneMoreSecret/pull/35)) * **Crash Fix: *Settings > Private Keys***: * Kept reflectively-instantiated `KeyboardLayout` constructors (`USLayout`, `GermanLayout`, `SwissLayout`) from being stripped by R8 full mode in release builds, preventing immediate app termination and ensuring persistent layout preferences across updates. * **Crash Fix: ML Kit Camera Initialization**: * Retained default constructors for `ComponentRegistrar` implementations in ProGuard rules, fixing `NullPointerException` crashes in the `standard` release build when scanning barcodes. * **Crash Report Deobfuscation**: * Preserved line numbers (`SourceFile`, `LineNumberTable`) in release builds so crash reports can be accurately deobfuscated via `mapping.txt`. * **Bluetooth HID Key Release**: * Ensured a clean `KBD_NONE` report is sent upon typing completion or cancellation in `OutputViewModel` to prevent stuck modifier keys. * **Stale Prompt Dismissal**: * Fixed an issue where stale `oms4web` unlock screens remained displayed on app resume. * **UI Layout Collapse**: * Fixed layout constraints in `KeyRequestPairing` and `Oms4webUnlock` to prevent bottom-anchored content collapse. - Feb 20, 2026 0.40-beta0.40-beta is a minor bug fix to v. 0.39-beta (an issue when generating a new private key). Release notes have been copied from 0.39-beta. # This is a 1st *beta* release johnwu0011 came accross on Discord at around Christmas and was like "why don't you write a password manager?". And somehow, here we are with [oms4web](https://stud0709.github.io/oms4web/). *oms4web* is written in javascript (I did not want any backend - after all, it's you data!), so I immediately discovered the ugly world of cross-compatibility issues between Android, Java and Javascript cryptography API. This resulted in multiple changes under the hood, but here's what you need to know from the user perspective: - The key storage strategy has changed. The app creates now its own internal key and uses it to protect yours. This allows to be more flexible with encryption settings, which is crucial for javascript compatibility. - Because of that, you'll have to import your private key once again. It nothing helps, uninstall the app and install it again. It still nothing helps, let me know :) - File decryption request generated by omsCompanion has changed, you'll have to update the same to the [latest version](https://github.com/stud0709/oms_companion/releases/tag/v0.7-beta). - and of course, you neew this version to work with *oms4web*.
More…
As always, let me know if you have issues. Among other things, I finally started migration to Kotlin, so the codebase has changed substantially. Cheers, stud0709 - Feb 12, 2026 0.39-beta# This is a 1st *beta* release johnwu0011 came accross on Discord at around Christmas and was like "why don't you write a password manager?". And somehow, here we are with [oms4web](https://stud0709.github.io/oms4web/). *oms4web* is written in javascript (I did not want any backend - after all, it's you data!), so I immediately discovered the ugly world of cross-compatibility issues between Android, Java and Javascript cryptography API. This resulted in multiple changes under the hood, but here's what you need to know from the user perspective: - The key storage strategy has changed. The app creates now its own internal key and uses it to protect yours. This allows to be more flexible with encryption settings, which is crucial for javascript compatibility. - Because of that, you'll have to import your private key once again. It nothing helps, uninstall the app and install it again. It still nothing helps, let me know :) - File decryption request generated by omsCompanion has changed, you'll have to update the same to the [latest version](https://github.com/stud0709/oms_companion/releases/tag/v0.7-beta). - and of course, you neew this version to work with *oms4web*. As always, let me know if you have issues. Among other things, I finally started migration to Kotlin, so the codebase has changed substantially.
More…
Cheers, stud0709 - minor bug fixes