Release notes · Archive
x2y Authenticator v1.0.5 release notes
v1.0.5The Security & Usability Release: Security Center, Backup v2, auto-lock, clipboard protection, Companion sessions, vault redesign and diagnostics.
Free — no account, no cloud sync, no telemetry. These notes are kept exactly as published for the v1.0.5 build.
At a glance
- Versionv1.0.5
- ReleaseSecurity & Usability
- Backup formatBackup v2
- PIN storageSalted SHA-256
- Brand registry90+ services
- Telemetry0 bytes
Superseded by v1.2.0. Every earlier release note remains published and indexable.
Release overview
Every x2y Authenticator release
You are reading the archived v1.0.5 notes. Select another version to read its notes.
| v1.2.0 | The Trust Update. Reliability, security fixes, backup protection, Master QR restore, screenshot protection, and local reminders. |
|---|---|
| v1.1.0 | The Powerhouse Update. HOTP, Steam Guard, migration tools, trash, favorites, insights, biometric improvements, and Companion history. |
| v1.0.5 YOU ARE HERE | Security & Usability Release. Security Center, Backup v2, auto-lock, clipboard protection, Companion sessions, vault redesign, and diagnostics. |
| v1.0.0 | Initial Release. Offline TOTP vault, Stealth Mode, encrypted backups, LAN Companion, folders, and NTP synchronization. |
v1.0.5
Security & Usability Release
Release focus: align the daily user experience with the application's security model.
Security Center
A centralized security audit was added covering offline vault storage, biometric protection, cloud-sync status, account requirement, backup encryption, backup verification, screenshot protection, clipboard clearing, auto-lock, Stealth Mode configuration and telemetry status. Each condition includes a status, an explanation and a relevant settings shortcut.
Backup v2
Backup envelopes now include a creation timestamp, account count and a SHA-256 integrity checksum. Restore previews include account count, folder count, creation date and format version. Test restore without writing data, merge restore, replace restore, legacy v1.0.0 restore support and timestamped backup filenames such as x2y_vault_YYYYMMDD.x2y were added.
PIN storage
PINs are stored using salted SHA-256 hashes. Existing legacy unsalted hashes remain compatible and are upgraded after a successful unlock.
Auto-lock
Configurable automatic locking was added: immediately, 30 seconds, 1 minute, 5 minutes, 15 minutes or never, plus lock when leaving the foreground and a manual “Lock Now” action.
Clipboard protection
Copied authentication codes can automatically clear after 15 seconds, 30 seconds, 60 seconds or never. A generation guard prevents an older clipboard-clear operation from removing a newer copied value.
Screenshot protection
Screenshot protection became an explicit setting. FLAG_SECURE is enabled by default, applied from the first frame and configurable through Settings.
Biometric settings
Biometric authentication is controlled through an explicit, revocable setting, and the biometric unlock option is hidden when device biometrics are unavailable.
WiFi Companion
Six-character pairing codes, session tokens, per-device revocation, a disconnect-all control, a configurable session timeout, connection history, device identification and client IP reporting were added. Supported session timeouts are 5, 15, 30 and 60 minutes, and locking the vault immediately stops the LAN Companion server.
Privacy and diagnostics
| Core vault | Blocked |
|---|---|
| Analytics | None |
| Crash reporting | None |
| Cloud sync | None |
| Telemetry | None |
| Companion | LAN-only |
| NTP | Optional |
Android permission explanations and exportable diagnostic reports were also added. Diagnostics are secret-free, key-free and account-name-free.
NTP status
Time synchronization now reports the synchronization result, the measured clock offset and the offset in milliseconds.
Vault redesign
A complete Material 3 vault interface was introduced. Search covers issuer, account and folder; sorting covers A–Z, recently used, recently added and expiring soon; organization adds folder filters, folder suggestions and brand-based organization.
- Account cards with brand avatars, grouped authentication codes, circular countdown timers, one-tap copy and clipboard-clear confirmation
- Long-press actions: edit, change folder, copy code, reveal secret, export and delete
- Account editing for issuer, account, secret, folder, color and advanced parameters
- Secret masking, secret reveal warnings, explicit deletion confirmation and single-account otpauth:// export
- Empty-state onboarding, recently-used tracking and duplicate detection
TOTP and QR import
Support was added for RFC 6238 configurations: SHA-1, SHA-256 and SHA-512, 6-digit and 8-digit codes and 10–120 second periods. Strict otpauth:// parsing, friendly parser errors, Base32 validation and normalization, URI export, 3+3 and 4+4 code formatting, QR import confirmation and invalid-code handling were added. Scanner improvements cover torch control, camera switching, single-shot detection and a framing overlay.
Brand recognition
A registry containing 90+ recognized services was added. Brand recognition can provide an application icon, brand color, suggested folder and canonical service name, while unknown issuers receive a safe fallback presentation.
PC Companion dashboard
The PC dashboard was redesigned with the x2y visual identity, inline SVG branding, live search, circular countdowns, session-expiry handling, click-to-copy codes and cache-prevention headers.
Stealth Mode
A guided three-step setup was added: real PIN, stealth PIN and decoy preparation. It includes REAL VAULT and DECOY VAULT indicators, optional decoy-account seeding, sample accounts, PIN management and real-vault biometric resolution.
Settings and documentation
Settings are organized into Security Center, Appearance, Security, Recovery, Companion, Guide and About. An in-app About page, in-app changelog, How-It-Works cards and NTP status information were added.
Engineering
Major internal improvements include database schema v2, non-destructive database migration and rewrites of the backup, OTP, brand, security and biometric services, plus new clipboard, screen-security, companion, companion web and diagnostics services. Dedicated test suites were added for OTP, backups, brands and account models, alongside a native FLAG_SECURE method channel, cross-platform theme portability, an audited icon system and README/CHANGELOG documentation. No new third-party dependencies were introduced.
Compatibility
What v1.0.5 restores
Backup format support is cumulative. The table below is what the current build restores; older release notes describe how each format was introduced.
| Backup v2 | Introduced in v1.0.5 with timestamp, account count and SHA-256 integrity checksum |
|---|---|
| Legacy v1.0.0 backup | Restore supported |
| Legacy iv:ciphertext backup | Restore supported |
| PIN hashes | Legacy unsalted hashes upgraded after a successful unlock |
| Segmented Master QR | Not available in v1.0.5 — added in v1.2.0 |
Downloads
Install the current build (v1.2.0)
v1.0.5 has been superseded. Keep these notes for reference, and install the latest signed APK for current fixes.
Security notice