Skip to content

Releases: DebanganMALI/Obscura

Obscura 0.1.1

Choose a tag to compare

@github-actions github-actions released this 25 Sep 18:48

A small release that fixes how Obscura identifies itself to your system.

What changed

  • The installers now name Debangan Mali as the publisher. Windows' Apps & Features previously showed "github".
  • The .deb and .rpm packages now carry the homepage, copyright and GPL-3.0-or-later licence.

Nothing about the vault format, the cryptography or your data has changed. Vaults created with 0.1.0 open exactly as before. A test in the repository opens a vault written by 0.1.0 with both its password and its recovery code.

Downloads

Platform File
Windows Obscura_0.1.1_x64-setup.exe
Windows, MSI Obscura_0.1.1_x64_en-US.msi
Debian, Ubuntu Obscura_0.1.1_amd64.deb
Fedora, RHEL Obscura-0.1.1-1.x86_64.rpm
Any Linux Obscura_0.1.1_amd64.AppImage

The installers are not code signed, so Windows shows a SmartScreen warning. Choose More info, then Run anyway.

Verify what you downloaded

sha256sum -c SHA256SUMS --ignore-missing
gh attestation verify Obscura_0.1.1_x64-setup.exe --repo DebanganMALI/Obscura
gh attestation verify Obscura_0.1.1_x64-setup.exe --repo DebanganMALI/Obscura --predicate-type https://cyclonedx.org/bom

The full feature list and known limitations are in the 0.1.0 release notes and SECURITY.md.

Obscura 0.1.0

Choose a tag to compare

@github-actions github-actions released this 24 Sep 19:27

The first public release of Obscura: an offline password manager for Windows and Linux. Your vault is one encrypted file on your own disk. No account, no telemetry, and no network code at all.

Downloads

Platform File
Windows Obscura_0.1.0_x64-setup.exe
Windows, MSI Obscura_0.1.0_x64_en-US.msi
Debian, Ubuntu Obscura_0.1.0_amd64.deb
Fedora, RHEL Obscura-0.1.0-1.x86_64.rpm
Any Linux Obscura_0.1.0_amd64.AppImage

Windows will warn you

The installers are not code signed, so SmartScreen shows "Windows protected your PC" the first time you run one. Choose More info, then Run anyway. The README explains why, and what to verify instead.

Verify what you downloaded

Get-FileHash .\Obscura_0.1.0_x64-setup.exe -Algorithm SHA256
sha256sum -c SHA256SUMS --ignore-missing
gh attestation verify Obscura_0.1.0_x64-setup.exe --repo DebanganMALI/Obscura
gh attestation verify Obscura_0.1.0_x64-setup.exe --repo DebanganMALI/Obscura --predicate-type https://cyclonedx.org/bom

The checksum proves the file arrived intact. The first attestation proves which commit and workflow run built it. The second proves which bill of materials, Obscura_v0.1.0.cdx.json, describes it.

What is in it

  • Argon2id calibrated to your machine, XChaCha20-Poly1305 with a separate key for every entry, and HKDF-SHA512
  • Hybrid X25519 + ML-KEM-768 wrapping for printed recovery codes
  • Four ways to unlock: master password, Windows Hello, a phone or tablet passkey, or a recovery code
  • Rollback detection, so a restored older copy of your vault is noticed rather than accepted
  • One time codes, a password generator, CSV import from other managers, and encrypted export
  • Auto-lock on idle, and clipboard copies that clear themselves
  • A master password minimum of 15 characters, following NIST SP 800-63B-4

The obscura command line tool is not in the installers yet. Build it from source with cargo install --path crates/obscura-cli --locked.

Known limitations

  • Obscura has not been independently audited, and the interface has no automated tests
  • Secrets are wiped from memory when dropped, but their pages are not locked against swap
  • New master passwords are not yet checked against a list of breached passwords

SECURITY.md has the full list and how to report a vulnerability.

Requirements

Windows 10 version 1809 or newer, x64. Any Linux desktop with WebKitGTK 4.1.

Licensed GPL-3.0-or-later.