Repository navigation
Releases: DebanganMALI/Obscura
Release list
Obscura 0.1.1
A small release that fixes how Obscura identifies itself to your system.
What changed
- The installers now name Debangan Mali as the publisher. Windows' Apps & Features previously showed "github".
- The
.deband.rpmpackages now carry the homepage, copyright and GPL-3.0-or-later licence.
Nothing about the vault format, the cryptography or your data has changed. Vaults created with 0.1.0 open exactly as before. A test in the repository opens a vault written by 0.1.0 with both its password and its recovery code.
Downloads
| Platform | File |
|---|---|
| Windows | Obscura_0.1.1_x64-setup.exe |
| Windows, MSI | Obscura_0.1.1_x64_en-US.msi |
| Debian, Ubuntu | Obscura_0.1.1_amd64.deb |
| Fedora, RHEL | Obscura-0.1.1-1.x86_64.rpm |
| Any Linux | Obscura_0.1.1_amd64.AppImage |
The installers are not code signed, so Windows shows a SmartScreen warning. Choose More info, then Run anyway.
Verify what you downloaded
sha256sum -c SHA256SUMS --ignore-missing
gh attestation verify Obscura_0.1.1_x64-setup.exe --repo DebanganMALI/Obscura
gh attestation verify Obscura_0.1.1_x64-setup.exe --repo DebanganMALI/Obscura --predicate-type https://cyclonedx.org/bomThe full feature list and known limitations are in the 0.1.0 release notes and SECURITY.md.
Obscura 0.1.0
The first public release of Obscura: an offline password manager for Windows and Linux. Your vault is one encrypted file on your own disk. No account, no telemetry, and no network code at all.
Downloads
| Platform | File |
|---|---|
| Windows | Obscura_0.1.0_x64-setup.exe |
| Windows, MSI | Obscura_0.1.0_x64_en-US.msi |
| Debian, Ubuntu | Obscura_0.1.0_amd64.deb |
| Fedora, RHEL | Obscura-0.1.0-1.x86_64.rpm |
| Any Linux | Obscura_0.1.0_amd64.AppImage |
Windows will warn you
The installers are not code signed, so SmartScreen shows "Windows protected your PC" the first time you run one. Choose More info, then Run anyway. The README explains why, and what to verify instead.
Verify what you downloaded
Get-FileHash .\Obscura_0.1.0_x64-setup.exe -Algorithm SHA256sha256sum -c SHA256SUMS --ignore-missing
gh attestation verify Obscura_0.1.0_x64-setup.exe --repo DebanganMALI/Obscura
gh attestation verify Obscura_0.1.0_x64-setup.exe --repo DebanganMALI/Obscura --predicate-type https://cyclonedx.org/bomThe checksum proves the file arrived intact. The first attestation proves which commit and workflow run built it. The second proves which bill of materials, Obscura_v0.1.0.cdx.json, describes it.
What is in it
- Argon2id calibrated to your machine, XChaCha20-Poly1305 with a separate key for every entry, and HKDF-SHA512
- Hybrid X25519 + ML-KEM-768 wrapping for printed recovery codes
- Four ways to unlock: master password, Windows Hello, a phone or tablet passkey, or a recovery code
- Rollback detection, so a restored older copy of your vault is noticed rather than accepted
- One time codes, a password generator, CSV import from other managers, and encrypted export
- Auto-lock on idle, and clipboard copies that clear themselves
- A master password minimum of 15 characters, following NIST SP 800-63B-4
The obscura command line tool is not in the installers yet. Build it from source with cargo install --path crates/obscura-cli --locked.
Known limitations
- Obscura has not been independently audited, and the interface has no automated tests
- Secrets are wiped from memory when dropped, but their pages are not locked against swap
- New master passwords are not yet checked against a list of breached passwords
SECURITY.md has the full list and how to report a vulnerability.
Requirements
Windows 10 version 1809 or newer, x64. Any Linux desktop with WebKitGTK 4.1.
Licensed GPL-3.0-or-later.