PocketVault v2.5.1
This is the official Play App Signing build generated from the same Android App Bundle published on Google Play.
- Version name:
2.5.1 - Version code:
11 - Package name:
com.turisla.hellopocket - Source tag:
v2.5.1 - Source commit:
9f715b72bf5418e45c94e6a6e5983b0cdda32a23 - Distribution artifact: Play-generated signed Universal APK
- Play App Signing certificate SHA-256:
80:D6:DE:92:50:30:84:33:55:BE:73:7D:49:F8:F6:A4:16:85:5A:B6:CD:59:44:5A:AC:93:F2:7C:64:10:E7:F1 - Uploaded AAB SHA-256:
050244b7e15b1603f4ef10066e228ef758dab4c36335260f3c40a37b13735941 - Universal APK SHA-256:
964fe30460dbb598a86d3b15a779e4288309c36a69653d46f4aa4793072b14e9
Changes
Added
- A narrowly scoped, one-time migration for early V2 vaults and backups. The app authenticates core data, TOTP entries, and every referenced attachment before activation, creates an automatic
.hpbbackup of an installed vault, and then atomically switches to the upgraded directory. - Dedicated messages for a failed safety upgrade and for legacy V2 vaults that require the master password instead of biometric convenience unlock.
Changed
- Early V2 Keysets wrapped with the historical 100,000-iteration PBKDF2 parameter are accepted only for authenticated migration. The upgraded vault receives a fresh salt, a new vault identifier, associated-data-bound ciphertext, complete authenticated snapshot metadata, and a 600,000-iteration Keyset wrapper.
- Early V2 backup imports are normalized to the current format before they can replace an installed vault. V1 remains unsupported and is never migrated or overwritten.
Fixed
- A 2.5.0 compatibility regression that reported some valid early V2 vaults as damaged even though their files had not been overwritten.
- Password hints from early V2 configurations are readable again after an incorrect master-password attempt.
- Automatic-backup retention now runs only after a migrated or imported vault is activated successfully, so a failed switch cannot remove older backup history.
Verification
The attached APK was downloaded from Google Play Console, carries a verified Source Stamp, and is signed with the official Play App Signing certificate.
The Google Play and GitHub distributions use the same package name and signing identity.
Only the Play-generated Universal APK is attached to this release. The AAB is retained locally for traceability and is not distributed as an installable GitHub asset.