Skip to content
hughk edited this page Oct 3, 2026 · 2 revisions

Welcome to the Pin Vault Wiki

Pin Vault is an open-source, privacy-first Android application engineered to safeguard debit card, credit card, and banking PINs using visual steganography. Instead of displaying sensitive codes in plaintext, Pin Vault hides them inside randomized grids of colored number tiles that only you know how to decipher.


📚 Wiki Navigation


🛡️ Core Philosophy: Zero Cleartext & Shoulder-Surf Shielding

Conventional password managers and digital wallets display PIN numbers directly on screen upon authentication. In public environments—such as retail checkout counters, ATMs, transit stations, and crowded offices—this exposes your secret codes to:

  1. Shoulder Surfing: Observers standing nearby looking over your shoulder.
  2. CCTV & Security Cameras: High-resolution surveillance cameras positioned overhead.
  3. Screen Grabbers / Spyware: Malicious background processes attempting display scraping.

Pin Vault eliminates these attack vectors:

  • Visual Camouflage: Even when the vault is unlocked, the PIN is never spelled out as a contiguous string. Observers see a colorful grid filled with randomized numbers and decoy lines.
  • Android Display Shielding: FLAG_SECURE is active throughout the app, blocking Android OS screenshots, recent apps switcher thumbnails, and untrusted display mirroring.
  • Zero Internet Permissions: Pin Vault requests zero network permissions (android.permission.INTERNET is absent from AndroidManifest.xml). Data never leaves your physical device.

🚀 Version 0.997 Release Highlights

The current v0.997 (Beta) release introduces major architectural enhancements:

  • 👆 Artist Fingerpaint Mode: Draw custom geometric shapes across the matrix with directional numbered chevrons.
  • ⏱️ Dynamic TOTP Authenticator: Scan 2FA QR codes to camouflage live rolling 6-digit one-time passcodes.
  • 🔐 RSA-OAEP Hardware Encryption: Upgraded cryptographic sealing to RSA/ECB/OAEPWithSHA-256AndMGF1Padding in the Android KeyStore / TEE, eliminating chosen-ciphertext padding oracle vulnerabilities.

Clone this wiki locally