Releases: munzzyy/magpie
Release list
0.4.4
One entry reads as one entry, the top bar fits a phone, and Settings says who made the app.
A journal with one entry says "1 entry, chain intact" instead of "1 entries", in English and Spanish. On a phone the timeline's top bar no longer runs off the screen: the chain badge gets its own line and the lock button is back in view. Settings now ends with the app version and a "Made by Munzzyy" credit.
Magpie is GPL-3.0-or-later from this release on. 0.4.3 and earlier stay MIT.
0.4.3
A file too big to hold is turned away, not a crash.
Picking a very large file to attach used to take the app down: it read the whole thing into memory before anything could stop it. Attachments are capped at 50 MB now, and anything larger is refused up front with a message, so the app stays standing.
0.4.2
Backups survive a real attachment.
Sealing a backup of a journal that held a file of any real size failed: the encode step spread the whole attachment across a single function call and hit the argument limit. It builds the base64 in chunks now, so a backup carries its attachments no matter how big they are.
0.4.1
The file buttons open something now.
Attaching a file to a note, and picking a backup to restore, both did nothing: the button opened no file picker at all. The WebView had never been handed a file-chooser, so every file input was dead. Both work now.
0.4.0
The chain proves order, not the clock.
- verifyChain and verify.py both certified a chain clean even when an
entry's timestamp was earlier than the one before it, a device clock
jumping back for any reason (drift, a time zone change, a reset) and
nobody noticing. Both now catch it and say so: the badge and the export
verifier report a warning naming the entry, never a rejection. Refusing
to record something because a clock moved would be worse than the drift
itself, and the chain was never proving clock order to begin with, only
that each entry was added after the one before it.
0.3.0
The journal grows a spine, a backup, and a longer memory.
- The timeline draws its chain: a spine, a dot and hash chip per entry, an
anchor line saying how far the record is pinned, and a sealing snap when
an entry joins. - Sealed backup and restore: one encrypted envelope under the vault key,
only the key-derivation parameters readable outside it. Restore verifies
the whole chain in memory before a byte lands, with five distinct
refusal codes for everything that can be wrong. - verify.py --extends proves one export is an append-only extension of
another; exports self-verify before they can leave the app. - Multi-file attach, in-memory search that a lock wipes, a first-run empty
state, and a wrong-passphrase shake that still announces itself.
Verify what you install
sha256 magpie-0.3.0.apk e2836b2347490f8361dfe6b688f5733a128325bf21f565da6517e20d99034456
sha256 magpie-0.3.0.aab 6be3ac94ae4c5926a1bbe90fe2853e9995e1bf25da842837f139f81142e4c534
signing cert sha256 35d26c85cf963570aafda3dccce4d28fcb041f712cf15cd24ab8cc7d694be526
magpie.apk is the same file as magpie-0.3.0.apk under a stable name.
0.2.0
The iOS round.
- An iOS wrapper in
ios/on the permanentmagpie://localhostorigin,
with export reaching the system share sheet through a native bridge and
WebKit storage excluded from iCloud and device backups, because an
evidence vault must not quietly ride into a cloud copy. docs/IOS.md
carries the honest capability table. - A wrong passphrase now announces itself to screen readers instead of
failing silently, screens move focus when they open, headings exist past
the lock screen, and the delete confirm has a label. - Storage asks the browser to persist; settings show days since the last
export; attached photos keep their metadata on purpose and the copy says
so where you attach them.
Verify what you install
sha256 magpie-0.2.0.apk 888147dea282e3e764127e8f971bf37316b088af9e29a702f39c5a03f81942d0
sha256 magpie-0.2.0.aab e8594a4afa04db049fec81863eb31015d920f198feb404b3536e67897d79701b
signing cert sha256 35d26c85cf963570aafda3dccce4d28fcb041f712cf15cd24ab8cc7d694be526
magpie.apk is the same file as magpie-0.2.0.apk under a stable name.
Magpie 0.1.0
First release.
Magpie is an incident journal with receipts, for the disputes life
actually throws at people. Every entry (photo, note, file) is encrypted
on your device and hash-chained to the one before it, so the record
cannot be quietly rewritten, by anyone, you included. Exports are plain
zips carrying your files, the chain manifest, and a small python script
anyone can run to verify the whole record without Magpie. Share the
one-line head hash early and the journal is pinned to that moment.
Zero permissions: photos come through the system camera app and the OS
refuses every network connection. There is no passphrase recovery on
purpose, and the threat model says plainly what the chain does and does
not prove. English and Spanish. MIT.
Verify what you installed:
sha256 (magpie-0.1.0.apk): 2a4b0b0db44d0478047b7f6f72dfbe3261f39da479691444244ab50063735cd5
signing certificate SHA-256: 35d26c85cf963570aafda3dccce4d28fcb041f712cf15cd24ab8cc7d694be526
Check them with sha256sum and apksigner verify --print-certs.