Skip to content

Releases: munzzyy/magpie

0.4.4

Choose a tag to compare

@munzzyy munzzyy released this 28 Sep 01:14

One entry reads as one entry, the top bar fits a phone, and Settings says who made the app.

A journal with one entry says "1 entry, chain intact" instead of "1 entries", in English and Spanish. On a phone the timeline's top bar no longer runs off the screen: the chain badge gets its own line and the lock button is back in view. Settings now ends with the app version and a "Made by Munzzyy" credit.

Magpie is GPL-3.0-or-later from this release on. 0.4.3 and earlier stay MIT.

0.4.3

Choose a tag to compare

@munzzyy munzzyy released this 12 Sep 11:31
8711c87

A file too big to hold is turned away, not a crash.

Picking a very large file to attach used to take the app down: it read the whole thing into memory before anything could stop it. Attachments are capped at 50 MB now, and anything larger is refused up front with a message, so the app stays standing.

0.4.2

Choose a tag to compare

@munzzyy munzzyy released this 12 Sep 03:50
1c27a26

Backups survive a real attachment.

Sealing a backup of a journal that held a file of any real size failed: the encode step spread the whole attachment across a single function call and hit the argument limit. It builds the base64 in chunks now, so a backup carries its attachments no matter how big they are.

0.4.1

Choose a tag to compare

@munzzyy munzzyy released this 11 Sep 21:31
33c5f0f

The file buttons open something now.

Attaching a file to a note, and picking a backup to restore, both did nothing: the button opened no file picker at all. The WebView had never been handed a file-chooser, so every file input was dead. Both work now.

0.4.0

Choose a tag to compare

@munzzyy munzzyy released this 08 Sep 21:03
1b1e6b3

The chain proves order, not the clock.

  • verifyChain and verify.py both certified a chain clean even when an
    entry's timestamp was earlier than the one before it, a device clock
    jumping back for any reason (drift, a time zone change, a reset) and
    nobody noticing. Both now catch it and say so: the badge and the export
    verifier report a warning naming the entry, never a rejection. Refusing
    to record something because a clock moved would be worse than the drift
    itself, and the chain was never proving clock order to begin with, only
    that each entry was added after the one before it.

0.3.0

Choose a tag to compare

@munzzyy munzzyy released this 07 Sep 19:35

The journal grows a spine, a backup, and a longer memory.

  • The timeline draws its chain: a spine, a dot and hash chip per entry, an
    anchor line saying how far the record is pinned, and a sealing snap when
    an entry joins.
  • Sealed backup and restore: one encrypted envelope under the vault key,
    only the key-derivation parameters readable outside it. Restore verifies
    the whole chain in memory before a byte lands, with five distinct
    refusal codes for everything that can be wrong.
  • verify.py --extends proves one export is an append-only extension of
    another; exports self-verify before they can leave the app.
  • Multi-file attach, in-memory search that a lock wipes, a first-run empty
    state, and a wrong-passphrase shake that still announces itself.

Verify what you install

sha256 magpie-0.3.0.apk  e2836b2347490f8361dfe6b688f5733a128325bf21f565da6517e20d99034456
sha256 magpie-0.3.0.aab  6be3ac94ae4c5926a1bbe90fe2853e9995e1bf25da842837f139f81142e4c534
signing cert sha256  35d26c85cf963570aafda3dccce4d28fcb041f712cf15cd24ab8cc7d694be526

magpie.apk is the same file as magpie-0.3.0.apk under a stable name.

0.2.0

Choose a tag to compare

@munzzyy munzzyy released this 07 Sep 06:26

The iOS round.

  • An iOS wrapper in ios/ on the permanent magpie://localhost origin,
    with export reaching the system share sheet through a native bridge and
    WebKit storage excluded from iCloud and device backups, because an
    evidence vault must not quietly ride into a cloud copy. docs/IOS.md
    carries the honest capability table.
  • A wrong passphrase now announces itself to screen readers instead of
    failing silently, screens move focus when they open, headings exist past
    the lock screen, and the delete confirm has a label.
  • Storage asks the browser to persist; settings show days since the last
    export; attached photos keep their metadata on purpose and the copy says
    so where you attach them.

Verify what you install

sha256 magpie-0.2.0.apk  888147dea282e3e764127e8f971bf37316b088af9e29a702f39c5a03f81942d0
sha256 magpie-0.2.0.aab  e8594a4afa04db049fec81863eb31015d920f198feb404b3536e67897d79701b
signing cert sha256      35d26c85cf963570aafda3dccce4d28fcb041f712cf15cd24ab8cc7d694be526

magpie.apk is the same file as magpie-0.2.0.apk under a stable name.

Magpie 0.1.0

Choose a tag to compare

@munzzyy munzzyy released this 07 Sep 03:14

First release.

Magpie is an incident journal with receipts, for the disputes life
actually throws at people. Every entry (photo, note, file) is encrypted
on your device and hash-chained to the one before it, so the record
cannot be quietly rewritten, by anyone, you included. Exports are plain
zips carrying your files, the chain manifest, and a small python script
anyone can run to verify the whole record without Magpie. Share the
one-line head hash early and the journal is pinned to that moment.

Zero permissions: photos come through the system camera app and the OS
refuses every network connection. There is no passphrase recovery on
purpose, and the threat model says plainly what the chain does and does
not prove. English and Spanish. MIT.

Verify what you installed:

sha256 (magpie-0.1.0.apk): 2a4b0b0db44d0478047b7f6f72dfbe3261f39da479691444244ab50063735cd5
signing certificate SHA-256: 35d26c85cf963570aafda3dccce4d28fcb041f712cf15cd24ab8cc7d694be526

Check them with sha256sum and apksigner verify --print-certs.