Skip to content

Releases: nightdropapp/nightdrop

Night Drop 0.1.25

Choose a tag to compare

@nightdropapp nightdropapp released this 27 Sep 07:45

Stays reachable on fast connections

After running for a while on a fast connection, Night Drop could become unreachable: contacts' messages stopped arriving directly, and it took minutes (or forever) to come back online after a restart.

The cause was in how the Tor library learns its circuit-build timeout. It learns only from the connections that succeed, so on a fast link the timeout kept shrinking — to about half a second — until ordinary connections were being abandoned. Each abandoned connection counted against the Tor entry relay it used, and once enough had, that relay was disabled for good. With none left, the app could not publish its address at all. The timeout now has a two-second floor, which stops the spiral without slowing anything down.

If your app has been slow to come online, this release fixes it going forward.

Also

  • A stalled connection can no longer freeze delivery. If a Tor connection stopped moving mid-transfer, sending and receiving could stop until the app was restarted. Connections that make no progress for 60 seconds are now dropped and retried.
  • Offline messages are stored on the relay once, not twice. The relay was being counted twice under two names, doubling both the copies and the mail checks.
  • An unopened burn message that expires now leaves a marker ("Burn message expired unopened") instead of vanishing silently.
  • Donations: Bitcoin, through a silent payment address (each payment lands at a fresh output, so donations cannot be linked to each other or to the address), and Zcash.

Verifying

Every binary is signed with the release key and listed in SHA256SUMS, itself signed. See SECURITY.md for the full verification steps; nightdrop-signing-key.asc is attached.

Night Drop 0.1.24

Choose a tag to compare

@nightdropapp nightdropapp released this 26 Sep 20:08

Background delivery keeps going after you swipe the app away

With background delivery on, swiping Night Drop out of your recent apps used to stop it: nothing arrived until you opened the app again. Now it keeps receiving, and notifies you, until you choose to stop it.

Exit

⋮ › Exit disconnects from Tor cleanly and closes the app, without touching your identity or chats — the next launch opens them as usual. It is the deliberate way to go offline now that swiping no longer does it. Thanks to the reporter of #15 for the suggestion.

While the app is closed, messages sent to you wait on the relay for up to 24 hours. Open Night Drop within that time to receive them; after that they expire, and the sender sees them as not delivered. The Exit dialog says so.

Hiding the "Watching for messages" notification

Android requires a visible notification while an app works in the background, and does not let the app make it quieter than it already is. You can hide it yourself: turn off the Background delivery status notification category (on Samsung: App info › Notifications › Notification categories, or long-press the notification). Messages keep arriving and still notify — they use a separate category. The category was renamed so it can no longer be confused with the in-app Background delivery switch, which does stop delivery.

Known limit

After the phone restarts or the app is updated, background delivery resumes only once you open Night Drop. Making it start on its own needs a larger change and is not in this release.

Also

  • Closing the app no longer drops a change that was still waiting to be saved (saves are grouped over a few seconds).

Verifying

Every binary is signed with the release key and listed in SHA256SUMS, itself signed. See SECURITY.md for the full verification steps; nightdrop-signing-key.asc is attached.

Night Drop 0.1.23

Choose a tag to compare

@nightdropapp nightdropapp released this 26 Sep 18:02

Burn messages

Long-press Send — or the attach button, for a photo or video — to send a message that arrives blurred and is deleted a set time after the other person opens it: 10 seconds, 30 seconds, a minute or five minutes. If it is never opened it is deleted after 24 hours. The timer starts when it is revealed, not when it is sent, so a message waiting for someone who is offline is not burned before they see it.

What it is not. It is a courtesy against a careless or forgetful recipient, not a control over a hostile one: a screenshot, a screen recording or a camera pointed at the screen all still work, as they do in every app that offers this. It is shown as a blur, never a padlock, for that reason.

  • Both of you need this version. Burn is only offered once the other person's app has said it understands it; until then a burn message would arrive as an ordinary, permanent one.
  • Your own copy is kept for up to 24 hours, not deleted when they open it — unless they turn on burn read receipts (off by default, and their choice, because it tells you when they read it).
  • With server storage on, a copy also sits on the relay until their app next collects its mail — normally minutes, up to 24 hours if it never comes back online. The burn menu says so when it applies.

Fixes

  • Reopening the app on Android shortly after closing it could show "Couldn't open your saved session", with Try again failing until it recovered by itself a minute or so later. Nothing was lost — the saved data was never touched — but it was alarming. See docs/advisories/2026-09-26-reopen-after-swipe-showed-recovery-screen.md.
  • The chat header no longer puts the verify shield next to Back on a phone. Only the server-storage and disappearing-timer icons stay in the bar; verify, rename, back-up and delete are in the ⋮ menu.

Verifying

Every binary is signed with the release key and listed in SHA256SUMS, itself signed. See SECURITY.md for the full verification steps; nightdrop-signing-key.asc is attached.

Night Drop 0.1.22

Choose a tag to compare

@nightdropapp nightdropapp released this 22 Sep 02:58

Tor over WebTunnel, when the network blocks it

If your network blocks Tor, Night Drop can now use a WebTunnel bridge: Tor carried inside ordinary HTTPS to a normal-looking web server. Add one under Bridges — now reachable before you create an identity, which is when you are most likely to need it. Previously the editor sat behind the home screen, which you could only reach with a working identity, which needed a working Tor bootstrap.

What this is tested against, and what it is not. It is tested against a network that blocks Tor by address, with a control confirming direct Tor could not build a single circuit; and against an intrusion-detection system carrying 52,311 public signatures, over a thousand of them for Tor, which raised nothing and saw only ordinary TLS. It has never been run from inside a country that filters this way, and public tooling is a far weaker adversary than a national firewall. One property is not disguised at all: the shape of the traffic. A connection that pulls tens of megabytes while sending very little does not look like reading a web page, however ordinary the handshake is. If being identified as a Tor user is itself dangerous where you are, do not rely on this alone.

Fixes

  • Repeatedly tapping reconnect could leave the app offering to set up a new identity over an existing one. Launching is no longer re-entrant, and creating an identity now refuses to displace saved data unless the recovery screen asked for it.
  • The sealed onion key now travels with the state file it unseals, so recovering a set-aside identity keeps its .onion address instead of coming back on a new one.
  • A native library that fails to load reaches the error screen instead of leaving the splash on screen for ever.

Verifying

Every binary is signed with the release key and listed in SHA256SUMS, itself signed. See SECURITY.md for the full verification steps; nightdrop-signing-key.asc is attached.

Night Drop 0.1.21

Choose a tag to compare

@nightdropapp nightdropapp released this 13 Aug 23:23

No automatic update check on F-Droid installs

If you installed Night Drop from F-Droid, it no longer checks for its own updates — F-Droid already does that for you, and two updaters doing the same job is one too many.

Every other build still asks the Night Drop onion site, over Tor, at most once a day whether a newer version exists, and only ever tells you. Nothing is downloaded until you press Download, nothing is installed automatically, and the app deliberately does not hold the Android permission that would let it install anything. That check exists for sideloaded APKs and the desktop AppImage, which have no update channel of their own.

"Update app" in the menu keeps working everywhere: if you deliberately ask, you get a real answer.

This is now stated in About and in the store description, rather than only in our docs. It came out of an F-Droid inclusion review, where the reviewer concluded we did not check for updates automatically — we did, and this makes the app match what a reviewer can reasonably observe.

Also

The banner shown while your onion address publishes no longer claims "1–3 min". A reviewer measured about five minutes, and our own device logs show four and six. The wait depends on the network, so the app now says "several minutes" instead of a number it cannot keep.

Verifying this download

Every file is GPG-signed by security@nightdrop.app (key included below), and SHA256SUMS covers all of them — see SECURITY.md for the steps.

The three per-ABI APKs are reproducible from source by F-Droid: versionCodes 4071 (armeabi-v7a), 4072 (arm64-v8a), 4073 (x86_64). NightDrop.apk is the universal build (4074) — take that if you are unsure.

Night Drop 0.1.20

Choose a tag to compare

@nightdropapp nightdropapp released this 10 Aug 13:17

Background delivery no longer stops after six hours

On Android 15 and 16 the system was ending background delivery once it had run six cumulative hours in a day, and nothing said so — Night Drop simply stopped receiving messages until you reopened it, and did not resume on its own. Measured on a phone overnight: the service ended at exactly 6h 0m 0s and the app received nothing for the next five hours.

The connection now runs under a foreground-service type that has no such budget. And if the system ever does stop it for some other reason, the app tells you instead of quietly going offline — that silence was the real problem, since a messenger that has stopped receiving looks exactly like a messenger nobody has written to.

Also in this release

Cover traffic is remembered. Turning it on and restarting the app used to switch it back off silently. Dummy traffic is meant to be indistinguishable from nothing, so this was not something you could have noticed.

Chats warn when the other person cannot report screenshots. On any Android below 14, and on desktop, a screenshot raises no notice at all — so the absence of one from that peer was never evidence that none was taken. The warning is shown to you, about them: the person deciding what to send is the one who needs it.

Deleting your identity now removes Tor's directory cache too. It held no keys or contacts, but it did carry a timestamp of when Tor last ran, next to an app that presents itself as freshly installed.

Verifying this download

Every file is GPG-signed by security@nightdrop.app (key included below), and SHA256SUMS covers all of them. See SECURITY.md for the full verification steps.

The three per-ABI APKs are reproducible from source by F-Droid: versionCodes 4061 (armeabi-v7a), 4062 (arm64-v8a), 4063 (x86_64). NightDrop.apk is the universal build (4064) — take that one if you are unsure which to use.

Night Drop 0.1.19

Choose a tag to compare

@nightdropapp nightdropapp released this 07 Aug 11:52

No user-visible changes. If you are on 0.1.18, this release gives you nothing you do not already have.

What changed

The Android release build now declares that it minifies and shrinks its code, rather than inheriting that from Flutter's default. Both were already happening — 0.1.18 and every release before it were minified and resource-shrunk — so the app behaves exactly as 0.1.18 did. What this buys is that a change in Flutter's defaults can no longer switch it off without anyone noticing.

Requested by the F-Droid reviewer on fdroiddata!43625.

Because code shrinking can break reflective calls at runtime and never at build time, this was smoke-tested on hardware rather than trusted to a green build: launch, identity restored from the OS keystore, Tor to a published onion service, QR pairing scan, background message delivery with the app off screen, and the new-message notification.

Verifying this release

gpg --import nightdrop-signing-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum -c SHA256SUMS

Fingerprint: 079B A016 9201 A8AB 11F3 2385 884E ACB8 89D0 2002

The three per-ABI APKs are built by the F-Droid recipe in fdroid/app.nightdrop.yml at commit 32f8759, so they can be reproduced independently.

Night Drop 0.1.18

Choose a tag to compare

@nightdropapp nightdropapp released this 07 Aug 00:23

Night Drop can now tell you when a newer release exists and fetch it for you, over Tor, from its own onion site. Until now the only way to learn about a security fix was to go looking — which is exactly the gap that left Linux users on 0.1.15 for three days.

What changed

The app checks for updates over Tor, and only over Tor. It asks our own .onion for a small manifest, at most once a day, and compares versions on your device. The request carries no version, no identifier, no cookie and no varying header, so the site cannot tell one user from another or a first check from a hundredth. There is no clearnet path in the code at all: a connection that cannot be made anonymously is skipped, not downgraded.

Tapping the notice downloads that build and checks it before you ever see it. The file is streamed to disk rather than held in memory, hashed against the SHA-256 the site published, and only then moved into your Downloads folder — so a file you can see is always one that passed verification. It reaches the public Downloads folder without the app holding any storage permission. A progress bar shows how far along it is, and the download keeps running with the screen off; it survives Doze on a Samsung, which is where we tested it.

Nothing installs itself. The app hands you a verified file and stops. Android checks the signature and asks you, which is the right place for that decision to live, and it refuses anything not signed by our release key.

A failed check now says so. "Update app" used to report Night Drop is up to date when it simply could not reach the site — a confident lie on the one screen where you deliberately asked, hiding the very fix the feature exists to surface. It now distinguishes the two.

The main Android download installs over per-ABI builds again. The universal APK carried a version code below the per-ABI builds of the same release, so Android treated it as a downgrade and refused it. Anyone who installed from F-Droid — or through the new in-app updater, which fetches the build matching your device — got "App not installed" from the site's primary download with nothing to explain why. Fixed, and it stays ordered correctly from here.

Verifying this release

gpg --import nightdrop-signing-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum -c SHA256SUMS

Fingerprint: 079B A016 9201 A8AB 11F3 2385 884E ACB8 89D0 2002

The three per-ABI APKs are built by the F-Droid recipe in fdroid/app.nightdrop.yml at commit 37cbf9b, so they can be reproduced independently.

Night Drop 0.1.17

Choose a tag to compare

@nightdropapp nightdropapp released this 04 Aug 21:50

Night Drop was resetting its own Tor connection on devices that were working perfectly — roughly once every launch — and the replacement connection was slower than the one it discarded. That is fixed, and it is the reason this release exists.

What changed

Tor connects faster and stays connected. The app's automatic "repair" for a stuck Tor connection was firing on healthy devices: it judged health by whether the onion descriptor had published, which turns out to report bootstrap progress, not liveness. A phone with its descriptor on 8/8 directories for both time periods, all four introduction points up and zero upload failures still read as "not published" — so about two and a half minutes into every session the app threw away its entry guards and its learned connection timings and started over. Automatic repair now only happens on evidence that messages actually are not moving.

A pairing code no longer dies mid-pairing. An in-flight short code was held only in memory, so anything that rebuilt the connection discarded it while the inviter's screen still showed the code — the person joining timed out and it looked like the inviter's fault. Codes now survive, including across an app restart within their ten-minute life.

Background delivery is offered during setup, with what it costs and what it does not do, instead of being buried in a menu. Android suspends the app whenever it is off screen, so without it messages only arrive when you open the app. Deleting your identity now turns it back off.

Verifying this release

gpg --import nightdrop-signing-key.asc
gpg --verify SHA256SUMS.asc SHA256SUMS
sha256sum -c SHA256SUMS

Fingerprint: 079B A016 9201 A8AB 11F3 2385 884E ACB8 89D0 2002

The three per-ABI APKs are built by the F-Droid recipe in fdroid/app.nightdrop.yml at commit 7ef09fa, so they can be reproduced independently.

Night Drop 0.1.16

Choose a tag to compare

@nightdropapp nightdropapp released this 02 Aug 21:22

A chat request could turn itself into an accepted contact. Restarting the app was enough: the request came back as a normal chat you had never approved, and that person's messages were accepted from then on. Approval survives a restart now. Worth a glance at your chat list after updating.

Your onion address and your contacts' addresses no longer sit unencrypted on disk. They move into the same sealed store as your messages, so a seized or cloned phone no longer reveals who you talk to. Your own address does not change when you update.

Deleting your identity is thorough. On Android parts of it could quietly survive — including the key protecting what you had just destroyed, and the address itself, so a "new" identity could come back on the old one's address. A wipe also leaves the app able to start again; before, it could refuse to open afterwards.

"Sent" now means their device has it. One tick says it left your phone, two ticks say the other device confirmed that exact message. Previously a message that never arrived looked identical to one that did.


Version codes jump to 4021/4022/4023 (from 1016/2016/4016). F-Droid asks Flutter apps to use versionCode * 10 + abi; the base was raised so the new scheme stays above what Flutter's own numbering had already published, since Android refuses a downgrade.

Verify downloads with sha256sum -c SHA256SUMS against the signed manifest. The per-ABI APKs are reproducible builds from F-Droid's container at the fixed build path.