Skip to content

Releases: regaan/LockRoot

Lockroot v1.2.1

Choose a tag to compare

@github-actions github-actions released this 22 May 20:14
34e9c5a

Security hardening and v2 vault format finalization release.

Changed

  • Finalized the shared v2 encrypted vault/export envelope.
  • Standardized current vault/export writes around Lockroot_VAULT / Lockroot_EXPORT, Argon2id, and AES-256-GCM.
  • Clarified legacy migration behavior across Android, iOS, macOS, Windows, and Linux.
  • Updated README, security notes, threat model, crypto notes, and vault format documentation.

Security

  • Hardened vault unlock, save, and migration paths.
  • Added compatible legacy migration behavior where the platform can decrypt the old vault format.
  • Improved desktop vault/export handling around the newer shared envelope shape.
  • Clarified that wrong passwords, tampered ciphertext, and tampered envelope metadata fail authentication.

Testing

  • Updated Android vault codec and repository tests.
  • Added desktop smoke coverage for v2 vault/export behavior.
  • Verified Android release unit tests, Windows release build, Linux release build, and desktop smoke tests.

Lockroot v1.2.0

Choose a tag to compare

@github-actions github-actions released this 20 May 20:59

Lockroot 1.1.1 Release Notes

Lockroot 1.1.1 is a hardening and desktop expansion release for Android, iOS, Windows, and Linux. It fixes audit findings around unlock throttling, password policy consistency, clipboard handling, capture protection, KDF validation, and release packaging.

Security Fixes

  • Android screenshot and screen-recording protection now applies in all build types with FLAG_SECURE.
  • Android vault session key cleanup now uses random overwrite, zeroing, and a volatile sink.
  • iOS unlock now throttles repeated failed password attempts with exponential backoff.
  • iOS validates Argon2id KDF parameters before accepting vault/export metadata.
  • iOS clipboard auto-clear no longer captures the copied secret in the delayed cleanup task.
  • Windows master and export passwords now require at least 12 characters.
  • Windows unlock now throttles repeated failed password attempts with exponential backoff.
  • Windows now auto-locks after inactivity and when minimized.
  • Windows asks the OS to exclude Lockroot windows from normal screen capture where supported.
  • Windows clipboard auto-clear no longer stores the copied secret for comparison.
  • Windows Argon2id parameters are now range-validated before key derivation.
  • Windows derived vault keys are allocated in pinned managed arrays and wiped after use.

App Fixes

  • iOS search now includes notes, matching Android behavior.
  • Windows password generator now enforces a 12 to 128 character range.
  • README now documents Android, iOS, and Windows security behavior more accurately.
  • Linux native desktop app added with setup, unlock, entry management, password generator options, encrypted export/import preview, settings, privacy, terms, and about screens.
  • Linux uses the same Argon2id + AES-256-GCM vault/export format as Windows.

Release Packaging

  • Android release is now versionCode 3 / versionName 1.1.1.
  • Windows installer is now labeled 1.1.1.
  • GitHub release workflow now publishes Android, Windows, and Linux artifacts.
  • Linux release artifacts include AppImage, .deb, .rpm, and tarball builds.
  • The old iOS simulator artifact workflow was removed because iOS is live on the App Store.

Downloads

Lockroot v1.1.1

Choose a tag to compare

@github-actions github-actions released this 20 May 18:20

Lockroot 1.1.1 Release Notes

Lockroot 1.1.1 is a hardening release for Android, iOS, and Windows. It fixes audit findings around unlock throttling, password policy consistency, clipboard handling, capture protection, KDF validation, and release packaging.

Security Fixes

  • Android screenshot and screen-recording protection now applies in all build types with FLAG_SECURE.
  • Android vault session key cleanup now uses random overwrite, zeroing, and a volatile sink.
  • iOS unlock now throttles repeated failed password attempts with exponential backoff.
  • iOS validates Argon2id KDF parameters before accepting vault/export metadata.
  • iOS clipboard auto-clear no longer captures the copied secret in the delayed cleanup task.
  • Windows master and export passwords now require at least 12 characters.
  • Windows unlock now throttles repeated failed password attempts with exponential backoff.
  • Windows now auto-locks after inactivity and when minimized.
  • Windows asks the OS to exclude Lockroot windows from normal screen capture where supported.
  • Windows clipboard auto-clear no longer stores the copied secret for comparison.
  • Windows Argon2id parameters are now range-validated before key derivation.
  • Windows derived vault keys are allocated in pinned managed arrays and wiped after use.

App Fixes

  • iOS search now includes notes, matching Android behavior.
  • Windows password generator now enforces a 12 to 128 character range.
  • README now documents Android, iOS, and Windows security behavior more accurately.

Release Packaging

  • Android release is now versionCode 3 / versionName 1.1.1.
  • Windows installer is now labeled 1.1.1.
  • GitHub release workflow now publishes Android and Windows artifacts only.
  • The old iOS simulator artifact workflow was removed because iOS is live on the App Store.

Downloads

Lockroot v1.1.0

Choose a tag to compare

@github-actions github-actions released this 20 May 15:03

Lockroot Mobile Release Notes

Lockroot is an open-source password manager focused on local control, privacy, and practical mobile security.

Release Status

  • Android is in Google Play internal testing.
  • iOS is live on the App Store: https://apps.apple.com/app/id6770449898
  • GitHub Android artifacts are temporary until the public Play Store link is available.

Android

This release includes Android release build artifacts:

  • Lockroot-android-release.apk
  • Lockroot-android-release.aab
  • Lockroot-android-SHA256SUMS.txt

The APK/AAB are release builds. They are signed with a temporary GitHub Actions signing key created during the workflow run, not the Google Play upload key.

Because the temporary signing key changes per workflow run, uninstall any previous GitHub-release APK before installing a newer one from GitHub.

iOS

The iOS app is available on the App Store:

The GitHub release workflow may also attach a simulator build for verification, but iPhone users should install Lockroot from the App Store.

Security Model

  • Master password key derivation uses Argon2id.
  • Vault encryption uses XChaCha20-Poly1305.
  • Export/import uses a separate export password and derived key.
  • Wrong passwords and modified vaults fail authentication.
  • Lockroot has no recovery backdoor.

Source Code

GitHub: https://github.com/regaan/LockRoot

Website: https://lockroot.rothackers.com

Lockroot v1.0.0

Choose a tag to compare

@github-actions github-actions released this 18 May 10:13

Lockroot Mobile Release Notes

Lockroot is an open-source password manager focused on local control, privacy, and practical mobile security.

Release Status

  • Android is in Google Play internal testing.
  • iOS is in closed testing/App Store preparation.
  • These GitHub artifacts are temporary until public store links are available.

Android

This release includes Android release build artifacts:

  • Lockroot-android-release.apk
  • Lockroot-android-release.aab
  • Lockroot-android-SHA256SUMS.txt

The APK/AAB are release builds. They are signed with a temporary GitHub Actions signing key created during the workflow run, not the Google Play upload key.

Because the temporary signing key changes per workflow run, uninstall any previous GitHub-release APK before installing a newer one from GitHub.

iOS

This release includes:

  • Lockroot-iOS-simulator.app.zip
  • Lockroot-ios-simulator-SHA256SUMS.txt

The iOS artifact is an unsigned simulator release build for verification only. It cannot be installed on a physical iPhone.

Security Model

  • Master password key derivation uses Argon2id.
  • Vault encryption uses XChaCha20-Poly1305.
  • Export/import uses a separate export password and derived key.
  • Wrong passwords and modified vaults fail authentication.
  • Lockroot has no recovery backdoor.

Source Code

GitHub: https://github.com/regaan/LockRoot

Website: https://lockroot.rothackers.com