Clockwork 向け Android

Clockwork

Kevin

バージョン 1.5.2

TOTP codes without a network permission. Offline by design, nothing stored.

ダウンロード数 9
Ads

これを評価する

アンチウイルス & セキュリティスキャン結果

スキャン日: Aug 12, 2026 ソフトウェアバージョン: 1.5.2
ステータス: ✅ 信頼でき、安全にインストール可能 このアプリはKevinによって信頼できるデジタル署名で署名されており、既存のClockworkインストールを更新します 証明書のフィンガープリント: 67b1034f5b32e1d4096249272072ad8357d4917b 発行者: C:UK, CN:FDroid, L:ORG, O:fdroid.org, ST:ORG, OU:FDroid APKファイルのセキュリティ確認方法
Androidアンチウイルス ステータス
K7GW 安全 ✅
DrWeb 安全 ✅
VirIT 安全 ✅
ClamAV 安全 ✅
Google 安全 ✅
Ikarus 安全 ✅
Lionic 安全 ✅
Sophos 安全 ✅
Yandex 安全 ✅
Alibaba 安全 ✅
Tencent 安全 ✅
Xcitium 安全 ✅
Fortinet 安全 ✅
Kingsoft 安全 ✅
Symantec 安全 ✅
AhnLab-V3 安全 ✅
Kaspersky 安全 ✅
Microsoft 安全 ✅
Trustlook 安全 ✅
ESET-NOD32 安全 ✅
Avast-Mobile 安全 ✅
NANO-Antivirus 安全 ✅
BitDefenderFalx 安全 ✅

Clockwork 2段階認証 アプリ 向け Android 説明

Clockwork generates two-factor codes (TOTP, RFC 6238) entirely on your device. The Android app declares no INTERNET permission — it cannot go online, and you can check that claim yourself in the manifest.

The app is the projects single-file web build carried by a system WebView: the same clockwork.html you can download from a release and open on any computer.

What it does:

  • Generates TOTP codes — SHA-1, SHA-256 or SHA-512, 6 to 8 digits, any period. The countdown is a 30-mark dial with a rotating hand, not a progress ring.
  • Takes input in every shape you are likely to have it: raw Base32, otpauth:// URIs, a whole Google Authenticator export, or a QR code from the camera or an image.
  • Explains broken lines instead of failing silently.
  • Optionally remembers your secrets behind a passphrase — strictly opt-in, AES-256-GCM over PBKDF2-SHA-256 with 600,000 iterations, with an auto-lock. Without the vault, nothing is stored at all.
  • Speaks 37 languages, all bundled, including right-to-left layouts.

The camera permission exists solely for the QR scanner and is declared optional hardware; importing a QR code from an image works without it. Auto-backup is disabled, so the encrypted vault never leaves the device.

The OTP algorithms are implemented from scratch against the RFC test vectors — no OTP library. The only borrowed crypto primitive is the Web Crypto API.

Important, independent of this app:

Set up backup codes with every provider before relying on any authenticator. They are the only thing that gets you back in when the secret is gone.

Ads


仕様