1Key Password Manager 대상 Android

1Key Password Manager

Rouf Syed

버전 1.1.1

Offline password manager. 2FA + notes. No account, no network, no telemetry.

다운로드 59
Ads

이 항목을 평가하기

안티바이러스 & 안전 검사 결과

검사 날짜: Jul 27, 2026 소프트웨어 버전: 1.1.1
상태: ✅ 신뢰할 수 있고 설치에 안전합니다. 이 앱은 Rouf Syed에 의해 신뢰할 수 있는 인증된 디지털 서명으로 서명되었으며, 기존 1Key Password Manager 설치를 업데이트합니다. 인증서 지문: 5e429e717c5498e1e60fc04a9f64e5e49ad9dee0 발행자: C:IN, CN:Rouf Syed, L:Mumbai, O:Unknown, ST:Maharashtra, OU:Unknown APK 파일 보안을 확인하는 방법
안드로이드 안티바이러스 상태
K7GW 클린 ✅
DrWeb 클린 ✅
VirIT 클린 ✅
ClamAV 클린 ✅
Google 클린 ✅
Ikarus 클린 ✅
Lionic 클린 ✅
Sophos 클린 ✅
Yandex 클린 ✅
Alibaba 클린 ✅
Tencent 클린 ✅
Xcitium 클린 ✅
Fortinet 클린 ✅
Kingsoft 클린 ✅
Symantec 클린 ✅
AhnLab-V3 클린 ✅
Kaspersky 클린 ✅
Microsoft 클린 ✅
Trustlook 클린 ✅
ESET-NOD32 클린 ✅
Avast-Mobile 클린 ✅
NANO-Antivirus 클린 ✅
BitDefenderFalx 클린 ✅

1Key Password Manager 비밀번호 관리자 앱 대상 Android 설명

1Key is a local-first password manager for Android. Your vault lives on your device, encrypted with a key only you hold, and never moves unless you export it yourself. There is no account to create, no server to breach, and no network connection of any kind — the INTERNET permission is stripped from the manifest, so the operating system itself enforces the offline guarantee.

Security

  • Vault key derived from your master password with Argon2id (m=64 MiB, t=3, p=1 by default; configurable up to m=256 MiB, t=16)
  • Every credential field encrypted separately with AES-256-GCM, bound to its row and column via additional authenticated data — an attacker with raw database write access cannot swap ciphertexts between rows
  • Master-password verifier stored in EncryptedSharedPreferences, itself wrapped by an Android Keystore-bound key (TEE or StrongBox where available), so offline brute-force of a leaked device image is not possible
  • Optional 128-bit Secret Key mixed into the KDF for defense-in-depth against a compromised master password
  • Biometric unlock backed by hardware-secure key; requires master-password confirmation to enable
  • Tiered attempt limiting: 3, 5, and 10 wrong attempts trigger 30-second, 5-minute, and 1-hour cooldowns; counters survive process kills

Vault

  • Store credentials with title, username, password, URL, notes, and custom fields
  • Tag-based organisation, favourites, full-text search
  • TOTP / 2FA codes stored in the same entry as the password they protect — no app switching
  • Live-preview Markdown in notes with a helper bar; disable in Settings if you prefer plain text
  • Soft-delete recycle bin (toggle off if you prefer immediate deletion)
  • Credential history preserves previous values on edit

Autofill

  • System-level Autofill Service — fill logins into any app or browser without leaving them
  • URL-only matching by default (no fuzzy suggestions) to keep phishing risk down
  • Save prompt on submit; per-action confirmation for cross-host URL saves

Backup and import

  • Encrypted backup as a .1key file (AES-256-GCM with Argon2id key derivation)
  • Plain CSV / JSON export for interoperability
  • Direct import from Google Passwords, LastPass, KeePass, 1Password, Dashlane, NordPass, Safari / iCloud Keychain — auto-detects format, no manual column mapping

Unlock options

  • Master password (always available)
  • 6-digit PIN
  • Biometric (fingerprint / face)
  • Background auto-lock: immediate / 30s / 1m / 5m
  • Inactivity auto-lock: never / 30s / 1m / 5m / 15m
  • Optional periodic master-password recheck (48h / 3d / 1w / 3w)

What 1Key does NOT do

  • No accounts, no email, no signup
  • No analytics, crash reporting, or telemetry
  • No cloud sync (backup files go to a folder you choose — local, USB, Drive, Dropbox, NAS — never through us)
  • No device identifiers, IP logging, or advertising IDs
  • No network connection at all — INTERNET permission is stripped

Anti-features

The QR-scanning and OCR features use Googles ML Kit library, which contains proprietary code. All ML Kit processing happens on-device with the INTERNET permission stripped, so no data can leave the phone even if the library tried to phone home — but F-Droid still flags the dependency as NonFreeDep. If you want a fully libre build, you can build from source without ML Kit.

Open source

Source: https://github.com/roufsyed/1Key
Licence: GPL-3.0-or-later
Reproducible builds: yes

Built because paying $48/year to autofill a password should not be a thing.

Ads


사양