Clockwork 대상 Android

Clockwork

Kevin

버전 1.5.2

TOTP codes without a network permission. Offline by design, nothing stored.

다운로드 9
Ads

이 항목을 평가하기

안티바이러스 & 안전 검사 결과

검사 날짜: Aug 12, 2026 소프트웨어 버전: 1.5.2
상태: ✅ 신뢰할 수 있고 설치에 안전합니다. 이 앱은 Kevin에 의해 신뢰할 수 있는 인증된 디지털 서명으로 서명되었으며, 기존 Clockwork 설치를 업데이트합니다. 인증서 지문: 67b1034f5b32e1d4096249272072ad8357d4917b 발행자: C:UK, CN:FDroid, L:ORG, O:fdroid.org, ST:ORG, OU:FDroid APK 파일 보안을 확인하는 방법
안드로이드 안티바이러스 상태
K7GW 클린 ✅
DrWeb 클린 ✅
VirIT 클린 ✅
ClamAV 클린 ✅
Google 클린 ✅
Ikarus 클린 ✅
Lionic 클린 ✅
Sophos 클린 ✅
Yandex 클린 ✅
Alibaba 클린 ✅
Tencent 클린 ✅
Xcitium 클린 ✅
Fortinet 클린 ✅
Kingsoft 클린 ✅
Symantec 클린 ✅
AhnLab-V3 클린 ✅
Kaspersky 클린 ✅
Microsoft 클린 ✅
Trustlook 클린 ✅
ESET-NOD32 클린 ✅
Avast-Mobile 클린 ✅
NANO-Antivirus 클린 ✅
BitDefenderFalx 클린 ✅

Clockwork 2단계 인증 앱 대상 Android 설명

Clockwork generates two-factor codes (TOTP, RFC 6238) entirely on your device. The Android app declares no INTERNET permission — it cannot go online, and you can check that claim yourself in the manifest.

The app is the projects single-file web build carried by a system WebView: the same clockwork.html you can download from a release and open on any computer.

What it does:

  • Generates TOTP codes — SHA-1, SHA-256 or SHA-512, 6 to 8 digits, any period. The countdown is a 30-mark dial with a rotating hand, not a progress ring.
  • Takes input in every shape you are likely to have it: raw Base32, otpauth:// URIs, a whole Google Authenticator export, or a QR code from the camera or an image.
  • Explains broken lines instead of failing silently.
  • Optionally remembers your secrets behind a passphrase — strictly opt-in, AES-256-GCM over PBKDF2-SHA-256 with 600,000 iterations, with an auto-lock. Without the vault, nothing is stored at all.
  • Speaks 37 languages, all bundled, including right-to-left layouts.

The camera permission exists solely for the QR scanner and is declared optional hardware; importing a QR code from an image works without it. Auto-backup is disabled, so the encrypted vault never leaves the device.

The OTP algorithms are implemented from scratch against the RFC test vectors — no OTP library. The only borrowed crypto primitive is the Web Crypto API.

Important, independent of this app:

Set up backup codes with every provider before relying on any authenticator. They are the only thing that gets you back in when the secret is gone.

Ads


사양