QRSA OTP Authentication app icon

QRSA OTP Authentication

RSA based OTP Authentication app using QR codes.

Sebastian Nielsen (sebbe.eu) · eu.sebbe.www.qrsa

Not rated yet 100+ downloads v1.4 35.5 KB Android 6.0+ PEGI 3 · Everyone

  • Signature matches the Google Play version Details

At a glance

Latest version
v1.4 (5)
Updated
Jan 13, 2018 (8 years ago)
APK size
35.5 KB
Requires
Android 6.0+ (API 23)
CPU support
Any (no native code)
Category
Tools (app)
Website
github.com/sebastiannielsen/QRSA
Developer contact
[email protected]

About this APK

QRSA OTP Authentication is an app by Sebastian Nielsen (sebbe.eu) in the Tools category. It has no native code, so it runs on any Android processor.

What's new in v1.4

1.4: - Added Md5 hash verification, to further protect against malleability attacks. 1.3: - Improved code so the app can more reliable kill itself. 1.2: - Added OTP into @string/app_name to match Google Play app name. 1.1: - Changed enroll function to exclude linebreaks in the public key. - Added new "u" enroll function. Read the description or GitHub page for more information. The "u" enroll function is recommended when enrolling from a computer.

Description

From the listing uploaded by “devjam”.

This is an app to authenticate users via their cell phone, by decrypting a one-time password encrypted by the server using a public key. The app is usable for any web service that implements this method of authentication. (See the github tracker for more information on how to implement this authentication on server-side) The app can be used with unlimited number of relying parties, as the same public key is used with all parties. Once the app is enrolled, the app generates a device-specific keypair that is present for the whole lifetime of the app (until its uninstalled). Updating the app won't erase the key however. Github Tracker: https://github.com/sebastiannielsen/QRSA Prerequisites for running the app: 1. The phone must support hardware based storage. This is a storage that uses a "Security Chip" inside the phone, making it impossible to copy the key off the phone. 2. The store must be initialized. Sometimes its possible to initialize the store by setting up a PIN lock screen, and then just generating a key. Removing the lock screen will usually keep the key, unless the key properties was setup to require lock screen. 3. In some cases, a secure lock screen MUST be used. This is dependent on phone model. 4. The secure chip inside phone, must support operations based on 2048 bit RSA/ECB/PKCS1.5 5. In some cases, a rooted phone may permanently disable the security chip for security reasons. To enroll, you must launch the URL qrsa://e from a browser or similiar. You can also enroll via a callback URL, by using qrsa://u. To use u, you must first append a "s" if you want to use HTTPS, or anything else for HTTP. Then the whole URL to be called, WITHOUT the scheme, in URLSafe Base64 format. The public key will be appended to end of URL. If the device is incompatible, it will return INCOMPATIBLE_DEVICE and its your responsibility to return a meaningful error message to the user. To authenticate, you launch the url qrsa://s or qrsa://c followed by URLSafe Base64 encoded data of the RSA public key encrypted text in the format PADDING::OTP::MESSAGE::HASH::PADDING. The "s" action is designed for scanned events and will show as OTP text on screen. The "c" action is designed for click events. The difference is that click events will cause the OTP code to be put in the user's clipboard instead, so the user immediately can proceed to pasting the code inside the OTP field. HASH is constructed by creating a md5 out of OTP + MESSAGE + OTP, where + denotes string concatenation. This HASH protects against some rough forms of malleability attacks on the encrypted text. The sandwiched construction prevents a attacker from moving the separator between OTP and MESSAGE. Note that the screenshots of the app has been intentionally censored to prevent trademark and/or copyright infringements (UI of android and other apps are copyright protected), as the interaction in the app is provided via a dialog box that appear on top of the calling app that caused the authentication to happen. If there is any issues on the app, you can find example code and more instructions on the public GitHub page, as this app is Open Source. Also, feel free to create any issues in the public github tracker.

Security & authenticity

Security rating: Trusted

Signing certificate

  • Signature matches the Google Play version Checked by the source store on Jan 14, 2018.
  • Certificate issued to “Sebastian Nielsen” This is the certificate of the Google Play version.

Store checks and file details

  • Developer signature verified Jun 2, 2020
  • Validated against Google Play Jan 14, 2018
  • Antivirus scan passed Nov 10, 2020
  • Signed byCN=Sebastian Nielsen, L=Goteborg, ST=Vastra Gotaland, C=SE
  • Signing certificate (SHA-1)7D:76:8B:BD:F9:FA:0E:30:E5:A7:B6:EC:8C:F9:91:B3:B6:64:84:80
  • File MD599ef26d3f484b26e116314afabc339dc
  • Uploaded by “devjam” Silver tier · 6,469 followers · uploading since 2016

Scans and ratings come from the source store; the certificate comparisons are AAPKs's own, made from the files' published signatures. AAPKs doesn't scan files itself — compare the MD5 and signer after downloading.

Required hardware & features

QRSA OTP Authentication APK: questions and answers

Can I install this APK over the version I already have?

Yes, if your installed copy is older. It is signed like the Google Play version, so Android installs it as an update and keeps your data.

Is the QRSA OTP Authentication APK safe?

No one can promise that a file is safe, but some things can be checked. The source store rates this file Trusted. Its signature matches the Google Play version. After downloading, check that the file's MD5 is 99ef26d3f484b26e116314afabc339dc.

Tags

More Tools apps