OneBox, short name 1bx

A private messaging app with three codes.

OneBox is a private messaging app. Its short name is 1bx.

You set a real code, a decoy code and a kill code. Messages are encrypted on the device before they are stored anywhere. The app is built for someone who needs one conversation to stay out of sight, and it is built to be quiet about that.

There is nothing to download yet and there is no signup on this page. What follows describes the parts of the app that are built.

The shape of it, in numbers

3codes you set: real, decoy, kill
6digits in the gate, the same shape as two-factor verification
256bits of AES key per message
2implementations checked against each other on the wire format

On the device

How messages are protected

The encryption happens on the device, before anything is written down. The key material is generated on the device as well.

Encrypted on the device

Each message is encrypted with AES-256-GCM, on the device, before it is stored or sent.

A fresh key for every message

Every message gets a fresh AES key and a fresh IV. Nothing is reused across messages.

The message key is itself wrapped

The per-message AES key is wrapped with RSA-OAEP. A symmetric key protected by an asymmetric one is hybrid encryption.

The private key never leaves

The RSA private key is generated on the device and never leaves it.

Tampering fails instead of lying

If a single bit of an encrypted message is flipped, decryption fails. It does not quietly return corrupted text that looks like a real message.

Two implementations agree

The Node and Dart implementations are checked against each other on the wire format, with a shared test vector. If one drifts, the check fails.

The gate

The screen that asks for your code

It is a six-digit field with ordinary failure wording. It names neither the product nor the account. To anyone holding the phone it looks like the two-factor prompt every other app has.

The code is the key, not a password

There is no stored passcode to compare against. The vault key is stored wrapped with AES-256-GCM under a key derived with PBKDF2, and the code is what unwraps it.

Nothing is left lying around

The plaintext copy of that key is deleted at install. From then on there is nothing on the device that opens the vault without the code.

Guessing is slow

A wrong code is rejected. Repeated attempts trigger a cooldown before another attempt is allowed.

This also means the app cannot help you get back in. There is no recovery path, because a recovery path would be a second way into the vault.

Three codes

Real, decoy, kill

You choose all three. The kill code and the decoy are handled the same way, at the same speed, with the same wording on screen.

Real code
Opens your messages.
Decoy code
Opens a real, working notes app. You can add, edit, delete and search notes, and they persist. It is not a mock screen and not an empty shell.
Kill code
Cryptographically destroys the key. It is instant, silent, permanent, and irreversible for you as well.

The decoy holds up

Notes written under the decoy code save, edit, search and delete like notes in any other app. Someone who taps through it for a minute finds a notes app.

The kill code looks like nothing

On screen the kill code and the decoy are indistinguishable. There is no confirmation prompt, no warning, no animation and no different message.

The name and icon stay put

After a wipe the app keeps its name and icon. It does not vanish from the home screen, because an app that disappears is its own announcement.

Fat-finger protection

Because there is no confirmation step, the kill code is required to differ from your real code in at least two digits. That rule is enforced as you type.

Day to day

On the phone

The ordinary behaviour of the app is part of the design. Most of it is about not drawing attention.

No notifications, ever

The app includes no push package and asks for no notification permission. There is no lock-screen preview, because there is no notification to preview.

The vault is out of cloud backup

On Android the vault is excluded from cloud backup, so the backup service does not take it off the device.

One-tap lock

A toolbar icon that looks like any other clears the plaintext on screen. It clears before the cover is drawn.

You tap to read

A message is decrypted when you open it. Nothing is decrypted on arrival; you tap each message to read it.

Feedback that goes one way

A button in the app emails a report privately to one mailbox. The destination address is kept on the server and is never sent inside the app.

Disguises you can install as

The app installs as a web app, under a name and icon you pick at install time from a set of ready-made disguises. Each one is a separate installable app reached from its own address.

  • Weather
  • Calculator
  • Notes
  • Calendar
  • Files
  • Photos
  • Compass
  • Settings

Status

Where this stands

OneBox is in development. The parts of it described above are built. There is nothing to download yet, and there is no signup on this page.

Questions about OneBox

Write to us.

hello@1bx.app