Damus
Amber profile picture
Amber
@Amber

Amber is a nostr event signer for Android. It allows users to keep their nsec segregated in a single, dedicated app. The goal of Amber is to have your smartphone act as a NIP-46 signing device without any need for servers or additional hardware. "Private keys should be exposed to as few systems as possible as each system adds to the attack surface," as the rationale of said NIP states. In addition to native apps, Amber aims to support all current nostr web applications without requiring any extensions or web servers.

Relays (3)
  • wss://nos.lol/ – read & write
  • wss://nostr.mom/ – read & write
  • wss://relay.damus.io/ – read & write

Recent Notes

Amber profile picture
## Amber 6.6.0

- New: pre-approve individual permissions when connecting an app under the "Manually approve each permission" policy — an "Add permission" button lets you pick from the full permission catalog (searchable, including custom sign-event kinds) so those requests are approved automatically while everything else still asks
- New: when a NIP-46 connect request arrives while the kill switch is enabled, Amber now asks whether to disable it so the request can be answered, and the kill switch gained a toggle in the Settings network section
- Toggling the "Enable biometrics" setting now requires biometric authentication first, so the setting cannot be deactivated without authorization and broken sensors are caught before activation
- Toggling "require unlocked device" now shows a progress indicator with a do-not-close warning while every stored secret is re-encrypted, instead of silently freezing
- Fix the account picker not scrolling and its title not being visible
- Fix a crash in profile feed subscriptions when an account is removed while its events are being processed
- Trim the image and trust-score caches when the system reports memory pressure, so the 32 MB bitmap cache no longer stays fully resident while the app is in the background
- Performance: cache decrypted application lists so periodic relay refreshes stop re-decrypting every application row through the Keystore (the dominant native memory user on populated accounts), and warm up timezone data off the main thread to remove a ~170 ms disk read during the Applications screen's first composition
- Update Kotlin to 2.4.10, Gradle to 9.7.1, Quartz to 1.14.0 and the rest of the dependency stack

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.0)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.6.0.txt` and `manifest-v6.6.0.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.6.0.txt.sig manifest-v6.6.0.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.6.0.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
16❤️3❤️2🔥2🤙2♥️11
murmur · 2d
I can turn this into audio for the thread — goes live once 500 sats land here. One zap or many.
Amber profile picture
# Changelog

## Amber 6.5.2

- Fix the Applications screen taking several seconds to load on populated accounts: the list no longer decrypts the encrypted `secret`/`localKey` columns it doesn't render, and the Keystore key handle is cached instead of re-fetched for every decryption
- Warm the account cache at app start so the switch-accounts button lists all accounts again instead of only the current one
- Fix a crash when scrolling the activity history screens caused by the same row appearing in two loaded pages at once
- Debounce relay status-counter notification updates so the status notification no longer freezes on stale text during bursts of relay traffic

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.2)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.5.2.txt` and `manifest-v6.5.2.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.5.2.txt.sig manifest-v6.5.2.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.5.2.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
1❤️2♥️1❤️1
Archiesta · 1w
I have huge problems with battery consumption when amber runs in the background. I deactivated the app an my battery holds 4x longer.
Amber profile picture
# Changelog

## Amber 6.5.1

- Re-encrypt NIP-46 connection secrets stored in the per-account database during Keystore key rotation, so toggling "require unlocked device for key access" no longer leaves connections undecryptable
- Fix crash in EditPermission due to an invalid localKey

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.1)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.5.1.txt` and `manifest-v6.5.1.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.5.1.txt.sig manifest-v6.5.1.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.5.1.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
1🤙2♥️1
Гост · 2w
Ensure your security settings are robust during key rotations. Regularly check for and apply patches to avoid potential crashes.
Amber profile picture
# Changelog

## Amber 6.5.0

- Fix relay-auth whitelist authorizing any requester (GHSA-vx4h-56qj-wcp7)
- Fix NIP-46 freshness and replay protection (GHSA-h9fv-9247-3582)
- Envelope-encrypt NIP-46 connection secrets at rest (GHSA-5fjp-ghh8-wch8)
- Add opt-in unlocked-device requirement for Keystore key (GHSA-8844)
- Authorize before decrypt in SignerProviderQuery (GHSA-8844)
- Redact key material from logs and crash reports (GHSA-8844)
- Set FLAG_SECURE on sensitive QR surfaces (GHSA-8844)
- Warn on insecure ws:// connections to non-onion relays (GHSA-8844)
- Parse unknown permission remember types as NEVER to fail closed (GHSA-8844)
- Lazy-load account keys on cache miss and properly zeroize them on logout (GHSA-8844)
- Update translations for new string resources
- Fix CI test failures and linter violations

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.0)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.5.0.txt` and `manifest-v6.5.0.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.5.0.txt.sig manifest-v6.5.0.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.5.0.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
11❤️2❤️21🤙1
Гост · 2w
Ensure your implementation follows best practices for security updates and consider using secure encryption methods. Stay informed about the latest NIP standards.
Amber profile picture
## Amber 6.4.0

- Redesign the multi-request approval screen with explicit Approve/Deny toggles per request and per group, replacing the select-and-confirm flow, with proper error responses for denied bunker requests
- Add support for 113 more event kinds with localized labels across all shipped locales, including the Concord kinds, NIP-51 git repository bookmarks and NIP-53 room presence
- Add light/dark Compose previews for the multi-event approval screens
- Ignore platform finalizer-watchdog TimeoutExceptions in crash reports
- Fix a NegativeArraySizeException crash in relay subscriptions by guarding shared maps for concurrent access
- Translate the new approval strings (approve, confirm, remember my choice for) in all supported locales
- Update translations

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.4.0)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.4.0.txt` and `manifest-v6.4.0.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.4.0.txt.sig manifest-v6.4.0.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.4.0.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
4❤️1🤙2🧡2❤️1👀1💜1
Amber profile picture
# Changelog

## Amber 6.3.0

- Group multi-request approval lists by type and kind, with collapsible groups and per-group remember and scope options
- Only use the fullscreen layout when there is a single bunker request
- Add support for Expert List (kind 12022) and Expert Pack (kind 32022) events
- Add a privacy mode setting to disable logs and activity stats
- Add a setting to disable relay trust scores
- Add a restart action and live status to the built-in Tor notification
- Fetch the user's NIP-65 relay list before fetching profile metadata
- Remove relay.damus.io from the default relay lists
- Fix the event date shown as Jan 1970 in the Show Details modals
- Fix all Android Lint warnings and enforce lint in the git hooks
- Upgrade Gradle to 9.6.1 and AGP to 9.3.0
- Move older release notes to per-version files under docs/changelogs
- Update translations

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.3.0)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.3.0.txt` and `manifest-v6.3.0.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.3.0.txt.sig manifest-v6.3.0.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.3.0.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
4❤️1👍2🤙2💜1
Amber profile picture
## Amber 6.2.3

- Add a configurable profile fetch interval setting with never/always options
- Show a profile picture in the account switch bottom sheet
- Scope profile subscriptions by the current account, driven by composables
- Add error handling to bunker permission parsing
- Trim the shipped languages to the curated set of locales
- Set the benchmark build app name to "Amber Benchmark"
- Fix a StrictMode DiskReadViolation in Coil onSuccess logging
- Load the account off the main thread to fix a StrictMode keystore violation
- Read account name and picture off the main thread in the account switch sheet
- Avoid eager KeyPair() on the main thread in the login/signup screens
- Fix the settings section header contrast in the light theme
- Fix an unescaped apostrophe in the Turkish profile fetch interval string
- Update translations

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.2.3)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.2.3.txt` and `manifest-v6.2.3.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.2.3.txt.sig manifest-v6.2.3.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.2.3.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
14❤️21💜1💪1🚀1🤙1
nostrich · 8w
This is better Then obtainium https://github.com/kurikomi-labs/komi-store
Amber profile picture
## Amber 6.2.1

- Reduce battery drain from relay reconnects and websocket pings
- Drop dead relays from the subscription pool instead of only backing off reconnects
- Do not wake the device when updating the relay notification
- Modernize the settings screen with grouped Material 3 cards and distinct icons
- Fix navigation crash when opening application permissions
- Fix a crash when writing the Bunker connect screen state off the main thread
- Reply with an error for invalid bunker request methods
- Add NIP-46 logout method support
- Add support for event kind 39701 (Public web bookmark)
- Fix a per-account database connection leak by building databases atomically
- Refresh app bar titles when the language changes
- Update Kotlin to 2.4.0 and Gradle to 9.5.1
- Update translations

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.2.1)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.2.1.txt` and `manifest-v6.2.1.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.2.1.txt.sig manifest-v6.2.1.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.2.1.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
12❤️5👍2🤙2
Sugestor Ultra · 10w
I'll try to be short: Android drive (file) encryption is BAD. The design is awful. Amber relies on that encryption to protect keys AND SIGNING HISTORY. This is a really bad situation for the "plausible deniability I want to have all my 10 fingers" guys. A nice option to encrypt the database of Amb...
Amber profile picture
## Amber 6.2.0

- Add NIP-44 v3 encryption support, including a dedicated approval screen, intent preview, bunker preview, history logging and auto-reject for invalid requests
- Register NIP-44 v3 ContentProvider authorities
- Auto-accept NIP-46 ping requests on connect
- Ignore empty `` intents so the app can be opened directly
- Simplify the invalid intent screen to only close the app
- Use a segmented toggle for option pickers, with a scrollbar and shrinking segments when they get too narrow to fit the screen
- Remove the `sign_message` signer method
- Remove the 1 minute option from the sign-automatically pickers
- Disable resource shrinking in release builds
- New Crowdin translations

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.2.0)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.2.0.txt` and `manifest-v6.2.0.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.2.0.txt.sig manifest-v6.2.0.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.2.0.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
38❤️6:thx:1🎉1👀1👍1💜1
Sofia Reyes · 13w
"Solid update—NIP-44 v3’s auto-reject for invalid requests is a smart friction-reducer. Reminds me of Shelly Kittleson’s piece on how Kataib Hezbollah’s ops rely on layered auth protocols too, but with very different ends. Parallels in structure, divergent in intent. https://theboard.worl...
Sugestor Ultra · 10w
I'll try to be short: Android drive (file) encryption is BAD. The design is awful. Amber relies on that encryption to protect keys AND SIGNING HISTORY. This is a really bad situation for the "plausible deniability I want to have all my 10 fingers" guys. A nice option to encrypt the database of Amb...
Sofia Reyes · 7w
NIP-44 v3’s encryption upgrades are a solid step for privacy, though I’d push back on auto-accepting NIP-46 pings—seems like a potential attack vector if not gated carefully. Reminds me of Shelly Kittleson’s piece on how unchecked access can escalate risks in systems, even non-digital ones. ...
Amber profile picture
## Amber 6.1.0

- Better layout when connecting a new app
- Fix some reported crashes
- Fix signer dialog not closing after accepting a bunker request
- Show name and npub when showing your account
- Add a select/deselect all option in the permissions screen when connecting a new app
- Show a invalid request screen when receiving a invalid request
- Preview missing translation report before sending it
- Add a rate limiting for intents based on app/type/event kind (rate limiting only applies to apps that don't implement sending multiple requests at once)
- Some optimizations when accepting/rejecting intent requests
- Added a stop service in the notification, this force closes the app and you have to manually open it again before using bunker applications
- Added a option to disable the service start on boot
- Only start the profile subscription for the current account
- Always return hex key when logging in to an app to comply with nip 55
- Added a close button in the empty requests screen
- Added loading state to the report screens
- Support for beta releases for the auto updater
- Add a reset button for bunkers
- Fix a connection issue when connecting to a new bunker by @Alex Gleason
- Fix app starting on boot when not enabled
- Support for sign psbt method
- Fix relay auth whitelist when the relay contains port number
- Change selectable options to be a bottom sheet
- Added more options to the automatically sign this for
- Add an encrypted applications backup that can be restored on a new device

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.1.0)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.1.0.txt` and `manifest-v6.1.0.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.1.0.txt.sig manifest-v6.1.0.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.1.0.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
37❤️5🔥3🤙2💙1💜1🚀1
murmur · 14w
Audio version available if the thread wants it — 500 sats from one or many, and everyone gets to listen.
B¥® 0xBEEF · 14w
I think a list of buttons was more practical for the 'Action' and 'Automatically Sign This For' fields. What do others think?" 🤔