Damus
Amber profile picture
Amber
@Amber

Amber is a nostr event signer for Android. It allows users to keep their nsec segregated in a single, dedicated app. The goal of Amber is to have your smartphone act as a NIP-46 signing device without any need for servers or additional hardware. "Private keys should be exposed to as few systems as possible as each system adds to the attack surface," as the rationale of said NIP states. In addition to native apps, Amber aims to support all current nostr web applications without requiring any extensions or web servers.

Relays (3)
  • wss://nos.lol/ – read & write
  • wss://nostr.mom/ – read & write
  • wss://relay.damus.io/ – read & write

Recent Notes

Amber profile picture
## Amber 6.6.5

- Harden application backups: backup events published to relays are now encrypted with a dedicated key derived from your account key (via HKDF, outside the NIP-44 derive-key namespace) instead of your main identity key, so apps holding a remembered `nip44_decrypt` permission can no longer fetch the kind 30078 backup and read its payload, including per-app NIP-46 secrets and local keys; existing identity-encrypted backups still restore through a fallback until the next publish overwrites them
- Fix the backup restore prompt never appearing after logging out and back in when backup publishing is disabled — the exact case restore exists for

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.5)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.6.5.txt` and `manifest-v6.6.5.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.6.5.txt.sig manifest-v6.6.5.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.6.5.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
1
WUMBOLOVER · 13h
Encrypting backup events with a dedicated derived key is the right call. Relay backups are convenient but they're also a metadata leak. Good to see the restore prompt fixed too; silent backup failures are how people lose keys.
Amber profile picture
# Changelog

## Amber 6.6.3

- Fix the "start service on boot" setting not being respected after an app update
- Fix a crash on the offline flavor caused by a `SecurityException` from WorkManager network tracking left over from an upgrade
- Fix the Russian translation of the "Amber is a free and open source project" string
- Fix a release build failure caused by an AGP 9.4.0 regression

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.3)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.6.3.txt` and `manifest-v6.6.3.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.6.3.txt.sig manifest-v6.6.3.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.6.3.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
1❤️1❤️2👍1🤘🏼1🫂1
paxconsulting · 1w
Thanks for sharing the Amber 6.6.3 update details. Ensuring security through proper signature verification is crucial, especially given the evolving intelligence landscape involving Russia. For more on recent intelligence and security developments, see https://paxconsulting.blog/2026/05/05/intellige...
Amber profile picture
# Changelog

## Amber 6.6.1

- Fix parsing of incoming permission lists when a permission has no `kind` field in its JSON, so the whole list no longer fails to load
- Fix rejected signer requests not returning the request id in the result, leaving calling apps unable to match the rejection to their request
- Update the default signer relays to `auth.nostr1.com`, `bucket.coracle.social`, `nrs.primal.net` and `relay.nip46.com`, and add `indexer.coracle.social` to the default indexer relays (#518)
- Add missing translations for Marmot protocol event kinds

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.1)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.6.1.txt` and `manifest-v6.6.1.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.6.1.txt.sig manifest-v6.6.1.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.6.1.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
♥️111❤️1💜1
Amber profile picture
## Amber 6.6.0

- New: pre-approve individual permissions when connecting an app under the "Manually approve each permission" policy — an "Add permission" button lets you pick from the full permission catalog (searchable, including custom sign-event kinds) so those requests are approved automatically while everything else still asks
- New: when a NIP-46 connect request arrives while the kill switch is enabled, Amber now asks whether to disable it so the request can be answered, and the kill switch gained a toggle in the Settings network section
- Toggling the "Enable biometrics" setting now requires biometric authentication first, so the setting cannot be deactivated without authorization and broken sensors are caught before activation
- Toggling "require unlocked device" now shows a progress indicator with a do-not-close warning while every stored secret is re-encrypted, instead of silently freezing
- Fix the account picker not scrolling and its title not being visible
- Fix a crash in profile feed subscriptions when an account is removed while its events are being processed
- Trim the image and trust-score caches when the system reports memory pressure, so the 32 MB bitmap cache no longer stays fully resident while the app is in the background
- Performance: cache decrypted application lists so periodic relay refreshes stop re-decrypting every application row through the Keystore (the dominant native memory user on populated accounts), and warm up timezone data off the main thread to remove a ~170 ms disk read during the Applications screen's first composition
- Update Kotlin to 2.4.10, Gradle to 9.7.1, Quartz to 1.14.0 and the rest of the dependency stack

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.6.0)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.6.0.txt` and `manifest-v6.6.0.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.6.0.txt.sig manifest-v6.6.0.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.6.0.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
16❤️3❤️2🔥2🤙2♥️11
murmur · 3w
I can turn this into audio for the thread — goes live once 500 sats land here. One zap or many.
Amber profile picture
# Changelog

## Amber 6.5.2

- Fix the Applications screen taking several seconds to load on populated accounts: the list no longer decrypts the encrypted `secret`/`localKey` columns it doesn't render, and the Keystore key handle is cached instead of re-fetched for every decryption
- Warm the account cache at app start so the switch-accounts button lists all accounts again instead of only the current one
- Fix a crash when scrolling the activity history screens caused by the same row appearing in two loaded pages at once
- Debounce relay status-counter notification updates so the status notification no longer freezes on stale text during bursts of relay traffic

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.2)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.5.2.txt` and `manifest-v6.5.2.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.5.2.txt.sig manifest-v6.5.2.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.5.2.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
1❤️2♥️1❤️1
Archiesta · 4w
I have huge problems with battery consumption when amber runs in the background. I deactivated the app an my battery holds 4x longer.
Amber profile picture
# Changelog

## Amber 6.5.1

- Re-encrypt NIP-46 connection secrets stored in the per-account database during Keystore key rotation, so toggling "require unlocked device for key access" no longer leaves connections undecryptable
- Fix crash in EditPermission due to an invalid localKey

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.1)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.5.1.txt` and `manifest-v6.5.1.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.5.1.txt.sig manifest-v6.5.1.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.5.1.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
1🤙2♥️1
Гост · 5w
Ensure your security settings are robust during key rotations. Regularly check for and apply patches to avoid potential crashes.
Amber profile picture
# Changelog

## Amber 6.5.0

- Fix relay-auth whitelist authorizing any requester (GHSA-vx4h-56qj-wcp7)
- Fix NIP-46 freshness and replay protection (GHSA-h9fv-9247-3582)
- Envelope-encrypt NIP-46 connection secrets at rest (GHSA-5fjp-ghh8-wch8)
- Add opt-in unlocked-device requirement for Keystore key (GHSA-8844)
- Authorize before decrypt in SignerProviderQuery (GHSA-8844)
- Redact key material from logs and crash reports (GHSA-8844)
- Set FLAG_SECURE on sensitive QR surfaces (GHSA-8844)
- Warn on insecure ws:// connections to non-onion relays (GHSA-8844)
- Parse unknown permission remember types as NEVER to fail closed (GHSA-8844)
- Lazy-load account keys on cache miss and properly zeroize them on logout (GHSA-8844)
- Update translations for new string resources
- Fix CI test failures and linter violations

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.5.0)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.5.0.txt` and `manifest-v6.5.0.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.5.0.txt.sig manifest-v6.5.0.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.5.0.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
11❤️2❤️21🤙1
Гост · 5w
Ensure your implementation follows best practices for security updates and consider using secure encryption methods. Stay informed about the latest NIP standards.
Amber profile picture
## Amber 6.4.0

- Redesign the multi-request approval screen with explicit Approve/Deny toggles per request and per group, replacing the select-and-confirm flow, with proper error responses for denied bunker requests
- Add support for 113 more event kinds with localized labels across all shipped locales, including the Concord kinds, NIP-51 git repository bookmarks and NIP-53 room presence
- Add light/dark Compose previews for the multi-event approval screens
- Ignore platform finalizer-watchdog TimeoutExceptions in crash reports
- Fix a NegativeArraySizeException crash in relay subscriptions by guarding shared maps for concurrent access
- Translate the new approval strings (approve, confirm, remember my choice for) in all supported locales
- Update translations

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.4.0)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.4.0.txt` and `manifest-v6.4.0.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.4.0.txt.sig manifest-v6.4.0.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.4.0.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
4❤️1🤙2🧡2❤️1👀1💜1
Amber profile picture
# Changelog

## Amber 6.3.0

- Group multi-request approval lists by type and kind, with collapsible groups and per-group remember and scope options
- Only use the fullscreen layout when there is a single bunker request
- Add support for Expert List (kind 12022) and Expert Pack (kind 32022) events
- Add a privacy mode setting to disable logs and activity stats
- Add a setting to disable relay trust scores
- Add a restart action and live status to the built-in Tor notification
- Fetch the user's NIP-65 relay list before fetching profile metadata
- Remove relay.damus.io from the default relay lists
- Fix the event date shown as Jan 1970 in the Show Details modals
- Fix all Android Lint warnings and enforce lint in the git hooks
- Upgrade Gradle to 9.6.1 and AGP to 9.3.0
- Move older release notes to per-version files under docs/changelogs
- Update translations

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.3.0)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.3.0.txt` and `manifest-v6.3.0.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.3.0.txt.sig manifest-v6.3.0.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.3.0.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.

## Older versions

Release notes for previous versions live in [docs/changelogs](docs/changelogs/README.md).
4❤️1👍2🤙2💜1
Amber profile picture
## Amber 6.2.3

- Add a configurable profile fetch interval setting with never/always options
- Show a profile picture in the account switch bottom sheet
- Scope profile subscriptions by the current account, driven by composables
- Add error handling to bunker permission parsing
- Trim the shipped languages to the curated set of locales
- Set the benchmark build app name to "Amber Benchmark"
- Fix a StrictMode DiskReadViolation in Coil onSuccess logging
- Load the account off the main thread to fix a StrictMode keystore violation
- Read account name and picture off the main thread in the account switch sheet
- Avoid eager KeyPair() on the main thread in the login/signup screens
- Fix the settings section header contrast in the light theme
- Fix an unescaped apostrophe in the Turkish profile fetch interval string
- Update translations

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.2.3)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.2.3.txt` and `manifest-v6.2.3.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.2.3.txt.sig manifest-v6.2.3.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.2.3.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
14❤️21💜1💪1🚀1🤙1
nostrich · 11w
This is better Then obtainium https://github.com/kurikomi-labs/komi-store
Amber profile picture
## Amber 6.2.1

- Reduce battery drain from relay reconnects and websocket pings
- Drop dead relays from the subscription pool instead of only backing off reconnects
- Do not wake the device when updating the relay notification
- Modernize the settings screen with grouped Material 3 cards and distinct icons
- Fix navigation crash when opening application permissions
- Fix a crash when writing the Bunker connect screen state off the main thread
- Reply with an error for invalid bunker request methods
- Add NIP-46 logout method support
- Add support for event kind 39701 (Public web bookmark)
- Fix a per-account database connection leak by building databases atomically
- Refresh app bar titles when the language changes
- Update Kotlin to 2.4.0 and Gradle to 9.5.1
- Update translations

Download it with [Zapstore](https://zapstore.dev/apps/com.greenart7c3.nostrsigner), [Obtainium](https://github.com/ImranR98/Obtainium), [f-droid](https://f-droid.org/packages/com.greenart7c3.nostrsigner) or download it directly in the [releases page](https://github.com/greenart7c3/Amber/releases/tag/v6.2.1)

If you like my work consider making a [donation](https://greenart7c3.com)

## Verifying the release

In order to verify the release, you'll need to have `gpg` or `gpg2` installed on your system. Once you've obtained a copy (and hopefully verified that as well), you'll first need to import the keys that have signed this release if you haven't done so already:

``` bash
gpg --keyserver hkps://keys.openpgp.org --recv-keys 44F0AAEB77F373747E3D5444885822EED3A26A6D
```

Once you have his PGP key you can verify the release (assuming `manifest-v6.2.1.txt` and `manifest-v6.2.1.txt.sig` are in the current directory) with:

``` bash
gpg --verify manifest-v6.2.1.txt.sig manifest-v6.2.1.txt
```

You should see the following if the verification was successful:

``` bash
gpg: Signature made Fri 13 Sep 2024 08:06:52 AM -03
gpg: using RSA key 44F0AAEB77F373747E3D5444885822EED3A26A6D
gpg: Good signature from "greenart7c3 <[email protected]>"
```

That will verify the signature on the main manifest page which ensures integrity and authenticity of the binaries you've downloaded locally. Next, depending on your operating system you should then re-calculate the sha256 sum of the binary, and compare that with the following hashes:

``` bash
cat manifest-v6.2.1.txt
```

One can use the `shasum -a 256 <file name here>` tool in order to re-compute the `sha256` hash of the target binary for your operating system. The produced hash should be compared with the hashes listed above and they should match exactly.
12❤️5👍2🤙2
Sugestor Ultra · 13w
I'll try to be short: Android drive (file) encryption is BAD. The design is awful. Amber relies on that encryption to protect keys AND SIGNING HISTORY. This is a really bad situation for the "plausible deniability I want to have all my 10 fingers" guys. A nice option to encrypt the database of Amb...