OneBox, short name 1bx
A private messaging app with three codes.
OneBox is a private messaging app. Its short name is 1bx.
You set a real code, a decoy code and a kill code. Messages are encrypted on the device before they are stored anywhere. The app is built for someone who needs one conversation to stay out of sight, and it is built to be quiet about that.
It is unfinished and unreleased. There is nothing to download yet and there is no signup on this page. What follows describes the parts that work today, and then states plainly what the app cannot do.
The shape of it, in numbers
On the device
How messages are protected
The encryption happens on the device, before anything is written down. The key material is generated on the device as well.
Encrypted on the device
Each message is encrypted with AES-256-GCM, on the device, before it is stored or sent.
A fresh key for every message
Every message gets a fresh AES key and a fresh IV. Nothing is reused across messages.
The message key is itself wrapped
The per-message AES key is wrapped with RSA-OAEP. A symmetric key protected by an asymmetric one is hybrid encryption.
The private key never leaves
The RSA private key is generated on the device and never leaves it.
Tampering fails instead of lying
If a single bit of an encrypted message is flipped, decryption fails. It does not quietly return corrupted text that looks like a real message.
Two implementations agree
The Node and Dart implementations are checked against each other on the wire format, with a shared test vector. If one drifts, the check fails.
The gate
The screen that asks for your code
It is a six-digit field with ordinary failure wording. It names neither the product nor the account. To anyone holding the phone it looks like the two-factor prompt every other app has.
The code is the key, not a password
There is no stored passcode to compare against. The vault key is stored wrapped with AES-256-GCM under a key derived with PBKDF2, and the code is what unwraps it.
Nothing is left lying around
The plaintext copy of that key is deleted at install. From then on there is nothing on the device that opens the vault without the code.
Guessing is slow
A wrong code is rejected. Repeated attempts trigger a cooldown before another attempt is allowed.
This also means the app cannot help you get back in. There is no recovery path, because a recovery path would be a second way into the vault.
Three codes
Real, decoy, kill
You choose all three. The kill code and the decoy are handled the same way, at the same speed, with the same wording on screen.
- Real code
- Opens your messages.
- Decoy code
- Opens a real, working notes app. You can add, edit, delete and search notes, and they persist. It is not a mock screen and not an empty shell.
- Kill code
- Cryptographically destroys the key. It is instant, silent, permanent, and irreversible for you as well.
The decoy holds up
Notes written under the decoy code save, edit, search and delete like notes in any other app. Someone who taps through it for a minute finds a notes app.
The kill code looks like nothing
On screen the kill code and the decoy are indistinguishable. There is no confirmation prompt, no warning, no animation and no different message.
The name and icon stay put
After a wipe the app keeps its name and icon. It does not vanish from the home screen, because an app that disappears is its own announcement.
Fat-finger protection
Because there is no confirmation step, the kill code is required to differ from your real code in at least two digits. That rule is enforced as you type.
Day to day
On the phone
The ordinary behaviour of the app is part of the design. Most of it is about not drawing attention.
No notifications, ever
The app includes no push package and asks for no notification permission. There is no lock-screen preview, because there is no notification to preview.
The vault is out of cloud backup
On Android the vault is excluded from cloud backup, so the backup service does not take it off the device.
One-tap lock
A toolbar icon that looks like any other clears the plaintext on screen. It clears before the cover is drawn.
You tap to read
A message is decrypted when you open it. Nothing is decrypted on arrival; you tap each message to read it.
Feedback that goes one way
A button in the app emails a report privately to one mailbox. The destination address is kept on the server and is never sent inside the app.
Disguises you can install as
The app installs as a web app, under a name and icon you pick at install time from a set of ready-made disguises. Each one is a separate installable app reached from its own address.
- Weather
- Calculator
- Notes
- Calendar
- Files
- Photos
- Compass
- Settings
The one-tap lock and the backup exclusion are Android features. There is no iOS version of either one.
What this cannot do
An app that feels safer than it is, is dangerous. So here are the limits, in plain language.
- If someone has your unlocked phone and knows where to look, no app on it helps. The lock screen is the boundary that matters, and this app cannot extend it.
- Someone with access to your email account or your cloud account can see that something is going on, even when they cannot read the content.
- A disguise, if it is discovered, reads as a deliberate secret. That is worse than a boring app that was installed and forgotten.
- There is no automatic decryption. You tap each message to decrypt it.
- There is no forward secrecy and no key ratchet. That was a deliberate decision for this version, not an oversight.
- There is no iOS version of the lock button or the backup exclusion. Those two remain Android only.
- This is not a substitute for safety planning. Established domestic-abuse support resources exist for the non-technical part of this problem, and that part matters more than the software.
Status
Where this actually stands
OneBox is unfinished and unreleased. It has never run on a physical phone, so nothing on this page describes real-world use. There is no stable release and no date for one.
- Unfinished. Some paths are complete and checked against each other. Others are deliberately absent, and the limits panel above lists them.
- Unreleased. There is nothing to install, no stable release, and no signup on this page.
- Never run on a phone. No security-relevant path in this app has ever been exercised on a physical device.
- No certification. There is no security certification and no independent review of this work.
If a claim here reads as stronger than the app deserves
Say so. This page is written to be checked against the app, and a correction is more useful than a compliment.