Insight series

Building Signet

The security decisions behind Signet: vault sessions, hardware boundaries, backup formats, threat modelling, and claims that can be checked.

Series progress

5 of 5 published

New instalments appear here as they are released.

These notes document decisions made while building Signet, the Attomus authenticator for iOS and Android. They cover the points where security properties depend on precise boundaries rather than reassuring language.

Part 3 of 5

Why We Chose a 28-Byte Backup Header

A backup format is more than ciphertext. Signet's 28-byte header makes each backup self-describing, upgradeable, and tamper-evident without hiding the parameters needed to derive its key.

Read article
About this series

Building Signet

The security decisions behind Signet: vault sessions, hardware boundaries, backup formats, threat modelling, and claims that can be checked.

All insights
Newsletter

Subscribe for Attomus insight

Briefings on cybersecurity, resilient delivery, and the practical realities of operating in higher-trust environments.

You can unsubscribe with one click, and we will never share your email address. Privacy notice.

Submitting stays on Attomus, and we will guide you to the next step straight after.