How AmberHush protects your photos
Security claims are only useful if you can check them. Here is what AmberHush encrypts, who holds the keys, where its protection ends, and how to get your photos back without the app.
What’s encrypted
Everything in your vault is stored as BGE v3 files: photos, videos, both parts of Live Photos, thumbnails, album names, favorites, and the catalog that records capture dates, locations and file names. Each file gets its own random AES-256-GCM key, which encrypts the data and detects any change to it. That key is in turn encrypted with your vault’s RSA-4096 public key.
Nothing is kept on disk as a plain file. Imports are encrypted as they stream in, and decrypted photos exist only in memory while you look at them. There are two short-lived exceptions:
- iOS only hands over the video part of a Live Photo as a file. It’s written to a protected staging folder for about three seconds and deleted as soon as it’s sealed.
- When you share a photo, a decrypted copy goes to the share sheet and is deleted when the sheet closes.
Someone with a copy of the files can still see how many encrypted files there are and their sizes, each file’s BGE header with a key identifier, and a backup’s date and total size.
Who holds the keys
Your vault’s private key is the only thing that can decrypt it, and AmberHush never sends it anywhere. On your iPhone it is kept encrypted, in one of two ways:
| Master password mode | Face ID mode | |
|---|---|---|
| The key is protected by | Your master password, stretched with PBKDF2 as BGE Password Mode specifies | A random master password of at least 128 bits, kept only in this iPhone’s Keychain and never synced to iCloud |
| Day to day | Face ID if you turn it on, accepted only for the faces enrolled now | Face ID |
| Your iPhone passcode | Never accepted | Accepted as the fallback |
Two more ways back in, both kept by you:
- Recovery code: 28 characters you save yourself. It resets a forgotten master password and opens your backups on another iPhone.
- Key file: an export of the private key, protected by a password you choose.
The developer has none of these. If you lose your master password and your recovery code, and have no key file, nobody can recover your photos.
The secure camera
The camera doesn’t need the private key. Each shot is encrypted with your vault’s public key the moment it’s taken, which is why the camera can open from the Lock Screen or Control Center without unlocking the vault. Someone using it there can add photos but can’t see any that are already in the vault.
Photos stay in memory until they’re sealed, and videos are encrypted in 1 MB pieces while they record. Everything taken is checked and added to the library the next time you unlock.
Private spaces
Each private space has its own key, protected by its own password. Your master password, Face ID and iPhone passcode can’t open, list or delete it. Its name is stored inside it, so it only appears once the space is open.
Private spaces are kept out of sight, not hidden in the cryptographic sense: someone examining the files can tell that encrypted spaces exist, even without being able to see what’s in them.
Backups
A backup is a copy of the encrypted files plus an encrypted list of them, written to a folder you choose. Nothing is decrypted on the way, and each file is read back and checked after it’s written. You can verify a whole backup later, or browse it in the app.
Backups only add: a photo you delete from the vault stays in the backups that already have it. To remove it everywhere, delete or replace those backups too.
Include in iPhone Backup is off by default. If you turn it on, the encrypted vault becomes part of your iPhone’s backup in iCloud or on your computer.
What it protects against
- Someone who picks up or finds your iPhone but doesn’t have your master password (or, in Face ID mode, your passcode).
- Someone who copies the app’s files, an iPhone backup or your AmberHush backups. They get encrypted data only and would have to guess your master password offline, so choose a strong one. In Face ID mode the random password makes guessing impractical.
- A cloud service or drive that stores your backups. It sees encrypted files only.
- AmberHush going away. The format is public, and a free tool can decrypt it.
What it can’t protect against
- In Face ID mode, someone who knows your iPhone passcode.
- Someone who makes you unlock the vault, or uses it while it’s unlocked.
- A photo of your screen taken with another device.
- Malware or an attacker in full control of iOS.
- Copies you share or export yourself.
- The record of camera and microphone use in iOS’s App Privacy Report, which shows when AmberHush used them, though not what was taken.
- Losing every way back in: without your master password, recovery code or key file, the vault can’t be opened.
AmberHush hasn’t had an independent security audit yet. The file format is public so that anyone can check its design.
Decrypting without AmberHush
Every file is standard BGE v3, described in the public specification. With a backup and one of your credentials, the free bge command-line tool for macOS and Linux decrypts it. The same steps, with your vault’s Key ID, are in the app under Settings › Help, in “If AmberHush Is Gone”.
- Install bge:
brew install --cask dotbge/tap/bge, or download it from dotbge.com. - Get your private key from the backup:
- With the master password:
bge decrypt identity.password.bge -p, then enter the master password. - With the recovery code:
bge decrypt recovery.private.bge -p, enter the code exactly as written, then use that recovery key to openidentity.recovery.bge. - With a key file:
bge decrypt identity.private.bge -p, then enter its export password.
- With the master password:
- Decrypt photos with the key:
bge decrypt <photo>.bge -k key.pem. The backup’s file list, named inmanifest.jsonunder “list”, says which file is which; decrypt it the same way.
When it goes online
AmberHush has no servers. It goes online only for:
- the App Store, when you buy or restore AmberHush Pro;
- Apple Maps, if you turn on Maps and Place Names, to show where a photo was taken;
- the backup locations you choose, such as iCloud Drive, which iOS uploads.
See the privacy policy for details.