Skip to content

sub rosa by naiveHA

F-Droid

Open source

Program the static password and/or OpenPGP keys to your YubiKey or Nitrokey 3

Version
2.1.0
Size
42.7 MB
Updated
Jul 14, 2026
Get from Download APK (v2.1.0)
Signing certificate on record

About this app

Uncomplicatedly simple: if you manage your long, complicated and secure passwords in a password manager app (like KeePassDroid) on your Android device, you can now "type" them easily on any other device, be it a phone, tablet, or PC running Windows, Linux, or macOS.

sub rosa allows you to program the static password of your YubiKey which then can be used to "type" the password with the touch of a finger.

Once you are done "typing" your long, complicated and secure password, remember to wipe clean your YubiKey... Is not much security if anyone can "type" your password by touching the YubiKey!

The various keyboards accept the following characters:

• US: space, \n, \t and abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!"#$%&'`()*+-=,./:;<>?@[\]^_{}|~ • UK: space, \n, \t and abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!@£$%&'`()*+-=,./:;<>?"[#]^_{}~¬ • DE: space, \n, \t and abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!"#$%&'()*+-=,./:;<>?^_`§´ÄÖÜßäöü • FR: space, \n, \t and abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!"$%&'()*+-=,./:;IT: space, \n, \t and abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789!"#$%&'()*+,-./:;?@\^_`|£§°çèéàìòù • MODHEX: bcdefghijklnrtuvBCDEFGHIJKLNRTUV

Since version 2.0.0, sub rosa has added support for OpenPGP. You can now provision an OpenPGP key onto your YubiKey or Nitrokey 3.

In keeping with the app’s motto, “Uncomplicatedly simple,” you can encrypt, decrypt, sign, and authenticate with your security key, then wipe it clean and write another OpenPGP key to change your digital identity.

SSH authentication is simpler now—you no longer need to reuse the same SSH key or buy multiple security keys

sub rosa is an Android app, built on top of YubiKit library provided by Yubico,

Version 2.0.0 - Adding support for Nitrokey 3 - Adding OpenPGP support for Yubikey and Nitrokey

Licensed under Apache-2.0, by naiveHA.

OfficialSignature VerifiedOpen Source

What's New in v2.1.0

Imported from the F-Droid repository index.

Version history

v2.1.0Latest
Signature continuous

Jul 14, 2026 · 42.7 MB · Android API 3137 · code 9

Imported from the F-Droid repository index.

VIBRATENFCacab.naiveha.subrosa.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

SHA-256 341950e8db7b250b965f62d37d4c432077d9054edf00cc081a1a6b2b5186745f

v2.0.0
Signature continuous

Jul 6, 2026 · 42.7 MB · Android API 3137 · code 8

Imported from the F-Droid repository index.

VIBRATENFCacab.naiveha.subrosa.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

SHA-256 4d8b69dd1bde424857466a4a817385cd83404ec53df5ede76123c276117672c1

v1.0.10
Signature continuous

Apr 19, 2026 · 4 MB · Android API 3136 · code 7

Imported from the F-Droid repository index.

VIBRATEacab.naiveha.subrosa.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSIONNFC

SHA-256 01f3909d376a5cf433004cd3eed7452732f5dda07895ce276ee3cd43d2e6db3f

Will it run on your device?

CompatibilityLikely to run

74%

  • Targets newer Android builds, so legacy devices may be excluded.
  • Multiple CPU architectures are covered.
  • Aligned with the latest Android target SDK expectations.
What changed in this release
Size delta
0 MB
Added permissions
None
Removed permissions
None

Installation Guide

1

Open Settings on your Android device

2

Go to Security → Unknown sources (or Install unknown apps)

3

Enable "Allow from this source" for your browser or file manager

4

Open the downloaded APK file from your Downloads folder

5

Tap "Install" and wait for installation to complete

6

Launch the app from your home screen

Make sure to re-enable Unknown Sources restrictions after installation for security.

How to install this safely

How to verify the file you downloaded

Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.

What the signing certificate proves

Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be acab.naiveha.subrosa is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.

How to roll back to an earlier version

If the current release misbehaves, 2.0.0 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall sub rosa by naiveHA first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.

Why we list sources instead of hosting everything

The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of sub rosa by naiveHA, and a listing is removed when the evidence for it stops holding up.

Get sub rosa by naiveHA

Every source we list for acab.naiveha.subrosa is legality-reviewed. Pirated or cracked builds are never offered.

Other sources

F-Droid listing

official

F-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.

Source code

verified publisher

The upstream repository this build is compiled from.

We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.

App Information

Developer
F-Droid
Category
Security Privacy
Android
12+
Architectures
arm64-v8a, armeabi-v7a, x86, x86_64
Version
2.1.0 (code 9)
Size
42.7 MB
Updated
Jul 14, 2026
Package name
acab.naiveha.subrosa

Security Verification

File integrity
SHA-256 recorded
Signing certificate
Fingerprint on record
Official source
Download APK (v2.1.0)

We record provenance; we do not run malware scans. Verify the hash yourself before installing.

SHA-256 Hash

341950e8db7b250b965f62d37d4c432077d9054edf00cc081a1a6b2b5186745f

Signing certificate

512ccef51ab8ba405c22f193ea1205629f7888be8be069b67bea768bc0e536ac

Permissions Required

What each permission lets sub rosa by naiveHA do. A highlighted one is worth a second look — not necessarily wrong, just worth asking whether this app needs it.

VIBRATEMake the device vibrate.
NFCUse NFC (tap-to-pay style short-range communication).
acab.naiveha.subrosa.DYNAMIC_RECEIVER_NOT_EXPORTED_PERMISSION

Previous Versions

Signature verified

The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.

More Security Privacy apps

More from F-Droid

IsPhoneEncrypted

Marco Seguri

v1.0.01.3 MBAndroid API 10+

Note Crypt Pro

F-Droid

v1.441.4 MBAndroid API 19+

Oversec

oversec

v1.5.155.3 MBAndroid 5.0+

SELinuxModeChanger

F-Droid

v11.01.4 MBAndroid API 17+

CryptoPass

F-Droid

v1.20.1 MBAndroid API 9+

My Wifi Passwords

F-Droid

v1.0.12.1 MBAndroid API 15+

Report a problem with this listing

A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.

Report a problem