Echo communications through Android.
About this app
Summary of Smoke
* Aliases. Preserve your contacts. * Almost zero-dependency software. * Application lock. * Argon2id and PBKDF2 key-derivation functions. * Automatic, oscillatory public-key exchange protocol, via SipHash. * BSD 3-clause license. * Completed. * Content is recorded via authenticated encryption. * Decentralized. TCP, and UDP multicast and unicast. * Does not require Internet connectivity. * Does not require registration. Telephone numbers are not required. * Encrypted communications. * Eventful tasks. Limited polling. * F-Droid. * Fiasco forward secrecy. * Future-proof software. * Introduces Cryptographic Discovery. Cryptographic Discovery is a practical protocol which creates coordinated data paths. * Juggling Juggernaut Protocol! * Manufactured tool tips! * McEliece Fujisaka and Pointcheval. * Message structures do not explicitly expose contents. Header-less protocols! Some messages do include type information. * Mobile servers via SmokeStack. * Obfuscation of resident secret keys. * Optional foreground services. * Optional silence over the wires. * Original implementation of SipHash. * Ozone destinations: private and public repositories. * Post offices for messages of the past. * Private servers. * Public and private public-key servers. * Rainbow digital signature scheme. * Reliable distribution of archived messages. * Reliable distribution of deliverable text messages. * SPHINCS digital signature scheme. * SSL/TLS through SmokeStack. * Semi-compatible with Spot-On via Fire. * Share files with TCP utilities such as Netcat. * SipHash-128. * Smoke and mirrors. * Software congestion control. * Software manual included. * Steam, reliable file sharing. TCP over the Echo! * Steamrolling, or, real-time broadcasting of inbound Steams to fellow participants. * Super McEliece: m = 13, t = 118.
Licensed under MIT.
What's New in v2024.06.25
Imported from the F-Droid repository index.
- * GitHub ticket #48. The oid variable in Fire::deleteFire() may not be
- defined and referencing a tarnished variable will terminate Smoke.
Version history
Jun 28, 2024 · 3.9 MB · Android API 25–28 · code 20240625
Imported from the F-Droid repository index.
- * GitHub ticket #48. The oid variable in Fire::deleteFire() may not be
- defined and referencing a tarnished variable will terminate Smoke.
SHA-256 39e5568f0442d27b104d2c016062fee61e66afd127a3104b94c7f8b3441be561
Jan 7, 2024 · 3.9 MB · Android API 25–28 · code 20240105
Imported from the F-Droid repository index.
- * Cancel the future.
- * Minimum SDK of 25.
- * Partially-blocked socket reads.
- * Permanent darkness.
SHA-256 0f520ea85ed3c978b5901d578f4c690b798ae8087d366f970b934c4f4c240a7d
Dec 27, 2023 · 8 MB · Android API 28–28 · code 20231225
Imported from the F-Droid repository index.
- * Removed Makefile targets as they are difficult to support:
- launch-emulator-1, launch-emulator-2, load-apk-release, release.
- * Removed import statements.
- * Removed redundant conversions.
- * Replaced StringBuilder with String in some instances.
- * String comparisons and equalsIgnoreCase().
SHA-256 9056f905dcc119e2c4fa09b55c5a0cf4f30417551354446a76a27a02800ebaa6
Will it run on your device?
73%
- Runs on a broad range of modern Android versions.
- ABI coverage is focused on newer 64-bit devices.
Installation Guide
Open Settings on your Android device
Go to Security → Unknown sources (or Install unknown apps)
Enable "Allow from this source" for your browser or file manager
Open the downloaded APK file from your Downloads folder
Tap "Install" and wait for installation to complete
Launch the app from your home screen
Make sure to re-enable Unknown Sources restrictions after installation for security.
How to install this safely
How to verify the file you downloaded
Before you install anything, confirm the file is the one described here. On a computer, run shasum -a 256 your-download.apk (macOS or Linux) or certutil -hashfile your-download.apk SHA256 (Windows), then compare the output character-for-character with the SHA-256 on this page. If a single character differs, the file is not the build we recorded — delete it.
What the signing certificate proves
Every Android app is signed with a private key that only its developer holds. The fingerprint on this page is a hash of the matching public certificate, and it proves continuity rather than identity: it tells you a build came from whoever signed the earlier ones. Android enforces this at install time — if a package claiming to be org.purple.smoke is signed with a different key, the system will refuse to install it over your existing copy. A fingerprint that changes between releases is worth pausing on, because a repackaged app that has been modified by someone else cannot keep the original signature.
How to roll back to an earlier version
If the current release misbehaves, 2024.01.05 is the last build before it. Android will not install an older version code over a newer one, so you must uninstall Smoke first — which clears its local data unless you have a backup. Reinstall the older APK only if its signing fingerprint matches the build you already trust, and check the API range: an older release may target an Android version your device has moved past.
Why we list sources instead of hosting everything
The official store channel is almost always the right choice: it updates automatically and carries the publisher's own distribution guarantees. A direct APK is useful when a device has no store access, when a rollout has not reached your region, or when you need a specific version — and only when the publisher has authorized that copy. APKBrowse does not list pirated, cracked, or unauthorized rebuilds of Smoke, and a listing is removed when the evidence for it stops holding up.
Get Smoke
Every source we list for org.purple.smoke is legality-reviewed. Pirated or cracked builds are never offered.
Other sources
F-Droid listing
officialF-Droid builds this app from source and signs it. This is its official listing, with older builds and full release notes.
Source code
verified publisherThe upstream repository this build is compiled from.
We check legality and signature continuity, but device behaviour still varies. Install at your own discretion.
App Information
Security Verification
We record provenance; we do not run malware scans. Verify the hash yourself before installing.
SHA-256 Hash
39e5568f0442d27b104d2c016062fee61e66afd127a3104b94c7f8b3441be561
Signing certificate
8483a38ba820f47d73f633f4de54e8ba066a4e6d5c9a15405ede9aadaa9a5534
Permissions Required
What each permission lets Smoke do. A highlighted one is worth a second look — not necessarily wrong, just worth asking whether this app needs it.
Previous Versions
The signing certificate fingerprint for this release is on record, so a build that does not match it did not come from this publisher.
More Social apps
More from F-DroidReport a problem with this listing
A listing is only as good as its corrections. If a source is broken, a signature looks wrong, or this app should not be here, tell the moderation team.