This release is the result of an in-depth security review of the entire BitBanana codebase. Many areas of the app have been hardened, and several issues were fixed along the way. We are not aware of any of them ever having been exploited. Most of them could only be abused under specific circumstances, but we recommend all users to update.
Security & privacy improvements
Connections
- LNURL services and LndHub accounts now require an encrypted connection (HTTPS or Tor .onion). Unencrypted connections are only allowed within your private network.
- Fetching a BTCPay Server configuration follows the same rules.
- TLS certificates are now always verified for LND and Core Lightning nodes that are reached via Tor on a clearnet address.
- Nostr Wallet Connect can now be used over Tor. Relays with .onion addresses automatically use Tor.
- BIP353 lookups now use DNS-over-HTTPS (over Tor if Tor is enabled) and are faster thanks to prefetching.
- Additional checks for LNURL-pay success actions
- Signing the LNURL-auth canonical phrase is no longer possible.
- Updated Tor to 0.4.8.22
App lock
- Biometric unlock now only accepts strong biometrics and is cryptographically bound to the biometrics enrolled on your device. If they change (e.g. a new fingerprint is added), biometric unlock is disabled until you enable it again in the settings.
- Biometric unlock is no longer enabled by default for new installations.
- The wait time now doubles after each failed unlock attempt, and changing the system time no longer affects it.
- More reliable auto-lock timeout
Data
- Stronger backup encryption
- App lock settings are no longer part of backups.
- App data is no longer copied by Android's device-to-device transfer.
- The keyboard no longer learns from what you type into BitBanana.
- Sensitive data copied to the clipboard is now flagged as sensitive, so Android hides it in the clipboard preview.
- Overlays of other apps are hidden while BitBanana is in the foreground (Android 12+).
- Sensitive information is redacted from the in-app logs and no longer written to the system log in release builds.
- Hardened storage of cached data
- Developer settings no longer have any effect in release builds.
Other Changes
- Target SDK 36 with edge-to-edge design
- Updated translations
Bug fixes:
- Fixed value input getting corrupted while typing for some fiat currencies
- Fixed several possible crashes, e.g. when returning to the app, switching nodes while loading, swiping with multiple fingers or handling malformed scanned or pasted data
- Fixed the payment route view for payments with more than two routes
Verify
Follow these instructions to verify the release.