Add explicit backup/data-extraction excludes as defense-in-depth

allowBackup is already false, but backup_rules.xml and
data_extraction_rules.xml were empty stubs. Add explicit <exclude>
entries for the sharedpref, database and DataStore (file/datastore)
domains so the signer's secret material can never leave the device
via cloud backup or device-to-device transfer even if backups were
ever enabled.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01CX7WR4DwXfEyMW55r9jLjn
This commit is contained in:
Claude
2026-06-19 09:35:27 +00:00
parent 089424a7e6
commit 275d726996
2 changed files with 32 additions and 18 deletions
+14 -8
View File
@@ -1,13 +1,19 @@
<?xml version="1.0" encoding="utf-8"?><!--
Sample backup rules file; uncomment and customize as necessary.
Backup rules used for fullBackupContent on devices older than API 31.
See https://developer.android.com/guide/topics/data/autobackup
for details.
Note: This file is ignored for devices older that API 31
See https://developer.android.com/about/versions/12/backup-restore
Amber sets android:allowBackup="false", so backups are already disabled.
These explicit excludes are defense-in-depth: even if backups were ever
enabled, the signer's secret material (encrypted keys, per-account
SharedPreferences, Room databases and DataStore files) must never leave
the device.
-->
<full-backup-content>
<!--
<include domain="sharedpref" path="."/>
<exclude domain="sharedpref" path="device.xml"/>
-->
</full-backup-content>
<!-- Encrypted keys / settings live in SharedPreferences (prefs, prefs_<npub>). -->
<exclude domain="sharedpref" path="." />
<!-- Per-account apps/permissions, logs and history Room databases (amber_db_<npub>, etc.). -->
<exclude domain="database" path="." />
<!-- DataStore preferences (secure_datastore_<npub>, app_datastore). -->
<exclude domain="file" path="datastore" />
</full-backup-content>
+18 -10
View File
@@ -1,19 +1,27 @@
<?xml version="1.0" encoding="utf-8"?><!--
Sample data extraction rules file; uncomment and customize as necessary.
Data extraction rules for cloud backup and device-to-device transfer
on API 31+.
See https://developer.android.com/about/versions/12/backup-restore#xml-changes
for details.
Amber sets android:allowBackup="false", so cloud backups are already
disabled. These explicit excludes are defense-in-depth: the signer's
secret material (encrypted keys, per-account SharedPreferences, Room
databases and DataStore files) must never leave the device through
either cloud backup or device transfer.
-->
<data-extraction-rules>
<cloud-backup>
<!-- TODO: Use <include> and <exclude> to control what is backed up.
<include .../>
<exclude .../>
-->
<!-- Encrypted keys / settings live in SharedPreferences (prefs, prefs_<npub>). -->
<exclude domain="sharedpref" path="." />
<!-- Per-account apps/permissions, logs and history Room databases (amber_db_<npub>, etc.). -->
<exclude domain="database" path="." />
<!-- DataStore preferences (secure_datastore_<npub>, app_datastore). -->
<exclude domain="file" path="datastore" />
</cloud-backup>
<!--
<device-transfer>
<include .../>
<exclude .../>
<exclude domain="sharedpref" path="." />
<exclude domain="database" path="." />
<exclude domain="file" path="datastore" />
</device-transfer>
-->
</data-extraction-rules>
</data-extraction-rules>