CodeWords security

Confirm the enrolled phone and the exact request.

CodeWords adds a separate signed challenge when a call, message or email asks you to do something sensitive. It reduces reliance on the channel that may be under attack.

Protocol summary updated 27 August 2026 • Current release assurance

Protected device keys

Each installation creates signing keys held in platform-protected storage where the phone supports it. The service registers public keys, not the private signing key.

Changing signed QR frames

The presenting phone changes frames about every 1.2 seconds. The scanner requires three fresh, sequential frames and rejects an expired session.

A fresh signed Bluetooth challenge

The scanner connects to the matching advertised service and sends a fresh random challenge. The presenting phone signs it, and the scanner and service verify the answer against the public key carried by LiveQR.

Request-bound answers

The full action, amount, recipient or account details are shown before approval. A signed challenge expires after five minutes and can be answered once.

Clear negative signals

The enrolled phone can confirm, deny or report pressure. A new phone must be added again and must not silently inherit old trusted relationships.

Minimal permissions

Camera and nearby-device access support direct setup. CodeWords does not need contact-book upload, call audio, microphone recordings or precise location for this flow.

A valid confirmation means

  • The previously enrolled phone responded.
  • The responder opened CodeWords and approved the request shown.
  • The signed answer was fresh and bound to those details.

It does not prove

  • That a voice, email address, video image or legal identity is genuine.
  • That the phone is not stolen and already unlocked.
  • That the person is free from pressure or that the action is safe.
  • An exact physical distance between the phones.

What Bluetooth proves today

CodeWords exchanges a fresh application-authenticated Bluetooth challenge tied to the LiveQR session. The challenge is signed, but it is not application-encrypted and the phones do not need to pair. This makes passive copying and forgery less useful, but it does not prove an exact distance. A modified app or coordinated relay can still attack the ceremony. The comparison words and number help both people detect a mismatched session before accepting.

Found a security issue?

Contact us before sharing exploit details publicly. Include the affected app version and a minimal reproduction. Do not send live QR payloads, private keys, passwords or another person's challenge content.

Report a CodeWords security issueGet product support