yourTimecard

Security

yourTimecard has no passwords. There is nothing for you to choose, remember, reuse, or be tricked into typing somewhere it doesn't belong. Instead, each device proves who it is with a key that only that device holds — the same approach as the passkeys now built into iPhone, Android, Windows and the Mac.

Keeping it simple

There is no password to steal, guess, or trick out of you — so there is no known way for anyone to sign in as you without physically holding your unlocked device.* Keep a passcode or Face ID on your phone and that is genuinely the whole of it.

* Assuming a phone that hasn't been jailbroken or rooted.

How it works

When you pair a device with an invite code, the app creates a matched pair of keys right there on the phone:

From then on, every request your app makes is signed with the private key. The server checks the signature against the public key it has on file. Nothing that could be replayed as a password ever crosses the network, and the invite code that started it all is one-shot and expires within the hour.

Why this is the stronger approach

There is no secret to steal from us

Password breaches are worth stealing because a password database is a pile of reusable secrets. Our database holds public keys. If someone walked off with the whole thing they would still be unable to sign a single request, because the half that signs never left your phone. There is no crackable hash, no rainbow table, no offline guessing.

It cannot be phished

A convincing fake login page works because you can be persuaded to type a password into it. You can't type a key you have never seen, and it can't be read off your screen or repeated over the phone. The most common way accounts are taken over simply doesn't apply.

Nothing is reused

Reused passwords mean one breach anywhere becomes a breach everywhere. Your device's key exists only for yourTimecard, was generated on your device, and is shared with nothing else.

Access ends the moment a device is removed

Because credentials belong to devices rather than people, unpairing a lost or stolen phone ends its access immediately, without disturbing anyone else and without anybody changing a password. Each device your team pairs is listed and can be removed on its own.

The gold standard, and who says so

This is not a private invention. Signing with a device-held key is the model behind WebAuthn / FIDO2, published by the FIDO Alliance and the W3C, and shipped as passkeys by Apple, Google and Microsoft. The US government's CISA and the UK's NCSC both recommend phishing-resistant, hardware-backed credentials over passwords and over one-time codes sent by text.

We use the same cryptography those standards rest on — Ed25519 public-key signatures — applied to a job where it fits particularly well. A time clock is used by people at the start of a shift, often outdoors, often in a hurry, sometimes on a shared or borrowed phone. Asking them to invent and recall yet another password is how you end up with Summer2024! written on the break-room wall.

What this does not cover

Being honest about the edges matters as much as the strengths:

Location and your data

What we record, when we record it, and who can see it is covered separately in our Privacy Policy — including the tracking modes a business can choose and what each one means for you.

Reporting a problem

If you believe you have found a security issue, please tell us before telling anyone else, and give us a reasonable chance to fix it: yourTimecard@liquidsteam.com.