What's New in OpenDrop 1.0

OpenDrop 1.0 is out. This is the first build I'd put in front of anyone — preview releases were always meant for me, and a few patient testers, to break things. 1.0 is the baseline I'd want on my own phone, on my own desktop, with my own files moving across it. Here's what's new, what changed since the previews, and what isn't in the box yet. If you'd rather skim the full machine-readable list, the changelog page has the version markers and protocol numbers.

The headline: encryption everywhere, no exceptions

Every file you transfer through OpenDrop 1.0 is end-to-end encrypted on the sending device with ChaCha20-Poly1305 IETF AEAD (RFC 8439). The 32-byte content key is derived with HKDF-SHA256 from your account's shared secret — computed identically on each of your devices, so the key never travels over the network — with a fresh random 12-byte nonce prefix per transfer. Encryption is applied on every path:

On iOS we run the cipher through Apple CryptoKit; on Android API 28+ we use BoringSSL; older Android devices and the desktop run a pure-Dart or pure-Python fallback. The wire format is byte-identical across every implementation and is pinned by a shared test-vector file in the repo. Our infrastructure (the Cloudflare Worker control plane and our Fly.io / Oracle Cloud relay) routes ciphertext only and cannot read your files.

The desktop server and mobile clients advertise and require X-OpenDrop-Protocol: 2 on every request. Servers respond with HTTP 426 Upgrade Required to any client below protocol v2, and v1.0 clients refuse to connect to a server that reports a lower protocol version. The goal is to remove the downgrade-attack surface: there is no plaintext fallback, no "compatibility mode," no flag to disable encryption.

Auto-fallback transport: Wi-Fi, peer-to-peer, and the cloud

One of the questions I hear most often is "what does it use when?" The short answer: whatever's fastest and available, automatically.

You do not pick the path manually. The app negotiates based on what it discovers during the mDNS phase and the relay connection state.

Cross-platform parity at launch

1.0 ships at the same baseline on iOS, Android, Windows, and Linux. The macOS desktop is the same Nuitka-compiled PySide6 build that ships on Windows and Linux, still in active development and not yet on the Mac App Store. The Flutter mobile apps use Apple CryptoKit on iOS and BoringSSL-accelerated AEAD on Android API 28+. The desktop server bundles an LGPL ffmpeg build for file conversion.

Platform Minimum version Distribution
iOS16.0+Apple App Store
Android7.0 (API 24)+Google Play Store
Windows10 or 11Microsoft Store + direct .exe
LinuxUbuntu 22.04+, Debian 10+ (x86_64 and aarch64).AppImage
macOS12+PySide6 desktop, in development; Mac App Store coming

What OpenDrop Pro adds

The free tier covers direct-LAN streaming, remote transfers over our Oracle Cloud relay, QR pairing, BLE nearby transfer, and the single-device mesh. OpenDrop Pro at $2.99/month or $24.99/year (about 30% off annual) adds:

UX and theming

Nine built-in color palettes ship at 1.0: OpenDrop Brand (cerulean blue plus aqua cyan, the default), Ocean Breeze, Tide Pool, Sea Glass, Lilac Night, Cloud Blue, Peach Cream, Rose Petal, and Lavender Mist. Light, dark, and follow-system modes. iOS Cupertino dialogs honor system text size and Dynamic Type.

Other UX additions:

New privacy controls

The 1.0 release includes a few launch-day privacy improvements:

Headless and CLI mode

The desktop server can run without a GUI. A CLI client talks to a running GUI through a shared connection file, and single-instance detection on a dynamically chosen port keeps multiple invocations from colliding. The CLI is included in every desktop build and is the same binary as the GUI — there's no separate install. For automation, the CLI accepts pipes and lets you script transfers from a shell or scheduled task.

If you have an older build

Pre-1.0 builds were internal previews only. They cannot interoperate with the 1.0 protocol — any pre-1.0 client connecting to a 1.0 server gets HTTP 426 Upgrade Required. There is no compatibility mode and no plan to add one; the security goal is to eliminate the plaintext path. Please install the latest 1.0+ build from the download page before continuing to use OpenDrop.

What's still in flight

That's the 1.0 line. Thank you to everyone who tested the preview builds, filed bugs, and yelled at me when something broke. The next milestones on the roadmap are: macOS desktop to GA, per-device and per-purpose key derivation (the info-tag work outlined in the AEAD module), and per-account subprocessor configurability for self-hosters. If something on that list matters to you, email support@nfdgames.com; I'm the engineer and I'll read it.

Try OpenDrop 1.0

Download for iOS, Android, Windows, or Linux. Free, no account required for direct LAN transfers.

Download OpenDrop