Combining TOR, WebRTC and Git into a Decentralized E2EE P2P Messaging App
Not better than WhatsApp, Signal, SimpleX, Cwtch or Ricochet. You definitely shouldn't selfhost this or replace any of your existing apps or services. It's far from finished. Unaudited and unreviewed. If you want to test it out, please use it responsibly.
I'd like to share what I'm working on and interested to see if anyone wants to share feedback on the approach. I set some requirements on the roadmap below. I'm aiming for "the most secure, private and decentralized" messaging app. A target so ambitious i expect it to be impossible.
Im sure the roadmap only has a fraction of the list needed, but let me know what i've overlooked, even if its impossible(, i'd like the set of requirements to be exhaustive).
It's a fairly a unique stack and architecture in contrast to the traditional approach with mainstream messaging apps (and thats not a good thing!). To put it briefly, its a Rust-based frontend with a Git-server backend, which can be used to establish a E2EE Tor/WebRTC connection.[](https://app.glitr.io)
Features:
* No installation
* No registration
* PWA
* Android
* TUI
* WebRTC
* Tor routing
* TURN server
* Git-host backend
* Local-first
* Encrypted-at-rest
* Signal protocol
* Post Quantum cryptography
* Calls
* File-transfer
Note: Its still a work in progress and **there will be breaking changes**, but it would be interesting to hear your thoughts and questions on the approach.
Roadmap: [https://glitr.io/docs/technical/roadmap](https://glitr.io/docs/technical/roadmap)
**IMPORTANT DISCLAIMER:** While this is aiming to provide a secure experience, it's a work-in-progress and far from finished. It is unreviewed and unaudited. I'm sharing here for testing, feedback and demo purposes only. **Pease use it responsibly.**
**AI Disclosure:** The first messenger version ([chat](https://github.com/positive-intentions/chat)) was written without it. As AI has improved, it has slowly been integrated into various processes, and now, AI is part of the workflow. Using AI is an understandable concern, **especially** for a cybersecurity project like this, so its import to be upfront about its usage. I think its notable that the project has reached a point of AI generated formal verification which should help overcome some concerns overlooked by unit-tests. The project has reached a stage of aiming for clear transparent comprehensive documentation as well as a self-audit. The entire set of documentation and self-audited details are intended for my benefit. **They are not an audit. Id like to aim for them to be a starting point for third-party review like for a** [related project](https://www.reddit.com/r/CyberSecurityAdvice/comments/1su8lir/security_audit_feedback_from_radically_open/)**.**
https://redd.it/1x0n2pe
@r_SelfHosted
Not better than WhatsApp, Signal, SimpleX, Cwtch or Ricochet. You definitely shouldn't selfhost this or replace any of your existing apps or services. It's far from finished. Unaudited and unreviewed. If you want to test it out, please use it responsibly.
I'd like to share what I'm working on and interested to see if anyone wants to share feedback on the approach. I set some requirements on the roadmap below. I'm aiming for "the most secure, private and decentralized" messaging app. A target so ambitious i expect it to be impossible.
Im sure the roadmap only has a fraction of the list needed, but let me know what i've overlooked, even if its impossible(, i'd like the set of requirements to be exhaustive).
It's a fairly a unique stack and architecture in contrast to the traditional approach with mainstream messaging apps (and thats not a good thing!). To put it briefly, its a Rust-based frontend with a Git-server backend, which can be used to establish a E2EE Tor/WebRTC connection.[](https://app.glitr.io)
Features:
* No installation
* No registration
* PWA
* Android
* TUI
* WebRTC
* Tor routing
* TURN server
* Git-host backend
* Local-first
* Encrypted-at-rest
* Signal protocol
* Post Quantum cryptography
* Calls
* File-transfer
Note: Its still a work in progress and **there will be breaking changes**, but it would be interesting to hear your thoughts and questions on the approach.
Roadmap: [https://glitr.io/docs/technical/roadmap](https://glitr.io/docs/technical/roadmap)
**IMPORTANT DISCLAIMER:** While this is aiming to provide a secure experience, it's a work-in-progress and far from finished. It is unreviewed and unaudited. I'm sharing here for testing, feedback and demo purposes only. **Pease use it responsibly.**
**AI Disclosure:** The first messenger version ([chat](https://github.com/positive-intentions/chat)) was written without it. As AI has improved, it has slowly been integrated into various processes, and now, AI is part of the workflow. Using AI is an understandable concern, **especially** for a cybersecurity project like this, so its import to be upfront about its usage. I think its notable that the project has reached a point of AI generated formal verification which should help overcome some concerns overlooked by unit-tests. The project has reached a stage of aiming for clear transparent comprehensive documentation as well as a self-audit. The entire set of documentation and self-audited details are intended for my benefit. **They are not an audit. Id like to aim for them to be a starting point for third-party review like for a** [related project](https://www.reddit.com/r/CyberSecurityAdvice/comments/1su8lir/security_audit_feedback_from_radically_open/)**.**
https://redd.it/1x0n2pe
@r_SelfHosted