Edit for clarity:

IMPORTANT DISCLAIMER: While this is aiming to provide a secure experience, it’s far from finished. It cannot be audited or reviewed because it’s close-source. I’m sharing here for testing, feedback and demo purposes only. If you are unsure, this isn’t for you (you safely can move away from this post before it ruins your day). Feel free to reach out for clarity on any of the details instead of diving into the documentation. Pease use responsibly.

This project demonstates a unique approach and architecture in contrast to mainstream messaging apps.

The core philosophy around secure messaging here is that it can work in a way that avoids installation and registration by enabling users to host their own data (and user incompetence will be one of many nuanced vulnerabilities in this approach)

The project is unstable and experimental. It’s far from finished, but im putting together some docs for “how it works”. It’s pretty outside-the-box thinking (and that shouldn’t inspire confidence!), so it’s worth repeating: Pease use responsibly.

Website/Docs: glitr.io

Demo

Features:

  • WebApp
  • P2P / WebRTC
  • Local-first / Local-only
  • No installation
  • TURN server
  • Encrypted-at-rest
  • Signal protocol
  • Post Quantum cryptography
  • Video calls
  • TOR / anonymous via Git
  • Serverless over WebRTC

Some of the core concepts:

FAQ:

  • Why git?
    • When it comes to secure messaging, self-hosting is generally encouraged. While not quite nessesarily self hosted, it would make it easier for the majority of users to get started. Users can choose a git storage provider of their choice (GitHub, Gitlab, etc), or host their own git server.
  • Serverless WebRTC?
  • Ready for production?
    • No. While this is aiming to provide a secure experience, it cannot be audited or reviewed. Shared for testing, feedback and demo purposes only.
  • EU Chat Control?
  • Threat model?
    • It’s a work in progress. There are many details still to be implemented before I can share the initial draft.
    • It’s close source and unaudited so the best I can offer is “trust me bro”… And you shouldn’t need to. The app doesn’t require sensitive details, so don’t use any when testing it out.
  • Open source?
    • Open source from the onset is not something I can support at this stage. Hopefully I can work towards that goal. I’m aware this goes against the cybersecurity rhetoric. There are open source versions of various ideas linked above, but it’s important to be clear, that glitr.io is close source in contrast to my other work.
  • Where can I find out more?

I hope my wording here wasn’t too negative. When working in cybersecurity, there are countless nuances to consider and I would prefer to be discouraging than inspire undue confidence in the project.


Original post:

This might become the worlds most secure messaging app.

This project demonstates a unique approach to secure messaging. The approach is different enough that it can’t be easily compared to Signal or SimpleX.

The core philosophy around secure messaging here is that it can work in a way that avoids installation and registration by enabling users to host their own data.

The project is far from finished, but im putting together some docs for the “how it works”. It’s pretty outside-the-box thinking (and that doesnt make it a good idea), so it would be great if you could share your thoughts on the approach.

Website: Glitr.io

Demo

Features:

  • WebApp
  • P2P / WebRTC
  • Local-first / Local-only
  • No installation
  • TURN server
  • Encrypted-at-rest
  • Signal protocol
  • Post Quantum cryptography
  • Video calls
  • TOR / anonymous via Git
  • Serverless over WebRTC

Some of the core concepts:

FAQ:

  • Why git?
    • When it comes to secure messaging, self-hosting is generally encouraged. While not quite nessesarily self hosted, it would make it easier for the majority of users to get started. Users can choose a git storage provider of their choice (GitHub, Gitlab, etc), or host their own git server.
  • Ready for production?
    • No. While this is aiming to provide a secure experience, it cannot be audited or reviewed. Shared for testing, feedback and demo purposes only. Please use responsibly.
  • Where can I find out more?
  • BetterDev@programming.dev
    link
    fedilink
    arrow-up
    6
    ·
    9 days ago

    I think the primary issue here, and the underlying cause of a lot of the negative feedback you’re getting is: you’re making some very bold claims right off the bat that aren’t substantive but present this project as something its not even close to being yet, and probably won’t ever be, unless you get some serious buy-in and help from some of the smartest people on the planet.

    “This might become the worlds most secure messaging app.”

    Really? Do you have any basis for such an assertion? My NAS might become the world largest repository of half-finished side projects. Do I have any reason to believe that it will be though? I do have a lot of unfinished side projects on there, but the only reason I’d ever make such an assertion is if I thought that it had a real shot at being the case.

    “This project demonstates a unique approach to secure messaging. The approach is different enough that it can’t be easily compared to Signal or SimpleX.”

    Yeah, it sure does demonstrate a unique approach alright. Does that make it incomparable to (what is widely considered to be) the worlds actual most secure messaging app?

    Look, man, I like fucking around with tools in hacky, weird ways as much as the next guy. I even built a self-hosted, federated, zero-knowledge multi-user file storage platform, but you don’t see me out here saying “this may be the most secure file storage system in the world”. You’re advertising what is at this point a hobby project, and trying to pass it off as something worthy of other people’s time, to give you feedback and ideas.

    You want some real feedback? OK here’s why I wouldn’t use this:

    1. I don’t know you, and so far, you’re not inspiring confidence I should trust you with data I’d like to keep private.
    2. regardless of if all data that lands on the actual repository is encrypted, you’re still leaking a ton of metadata to to anybody who can read the repo in ways that other services don’t.
    3. you brush off the AI coding concerns as if they’re unimportant. Look man, I don’t care, you do you, but you’re claiming this is a secure messaging platform. I’m not the guy who will tell you not to use AI for coding. I use it for coding too at work; but while coding with AI, you still have to be hypervigilant if you’re going to end up with anything even remotely approaching good code. I’ve been around the block a few times, I’ve vibe coded, and I’ve built good code with it. But when other people are trusting me to do a good job, I understand their concerns, and I use AI for what its good at: typing fast and language fluency. I use it like a fancy keyboard that talks back. If it has made decisions for you (and it doesn’t always tell you when it does), that’s not a keyboard anymore. Thats a million monkeys pressing keys on a keyboard, and you’re hoping you get Shakespeare.

    I wish you the best of luck on this project. If you want serious feedback from people, show them your effort. I see someone that wants to be important utilizing the tools at their disposal to shoot their shot at getting some useful feedback. That’s not a bad thing to be. But I think the particular audience you’re aiming this at, and the type of thing you’re making, and the way you describe it, need reconsideration, by you, the human.