#e2ee
47 posts · Last used 6d
Fedi, I have a design problem I'd appreciate thoughts on.
I've been building a federated E2EE messenger (based on MLS) where the server learns as close to nothing as possible about you, so there's no accounts or user records. Which raised the obvious question: how do you rate limit anything?
The answer I went with is PrivacyPass. You authenticate once to get a batch of tokens, so the server knows who you are at that moment. Then you spend them anonymously - they're blinded at issuance, so when one comes back the server can verify it's valid but can't tell who it gave it to. Rate limiting happens at issuance, not at send time. You get a budget: 2,000 tokens/hour, 10,000 burst. (the numbers are based on napkin math and can be adjusted)
Now the actual problem: one token buys one envelope, and an envelope goes to one device. Group messages fan out client-side, so a message to a group of D devices costs D tokens. At two devices per person, a 250-person group is 500 tokens per message which is about 4 messages/hour. So groups pretty much have to cap out around 200-250 people.
I can't just make fan-out cheaper, because the server can't see group membership. It genuinely cannot distinguish "500 envelopes because my group is large" from "500 envelopes because I'm spamming 500 strangers." Any discount that makes fan-out affordable makes spam affordable by exactly the same factor.
The only structural escape I've found is to stop fanning out - one envelope that many people fetch. But then the server sees N people reading one mailbox, which hands it the group membership the per-recipient design exists to hide.
So:
- Is there a way to prove "this batch is fan-out to a group I belong to" without revealing the group or its members? Feels anonymous-credential-shaped but I haven't found the primitive.
- Is ~250 people a reasonable ceiling to just accept?
- Anything obvious I'm missing?
Decentralized browser-based P2P E2EE messaging.
The key detail that sets this apart from other messaging apps is the browser-based client-side cryptography philosophy.
No need to install anything. Your ID is crypto-random and so the app doesnt need to rely on any central registration system like phone numbers. Your ID is unguessable and to connect to someone, you have to explicitly share it.
WebRTC has other nuances like being to route through a shared network for secure/faster transfer.
I hope this project has reached a level i can share the following details. I've made a genuine effort towards documentation and transparancy. I dont think it'll ever be enough and so im still concerned it isnt ready to share. While im using AI throughout. This is not a vibecoded project. There is attention throughout for unit tests and formal-verification. With your feedback, id like to make improvements for clarity throughout.
This version of the app demonstrates a fairly unique approach using a browser-based, local-only and webrtc approach. I know it's impossible for any system to be the "world's most secure", but that isnt a reason to not try. By rigorously implementing an exhaustive list of security features and practices, the aim is to get as close as possible.
This is intended to demonstrate client-side managed secure cryptography.
I know ive tried to compress a lot of my journey into one post. The project above is going to be tricky to understand. Feel free to reach out for clarity on any of the details.
IMPORTANT: While this is aiming to provide a secure experience, It is not audited or reviewed. Shared for testing, feedback and demo purposes only. Please use responsibly.
#Privacy #OnlinePrivacy #DataPrivacy #Infosec #CyberSecurity #OpSec #DigitalRights #AntiSurveillance #DataOwnership #E2EE #P2P #PeerToPeer #WebRTC #LocalFirst #LocalOnly #NoCloud #NoRegistration #PWA #SignalProtocol #PostQuantum #Cryptography #SecureMessaging #PrivateChat #EncryptedChat #Decentralized #OpenSource #SelfHosted #BetaTesting #FeedbackWelcome #TechDemo #ProofOfConcept #BuildInPublic #IndieDev #DevCommunity
The upcoming update brings two major features preventing you from losing access to your memories 🎉
-
Passwordless Backups: Never again lose access to your twonly account if you have forgotten your password. Just select friends you trust and choose a second factor. Read our blog post for more details [1].
-
Encrypted Cloud Backups: More Details and additional features follow soon!



