6
Decentralized Encrypted P2P Chat
(chat.positive-intentions.com)
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Beginning of January 1st 2024 this rule WILL be enforced. Posts that are not tagged will be warned and if not fixed within 24h then removed!
With "guarantees" I meant things like whether you want to have perfect forward secrecy, or whether you want to provide some degree of deniability, and so on, not so much what kinds of guarantees you're relying on although they're definitely also good to keep in mind.
"As secure as possible" is a very all-encompassing goal which doesn't really say much – what I was trying to get at with my point about the guarantees you want to make is that you'll want to have a clear idea of what you actually mean with "as secure as possible" so you'll know what sort of eg. architectural decisions to make before you do a lot of work and paint yourself into a corner.
It's a very ambitious project, but I can guarantee it'll probably be very interesting to work on and you'll learn a lot regardless of the outcome, and I'm definitely rooting for you.
Still not sure what "guarantees" should look like. As a webapp there are some hard limitations on what a website can do on a browser. I guess that needs to be encoded.
I'd like to have all the buzzwords like forward secrecy and post-quantum proof. I don't know enough to list them all, but keen to see what else I can accommodate. When I say "as secure as possible", it might be better to interpret that as "aiming for the stars to land on the moon".
Not sure what it means to "provide some degree of deniability".
Thanks for the support!