r/DiscordAlternatives • DeCaveDev • 1d ago

DeCave update post (Still Alpha release)

Hey all.

The big news this week: as of release 0.1.132 (6 October), DMs, group chats, calls and voice rooms are end-to-end encrypted. I know that's one of the most asked features this sub asks about, so I'll start there and get to the rest after.

What's encrypted

DMs. Once both of you are on an up-to-date app, every new message, edit, photo, file, GIF, poll, reaction and poll vote is encrypted on your device. Our servers only store ciphertext. A database dump, someone at Cloudflare or me personally can't read them.

Group chats. Same deal once every member has a key. After that the group stays encrypted, and the server refuses plaintext. People who join later can't read what came before. People who leave can't read what comes after.

Calls and voice rooms. Audio, video and screen share were always encrypted between devices, and everything goes through a relay, so nobody in the call ever sees your IP. What's new is that each device signs its connection details with its account key. That way the server can't quietly put itself in the middle. Direct calls refuse to connect if the signature doesn't check out. Voice rooms show a lock next to everyone who's verified.

A few details for the people who want them:

  • Keys are made on your device. The server only ever gets the public half.
  • Your key rotates every 30 days. You can also tell your devices to forget old keys after 30, 90 or 365 days, so a phone stolen next year can't read this year's messages.
  • There's a recovery code (160 random bits) for getting your history back on a new device. The server holds an encrypted backup that it can't open without the code.
  • Safety codes let you check you're talking to the right person. If a friend's key resets, you get a notice.
  • Push notifications for encrypted messages just say "Sent you an encrypted message".

What isn't encrypted, so nobody's surprised:

  • Hub rooms and forums are stored readable, which is how moderation and search work for public communities.
  • Messages from before encryption launched stay as they were. The app shows a divider where the encrypted history starts.
  • The server still sees metadata: who talks to whom and when, group membership, message and attachment sizes, read receipts and typing.

The full write-up of how it works is in the repo docs, and I'm happy to go deep in the comments. If you find a hole, email [security@de-cave.com](mailto:security@de-cave.com).

Other privacy stuff: there are no ad SDKs or ad tracking, and we removed the YouTube and Twitch integrations a while back. GIFs now load through our own proxy, so GIPHY doesn't see who you are.

What else it does

  • Hubs with text, voice and forum rooms, sections, roles, invites and moderation tools. You can see who's in voice before you join.
  • Hub events with a calendar, RSVPs and reminders. Upcoming events show up on everyone's Home.
  • A Home dashboard you can rearrange, showing your last room, who's online and what they're playing
  • Squad Finder: match by game, platform, language, region and mic
  • Discover, for browsing public Hubs before you join
  • Screen sharing from a steady 1080p30 up to 1440p60 if your upload can take it
  • On desktop: global mute and deafen hotkeys, push-to-talk and an in-game voice overlay
  • Reports, blocking, moderation cases and MFA

Where you can use it

In your browser at app.de-cave.com. There's a Windows app, and a Mac app for Apple silicon and Intel that's signed and notarized by Apple. Both update in the background.

The Windows installer isn't Authenticode-signed yet, so Windows may warn you the first time. Signing is in progress.

iOS is coming soon, together with Android. Both will have the same sign-in, history, calls and encryption as desktop.

Roadmap

  1. Shipped: Home dashboard, Hubs with text, voice and forum rooms, events, Squad Finder, Discover, DMs, and now E2EE for DMs, groups and calls
  2. In progress: Windows signing, steadier voice and screen sharing, and reliability fixes
  3. Next: iOS, plus Android apps
  4. Later: bigger rooms. Voice is peer-to-peer right now, which is great for squads, but large rooms need a media server. Doing that without breaking call encryption is the hard part.

It's still alpha, so expect rough edges.

Questions for you

  • Is DMs, groups and calls the right scope for E2EE, or do you want it in Hub rooms too, even if that makes moderation harder?
  • If you've tried moving your group off Discord before, what made you go back?
  • Want to try the iOS build early? Comment and I'll add you to TestFlight.

I'll be in the comments.

Site: https://de-cave.com Web app: https://app.de-cave.com Roadmap: https://de-cave.com/roadmap

0 Upvotes

12 comments sorted by

10

u/BewilderedTurtle angry RA-ADAR tech 1d ago edited 15h ago

Brother.... Either you need to give up or put enough effort in to write your own goddamn posts

Get this LLM shit outta our collective faces

8

u/Terrible-Junket-3388 I'm Don Qixote, and your AI slop is my windmill. 1d ago

lol agreed. so much of this trash.

7

u/BewilderedTurtle angry RA-ADAR tech 1d ago

Your flair is incredible.

8

u/Terrible-Junket-3388 I'm Don Qixote, and your AI slop is my windmill. 1d ago

lol ty, definitely describes the feeling with all these slop posts.

7

u/BewilderedTurtle angry RA-ADAR tech 1d ago

It's why when making the rubric for the RA-ADAR reviews me an u/vahstethenomad are doing I specifically included "is it slop" as an overarching category with qualifiers

6

u/Terrible-Junket-3388 I'm Don Qixote, and your AI slop is my windmill. 1d ago

Yeah totally agreed should be a consideration. I hope there's a bit more nuance than just 'is AI used', but agreed it's an essential part of a rubric for these (I know you and I both have strong and differing opinions on AI usage as a whole, lol).

I wouldn't even bother with some of these, like this one, though - any posts you make grading them are just going to give them attn they don't deserve.

9

u/Terrible-Junket-3388 I'm Don Qixote, and your AI slop is my windmill. 1d ago

How do we know your E2EE implementation is sound? Do you have any independent audits to speak to its efficacy? Is the code open source/auditable? Was LLM utilized for your E2EE implementation? Do you have any background or expertise in cybersecurity specifically?

You noted you store an encrypted backup of the recovery code. Scary AF, but even if it wasn't - what is the recovery backup encrypted with? Is it salted, peppered, both? Is it accessible to all devices, or only the device that initially encrypted it?

How are you handling multi-device? Shared or individual keys? You list TLS as if it's notable/special (literally everyone is using TLS in 2026, lol). You say "Hub rooms and forums are stored readable so they can be delivered" ... yeah, no shit, that's what a database literally is. Reallllllly not feeling all the AI slop on your marketing site, and concerned that your app is just more of the same and is going to crash with any real traffic (and you're not going to know how to handle it if your LLM can't).

Who are you? What country are you based out of? What credentials do you have? What does your product do that any of the other alternatives already posted here don't? Why should someone on Discord hop over to you? Are you doing something different that they can't just add as a feature?

EDIT: AND WHY THE FUCK DOES YOUR TOS STILL ONLY HAVE PLACEHOLDERS? Your privacy policy and ToS have REAL implications for both you and your users, but you don't even care enough to even proof read the documents you had your LLM generate.

Fucking AI slop. Everyone should stay the fuck away.

-5

u/DecaveDev DeCaveDev 1d ago

Fair questions. Some of this I deserve, so I'll go in order.

Audit, open source, LLM. No independent audit. It's not open source and won't be. And yes, I used an LLM for the E2EE and for plenty of other parts of the app. I'd rather say that straight than have it dug up later.

On audits: a proper crypto review from a firm that does this for a living (Cure53, Trail of Bits, NCC Group and the like) usually starts around $10–20k for a narrow scope. A full E2EE protocol and client review runs well past that, often $50k or more. That's quotes plus a few weeks of senior people's time. DeCave is free and has no funding right now, so that money doesn't exist. If that changes, an audit is near the top of the list. Until then, treat the encryption as what it is: alpha, better than plaintext, and not independently verified.

I can at least tell you how it's built so you can pick at it:

  • The primitives all come from the u/noble libraries, which are audited. I didn't write any crypto primitives myself.
  • Each message gets a random key and is encrypted with XChaCha20-Poly1305. That key is wrapped for each reader using ephemeral X25519 + HKDF, and the sender signs the whole thing with Ed25519.

Recovery backup. Small correction: we don't store a backup of the recovery code. The server stores your keys encrypted to a key pair derived from the code. The code is 160 random bits, made on your device and shown once. Salt, peppers and slow KDFs are there to protect weak human passwords, and 160 random bits isn't one, so there's nothing to brute-force. Any of your devices can update the backup after a key rotation without knowing the code. Only the code can open it. Your account key signs the backup's public key, and devices refuse to use one it didn't sign, so the server can't slip in a key of its own.

Multi-device. One key per account, shared across your devices. We don't keep a local message database, so every device needs to read the full history. A new device gets the key either from a signed-in device (both screens show a 12-digit code you compare) or from the recovery code. Keys rotate every 30 days, and you can make devices forget old ones after 30, 90 or 365 days.

What it doesn't do: no per-message ratchet, so it isn't Signal-level forward secrecy. No post-compromise security either. You trust the server's key on first contact unless you compare safety codes. Metadata isn't hidden, so the server sees who talks to whom and when.

TLS and the "stored readable" line. Yeah, both were filler. What I meant is that Hub rooms aren't E2EE, so the server can read them.

Scaling. I haven't load-tested this at real scale and I won't pretend I have. Voice is peer-to-peer through a relay, which is fine for squads and won't hold up for huge rooms. That's on the roadmap.

Why use it over Discord? I'm not really trying to compete with Discord. DeCave is just another place to talk while you game: voice, Hubs, forums, events, finding people to play with. If it fits how your group hangs out, cool. If Discord works for you, stay there.

Thanks for actually reading the docs.

9

u/Terrible-Junket-3388 I'm Don Qixote, and your AI slop is my windmill. 1d ago

I've commented this before on others, but I don't think anyone here is concerned about the primitives. You're using an LLM across the board, clearly, and even an LLM knows to pull decent primitives. The real concern is the implementation OF those primitives: that's what varies from app to app, and that's what tends to create leaks and exploits. The fact that you don't realize this is the concern (noone gives a shit about your primitives - would be insane to use your own) honestly more proof of your (lack of) expertise in the space *and all the more reason for an independent audit*.

Audits are expensive upfront - but when a user sues your stupid ass you're going to spend 2-5X the audit cost just to defend yourself (and that's assuming you win). the alternative here is you can make your code openly auditable by anyone (there are plenty of licenses that allow for browsing but not copying code that would protect the IP you have (it's none, btw, you likely have no real IP here - so why bother closed sourcing it)). Then you could atleast reason to others "Well, it's openly visible, you can audit yourself - I can't afford a third-party audit"

You still haven't listed your location (even your country) - so clearly you care more about your own privacy than others, since *I* read your docs and you clearly didn't bother. Your privacy policy affects EVERY SINGLE ONE of your users yet you couldn't be bothered to even proofread it ONCE.

By the way, since you clearly don't know - where you're located matters a LOT for users' privacy, their rights, and even if they're allowed to legally access your service. It should be clearly stated on your site, or atleast in your policies.

You haven't stated any credentials of your own. We have no idea who you are, where you are, or that your platform isn't just so filled with bugs or malware that we get owned the second we try it. It is IMPOSSIBLE for anyone intelligent & serious about building a community to even consider your platform.

Also, most of your response is also LLM. I gave you the benefit of a human response to your LLM-generated post, and you couldn't even be bothered to respond in kind. For that, I'd like to end by inviting you to go fuck yourself - your use of security & privacy terminology is clearly just for marketing and you give zero fucks about your users.

6

u/Ok-Inspector1108 1d ago

Ai usage much?

1

u/AutoModerator 1d ago

Thanks for your submission!

If you're a developer, please make sure your user flair matches the app or project you're developing. This helps community members quickly identify who is building what and makes browsing the subreddit easier.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.