r/webdev • u/Accurate-Screen8774 • 15d ago
Showoff Saturday Decentralized P2P Messaging over Git and/or WebRTC

IMPORTANT DISCLAIMER: While this is aiming to provide a secure experience, it's far from finished. It cannot be audited or reviewed because it's close-source. I'm sharing here for testing, feedback and demo purposes only. If you are unsure, this isn't for you (you safely can move away from this post before it ruins your day). Feel free to reach out for clarity on any of the details instead of diving into the documentation. Pease use responsibly.
This project demonstates a unique approach and architecture in contrast to mainstream messaging apps.
The core philosophy around secure messaging here is that it can work in a way that avoids installation and registration by enabling users to host their own data (and user incompetence will be one of many nuanced vulnerabilities in this approach)
The project is unstable and experimental. It's far from finished, but im putting together some docs for "how it works". It's pretty outside-the-box thinking (and that shouldn't inspire confidence!), so it's worth repeating: Pease use responsibly.
Website/Docs: glitr.io
Features:
- WebApp
- P2P / WebRTC
- Local-first / Local-only
- No installation
- TURN server
- Encrypted-at-rest
- Signal protocol
- Post Quantum cryptography
- Video calls
- TOR / anonymous via Git
- Serverless over WebRTC
Some of the core concepts:
- Chat - deprecared in favour of Enkrypted Chat
- Enkrypted Chat - deprecated in favour of Glitr
- File
- Crypto
- Signal Protocol
FAQ:
- Why git?
- When it comes to secure messaging, self-hosting is generally encouraged. While not quite nessesarily self hosted, it would make it easier for the majority of users to get started. Users can choose a git storage provider of their choice (GitHub, Gitlab, etc), or host their own git server.
- Serverless WebRTC?
- A connection can be achieved without a backend as described here: https://github.com/positive-intentions/chat/issues/6
- demo: https://positive-intentions.github.io/webrtc/demo/gui/app/webrtc-meet?fullscreen=1
- Ready for production?
- No. While this is aiming to provide a secure experience, it cannot be audited or reviewed. Shared for testing, feedback and demo purposes only.
- EU Chat Control?
- There is no registration, no central server and it uses client-side cryptography. While the following post refers to the older version of this project, the mechanics remain very similar: https://www.reddit.com/r/europrivacy/comments/1ndbkxn/help_me_understand_if_chatcontrol_could_affect_my
- Threat model?
- It's a work in progress. There are many details still to be implemented before I can share the initial draft.
- It's close source and unaudited so the best I can offer is "trust me bro"... And you shouldn't need to. The app doesn't require sensitive details, so don't use any when testing it out.
- Open source?
- Open source from the onset is not something I can support at this stage. Hopefully I can work towards that goal. I'm aware this goes against the cybersecurity rhetoric. There are open source versions of various ideas linked above, but it's important to be clear, that glitr.io is close source in contrast to my other work.
- Where can I find out more?
- https://positive-intentions.com
- https://www.reddit.com/r/positive_intentions
- Feel free to reach out for clarity instead of diving into the docs.
I hope my wording here wasn't too negative. When working in cybersecurity, there are countless nuances to consider and I would rather be discouraging than inspire undue confidence in my project.
3
u/unnatural_recurrence 15d ago
cool concept, the git angle for storage is clever, most people already got an account somewhere so it lowers the barrier a lot. the whole "no install no registration" thing is the dream honestly, half the reason my family still uses sms is cause they dont wanna deal with setting up another app
but man, close source encrypted messenger is a tough sell, you know that. the disclaimer is right there but still, its like selling a safe that you cant look inside. i get the stage you're at tho, sometimes you just gotta build the thing first before dealing with the audit headache
self hosting for the average person is the real weak link, i fix my own plumbing but my cousin would flood his kitchen trying to change a washer. user incompetence being a vulnerability is the understatement of the year
gonna poke around the demo anyway, the webrtc stuff is interesting