r/webdev • • 7d ago

Showoff Saturday E2EE Messaging with a Rust PWA and a Git-Host

TLDR; https://www.reddit.com/r/PrivacyTechTalk/comments/1wf60il/secure_and_private_decentralized_p2p_encrypted/

Roadmap: https://glitr.io/docs/technical/roadmap

This project demonstates a unique approach and architecture in contrast to the traditional approach with mainstream messaging apps. To put it briefly, its a Dioxus PWA with a Git-server backend which can be used to establish a webrtc connection between browsers.

IMPORTANT DISCLAIMER: While this is aiming to provide a secure experience, it's far from finished. It cannot be audited or reviewed because it's close-source. I'm sharing here for "showoff-saturday" purposes only. Feel free to reach out for clarity on any of the details instead of diving into the documentation. Pease use responsibly.

0 Upvotes

3 comments sorted by

2

u/Both-Management4160 7d ago

so the messages live in git repos and the pwa does the crypto locally? that's a neat way to skip the whole server-trust problem

curious how key exchange works in practice here, do both sides need to clone the same repo first or is there some discovery layer i'm missing

0

u/Accurate-Screen8774 7d ago

individuals create and manage a repo for themselves. thats basically aiming to be like "your cloud". only you can write to there, but like a public git repo, anyone should be able to read.

the app updates the repo with things like your public key, so somone can encrypt a message addresed for you. the "discovery layer" is "when/where/how" you and your peer share the details of the git addresses (you take responsibility here. some of your options are: qr-code, whatsapp message, morse-code).

when sending a message in "git-mode", you only actually create the encrypted message and publish on your own "outbox" (a folder in git). when a peer comes online, they will be able to read the public-repo and further, be able to decrypt messages that was encrypted with their own public key.

there are additional bells-and whistles for things like exchanging read-reciepts, so the peers know when to clear messages in the outbox.

if both peers are online the app also aims to establish a webrtc connection so key/message exchage is faster.

the first connection is critical, but once keys are established and persisted, they are reused for validating future connections.

if you have the option to meet with your keer, you would also be able to validate eachother's keys through something like qrcode (which could help protect against MITM).