this is following a previous post as seen here: https://programming.dev/post/51866250
apps like Whatsapp, Signal and SimpleXChat are great for secure messaging and far more mature than this project, but this approach is yet distict in the market. the core philosophy around secure messaging here is that it can work in a way that avoids installation and registration by enabling users to host their own data.
docs: https://glitr.io/
note: feel free to ask for clarity on any of the details around how the project works.
FAQ:
-
but why? - git over https adds an additional capability i had previously oerlooked https. webrtc cannot work over TOR and similar networks. this way, you can take advantage of the “gold standard” for onion routing while being able to avoid IP leaking from webrtc.
-
when is it ready for production? - not any time soon. standby for updates.
-
audit/review? - no, niether is possible/available. its simply too expensive. this project is close-source so you cannot verify it either. DO NOT “trust me bro”… this demo is proided for testing and demo purposes only. use responsibly.
-
the abridged version of how its put together: https://www.reddit.com/r/VibeCodeDevs/comments/1vme48q/refactor_js_to_rust/


i was unable to get traction on my project as FOSS. in fact, it only seems to put me at a competative disadvantage.
https://www.reddit.com/r/positive_intentions/comments/1tq1u62/introducing_enkrypted_chat
i sweated to get the project to that point. the key pushback was that it didnt have an audit. cybersecurity has a paywall nobody seems to talk about. a security audit that is worth respecting is prohibitively expensive. as someone feeling the hit of AI (im unemployed), im especially not investigating options for a security audit when i cant pay myself.
it isnt for lack of trying either i have countless rejections from providers of funding for open source projects. i have several open source examples if youre really curious to discuss details.
There are organizations that audit software for free, for smaller developers.
But they only do so if it is FOSS.
You have now essentially killed your project, since you will not be able to afford an audit, and nobody who knows what they are doing will look at an encryption protocol or app that hasn’t been audited.
(Sorry for this being so long… Feel free to reach out for clarity on the details. Long-story-short. Sure those orgs exist… But they aren’t rushing to fund projects that are simply open source)
You’re over simplifying. So let’s add some context relative to this project.
I have several open source projects. This project started off open source and I keep the version open source because it demonstrates a fairly unique concept around avoiding installation and registration.
https://github.com/positive-intentions/chat
I handcrafted that version. It’s open source with the commit history. It was before the days of agentic AI. I spent countless hours considering countless details. I could spend countless more on improving the quality there for things like unit tests.
I had something reasonably unique and so I tried to apply for funding. I tried very hard, several places, several times. All rejections.
Grant applications are a horrible experience. It’s not something I had experience in before and it carried a exhausting learning overhead… But if I could get funding, it would be worth it. As AI become more prominent, I’m sure these organisations are overwhelmed with how many submissions they have.
My conclusion is clear; if it’s been this hard to only receive rejections, I’m no longer going to bet on open source. It’s clearly not a good business plan.
I consider myself a seasoned developer. So as I’m working on my project, I’m taking on feedback and made improvements throughout.
I still believe in things like kerkhoffs principles. So as part of the continued development, I created a version of the signal protocol.
https://github.com/positive-intentions/signal-protocol
I aim for it to be for production use, but without a third party audit, open source is worthless. When sharing it online, the conversation cannot move past that it’s created with AI. It undermines all the time and effort I put into it. I created things like formal proofs/verification and security audits. I kept all the documentation honest that it was created by myself with AI. I think the approach is honest and transparent.
I see the project is well received in various subs, but the cryptography subs that can actually understand what I created, I just risk being banned for sharing AI slop… And thus this close source approach.
Going close source is particularly ambitious because there is an element of “trust me” to it (I don’t like it either)… but it appears to be the only way to proceed at the moment.
I don’t need it open source so people can debug my code. I open sourced it previously for discussion… I now realise my project is simply too complicated to discuss. It’s not for lack of trying.