Thread

🛡️
Likely won't be an official GrapheneOS channel due to moderation or bridging requirements but I am paying close attention to the encrypted Nostr identity messaging apps like Whitenoise and Keychat. For users who want the best as a messenger right now, then SimpleX is there and mature. Useable security comes a long way. We have a lot of apps that do it all, but we need an app that feels as good to use as Telegram does. I think encrypted messengers using Nostr as an identity could make a valuable replacement to Session since its selling point is not having an often personally identifiable identifier like phone numbers. Session has been the subject of criticisms with their crypto. Many of these apps including WhiteNoise have an advantage that it has perfect forward secrecy when Session doesn't. Session however benefits from having an onion routing network inbuilt. Build in onion routing and you have obseleted it. Certain apps like Keychat having their own inbuilt lightning wallet also is quite inventive. I think it could go somewhere if done right. It does what Signal tried with their MobileCoin thing but it is much less of a gimmick by lightning actually being useable. Zapping friends through the messenger like Apple Pay Cash does is a smart idea. Some may want these to be separate apps though. I'm also heavily concerned about cryptography, although I am not a cryptographer. I still use Signal because it is scrutinised. Upcoming apps using it need a lot of review first before I make large decisions. I will do a technical article on my thoughts in the future but it's probably less on the security front. I have a blog web page created, I just need to get a domain and a hosting to publish. I just have lots of other commitments right now.

Replies (3)

🛡️
I get Keychat is trying to be like the WeChat of Bitcoin and Nostr, but the browser thing doesn't move me and I turn it off. Not a technical criticism, I am just very conservative with my keys. I'd prefer a bunker like Amber and a separate messenger/wallet and browser or even all three separate that work seamlessly with one another. With what I mentioned about Session, see: Follow up after response to it:
🛡️
Nostr architecture solves so much by removing the requirement of a trusted server. White Noise uses Message Layer Security, an IETF standard with numerous audits and security proofs. The nostr-mls wrapper has been peer reviewed but not yet audited. I think the cryptography is sound. Best thing is that it's an open standard and there will be countless implementations that do one thing really well. Looking forward to that variety.
🛡️
I don't doubt the security of the crypto at all, nor MLS. I am just very cautious. WhiteNoise is clearly designed with care and caution. I have given both WhiteNoise and Keychat good praise as emerging apps in GrapheneOS public chat -- mostly as a Session replacement so far. Regulars have also said they were open to test them further and try them out.