166 karma · joined July 23, 2025
Regarding the extra complexity - the design was "no privileged party at all", the price is the complexity.
You're right about the DHT metadata -> queries expose requester IP to nodes on the path, so designing a social graph is possible. However, that is exactly why there are two modes:
- fast mode, which basically trades metadata privacy for lower latency and calls - anonymous routes everything (DHT queries also) over Tor
Regarding compromise recovery, you're also correct. That is on top of the v2 list.
> Additionally with the group size limits, lack of forward secrecy/post compromise security Direct (1:1) chats rotate keys every 15 messages - I thought about a similar approach for group chats, but it turned out to be very noisy, also a v2 feature to address.
You mentioned some valid flaws, but none of them seem fundamental/unsolvable. Of course, there is going to be a certain kind of trade-off when going fully decentralized, but these trade-offs are becoming smaller and smaller each day. In return, we are getting our privacy back. There is still a long way to go regarding the things that you mentioned, but also some basic UX: - Mobile app - Anonymous mode Tor alternative (thought about I2P, but it's very slow) - Calls in anonymous mode ...
And that's where the leader matters -> to make that option executable as a group. Without an agreed authority, it's N separate choices that have to stay consistent forever: one member with a stale roster keeps X in the loop by accident, or X kicks Y while Y kicks X and there are two rosters claiming to be the group. One signed kick says "we stopped talking to X" for everyone.
But then again, you're right. If 4 members want to kick out member#6, but member#5 doesn't want to, there is nothing we can do to stop member#5 from sending everything to member#6. That's not a software-solvable problem.
Best of luck!
If you go to google translate, select Croatian input "kijeovo" and click the speak button, you will hear how it is properly pronounced. Not that I care how people pronounce it, just wanted to share :)
However, there is also another way, which is already implemented and I am currently writing the how-to on my blog site, and that is using "trusted users". Basically, instead of 2 users trying to find each other on the DHT, they can just export their profiles in the "Profile" section. That prompts them to create a shared secret and exports a ".kiyeovo" file. You send that file to the other party, they click on the "+" in the sidebar header ->"import trusted user", select the ".kiyeovo" file and voila!
I know it's not nearly as convenient as what you're describing, but it's just a more "trustable" way of creating a contact which is also not that inconvenient.
I travel a lot and manage servers, so I’ve been wanting a dedicated “SSH machine” that I can always carry with me. With how good AI tooling has gotten, doing real work on a tiny device is suddenly very viable. The other day I SSH’d into a box from my phone while I was at the gym and just told Claude Code to fix a Kubernetes manifest issue. It was fixed and deployed in under two minutes.
I mentioned this idea at work and a few coworkers immediately said they’d buy one if it existed. Curious what others think.