I built a messenger with no servers. Come to break it!
Hi everyone. I’m msd1shka, an indie developer. I’m tired of hearing about "data safety" from companies that store terabytes of metadata. Servers hold all our contacts and chats; they know who talked to whom and when. An
Hi everyone. I’m msd1shka, an indie developer.
I’m tired of hearing about "data safety" from companies that store terabytes of metadata. Servers hold all our contacts and chats; they know who talked to whom and when. And that "someone" can leak the database or sell you out completely.
I didn't set out to create another "super-secure messenger." Instead, I decided to make it so the data to leak physically doesn't exist.
Meet Delta-Time. It’s P2P on Tor Hidden Services v3. No servers, no registration, no phone numbers, no emails. Your identity is your local key generated only on your device: Ed25519. Messages are signed, routing goes through the onion network, and there are no intermediary servers, meaning there is nothing to hand over to authorities or hackers.
⚠️ Straight to the point: this is an alpha from a single indie developer. There has been no audit, there may be flaws, and please read the Threat Model. If you are a security researcher or just like digging through other people's code, I invite you to break this. Seriously, find a hole; I’ll be glad.
Why not Signal or Matrix?
(They seem similar)
- Signal = phone number + central server + AWS (a combo of metadata collection).
- Matrix = federation, but home-servers still leave logs. I needed a system where I don't have to trust anyone.
How it works:
(For those who will break it or are interested in the architecture)
Transport: Tor Hidden Services v3. Forget STUN/TURN. Each client spins up its own ephemeral hidden service. Exchange happens directly between onion addresses. IP never leaves the network. Yes, connection takes time (from seconds to a couple of minutes). That’s the price of anonymity, but the UI has statuses to indicate network state.
Identity: Ed25519. The private key never leaves the device. Public key = your ID. Lost the key? Goodbye account. No recovery because there is no user database.
TOFU: Trust On First Use. Just like SSH. On first connect, you get a fingerprint. Verify it against what you received personally or via another channel. Confirm without looking? That’s on you. Cancelled? Chat blocks. Security > UX.
Storage: Encryption at Rest. History is encrypted on disk. Stole the phone? Good luck with brute force.
Stack
Python + Flet. Yes, Python. Perfect for a desktop alpha.
Tor is either system or bundled.
Roadmap
Alpha: P2P on Tor v3, keys, signatures, disk encryption, TOFU.
Beta: Proper Win/Linux builds, Android via Orbot, audit (waiting for reviewers).
Later: Serverless groups, iOS, rewriting core in Rust/C++.
Reality
I recommend you not to believe words like "100% secure." Trust the code.
Cryptographers, network specialists, reverse engineers: jump into the repo. Look for metadata leaks during Tor errors, check TOFU, intercept traffic, write issues. This is the best help for developing such a project.
Why do this at all?
We are losing freedom of speech and privacy. Messengers have turned into surveillance tools. Delta-Time is an attempt to regain control. It is a tool for legal communication without overseers.
Privacy is a basic right, not a messenger feature.
you can try it there
git clone https://github.com/msd1shka/delta-time.git
cd delta-time
pip install -r requirements.txt
flet run or python main.py
Repository link: github.com/msd1shka/Delta-Time
Discussion / Issues: Telegram (here you can find out how to contact me or simply follow the app's development)
What would you improve in the TOFU UX?
Any specific attack vectors I should prioritize in the Threat Model?
Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.

