Dev.to Security 🔐 Cybersecurity 👁 0 📖 3 min read

KaleidoTalk 3.0: End‑to‑End Encryption + Cover Traffic – A Privacy Messenger That Hides Metadata

I built an open‑source chat app that encrypts messages and protects traffic patterns – fixed‑size packets, random padding, heartbeat jitter, automatic key rotation, and an irreversible account freeze. No CAs, no metadata

KaleidoTalk 3.0: End‑to‑End Encryption + Cover Traffic – A Privacy Messenger That Hides Metadata

I built an open‑source chat app that encrypts messages and protects traffic patterns – fixed‑size packets, random padding, heartbeat jitter, automatic key rotation, and an irreversible account freeze. No CAs, no metadata leaks. GitHub repo.

TOFU Trust Window
Chat Box

Why Another Secure Messenger?

We all know the drill: “Your messages are end‑to‑end encrypted” – but what about the metadata? Packet sizes, timing, and frequency paint a detailed picture of your social graph, active hours, even relationships. Most apps don’t hide that.

KaleidoTalk was built from the ground up with a simple manifesto:

  • Encryption is non‑negotiable.
  • Source code must be public.
  • Users – not certificate authorities – verify trust.
  • Traffic analysis must be defeated.

Version 3.0 brings automatic key rotation, a modern GUI, and a unique account‑freeze mechanism. Let’s dive in.

The Cryptographic Core

  • Identity keys: Ed25519 (long‑term, for signing).
  • Key exchange: X25519 – ephemeral per message (forward secrecy).
  • Symmetric encryption: AES‑256‑GCM with HKDF‑SHA256 key derivation.
  • Authentication: Each message is signed with the sender’s identity key.

Every message uses a fresh ephemeral X25519 keypair. Even if your long‑term keys are compromised later, past messages remain safe.

Encryption Flow (simplified)

shared_secret = ECDH(ephemeral_priv, recipient_x25519_pub)
aes_key, nonce = HKDF(shared_secret, salt, info="kaleido-msg")
ciphertext, tag = AES_GCM_encrypt(aes_key, nonce, plaintext)
signature = Ed25519_sign(sender_priv, eph_pub + ciphertext + tag)

The server only sees opaque blobs – it cannot decrypt.

Cover Traffic: The Metadata Shield

All traffic is wrapped in 2048‑byte fixed‑length packets. Every packet contains:

  • A 1‑byte type (data, fragment, or pure padding)
  • Length, sequence, total fragments
  • Real payload (up to 2041 bytes)
  • The rest is random padding

Heartbeats

Both client and server send padding packets at randomised intervals (5s ± 1.67s jitter). This means:

  • An idle connection sends the same volume as an active one.
  • An observer cannot tell if you’re typing, reading, or away.

No more size‑based or timing‑based profiling.

Trust Without Central Authorities

KaleidoTalk uses Trust On First Use (TOFU) for both TLS certificates and user public keys. Instead of ugly hex strings, fingerprints are displayed as six BIP39 words – easy to read and compare out‑of‑band (e.g., in person).

Once verified, the trust is stored locally with an HMAC‑protected database. If tampering is detected, all trust relationships reset.

Automatic Key Rotation (24‑hour cycle)

X25519 keypairs are rotated automatically every 24 hours. The server keeps a list of recent public keys so messages sent with older keys can still be decrypted during the transition. This limits the window of compromise if a private key is leaked.

Account Freeze – Your Emergency Brake

If your password is stolen or forgotten, there is no password reset via email/SMS (which are attack vectors). Instead, during registration you generate an Ed25519 recovery certificate stored locally.

To freeze your account, you sign a message with that recovery key and send it to the server. The server verifies the signature and permanently sets a frozen flag – no login, no message delivery, active sessions killed. It is irreversible (can’t be undone by the server admin) – this prevents social‑engineering recovery attacks.

A standalone freeze_account.py tool lets you freeze even without the full client.

Performance & Scalability

  • Idle bandwidth: ~310–620 bytes/s (thanks to heartbeats).
  • Maximum efficiency: 99.66% for large messages (only 7‑byte header overhead).
  • Current implementation: thread‑per‑client – fine for small to medium private teams. The protocol is concurrency‑agnostic, so an async version is straightforward if needed.

Get Started in 3 Minutes

git clone https://github.com/hbzsoft/KaleidoTalk
cd KaleidoTalk
pip install -r requirements.txt

# Start server (auto‑generates TLS certs)
python run_server.py

# In another terminal, start client
python run_client.py
  • Verify the TLS fingerprint (shown as BIP39 words) on first connect.
  • Register, save your recovery key, and start chatting.

Admin tools and a standalone freeze tool are included.

What’s Next?

I’m actively developing KaleidoTalk. Future plans:

  • Asynchronous server for higher concurrency.
  • Mobile clients (Flutter/React Native).
  • Optional Tor integration for IP‑level anonymity.

Try it out, star the repo, open issues, or submit PRs. Every security review is welcome.

👉 GitHub Repository

👉 Full Whitepaper

Let’s make private communication truly private – not just in content, but in pattern.

📰 Read the original article on Dev.to Security

Originally published by Dev.to Security. Aggregated on AIWithGhost for educational purposes — full credit and traffic to the original publisher.