frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Show HN: Zero-identity messaging app with physics-based post-quantum encryption

2•ElyricFandross•1h ago
Show HN: Zero-identity messaging app with physics-based post-quantum encryption (Layer 2 from my own paper)

Hey HN,

I'm building a privacy-first messaging app in Flutter/Dart, developed with AI assistance (Gemini 2.5 Pro + Claude Opus 4.6). No phone number, no email, no account — no identity, nothing to track. Currently focused on Android.

*Six-layer defense architecture*

Layer 0 - Identity layer: Zero identifier. No account, no identity, nothing to track.

Layer 1 - Key exchange: X25519 + ML-KEM-768 hybrid. X25519 is Bernstein-designed, outside the NIST ecosystem. Even if ML-KEM has an NSA backdoor, X25519 still holds. The probability of both being broken simultaneously approaches zero.

Layer 2 - Key hardening (my original contribution): session_key = HKDF(shared_secret || Y), where Y = PQ_C(W(shared_secret)). Even if Layer 1 is fully compromised, the attacker still faces the Landauer thermodynamic lower bound + Margolus-Levitin operation limit. Physical law, not a mathematical assumption.

Layer 3 - Message encryption: ChaCha20-Poly1305, Bernstein-designed. High resistance to side-channel attacks. Retains 128-bit equivalent security strength post-quantum.

Layer 4 - Transport: SMP protocol reimplemented from scratch in Dart. No central server, P2P communication. Unidirectional queues — the server never knows who is talking to whom. No message retention on the server. Currently using SimpleX public relay.

Layer 5 - Endpoint: Android FLAG_SECURE screenshot prevention. Volume key triggers emergency wipe (messages + keys). Configurable wrong-password limit before irreversible wipe. Burn-after-reading on by default. Client-side encrypted backup, keys never leave the device.

*What is Layer 2*

Layer 2 is implemented from my Zenodo preprint. The core claim: a key derivation path passing through Product Quantization and Soft-ZCA whitening creates structure-induced quantum blindness against known quantum algorithm paradigms (HSP, Simon, Grover, etc.), making quantum attacks physically infeasible — grounded in physical law, not computational hardness assumptions.

Because Layer 2 is based on my public preprint paper, there is no closed-source issue. Anyone can implement their own encryption scheme using the paper as a foundation.

Paper: https://doi.org/10.5281/zenodo.19483649

Counterproofs welcome. If you can construct one, that result is itself a significant academic finding.

*Features*

- Contact establishment: QR code (in-person) or 10-character random code (remote) - Stickers: upload any image under 1MB, auto-converted to SVG vector format (in progress) - Local database: Hive - Languages: Traditional Chinese and English, both first-class - Code comments: bilingual beginner-level annotations throughout, written for readability

*Swappable GUI (in progress)*

Frontend/backend separation. Users can choose between WhatsApp-like, Telegram-like, WeChat-like, or Line-like interfaces. Non-commercial developers will be able to build their own GUI on top of the same backend in the future.

*Why Android first, not PWA*

PWA cannot control volume keys or implement FLAG_SECURE screenshot prevention. Both are necessary — not optional — for the device-seizure threat model.

*License*

Custom license. Commercial rights reserved to the author. Drafting terms that will prohibit MAMANGO(Meta, Amazon, Microsoft, Apple, Nvidia, Google, OpenAI) and their affiliates from commercial use or participation in development. Layer 2 licensing terms to follow separately.

*Current status*

Repo is public, README in progress. Landing page with waitlist opening soon. Will publish to app stores after v1.0.

Repo: https://codeberg.org/Kelvin_Brammidge/xlinendchat

Enterprises power agentic workflows in Cloudflare Agent Cloud with OpenAI

https://openai.com/index/cloudflare-openai-agent-cloud/
1•surprisetalk•1m ago•0 comments

US companies not going public because of hostile litigation environment

https://www.washingtonpost.com/opinions/2026/04/13/lawyers-class-action-lawsuits-public-companies/
1•dryadin•2m ago•0 comments

Transistor Runs on Air and Used in a DIY Digital Clock [video]

https://www.youtube.com/watch?v=E1BLGpE5zH0
1•arttaboi•3m ago•0 comments

Open Letter Opposing the Paramount-Warner Bros. Discovery Merger

https://blockthemerger.com/openletter
1•ChrisArchitect•3m ago•0 comments

The tool is not the author

https://resolve.works/articles/the-tool-is-not-the-author/
2•monneyboi•4m ago•0 comments

Show HN: NRC nuclear licensing RAG pipeline and regulatory embeddings dataset

https://huggingface.co/datasets/davenporten/nrc-regulatory-embeddings
1•davenporten•4m ago•0 comments

Show HN: Git-native solution for documenting software architecture

https://app.maniok.io
1•salzaverde•4m ago•0 comments

Show HN: MOS Tech 6502 emulated in pure Postgres

https://github.com/lasect/pg_6502
1•heywinit•5m ago•0 comments

Web scraping tarpits are catching legitimate data teams, not just AI crawlers

https://foura.ai/blog/web-scraping-tarpits-collateral-damage
1•angelhadjiev•5m ago•0 comments

Economic Software Testing (2019)

https://baatz.ch/2019/economic-software-testing/
1•rzk•6m ago•0 comments

OpenCode vs. Claude Code vs. Copilot

1•pjmalandrino•6m ago•0 comments

Joaquin Phoenix, Ben Stiller, Other Hollywood Names Oppose Paramount-Warner Deal

https://variety.com/2026/film/news/hollywood-open-letter-paramount-warner-bros-deal-1236720249/
1•randycupertino•6m ago•1 comments

Sam Altman reportedly targeted in second attack

https://www.theverge.com/ai-artificial-intelligence/910890/openai-sam-altman-second-home-attack-s...
2•Brajeshwar•7m ago•1 comments

Categorization Is 'Baked' into the Brain

https://www.nature.com/articles/s41583-026-01036-2
2•XzetaU8•9m ago•1 comments

Did NFTs leave a lasting mark or was it purely speculative?

1•Heyhum•11m ago•0 comments

Show HN: I built a tool that automatically turns tickets into design doc and PRs

3•rajivprab•12m ago•0 comments

Paris Court Issued Site Blocking Orders Against ISPs, DNS Resolvers and VPNs

https://torrentfreak.com/paris-court-issued-simultaneous-site-blocking-orders-against-isps-dns-re...
1•speckx•13m ago•0 comments

Philippines Asks Facebook to Curb Fake News, Warns of Legal Move

https://www.bloomberg.com/news/articles/2026-04-12/philippines-asks-facebook-to-curb-fake-news-wa...
3•1vuio0pswjnm7•13m ago•0 comments

Unmasking the Creator of Bitcoin

https://www.nytimes.com/2026/04/09/podcasts/the-daily/satoshi-nakamoto-bitcoin-creator.html
2•brandonb•14m ago•0 comments

The Harness Tax: The dead weight in your coding agent

https://twitter.com/siddhxrth10/status/2043703343453987133
1•siddhxrth•14m ago•0 comments

How Healthy Are Oats?

https://www.nytimes.com/2026/04/13/well/eat/oats-health-benefits-recipes.html
2•brandonb•14m ago•0 comments

The Graveyard of Unabsorbed Knowledge

https://verificationbottleneck.substack.com/p/the-graveyard-of-unabsorbed-knowledge
1•Giwwi•15m ago•1 comments

We May Be Living Through the Most Consequential Hundred Days in Cyber History

https://ringmast4r.substack.com/p/we-may-be-living-through-the-most
14•laurex•18m ago•0 comments

Show HN: I built a sandboxed agent that writes JSON rules to avoid repeat errors

1•grimm8000•19m ago•1 comments

Live Streaming from Space: Infrastructure Challenges Behind Video Beyond Earth

https://www.red5.net/blog/live-streaming-from-space-infrastructure-challenges/
1•mondainx•20m ago•0 comments

An Oligarchy of Old People

https://www.theatlantic.com/magazine/2026/05/gerontocracy-wealth-power/686585/
2•paulpauper•20m ago•0 comments

In Praise of 'Difficult' Kids

https://www.theatlantic.com/family/2026/04/raise-difficult-kids-on-purpose/686766/
2•paulpauper•21m ago•0 comments

Self-driving vehicles and the cross-country drive

https://marginalrevolution.com/marginalrevolution/2026/04/self-driving-vehicles-and-the-cross-cou...
1•paulpauper•22m ago•0 comments

Make Tmux Pretty and Usable

https://hamvocke.com/blog/a-guide-to-customizing-your-tmux-conf/
16•speckx•22m ago•7 comments

The largest orbital compute cluster is open for business

https://techcrunch.com/2026/04/13/the-largest-orbital-compute-cluster-is-open-for-business/
1•Brajeshwar•23m ago•0 comments