OnionChat
Desktop messenger over Tor, with no server, no account and no phone number.
Context
OnionChat is a desktop messenger built around one question: how little do two people really need to talk privately? The answer I arrived at is no server, no account, no phone number. Your onion address is your identity.
How it works
There is no central server. Every user hosts their own onion service, and messages travel directly from one onion to another inside the Tor network. There’s no point in the middle that could read, log or scan conversations, because that point doesn’t exist.
Encryption has two layers: Tor’s own, plus end-to-end encryption with the NaCl library (X25519 and XSalsa20-Poly1305), Ed25519 signatures and replay protection. Text, photos, videos, files and voice messages are encrypted, and on disk the database and your identity are encrypted too, with an optional startup password.
Threat-model choices
This is the part I care about most, because it isn’t code: it’s reasoning about what can go wrong.
On first contact the other person’s key is pinned, so a later attempt to swap it gets noticed. EXIF data and GPS location are stripped from photos, and the image is slightly altered to hinder automatic matching. Windows are protected from screen capture and the onion address never shows up in the title bar.
Above all, one thing is spelled out in the docs: against scanners built into the operating system, no app can do anything. A privacy project that pretends to solve everything is one you haven’t understood; this one says where its guarantees end.
Technical choices
Python, with PyNaCl for cryptography, SQLite for local data, a Tkinter interface and the Tor Expert Bundle included, so there’s no separate Tor setup.
Status
Finished, the code is on GitHub. It’s a prototype and hasn’t been security-audited: for truly sensitive conversations, use mature tools like Briar or Cwtch. One known limit: both people have to be online at the same time.