simplexmq
publications
Our great sponsors
simplexmq | publications | |
---|---|---|
49 | 51 | |
407 | 1,318 | |
5.2% | 2.6% | |
9.3 | 8.7 | |
4 days ago | 10 days ago | |
Haskell | Python | |
GNU Affero General Public License v3.0 | Creative Commons Attribution Share Alike 4.0 |
Stars - the number of stars that a project has on GitHub. Growth - month over month growth in stars.
Activity is a relative number indicating how actively a project is being developed. Recent commits have higher weight than older ones.
For example, an activity of 9.0 indicates that a project is amongst the top 10% of the most actively developed projects that we are tracking.
simplexmq
- The first messenger without user IDs
-
SimpleX Chat – fully open-source private messenger without any user IDs (not even random numbers) – v5.2 released with message delivery receipts ✅ and lots of other improvements.
Of course https://github.com/simplex-chat/simplexmq
-
How to use the ntf server ?
It's about ntf-server-ubuntu-20_04-x86-64 https://github.com/simplex-chat/simplexmq/releases/tag/v5.1.3
-
SimpleX Chat: private and secure messenger without any user IDs (not even random)
Also, it is covered in whitepaper here: https://github.com/simplex-chat/simplexmq/blob/stable/protocol/overview-tjr.md
-
SimpleX Chat – the private messenger without any user IDs (not even random numbers) – v5.1 released with message reactions 🚀 and self-destruct passcode
Please review the whitepaper and / or website home page. I also wrote this post some time ago about why I believe that using pairwise identifiers should be a minimal requirement for a communication system to be considered private.
-
Large file : 8Mb file limit
For more information see Simplex development roadmap xftp branch in github
-
SimpleX File Transfer Protocol (aka XFTP) – a new open-source protocol for sending large files efficiently, privately and securely – beta versions of XFTP relays and CLI are released - developed in Haskell!
The source code: https://github.com/simplex-chat/simplexmq/tree/xftp
-
SimpleX File Transfer Protocol (aka XFTP) – a new open-source protocol for sending large files efficiently, privately and securely – beta versions of XFTP relays and CLI are released!
You can download XFTP CLI (Linux) to send and receive files via the command line here - you need the file named xftp-ubuntu-20_04-x86-64, rename it to xftp.
- SimpleXMQ – SimpleX Messaging Protocol Written in Haskell
-
SimpleX Chat – the 1st messenger without user profile IDs (not even random numbers) – v4.4 released with disappearing messages and connection verification!
We absolutely should assume they can be compromised, but as SimpleX servers do not participate in the initial key exchange for e2e encryption, the server compromise will not lead to the compromise of e2e encryption security. I wrote more on MITM issue in this post. Further, the threat model here explains other consequences of compromised SimpleX servers.
publications
-
Skiff: Various Privacy Failures
Disagree, their reputation is tied to their audit quality.
But I'm pretty sure in this case the scope was bad. Like they coukd have had audits on "Do I use OpenSSL well?" and then misrepresent that all their privacy claims were audited.
Now it seems like Skiff conveniently didn't allow Trail of Bits to publish their reports, they are usually here: https://github.com/trailofbits/publications/tree/master/revi...
Disclaimer, I have used Trail of Bits service in the past (and 2 other auditors for an security campaign on a blockchain, cryptography + networking product).
- The Lisk v4.0 security audit 🔐
-
PyPI has completed its first security audit
Link to the report: https://github.com/trailofbits/publications/blob/master/revi...
They seem to not have analysed client-side of PIP itself, but I suppose there isn't anything you could say that isn't already obvious to everyone.
- SimpleX Chat security assessment by Trail of Bits [pdf]
-
Thoughts on Skiff? What do you like? What would you want to see improve?
Audits are mentioned on the Trail of Bits website https://github.com/trailofbits/publications and the Skiff one https://skiff.com/transparency. Skiff has been externally audited 4 times.
-
SimpleX Chat: private and secure messenger without any user IDs (not even random)
Here's the URL https://github.com/trailofbits/publications/blob/master/reviews/SimpleXChat.pdf It was in the article I have already linked.
-
Solidity digest fortnightly / 17-30 apr 2023
MYSO Finance Security Assesment by Trail of Bits
-
Audit Firms Ranking
Trail of Bits
-
Transparency at Skiff
Hi! I'm Skiff's CEO. We've had 3 security audits, including 2 from Trail of Bits - one of the best security auditing firms in the world https://github.com/trailofbits/publications. Skiff Mail is also open-source: https://github.com/skiff-org/skiff-mail as is our whitepaper https://skiff.com/whitepaper We've also been in the news quite a bit: https://www.theverge.com/2022/5/17/23075804/skiff-mail-email-privacy, https://www.wsj.com/articles/encryption-bans-what-is-this-russia-hacking-online-privacy-security-data-signal-whatsapp-emails-protection-11675436242 (I wrote this with our team!), https://techcrunch.com/2023/01/30/russia-skiff-block/, and more, even though we're only a year old. We collect no personally identifying information - not even IP addresses used - no backup emails, phones, etc. - no advertising, and we end-to-end encrypt BOTH email subject + body and don't have any metadata (time sent/received an exception). What can we do to share more of this with more people? We're a younger company but it's so important this is made public.
-
Skiff Apps
Hi! I'm Skiff's CEO. We've had 3 security audits, including 2 from Trail of Bits - likely the best security auditing firm in the world https://github.com/trailofbits/publications. Skiff Mail is also open-source: https://github.com/skiff-org/skiff-mail as is our whitepaper https://skiff.com/whitepaper
What are some alternatives?
simplex-chat - SimpleX - the first messaging network operating without user identifiers of any kind - 100% private by design! iOS, Android and desktop apps 📱!
slither - Static Analyzer for Solidity and Vyper
ContactDiscoveryService
manticore - Symbolic execution tool
imessage - A Matrix-iMessage puppeting bridge
echidna - Ethereum smart contract fuzzer
monomer - An easy to use, cross platform, GUI library for writing Haskell applications.
verified-smart-contra
webwormhole - Peer authenticated WebRTC.
codeql - CodeQL: the libraries and queries that power security researchers around the world, as well as code scanning in GitHub Advanced Security
paper-research-privacy-matrix.org - Privacy research on Matrix.org
security - Materials related to security: docs, checklists, processes, etc...