ChatPGP
End-to-End Encryption
PGP/GPG Integration: Native GnuPG (OpenKeychain on android)
Key Management: Generate new key pairs or import existing PGP keys
Digital Signatures: All messages are cryptographically signed for authenticity
Zero Knowledge: No server can decrypt your messages - only you and the recipient
No Central Servers: Operates entirely peer-to-peer using IPFS
Tor Network Integration: All communications routed through Tor for anonymity
Self-Sovereign Identity: Your PGP fingerprint is your unique identity
Censorship Resistant: Cannot be blocked or taken down by authorities
Text Messages: Secure encrypted text communication
Image Sharing: Send photos with thumbnail previews and full-resolution viewing
Real-time Delivery: Messages delivered instantly when recipients are online
Message Status Indicators: See when messages are sent, delivered, and read
Interactive Image Viewer: Zoom, pan, and view images in full screen
Network Scanning: Automatically discovers other ChatPGP users on the network
Presence Status: See who's online and when they were last active
User Verification: Public key fingerprints ensure you're talking to the right person
Contact Management: Automatically maintains your contact list
Tor Circuit Control: Create new Tor circuits for enhanced anonymity
Connection Status: Real-time monitoring of Tor and IPFS connectivity
Debug Tools: Comprehensive network diagnostics for troubleshooting
Secure File Storage: Images and files stored on IPFS with content addressing
Cross-Platform: Runs on Linux, coming to Android, iOS, Windows, macOS
Native Performance: Compiled to native code for optimal performance
System Integration: Uses platform-specific features where appropriate
User Search: Find contacts by name or PGP fingerprint
Connection Diagnostics: Built-in tools to debug network connectivity
Manual Peer Connection: Connect directly to specific IPFS peers
Network Statistics: View connection status, peer counts, and topic activity
Protected:
Message Content: Encrypted with recipient's public key
Message Metadata: Timestamps and sender information protected
User Identity: Only PGP fingerprints are shared, no personal data
Network Traffic: All communications routed through Tor
File Transfers: Images encrypted and distributed via IPFS
Not Collected:
No user registration required
No personal information stored
No message content accessible to third parties
No analytics or tracking
No centralized user database
Initial Setup
Key Generation: Create a new PGP key pair with custom name and email
Key Import: Import existing PGP keys for experienced users
Network Bootstrap: Automatic Tor and IPFS initialization
User Discovery: Automatic detection of other users on the network
System Requirements
Dependencies: Requires Tor, IPFS, and GnuPG to be installed
Network: Internet connection for initial Tor and IPFS setup
Storage: Local storage for keys and cached images
RAM: Lightweight operation with efficient resource usage
FAQ:
Why do I have to download/build something?
Because otherwise you'd have to upload your private PGP key
ChatPGP represents the future of secure, private communication - where your conversations remain yours, protected by cryptography and distributed across a network that no single entity can control or compromise.
Download at libertyklimuepdewpamrqtciexnrucs3zfninpuurs6evwbqcbkmfyd.onion/chatpgp
0.9.4
Available on Windows, MacOS and Linux now!
Source available!
0.9.5
Timer cascading issue fixed
0.9.6
Start up leak detection
Basic startup
0.9.7
Better tor setup
Better IPFS setup
Network manager
0.9.7.1
Fixed a tor startup bug when tor is already running on 9050 but not working or secure
0.9.8
Updated Image encryption
Future updates:
Sandboxing
Network kill switch
Key trust evaluation system
Update dl to have a binary for each OS
Tips:
If you let the app start it's own tor, it uses vanguards full
If you want to use your own tor, please enable vanguards full before starting it
!! DISCLAIMER !!
Do not run this anywhere except a CLEAN whonix or tails system.
PLEASE READ (and keep development discussion here):
/post/e5b798a65036865917d2 - credit to /u/pgpfreak
Message us at: F390E06C4B16F0395433937437FCAB069A4FBE39
Also read about more details on the risks of using this (well meant) app: /post/e5b798a65036865917d2
I see /u/mrbacon420 approved this. But note as far as I am concerned this application is featured here under provision.
This because several issues I have with this app:
1. ChatPGP is an p2p application and not a hidden servcie. Normally we don't really allow applications with no backend service to connect to.
2. ChatPGP makes use of the InterPlanetary Files System for discovery. In a previous post /u/Liberty exchange noted:
3. ChatPGP is made with Dart and Flutter. Both are open source projecst heavily backed by Google and meant for easy and fast multi platform coding. This means many libraries and other resources from Google and others are being used to make ChatPGP operational on different platforms.
In my opinion this is not the correct method to create a privacy-first application in general. I believe ChatPGP should therefor be seen as a Proof-of-Concept or prototype application and not to be used by anyone with a relevant threat model. I myself will not use it beyond testing for this reason.
The application is hosted on a dedicated page on the PrimeMarket website, which is fine as the user is not directed to the market itself. It's still a bit of advertising though. So it would be professional to have a git repo or dedicated page instead.
I've had a look a the code and generally it looks pretty ok. I don't get the impression this is a vibecode project. The only reason I believe this is not made by very experienced developer(s), is the choice of language and framework. I didn't see any malicious code or packages, but no guarantees: it's a very bloated project and I only checked for a few things. There can always be something obfuscated, so use at own risk!
I see /u/mrbacon420 approved this. But note as far as I am concerned this application is featured here under provision.
This because several issues I have with this app:
1. ChatPGP is an p2p application and not a hidden servcie. Normally we don't really allow applications with no backend service to connect to.
2. ChatPGP makes use of the InterPlanetary Files System for discovery. In a previous post /u/Liberty exchange noted:
Disclosure: Your device is used as an IPFS node (over tor with full vanguards) while the program is running.Perhaps this can be added again?
3. ChatPGP is made with Dart and Flutter. Both are open source projecst heavily backed by Google and meant for easy and fast multi platform coding. This means many libraries and other resources from Google and others are being used to make ChatPGP operational on different platforms.
In my opinion this is not the correct method to create a privacy-first application in general. I believe ChatPGP should therefor be seen as a Proof-of-Concept or prototype application and not to be used by anyone with a relevant threat model. I myself will not use it beyond testing for this reason.
The application is hosted on a dedicated page on the PrimeMarket website, which is fine as the user is not directed to the market itself. It's still a bit of advertising though. So it would be professional to have a git repo or dedicated page instead.
I've had a look a the code and generally it looks pretty ok. I don't get the impression this is a vibecode project. The only reason I believe this is not made by very experienced developer(s), is the choice of language and framework. I didn't see any malicious code or packages, but no guarantees: it's a very bloated project and I only checked for a few things. There can always be something obfuscated, so use at own risk!
So when Liberty first posed this, it showed as an onion with a key. I was unable to get the key to work.
Now, I have realized, the link is to download a ZIP file. I did not know that when I recommended him to post here and approved the post.
You and the freak bring up some good points (His are /post/e5b798a65036865917d2 )
I wouldn't be offended if you overrode my approval and put it back in the queue if you think that is best.
Now, I have realized, the link is to download a ZIP file. I did not know that when I recommended him to post here and approved the post.
You and the freak bring up some good points (His are /post/e5b798a65036865917d2 )
I wouldn't be offended if you overrode my approval and put it back in the queue if you think that is best.
I didn't see the post for /u/pgpfreak. Makes me feel like an amateur thank you ;)
Although it's a bit worrying, I also agree with him that we should encourage these kind of projects, which is the reason for an exception in the first place.
I see the /u/LibertyExchange already interacting and I have good hope there will be improvement soon. I will edit my orignal message with an extra warning.
Although it's a bit worrying, I also agree with him that we should encourage these kind of projects, which is the reason for an exception in the first place.
I see the /u/LibertyExchange already interacting and I have good hope there will be improvement soon. I will edit my orignal message with an extra warning.
[removed]
[removed]
Of course, I'd be glad to re-add the disclaimers! I just posted this in here because multiple people recommended that I do, completely agree this is completely a prototype/PoC and will add a disclaimer for that! I will update the post within 72 hours.