General

[RELEASE] ChatPGP

Started by LibertyExchange · Jul 31, 2025

#4356
ChatPGP

End-to-End Encryption

PGP/GPG Integration: Native GnuPG (OpenKeychain on android)

Key Management: Generate new key pairs or import existing PGP keys

Digital Signatures: All messages are cryptographically signed for authenticity

Zero Knowledge: No server can decrypt your messages - only you and the recipient

No Central Servers: Operates entirely peer-to-peer using IPFS

Tor Network Integration: All communications routed through Tor for anonymity

Self-Sovereign Identity: Your PGP fingerprint is your unique identity

Censorship Resistant: Cannot be blocked or taken down by authorities

Text Messages: Secure encrypted text communication

Image Sharing: Send photos with thumbnail previews and full-resolution viewing

Real-time Delivery: Messages delivered instantly when recipients are online

Message Status Indicators: See when messages are sent, delivered, and read

Interactive Image Viewer: Zoom, pan, and view images in full screen

Network Scanning: Automatically discovers other ChatPGP users on the network

Presence Status: See who's online and when they were last active

User Verification: Public key fingerprints ensure you're talking to the right person

Contact Management: Automatically maintains your contact list

Tor Circuit Control: Create new Tor circuits for enhanced anonymity

Connection Status: Real-time monitoring of Tor and IPFS connectivity

Debug Tools: Comprehensive network diagnostics for troubleshooting

Secure File Storage: Images and files stored on IPFS with content addressing

Cross-Platform: Runs on Linux, coming to Android, iOS, Windows, macOS

Native Performance: Compiled to native code for optimal performance

System Integration: Uses platform-specific features where appropriate

User Search: Find contacts by name or PGP fingerprint

Connection Diagnostics: Built-in tools to debug network connectivity

Manual Peer Connection: Connect directly to specific IPFS peers

Network Statistics: View connection status, peer counts, and topic activity

Protected:

Message Content: Encrypted with recipient's public key

Message Metadata: Timestamps and sender information protected

User Identity: Only PGP fingerprints are shared, no personal data

Network Traffic: All communications routed through Tor

File Transfers: Images encrypted and distributed via IPFS

Not Collected:

No user registration required

No personal information stored

No message content accessible to third parties

No analytics or tracking

No centralized user database

Initial Setup

Key Generation: Create a new PGP key pair with custom name and email

Key Import: Import existing PGP keys for experienced users

Network Bootstrap: Automatic Tor and IPFS initialization

User Discovery: Automatic detection of other users on the network

System Requirements

Dependencies: Requires Tor, IPFS, and GnuPG to be installed

Network: Internet connection for initial Tor and IPFS setup

Storage: Local storage for keys and cached images

RAM: Lightweight operation with efficient resource usage

FAQ:

Why do I have to download/build something?

Because otherwise you'd have to upload your private PGP key

ChatPGP represents the future of secure, private communication - where your conversations remain yours, protected by cryptography and distributed across a network that no single entity can control or compromise.

Download at libertyklimuepdewpamrqtciexnrucs3zfninpuurs6evwbqcbkmfyd.onion/chatpgp

0.9.4

Available on Windows, MacOS and Linux now!

Source available!

0.9.5

Timer cascading issue fixed

0.9.6

Start up leak detection

Basic startup

0.9.7

Better tor setup

Better IPFS setup

Network manager

0.9.7.1

Fixed a tor startup bug when tor is already running on 9050 but not working or secure

0.9.8

Updated Image encryption

Future updates:

Sandboxing

Network kill switch

Key trust evaluation system

Update dl to have a binary for each OS

Tips:

If you let the app start it's own tor, it uses vanguards full

If you want to use your own tor, please enable vanguards full before starting it

!! DISCLAIMER !!

Do not run this anywhere except a CLEAN whonix or tails system.

PLEASE READ (and keep development discussion here):

/post/e5b798a65036865917d2 - credit to /u/pgpfreak

Message us at: F390E06C4B16F0395433937437FCAB069A4FBE39
#4357
↳ Replying to @LibertyExchange
Also read about more details on the risks of using this (well meant) app: /post/e5b798a65036865917d2

I see /u/mrbacon420 approved this. But note as far as I am concerned this application is featured here under provision.

This because several issues I have with this app:

1. ChatPGP is an p2p application and not a hidden servcie. Normally we don't really allow applications with no backend service to connect to.

2. ChatPGP makes use of the InterPlanetary Files System for discovery. In a previous post /u/Liberty exchange noted:
Disclosure: Your device is used as an IPFS node (over tor with full vanguards) while the program is running.
Perhaps this can be added again?

3. ChatPGP is made with Dart and Flutter. Both are open source projecst heavily backed by Google and meant for easy and fast multi platform coding. This means many libraries and other resources from Google and others are being used to make ChatPGP operational on different platforms.

In my opinion this is not the correct method to create a privacy-first application in general. I believe ChatPGP should therefor be seen as a Proof-of-Concept or prototype application and not to be used by anyone with a relevant threat model. I myself will not use it beyond testing for this reason.

The application is hosted on a dedicated page on the PrimeMarket website, which is fine as the user is not directed to the market itself. It's still a bit of advertising though. So it would be professional to have a git repo or dedicated page instead.

I've had a look a the code and generally it looks pretty ok. I don't get the impression this is a vibecode project. The only reason I believe this is not made by very experienced developer(s), is the choice of language and framework. I didn't see any malicious code or packages, but no guarantees: it's a very bloated project and I only checked for a few things. There can always be something obfuscated, so use at own risk!
#4358
↳ Replying to @drisdane
So when Liberty first posed this, it showed as an onion with a key. I was unable to get the key to work.

Now, I have realized, the link is to download a ZIP file. I did not know that when I recommended him to post here and approved the post.

You and the freak bring up some good points (His are /post/e5b798a65036865917d2 )

I wouldn't be offended if you overrode my approval and put it back in the queue if you think that is best.
#4359
↳ Replying to @MrBacon420
I didn't see the post for /u/pgpfreak. Makes me feel like an amateur thank you ;)

Although it's a bit worrying, I also agree with him that we should encourage these kind of projects, which is the reason for an exception in the first place.

I see the /u/LibertyExchange already interacting and I have good hope there will be improvement soon. I will edit my orignal message with an extra warning.
#4360
↳ Replying to @drisdane
[removed]
#4361
↳ Replying to @MrBacon420
[removed]
#4362
↳ Replying to @drisdane
Of course, I'd be glad to re-add the disclaimers! I just posted this in here because multiple people recommended that I do, completely agree this is completely a prototype/PoC and will add a disclaimer for that! I will update the post within 72 hours.