-
Notifications
You must be signed in to change notification settings - Fork 0
Group Messaging
Available in: v1.9.0+
Group messaging lets you encrypt a single bundle and send it to multiple contacts at once. One file, one share — every recipient gets their own individually wrapped copy of the decryption key, so only they can open it.
When you send to a group, Occulta:
- Encrypts the message or file once using a random session key.
- For each recipient, wraps a copy of that session key using their individual cryptographic material — the same ECDH + ML-KEM key exchange used for single-recipient bundles.
- Packages everything into one
.occbundle with a section per recipient.
Each recipient's wrapped key is bound to them specifically. A bundle recipient cannot use their copy of the session key to impersonate another recipient or probe the group membership.
→ Technical details: wire format and crypto flows
A group is a named list of contacts stored on your device. There is no group server, no group account, no membership notification sent to contacts. When you send a bundle, the recipient list is determined by who is in the group at that moment.
Delivery is out-of-band, the same as individual bundles — share the .occ file via AirDrop, email, iMessage, Signal, or any other channel.
Group bundles use the same forward secrecy and post-quantum protection as single-recipient bundles. Each recipient's session key is wrapped using a fresh ephemeral key if a prekey is available for them, or the long-term key otherwise. ML-KEM material is applied silently when it exists for a contact.
A contact must have exchanged keys with you on Occulta v1.9.0 or later to be eligible for group membership. Older contacts are shown in the member picker but cannot be added until they update.
Groups support Occulta's full multi-layer duress model — the same one individual contacts use. Each of the up to 32 duress depths maintains its own independent member list, so a deeper coercion layer shows a genuinely different decoy group than a shallower one. Entering a duress PIN switches every group to its member list for that specific depth. The real member list is never revealed at any duress depth.
Every depth's member list is fixed at 32 slots and padded with random data. An observer who cannot decrypt the database cannot determine how many members are in any layer, or which layer was most recently edited.
Available in: v1.9.1+
If you use the Vault's secret-sharing recovery feature, a group message can also carry shard custody traffic to group members who are eligible trustees — the same distribution and recovery flow used for one-on-one messages, extended to groups. A member needs an up-to-date app version, exchanged post-quantum key material, and an available forward-secrecy key for that particular send to receive real shard content; everyone else in the group still receives the message normally.
- Maximum 32 members per layer.
- No message persistence or conversation threading.
- No delivery confirmation — the sender cannot know whether recipients have opened the bundle.
- No group admin roles or member change notifications.