Skip to content

Releases: boredpolymath/truth-beacon

TruthBeacon v0.1.5

Choose a tag to compare

@github-actions github-actions released this 07 Oct 23:36

TruthBeacon v0.1.5 — Official Release Notes

Bored Polymath Studios — Identity Ground-Truth & Community Stewardship


Overview

TruthBeacon v0.1.5 is a user-experience and interface alignment release that synchronizes both the standalone desktop security console and the official web distribution center with all recent architectural advancements:

  1. Complete UI Alignment with Machine-Bound AES-256-GCM Vault: Modernized all desktop console badges, security enclave pills, input help notes, and interactive FAQ guidance to accurately describe the zero-prompt machine-bound AES-256-GCM credential vault (0600 POSIX) replacing legacy OS keychain references.
  2. Auto-Updater Interface & Version Synchronization: Elevated the desktop header version pill, update polling fallback routines, and website manifests to v0.1.5 with full Minisign Ed25519 cryptographic auto-updater catalog (latest.json) support.
  3. Distribution Portal & Architecture Showcase Refresh: Updated the public website with dedicated highlights and architecture pillars for the zero-prompt vault and auto-updater engine, along with updated download matrices and verification snippets.
  4. Universal 2 Packaging & Cryptographic Integrity Verification: Rebuilt and staged production Universal 2 macOS artifacts (.dmg, .app.tar.gz), updated detached signatures, and verified clean-slate launch with 150 passing unit and integration tests.

What's New & Fixed in v0.1.5

1. Desktop Console Interface Modernization

  • Credential Enclave Status Pill: Replaced the legacy "OS Secure Enclave / Apple Keychain" pill in Discord Settings with the high-visibility "Zero-Prompt AES-256-GCM Vault Active" badge, reflecting local authenticated encryption with hardware entropy binding and strict owner-only (0600) POSIX permissions.
  • Form Field Security Guidance: Clarified token storage security notes to reassure operators that bot credentials are encrypted locally with machine-bound AES-256-GCM and never sent to remote cloud infrastructure.
  • Credential Purge Tooltip: Updated the disconnect button tooltip to explicitly reflect cryptographic zeroization and eradication from the local AES-256-GCM vault.
  • In-App FAQ Guidance: Revised the token storage security FAQ entry to provide precise technical disclosure of the Ring AEAD AES-256-GCM scheme, SHA-256 HKDF key derivation, and zero-telemetry policy.

2. Auto-Updater Engine & Version Bumping

  • Desktop Version Badge: Synchronized the interactive update button in the desktop header to default to v0.1.5.
  • IPC Update Dispatcher: Bumped IPC mock and fallback version values to 0.1.5.
  • Catalog Synchronization: Automated deployment of Tauri 2 latest.json updater catalogs across release directories and website assets.

3. Web Distribution Portal Alignment

  • Feature Highlights & Architecture Pillars: Added dedicated showcase cards for the AES-256-GCM Machine Vault and Cross-Platform Auto-Updater Engine on the official website.
  • Download Catalogs & Verification Snippets: Updated all direct download links, terminal SHA-256 verification instructions, and GPG signature endpoints to point to v0.1.5 deliverables.

Previous Highlights from v0.1.4

1. Resolved Startup Tokio Reactor Panic on Credential Auto-Connect

  • Issue: When bot credentials had been registered and stored in the secure vault, TruthBeacon automatically initiates background connection to the Discord Gateway daemon during startup. In v0.1.3, this async task was spawned using tokio::spawn inside Tauri's synchronous .setup(|app| ...) hook on the main thread. Because Tauri executes setup on the main thread outside of an active Tokio runtime context, tokio::spawn panicked immediately with:
    there is no reactor running, must be called from the context of a Tokio 1.x runtime
    
    Because the panic occurred inside macOS's native applicationDidFinishLaunching: Cocoa delegate, Rust's panic unwinding crossed an FFI C/Objective-C runtime boundary, triggering panic_cannot_unwind and causing abort() (SIGABRT).
  • Fix: Replaced direct tokio::spawn calls in src/lib.rs with tauri::async_runtime::spawn. Tauri manages its own background Tokio runtime handle, allowing asynchronous tasks to be safely scheduled from synchronous main-thread setup routines.
  • Defense-in-Depth: Hardened spawn_background_avatar_fetch and start_periodic_avatar_refresh in src/vault/avatar_sync.rs to use tauri::async_runtime::spawn, guaranteeing that background avatar hashing and periodic sync routines can never panic if invoked from synchronous threads.

2. Zero-Prompt Authenticated AES-256-GCM Machine Credential Vault

  • Frictionless Operator Experience: Replaced native OS Keychain integrations (keyring-rs) with an authenticated local vault. Native OS keychains frequently prompt users with modal security dialogues (such as macOS "TruthBeacon wants to access key truth_beacon_secure_vault in your keychain" or system lock prompts), interrupting background sync, headless test suites, and desktop startup.
  • Cryptographic Authenticated Encryption (AES-256-GCM): The vault stores bot credentials using ring::aead::AES_256_GCM with 12-byte cryptographically secure random nonces and 128-bit authentication tags, preventing ciphertext tampering or truncation.
  • Machine-Unique Key Derivation via SHA-256 HKDF: Encryption keys are deterministically derived using SHA-256 HKDF bound to host machine entropy, the current user environment, and application domain salts. Stolen vault files cannot be decrypted on other machines or user accounts.
  • Strict OS Filesystem Security: On Unix and macOS platforms, the vault storage file (~/.truthbeacon/vault.enc) is created with strict 0600 permissions (read/write by owner only), blocking multi-user host inspection.
  • Dual-Tier Zeroized In-Memory Cache: Credential lookups prioritize a thread-safe in-memory cache (RwLock<HashMap<String, Zeroizing<String>>>) wrapped in zeroize::Zeroizing. Lookups achieve sub-millisecond retrieval without disk access, decrypting the on-disk vault only on initial cold-start cache misses.
  • Secure Cryptographic Erasure & System Eradication: Credential deletion and system eradication (purge_all_credentials) overwrite the vault file with zeros before removing it from disk, ensuring no data residue remains.
  • Zero-Plaintext Policy Maintained: Bot tokens remain strictly zeroized in memory, are redacted in all log output ([REDACTED]), and are never serialized to JSON, SQLite, or plain text.

3. Cross-Platform Cryptographic Auto-Updater Engine (macOS, Windows, Linux)

  • Tauri 2 Plugin Updater Integration: Integrated tauri-plugin-updater with cryptographically enforced Minisign Ed25519 signature verification to protect operators against MITM tampering.
  • Passive Background & 1-Click Manual Updates: The desktop client executes a silent background update check 5 seconds after launch and provides an interactive version badge button in the main header.
  • Interactive Update Notification: Operators receive an in-app notification card with release highlights and a 1-click "Download & Install" workflow to seamlessly relaunch the updated application.
  • Full Platform Parity: Staged and verified across macOS (Universal 2 .app.tar.gz), Windows (NSIS .zip), and Linux (AppImage .tar.gz) alongside public latest.json release manifests.

4. Automated Release Pipeline, CI Signing & Artifact Packaging Hardening

  • CI/CD Minisign Key Integration: Configured TAURI_SIGNING_PRIVATE_KEY and automated key decoding in .github/workflows/ci.yml and .github/workflows/release.yml, ensuring production builds generate authentic cryptographically signed manifests.
  • Safe Fallback Signing across Packaging Scripts: Hardened scripts/build_macos_universal.sh, scripts/build_linux_bundle.sh, and scripts/build_windows_bundle.ps1 with fallback signature generation and validation checks, enabling graceful local development builds and offline packaging.
  • Automated Manifest Generator: Added scripts/generate_updater_manifest.py to deterministically assemble and format latest.json catalogs from release builds and signatures.
  • Detached GPG Signatures & Release Manifests: Staged updater tarballs and bundles in RELEASE_MANIFEST.md and SHA256SUMS.txt, verified with detached ASCII-armored GPG signatures (.asc).
  • Clean-Slate Smoke Testing: Updated scripts/smoke_test_clean_slate.py and scripts/verify_packaging_pipeline.py to validate clean-slate environment setup, zero-prompt vault operations, and release bundle integrity.

Previous Highlights from v0.1.3 & v0.1.2

1. Tauri 2 IPC Parameter Normalization

  • Resolved Argument Serialization: Tauri 2 commands expect camelCase argument names by default (guildId). Added automatic bidirectional casing normalization in ui/js/ipc.js to ensure seamless deserialization across all Tauri commands.
  • Resilient Daemon Lifecycle: Hardened background Discord Gateway connection lifecycle and periodic heartbeat transmission.

2. Automated 1-Click Bot Authorization & Pre-Calculated Permissions

  • Instant Client ID Extraction: TruthBeacon automatically extracts and base64-decodes your bot's application snowflake ID directly from segment 1 of your Bot Token upon pasting.
  • Pre-Calculated Permissions Bitfield: Eliminates manual Discord OAuth2 URL Generator calculations:
    $$\text{VIEW_CHANNEL (1024)} \mid \text{KICK_MEMBERS (2)} \mid \text{BAN_MEMBERS (4)} \mid \text{MODERATE_MEMBERS (1099511627776)} = \mathbf{1099511628806}$$
  • 1-Click "Authorize & Invite Bot" Button: Direct 1-click addition of the bot to your Discord server, plus a 1-click "Copy Link" utility.

3. Au...

Read more

TruthBeacon v0.1.4

Choose a tag to compare

@github-actions github-actions released this 07 Oct 14:03

TruthBeacon v0.1.4 — Official Release Notes

Orange Heart Industries — Identity Ground-Truth & Community Stewardship


Overview

TruthBeacon v0.1.4 is a critical stability patch resolving an immediate startup panic (EXC_CRASH (SIGABRT)) on macOS when launching with bot credentials saved in the native OS Keychain.


What's Fixed in v0.1.4

1. Resolved Startup Tokio Reactor Panic on Credential Auto-Connect

  • Issue: When bot credentials had been registered and stored in the native OS Keychain (truth_beacon_secure_vault), TruthBeacon automatically initiates background connection to the Discord Gateway daemon during startup. In v0.1.3, this async task was spawned using tokio::spawn inside Tauri's synchronous .setup(|app| ...) hook on the main thread. Because Tauri executes setup on the main thread outside of an active Tokio runtime context, tokio::spawn panicked immediately with:
    there is no reactor running, must be called from the context of a Tokio 1.x runtime
    
    Because the panic occurred inside macOS's native applicationDidFinishLaunching: delegate, Rust's panic unwinding crossed an FFI C/Objective-C runtime boundary, triggering panic_cannot_unwind and causing abort() (SIGABRT).
  • Fix: Replaced direct tokio::spawn calls in src/lib.rs with tauri::async_runtime::spawn. Tauri manages its own background Tokio runtime handle, allowing asynchronous tasks to be safely scheduled from synchronous main-thread setup routines.
  • Defense-in-Depth: Also hardened spawn_background_avatar_fetch and start_periodic_avatar_refresh in src/vault/avatar_sync.rs to use tauri::async_runtime::spawn, guaranteeing that background avatar hashing and periodic sync routines can never panic if invoked from synchronous threads.

Previous Highlights from v0.1.3 & v0.1.2

1. Tauri 2 IPC Parameter Normalization

  • Resolved Argument Serialization: Tauri 2 commands expect camelCase argument names by default (guildId). Added automatic bidirectional casing normalization in ui/js/ipc.js to ensure seamless deserialization across all Tauri commands.
  • Resilient Daemon Lifecycle: Hardened background Discord Gateway connection lifecycle and periodic heartbeat transmission.

2. Automated 1-Click Bot Authorization & Pre-Calculated Permissions

  • Instant Client ID Extraction: TruthBeacon automatically extracts and base64-decodes your bot's application snowflake ID directly from segment 1 of your Bot Token upon pasting.
  • Pre-Calculated Permissions Bitfield: Eliminates manual Discord OAuth2 URL Generator calculations:
    $$\text{VIEW_CHANNEL (1024)} \mid \text{KICK_MEMBERS (2)} \mid \text{BAN_MEMBERS (4)} \mid \text{MODERATE_MEMBERS (1099511627776)} = \mathbf{1099511628806}$$
  • 1-Click "Authorize & Invite Bot" Button: Direct 1-click addition of the bot to your Discord server, plus a 1-click "Copy Link" utility.

3. Automated Server Discovery (Zero Snowflake Hunting)

  • Automatic Discord Gateway Server Discovery: Integrated fetch_bot_guilds Tauri IPC command querying Discord v10 REST API (GET /users/@me/guilds).
  • Dynamic Discovered Servers Dropdown: Discovered servers appear in an interactive dropdown with server names and IDs.

4. Native OS Keychain & Zeroized In-Memory Cache Resilience

  • Persistent Credential Lifecycle: Dual-tier credential architecture combining native OS Secure Enclaves (keyring-rs targeting Apple Keychain Services, Windows Credential Manager DPAPI, and Linux Secret Service) with zeroized in-memory fallback caches.
  • Zero-Plaintext Security Policy: Bot tokens remain strictly zeroized and never touch SQLite databases, flat files, or unredacted serialization logs.

Core Security Engine

  1. Deterministic Multi-Script Homoglyph Detection:

    • Sub-50ms deterministic normalization and skeleton decomposition (NFKD).
    • Defeats cross-script lookalike substitutions across Cyrillic, Greek, Mathematical, and Latin lookalikes.
    • De-obfuscates invisible unicode anomalies, zero-width spaces, and bidirectional text overrides.
  2. Perceptual Avatar Clone Defense:

    • Discrete Cosine Transform (DCT) perceptual image hashing (img_hash).
    • Automatically flags unauthorized copies and subtle visual perturbations of moderator and VIP avatars.
  3. Snowflake Cryptographic Account Age Analysis:

    • Parses Discord 64-bit integer IDs directly to extract real account creation epochs.
    • Escalates risk tier when brand-new accounts (< 72 hours old) exhibit visual or naming similarity to benchmark staff.
  4. Zero-Telemetry Local Data Sovereignty:

    • 100% offline-first architecture; all benchmark vaults, audit logs, and incident records are retained exclusively on the operator's machine.

Platform Availability & Supported Operating Systems

  • macOS (Universal 2):
    • Supports Apple Silicon (M1/M2/M3/M4) and Intel Macs (macOS 10.15 Catalina or higher).
    • Packaged as a drag-and-drop .dmg installer with custom Orange Heart backdrop and a standalone portable .app bundle.
  • Windows (x64):
    • Supports Windows 10 and Windows 11 (64-bit).
    • Packaged via WiX (.msi) for enterprise deployment, NSIS (.exe) for standard setup, and a portable executable.
  • Linux (x86_64):
    • Supports Ubuntu 20.04+, Debian 11+, Fedora, and Arch.
    • Packaged as a native Debian .deb package and portable standalone .AppImage.

Verification & Checksums

All binaries are verified through GitHub Actions CI and signed with SHA-256 cryptographic checksums. Check SHA256SUMS.txt and RELEASE_MANIFEST.md for verification details.

TruthBeacon v0.1.3

Choose a tag to compare

@github-actions github-actions released this 06 Oct 16:27

TruthBeacon v0.1.3 — Official Release Notes

Orange Heart Industries — Identity Ground-Truth & Community Stewardship


Overview

TruthBeacon v0.1.3 is an essential patch release resolving a critical IPC parameter serialization mismatch in the bot pre-flight verification and server pairing engine.


What's Fixed in v0.1.3

1. Tauri 2 IPC Parameter Normalization (Discord Handshake & Membership Verification Fix)

  • Resolved CamelCase Argument Serialization: Tauri 2 commands expect camelCase argument names by default (guildId). In v0.1.2, passing guild_id in snake_case caused the Rust backend to deserialize guild_id as None, leading pre-flight handshake diagnostics to always report "Bot Not Found in Target Server" and "Missing Required Moderation Grants".
  • Automatic Casing Normalization: Added an IPC payload normalization layer in ui/js/ipc.js that automatically transforms all command arguments into both camelCase and snake_case representations, guaranteeing seamless deserialization across all Tauri commands.
  • Heartbeat & Resilient Daemon Lifecycle: Hardened background Discord Gateway connection lifecycle and periodic heartbeat transmission.

Previous Highlights from v0.1.2

1. Automated 1-Click Bot Authorization & Pre-Calculated Permissions

  • Instant Client ID Extraction: TruthBeacon automatically extracts and base64-decodes your bot's application snowflake ID directly from segment 1 of your Bot Token upon pasting. No need to navigate to the Discord Developer Portal's "General Information" tab just to hunt down an Application ID.
  • Pre-Calculated Permissions Bitfield: Eliminates the manual Discord OAuth2 URL Generator. TruthBeacon pre-calculates the exact bitwise integer required for anti-impersonation defense:
    $$\text{VIEW_CHANNEL (1024)} \mid \text{KICK_MEMBERS (2)} \mid \text{BAN_MEMBERS (4)} \mid \text{MODERATE_MEMBERS (1099511627776)} = \mathbf{1099511628806}$$
  • 1-Click "Authorize & Invite Bot" Button: A prominent action card provides direct 1-click addition of the bot to your Discord server, plus a 1-click "Copy Link" utility for server owners.

2. Automated Server Discovery (Zero Snowflake Hunting)

  • Automatic Discord Gateway Server Discovery: Added fetch_bot_guilds Tauri IPC command querying Discord v10 REST API (GET /users/@me/guilds).
  • Elimination of Developer Mode: Community leaders are no longer forced to enable Discord Developer Mode, right-click their server icon, and copy 19-digit numeric snowflake Guild IDs.
  • Dynamic Discovered Servers Dropdown: Discovered servers appear in an interactive dropdown with server names and IDs. If the bot is present in a single server, TruthBeacon auto-selects it instantly.

3. Native OS Keychain & Zeroized In-Memory Cache Resilience

  • Persistent Credential Lifecycle: Dual-tier credential architecture combining native OS Secure Enclaves (keyring-rs targeting Apple Keychain Services, Windows Credential Manager DPAPI, and Linux Secret Service) with zeroized in-memory fallback caches.
  • Zero-Plaintext Security Policy: Bot tokens remain strictly zeroized and never touch SQLite databases, flat files, or unredacted serialization logs.

Core Security Engine

  1. Deterministic Multi-Script Homoglyph Detection:

    • Sub-50ms deterministic normalization and skeleton decomposition (NFKD).
    • Defeats cross-script lookalike substitutions across Cyrillic, Greek, Mathematical, and Latin lookalikes.
    • De-obfuscates invisible unicode anomalies, zero-width spaces, and bidirectional text overrides.
  2. Perceptual Avatar Clone Defense:

    • Discrete Cosine Transform (DCT) perceptual image hashing (img_hash).
    • Automatically flags unauthorized copies and subtle visual perturbations of moderator and VIP avatars.
  3. Snowflake Cryptographic Account Age Analysis:

    • Parses Discord 64-bit integer IDs directly to extract real account creation epochs.
    • Escalates risk tier when brand-new accounts (< 72 hours old) exhibit visual or naming similarity to benchmark staff.
  4. Zero-Telemetry Local Data Sovereignty:

    • 100% offline-first architecture; all benchmark vaults, audit logs, and incident records are retained exclusively on the operator's machine.

Platform Availability & Supported Operating Systems

  • macOS (Universal 2):
    • Supports Apple Silicon (M1/M2/M3/M4) and Intel Macs (macOS 10.15 Catalina or higher).
    • Packaged as a drag-and-drop .dmg installer with custom Orange Heart backdrop and a standalone portable .app bundle.
  • Windows (x64):
    • Supports Windows 10 and Windows 11 (64-bit).
    • Packaged via WiX (.msi) for enterprise deployment, NSIS (.exe) for standard setup, and a portable executable.
  • Linux (x86_64):
    • Supports Ubuntu 20.04+, Debian 11+, Fedora, and Arch.
    • Packaged as a native Debian .deb package and portable standalone .AppImage.

Verification & Checksums

All binaries are verified through GitHub Actions CI and signed with SHA-256 cryptographic checksums. Check SHA256SUMS.txt and RELEASE_MANIFEST.md for verification details.

TruthBeacon v0.1.2

Choose a tag to compare

@boredpolymath boredpolymath released this 05 Oct 19:28

TruthBeacon v0.1.2 — Official Release Notes

Orange Heart Industries — Identity Ground-Truth & Community Stewardship


Overview

TruthBeacon v0.1.2 is a major usability and friction-removal release of our standalone desktop security console for Discord community leadership, pastoral teams, and server moderators.

This release completely eliminates manual setup friction, snowflake ID hunting, and complex bot permission calculations—empowering community leaders to pair TruthBeacon with their Discord servers in under 60 seconds with zero technical complexity.


What's New in v0.1.2

1. Automated 1-Click Bot Authorization & Pre-Calculated Permissions

  • Instant Client ID Extraction: TruthBeacon automatically extracts and base64-decodes your bot's application snowflake ID directly from segment 1 of your Bot Token upon pasting. No need to navigate to the Discord Developer Portal's "General Information" tab just to hunt down an Application ID.
  • Pre-Calculated Permissions Bitfield: Eliminates the manual Discord OAuth2 URL Generator. TruthBeacon pre-calculates the exact bitwise integer required for anti-impersonation defense:
    $$\text{VIEW_CHANNEL (1024)} \mid \text{KICK_MEMBERS (2)} \mid \text{BAN_MEMBERS (4)} \mid \text{MODERATE_MEMBERS (1099511627776)} = \mathbf{1099511628806}$$
  • 1-Click "Authorize & Invite Bot" Button: A prominent action card provides direct 1-click addition of the bot to your Discord server, plus a 1-click "Copy Link" utility for server owners.

2. Automated Server Discovery (Zero Snowflake Hunting)

  • Automatic Discord Gateway Server Discovery: Added fetch_bot_guilds Tauri IPC command querying Discord v10 REST API (GET /users/@me/guilds).
  • Elimination of Developer Mode: Community leaders are no longer forced to enable Discord Developer Mode, right-click their server icon, and copy 19-digit numeric snowflake Guild IDs.
  • Dynamic Discovered Servers Dropdown: Discovered servers appear in an interactive dropdown with server names and IDs. If the bot is present in a single server, TruthBeacon auto-selects it instantly.

3. Frictionless Automated Handshake Auto-Verification

  • Instant Pre-Flight Testing: When a server is selected from the discovered server list, TruthBeacon automatically triggers the 5-point diagnostic pre-flight verification in the background.
  • Instant Visual Confirmation: Token Format, Gateway Handshake, Privileged GUILD_MEMBERS Intent, Server Membership, and Moderation Capabilities turn green automatically without requiring operators to hunt down a separate test button.

4. Native OS Keychain & Zeroized In-Memory Cache Resilience

  • Persistent Credential Lifecycle: Dual-tier credential architecture combining native OS Secure Enclaves (keyring-rs targeting Apple Keychain Services, Windows Credential Manager DPAPI, and Linux Secret Service) with zeroized in-memory fallback caches.
  • Zero-Plaintext Security Policy: Bot tokens remain strictly zeroized and never touch SQLite databases, flat files, or unredacted serialization logs.

Core Security Engine

  1. Deterministic Multi-Script Homoglyph Detection:

    • Sub-50ms deterministic normalization and skeleton decomposition (NFKD).
    • Defeats cross-script lookalike substitutions across Cyrillic, Greek, Mathematical, and Latin lookalikes.
    • De-obfuscates invisible unicode anomalies, zero-width spaces, and bidirectional text overrides.
  2. Perceptual Avatar Clone Defense:

    • Discrete Cosine Transform (DCT) perceptual image hashing (img_hash).
    • Automatically flags unauthorized copies and subtle visual perturbations of moderator and VIP avatars.
  3. Snowflake Cryptographic Account Age Analysis:

    • Parses Discord 64-bit integer IDs directly to extract real account creation epochs.
    • Escalates risk tier when brand-new accounts (< 72 hours old) exhibit visual or naming similarity to benchmark staff.
  4. Zero-Telemetry Local Data Sovereignty:

    • 100% offline-first architecture; all benchmark vaults, audit logs, and incident records are retained exclusively on the operator's machine.

Platform Availability & Supported Operating Systems

  • macOS (Universal 2):
    • Supports Apple Silicon (M1/M2/M3/M4) and Intel Macs (macOS 10.15 Catalina or higher).
    • Packaged as a drag-and-drop .dmg installer with custom Orange Heart backdrop and a standalone portable .app bundle.
  • Windows (x64):
    • Supports Windows 10 and Windows 11 (64-bit).
    • Packaged via WiX (.msi) for enterprise deployment, NSIS (.exe) for standard setup, and a portable executable.
  • Linux (x86_64):
    • Supports Ubuntu 20.04+, Debian 11+, Fedora, and Arch.
    • Packaged as a native Debian .deb package and portable standalone .AppImage.

Verification & Checksums

All binaries are verified through GitHub Actions CI and signed with SHA-256 cryptographic checksums. Check SHA256SUMS.txt and RELEASE_MANIFEST.md for verification details.

TruthBeacon v0.1.1 — Cryptographically Signed Release

Choose a tag to compare

@boredpolymath boredpolymath released this 05 Oct 05:25

TruthBeacon v0.1.0 — Official Release Notes

Orange Heart Industries — Identity Ground-Truth & Community Stewardship


Overview

TruthBeacon v0.1.0 is the inaugural production release of our standalone desktop security console designed specifically for Discord community leadership, pastoral teams, and server moderators.

TruthBeacon continuously inspects live Discord member events in real-time, detecting and mitigating identity impersonation attacks before bad actors can exploit pastoral or administrative trust to defraud community members.


Key Capabilities

  1. Deterministic Multi-Script Homoglyph Detection:

    • Sub-50ms deterministic normalization and skeleton decomposition (NFKD).
    • Defeats cross-script lookalike substitutions across Cyrillic, Greek, Mathematical, and Latin lookalikes.
    • De-obfuscates invisible unicode anomalies, zero-width spaces, and bidirectional text overrides.
  2. Perceptual Avatar Clone Defense:

    • Discrete Cosine Transform (DCT) perceptual image hashing (img_hash).
    • Automatically flags unauthorized copies and subtle visual perturbations of moderator and VIP avatars.
  3. Snowflake Cryptographic Account Age Analysis:

    • Parses Discord 64-bit integer IDs directly to extract real account creation epochs.
    • Escalates risk tier when brand-new accounts (< 72 hours old) exhibit visual or naming similarity to benchmark staff.
  4. Zero-Telemetry Local Data Sovereignty:

    • No cloud snooping, no external logging, and no analytics beacons.
    • All benchmarks, audit logs, and incident records are retained exclusively on the operator's machine in encrypted SQLite databases.
    • Bot tokens and credentials securely held in the host operating system's native keychain (macOS Keychain, Windows Credential Manager, Linux Secret Service).
  5. Discord-Familiar Operator Interface:

    • Styled after Discord’s high-contrast dark theme (#111214, #1e1f22, #2b2d31, #313338) accented with Orange Heart warmth (#f97316).
    • Clean, non-technical triage card layout with comparative side-by-side identity adjudication.

Platform Availability & Supported Operating Systems

  • macOS (Universal 2):
    • Supports Apple Silicon (M1/M2/M3/M4) and Intel Macs (macOS 10.15 Catalina or higher).
    • Packaged as a drag-and-drop .dmg installer with custom Orange Heart backdrop and a standalone portable .app bundle.
  • Windows (x64):
    • Supports Windows 10 and Windows 11 (64-bit).
    • Packaged via WiX (.msi) for enterprise deployment, NSIS (.exe) for standard setup, and a portable executable.
  • Linux (x86_64):
    • Supports Ubuntu 20.04+, Debian 11+, Fedora, and Arch.
    • Packaged as a native Debian .deb package and portable standalone .AppImage.

Cryptographic Checksums (SHA-256)

fb48df662d01327789e6cac080afe49219ad1ff26723849fd96757fe15cdf3dd  TruthBeacon_0.1.0_universal.dmg
624611f1305d10e4d624be9b6544ec8dbaf5bf4038541f0f50a0c73e5d276839  TruthBeacon_0.1.0_macos_universal.zip
5616b4eb2b4c89828d8585abd41abcba65d6a61da6c05889377a510b8a9d43d4  truth-beacon-universal
775336e65cf81eae4bd2740f3425747cca82ba5d0732a52a57cf2cc708f87fdd  TruthBeacon_0.1.0_x64-setup.exe
3d794ff6d58f625ebea023322fe98b66e151b70bc05dc187f08bcd7510c32a0b  TruthBeacon_0.1.0_x64_en-US.msi
a7545c996c6c35f17c2b05c9abf1838ae1eeefdb393f27576d73b0105eddcca4  TruthBeacon-Portable.exe
8c1818ec1fab31bb5e2c8e006beed887520bb8a9b5d3a4f0f8377cc9c6222132  TruthBeacon_0.1.0_amd64.deb
611cf68b9a9e4d6cb7a49b35dab8a593bb5973b3613d1f59fac0ce72c38bedc7  TruthBeacon_0.1.0_amd64.AppImage

Installation & Quickstart

macOS:

  1. Double-click TruthBeacon_0.1.0_universal.dmg.
  2. Drag TruthBeacon into Applications.
  3. Open TruthBeacon from /Applications or Spotlight.
  4. On initial launch, navigate to Settings and supply your Discord Bot Token and Guild ID.
  5. In Benchmark Vault, import verified server leaders to establish ground-truth protection.

Windows:

  1. Run TruthBeacon_0.1.0_x64-setup.exe (or deploy TruthBeacon_0.1.0_x64_en-US.msi for enterprise management).
  2. For zero-install portable usage, launch TruthBeacon-Portable.exe directly from any folder or USB drive.
  3. Open TruthBeacon from the Start Menu or desktop shortcut.
  4. Navigate to Settings to securely save your Discord Bot Token and target Guild ID.

Linux:

  1. AppImage: Make executable (chmod +x TruthBeacon_0.1.0_amd64.AppImage) and run ./TruthBeacon_0.1.0_amd64.AppImage.
  2. Debian / Ubuntu: Install package via sudo dpkg -i TruthBeacon_0.1.0_amd64.deb (resolving dependencies with sudo apt-get install -f).
  3. Ensure system dependencies are met (libappindicator3-1, libsecret-1-0, and libwebkit2gtk-4.1-0).
  4. Launch TruthBeacon from your desktop environment menu or terminal (truth-beacon).

TruthBeacon v0.1.0

Choose a tag to compare

@boredpolymath boredpolymath released this 05 Oct 04:12

TruthBeacon v0.1.0 — Official Release Notes

Orange Heart Industries — Identity Ground-Truth & Community Stewardship


Overview

TruthBeacon v0.1.0 is the inaugural production release of our standalone desktop security console designed specifically for Discord community leadership, pastoral teams, and server moderators.

TruthBeacon continuously inspects live Discord member events in real-time, detecting and mitigating identity impersonation attacks before bad actors can exploit pastoral or administrative trust to defraud community members.


Key Capabilities

  1. Deterministic Multi-Script Homoglyph Detection:

    • Sub-50ms deterministic normalization and skeleton decomposition (NFKD).
    • Defeats cross-script lookalike substitutions across Cyrillic, Greek, Mathematical, and Latin lookalikes.
    • De-obfuscates invisible unicode anomalies, zero-width spaces, and bidirectional text overrides.
  2. Perceptual Avatar Clone Defense:

    • Discrete Cosine Transform (DCT) perceptual image hashing (img_hash).
    • Automatically flags unauthorized copies and subtle visual perturbations of moderator and VIP avatars.
  3. Snowflake Cryptographic Account Age Analysis:

    • Parses Discord 64-bit integer IDs directly to extract real account creation epochs.
    • Escalates risk tier when brand-new accounts (< 72 hours old) exhibit visual or naming similarity to benchmark staff.
  4. Zero-Telemetry Local Data Sovereignty:

    • No cloud snooping, no external logging, and no analytics beacons.
    • All benchmarks, audit logs, and incident records are retained exclusively on the operator's machine in encrypted SQLite databases.
    • Bot tokens and credentials securely held in the host operating system's native keychain (macOS Keychain, Windows Credential Manager, Linux Secret Service).
  5. Discord-Familiar Operator Interface:

    • Styled after Discord’s high-contrast dark theme (#111214, #1e1f22, #2b2d31, #313338) accented with Orange Heart warmth (#f97316).
    • Clean, non-technical triage card layout with comparative side-by-side identity adjudication.

Platform Availability & Supported Operating Systems

  • macOS (Universal 2):
    • Supports Apple Silicon (M1/M2/M3/M4) and Intel Macs (macOS 10.15 Catalina or higher).
    • Packaged as a drag-and-drop .dmg installer with custom Orange Heart backdrop and a standalone portable .app bundle.
  • Windows (x64):
    • Supports Windows 10 and Windows 11 (64-bit).
    • Packaged via WiX (.msi) for enterprise deployment, NSIS (.exe) for standard setup, and a portable executable.
  • Linux (x86_64):
    • Supports Ubuntu 20.04+, Debian 11+, Fedora, and Arch.
    • Packaged as a native Debian .deb package and portable standalone .AppImage.

Cryptographic Checksums (SHA-256)

fb48df662d01327789e6cac080afe49219ad1ff26723849fd96757fe15cdf3dd  TruthBeacon_0.1.0_universal.dmg
624611f1305d10e4d624be9b6544ec8dbaf5bf4038541f0f50a0c73e5d276839  TruthBeacon_0.1.0_macos_universal.zip
5616b4eb2b4c89828d8585abd41abcba65d6a61da6c05889377a510b8a9d43d4  truth-beacon-universal
775336e65cf81eae4bd2740f3425747cca82ba5d0732a52a57cf2cc708f87fdd  TruthBeacon_0.1.0_x64-setup.exe
3d794ff6d58f625ebea023322fe98b66e151b70bc05dc187f08bcd7510c32a0b  TruthBeacon_0.1.0_x64_en-US.msi
a7545c996c6c35f17c2b05c9abf1838ae1eeefdb393f27576d73b0105eddcca4  TruthBeacon-Portable.exe
8c1818ec1fab31bb5e2c8e006beed887520bb8a9b5d3a4f0f8377cc9c6222132  TruthBeacon_0.1.0_amd64.deb
611cf68b9a9e4d6cb7a49b35dab8a593bb5973b3613d1f59fac0ce72c38bedc7  TruthBeacon_0.1.0_amd64.AppImage

Installation & Quickstart

macOS:

  1. Double-click TruthBeacon_0.1.0_universal.dmg.
  2. Drag TruthBeacon into Applications.
  3. Open TruthBeacon from /Applications or Spotlight.
  4. On initial launch, navigate to Settings and supply your Discord Bot Token and Guild ID.
  5. In Benchmark Vault, import verified server leaders to establish ground-truth protection.

Windows:

  1. Run TruthBeacon_0.1.0_x64-setup.exe (or deploy TruthBeacon_0.1.0_x64_en-US.msi for enterprise management).
  2. For zero-install portable usage, launch TruthBeacon-Portable.exe directly from any folder or USB drive.
  3. Open TruthBeacon from the Start Menu or desktop shortcut.
  4. Navigate to Settings to securely save your Discord Bot Token and target Guild ID.

Linux:

  1. AppImage: Make executable (chmod +x TruthBeacon_0.1.0_amd64.AppImage) and run ./TruthBeacon_0.1.0_amd64.AppImage.
  2. Debian / Ubuntu: Install package via sudo dpkg -i TruthBeacon_0.1.0_amd64.deb (resolving dependencies with sudo apt-get install -f).
  3. Ensure system dependencies are met (libappindicator3-1, libsecret-1-0, and libwebkit2gtk-4.1-0).
  4. Launch TruthBeacon from your desktop environment menu or terminal (truth-beacon).