Skip to content

Release v0.1.8 - End-to-End Encryption

Choose a tag to compare

@blocksorg blocksorg released this 04 Nov 00:15
· 29 commits to main since this release

MigChat CLI v0.1.8 - End-to-End Encryption

This release introduces end-to-end encryption for all messages, providing strong security guarantees for user communications.

πŸ” Major Features

End-to-End Encryption

  • Signal Protocol/X3DH key agreement implementation
  • ChaCha20-Poly1305 authenticated encryption for all messages
  • X25519 Diffie-Hellman key exchange
  • Ed25519 digital signatures for authentication
  • Perfect forward secrecy with one-time prekeys
  • Argon2 password-based key encryption for local storage

Phase 3 Security Features

  • Key Fingerprint Verification: SHA256-based fingerprints for out-of-band verification
  • Key Change Warnings: Alerts when a contact's keys change
  • Secure Key Backup: Export and import encrypted key backups

Encryption Architecture

Client-side:
- Identity keys (X25519 keypair)
- Signed prekeys (X25519 keypair + Ed25519 signature)
- 100 one-time prekeys for forward secrecy
- Password-encrypted local key storage
- Session management with automatic key derivation

Server-side:
- Public key storage and distribution
- Key upload/retrieval API endpoints
- One-time prekey pool management

🎯 Security Properties

  • βœ… Confidentiality: Only sender and recipient can read messages
  • βœ… Authenticity: Cryptographic verification of sender identity
  • βœ… Forward Secrecy: Past messages remain secure if keys compromised
  • βœ… Deniability: No proof of message authorship to third parties

πŸ“¦ What's Changed

New Features

  • Added complete crypto module (src/crypto/) with:
    • keys.rs - Key generation, storage, and fingerprints
    • session.rs - X3DH protocol and session management
    • encrypt.rs - High-level encryption API
  • New "Security & Encryption" menu with:
    • View your fingerprint
    • Verify contact fingerprints
    • Export/import key backups
  • Automatic encryption for all new messages (πŸ”’ indicator)
  • Seamless handling of legacy unencrypted messages

API Changes

  • New endpoints: POST /api/keys/upload, GET /api/keys/:username
  • Enhanced message model to support encrypted content

Dependencies Added

  • x25519-dalek - Elliptic curve Diffie-Hellman
  • ed25519-dalek - Digital signatures
  • chacha20poly1305 - AEAD cipher
  • hkdf - Key derivation
  • hmac - Message authentication
  • argon2 - Password hashing
  • zeroize - Secure memory clearing

πŸ”§ Technical Details

Key Storage:

  • Location: ~/.config/migchat/keys/
  • Files: identity_key.enc, signed_prekey.enc, one_time_prekeys.enc
  • Encryption: Argon2 with user password

Migration Strategy:

  • Hard cutover: All new messages encrypted
  • Backward compatible: Can read old unencrypted messages
  • Clear user messaging: "End-to-end encryption enabled" notification

πŸ§ͺ Testing

Comprehensive testing completed:

  • βœ… CLI encryption setup and key generation
  • βœ… API infrastructure for key storage/retrieval
  • βœ… Real cryptographic key verification
  • βœ… Multi-user encryption scenarios
  • βœ… Message encryption and delivery

See full test results: Encryption Test Report

πŸ“ Commits

  • d813e6c: Merge PR #7 - E2E encryption feature
  • 15ad86a: Fix borrow checker errors in session management
  • 38e29c0: Merge PR #6 - E2E encryption feature
  • f141c84: Fix Rust compilation errors in crypto module
  • 40b6b7c: Merge PR #5 - E2E encryption feature
  • 857a8c4: Add end-to-end encryption support with Phase 3 features

πŸš€ Upgrade Instructions

  1. Download the new binary for your platform
  2. First login after upgrade will generate encryption keys
  3. You'll see your fingerprint displayed - save it for verification
  4. All new messages will be automatically encrypted

Note: Your existing message history remains unencrypted, but all new messages will use E2E encryption.

πŸ“š Documentation

For more information on using the encryption features:

  • View your fingerprint: Security & Encryption β†’ View Fingerprint
  • Verify contacts: Security & Encryption β†’ Verify Contact
  • Backup keys: Security & Encryption β†’ Export Backup

Full Changelog: v0.1.7...v0.1.8