Release v0.1.8 - End-to-End Encryption
MigChat CLI v0.1.8 - End-to-End Encryption
This release introduces end-to-end encryption for all messages, providing strong security guarantees for user communications.
π Major Features
End-to-End Encryption
- Signal Protocol/X3DH key agreement implementation
- ChaCha20-Poly1305 authenticated encryption for all messages
- X25519 Diffie-Hellman key exchange
- Ed25519 digital signatures for authentication
- Perfect forward secrecy with one-time prekeys
- Argon2 password-based key encryption for local storage
Phase 3 Security Features
- Key Fingerprint Verification: SHA256-based fingerprints for out-of-band verification
- Key Change Warnings: Alerts when a contact's keys change
- Secure Key Backup: Export and import encrypted key backups
Encryption Architecture
Client-side:
- Identity keys (X25519 keypair)
- Signed prekeys (X25519 keypair + Ed25519 signature)
- 100 one-time prekeys for forward secrecy
- Password-encrypted local key storage
- Session management with automatic key derivation
Server-side:
- Public key storage and distribution
- Key upload/retrieval API endpoints
- One-time prekey pool management
π― Security Properties
- β Confidentiality: Only sender and recipient can read messages
- β Authenticity: Cryptographic verification of sender identity
- β Forward Secrecy: Past messages remain secure if keys compromised
- β Deniability: No proof of message authorship to third parties
π¦ What's Changed
New Features
- Added complete crypto module (
src/crypto/) with:keys.rs- Key generation, storage, and fingerprintssession.rs- X3DH protocol and session managementencrypt.rs- High-level encryption API
- New "Security & Encryption" menu with:
- View your fingerprint
- Verify contact fingerprints
- Export/import key backups
- Automatic encryption for all new messages (π indicator)
- Seamless handling of legacy unencrypted messages
API Changes
- New endpoints:
POST /api/keys/upload,GET /api/keys/:username - Enhanced message model to support encrypted content
Dependencies Added
x25519-dalek- Elliptic curve Diffie-Hellmaned25519-dalek- Digital signatureschacha20poly1305- AEAD cipherhkdf- Key derivationhmac- Message authenticationargon2- Password hashingzeroize- Secure memory clearing
π§ Technical Details
Key Storage:
- Location:
~/.config/migchat/keys/ - Files:
identity_key.enc,signed_prekey.enc,one_time_prekeys.enc - Encryption: Argon2 with user password
Migration Strategy:
- Hard cutover: All new messages encrypted
- Backward compatible: Can read old unencrypted messages
- Clear user messaging: "End-to-end encryption enabled" notification
π§ͺ Testing
Comprehensive testing completed:
- β CLI encryption setup and key generation
- β API infrastructure for key storage/retrieval
- β Real cryptographic key verification
- β Multi-user encryption scenarios
- β Message encryption and delivery
See full test results: Encryption Test Report
π Commits
- d813e6c: Merge PR #7 - E2E encryption feature
- 15ad86a: Fix borrow checker errors in session management
- 38e29c0: Merge PR #6 - E2E encryption feature
- f141c84: Fix Rust compilation errors in crypto module
- 40b6b7c: Merge PR #5 - E2E encryption feature
- 857a8c4: Add end-to-end encryption support with Phase 3 features
π Upgrade Instructions
- Download the new binary for your platform
- First login after upgrade will generate encryption keys
- You'll see your fingerprint displayed - save it for verification
- All new messages will be automatically encrypted
Note: Your existing message history remains unencrypted, but all new messages will use E2E encryption.
π Documentation
For more information on using the encryption features:
- View your fingerprint: Security & Encryption β View Fingerprint
- Verify contacts: Security & Encryption β Verify Contact
- Backup keys: Security & Encryption β Export Backup
Full Changelog: v0.1.7...v0.1.8