|
1 | | -## Coldwire - An ultra secure messenger for the ultra paranoid |
2 | | - |
3 | | - |
4 | | -[](https://app.codacy.com/gh/Freedom-Club-FC/Coldwire/dashboard?utm_source=gh&utm_medium=referral&utm_content=&utm_campaign=Badge_grade) |
| 1 | +# Coldwire — The Ultra‑Paranoid Post‑Quantum Messenger |
| 2 | +  [](https://app.codacy.com/gh/Freedom-Club-FC/Coldwire/dashboard) |
5 | 3 |
|
6 | | -A post-quantum secure messenger for the ultra paranoid |
| 4 | +--- |
| 5 | +**Coldwire** is designed to survive *the worst attacks* and when operated correctly it offers significantly better security than any messenger currently available. |
| 6 | + |
| 7 | +## 🔒 Security Model & 🌟 Key Features |
| 8 | +- **Best‑case security**: achieves [unbreakable encryption](https://en.wikipedia.org/wiki/One-time_pad) under the principles of information theory using [one‑time pads](https://en.wikipedia.org/wiki/One-time_pad) |
| 9 | +- **Worst‑case security**: falls back only to ML‑KEM‑1024 (Kyber) resistance |
| 10 | +- **Perfect-Forward-Secrecy**: on every [OTP](https://en.wikipedia.org/wiki/One-time_pad) batch through ephemeral PQC key exchanges |
| 11 | +- **Plausible Deniability**: messages are not cryptographically tied to you, proving more deniability than [Off‑The‑Record messaging](https://en.wikipedia.org/wiki/Off-the-record_messaging) ! |
| 12 | +- **Mandatory SMP**: We enforce [Socialist millionaire problem](https://en.wikipedia.org/wiki/Socialist_millionaire_problem) before any chat. **MiTM attacks are impossible**. |
| 13 | +- **NIST PQC Tier‑5**: We use highest security algorithms (Kyber1024, Dilithium5) that provide AES‑256 strength using [OQS Project](https://openquantumsafe.org/) |
| 14 | +- **Minimal Attack Surface**: |
| 15 | + - Tkinter UI only, no embedded browsers or HTML |
| 16 | + - Minimal Python dependecies |
| 17 | + - All untrusted inputs truncated to safe lengths to prevent buffer‑overflow in liboqs or Tk |
| 18 | +- **Metadata‑Free**: Random 16‑digit session IDs, no server contacts, no logs, no server‑side metadata, enforced passwordless authentication. Everything is local, encrypted, and ephemeral. |
7 | 19 |
|
0 commit comments