talkrypt wiki¶
talkrypt is a minimalist, IRC-like, post-quantum, end-to-end-encrypted, forward-secret chat that runs over Tor. The cryptography is pure-Rust (RustCrypto) and PQ by default — ML-KEM-1024 for key establishment, ML-DSA-87 for identity, AES-256-GCM for content — aligned with NSA CNSA 2.0. There is no elliptic-curve identity key; the only EC anywhere is an optional, non-load-bearing X25519 hybrid half (defense-in-depth).
This wiki is the feature map. Each page links to the authoritative spec in
docs/ for the deep detail.
Honesty first. talkrypt is experimental, pre-release software. It is NOT independently audited, NOT FIPS-validated, NOT CSfC-accredited, NOT NSA-approved, and NOT authorized for classified use. It implements the CNSA 2.0 algorithms; that is not the same as certification. See Security Assurance and
SECURITY.md.
Start here¶
- Getting Started — install, host a chat, join one, share an invite.
- CLI Reference — every
talkryptsubcommand, flag, and in-chat/command.
Features¶
| Area | Page | What's in it |
|---|---|---|
| 🔐 Cryptography | Cryptography | ML-KEM-1024, ML-DSA-87, AES-256-GCM, SHA3/KMAC, the Double Ratchet, KEM postures, self-tests, RAM-capture hardening |
| 🪪 Identity | Identity & Accounts | ML-DSA identities, safety numbers, account→device→segment chains, device linking, username registries, contacts/friends |
| 💬 Messaging | Messaging & Transport | invites/QR, P2P/Hub/Hybrid topologies, groups (TreeKEM), Tor/Arti + TCP, the wire format, replay/MITM defenses |
| 🗝️ Key custody | Key Custody & Storage | custody tiers, at-rest sealing, hardware-backed sealing (StrongBox/Secure Enclave/TPM), the desktop helper |
| 🏷️ Classification | Classification & Compliance | markings, CNSA 2.0, FIPS posture, CSfC alignment, the honesty posture |
| 💻 Platforms | Platforms & Clients | CLI, TUI, the FFI, Android, iOS, the desktop helper, the roadmap |
| 📦 Packaging | Packaging & Release | build scripts, every artifact, dual SHA-256 + SHA3-256 hashing, the verifiers |
| 🛡️ Assurance | Security Assurance | the self-audit (F-1…F-15 / R-1…R-8), fuzzing, Miri, dependency scanning, the threat model |
In one paragraph¶
You create a chat and get a talkrypt://… invite (also a QR). A peer joins with
it; a one-time invite token + an out-of-band safety number
defeat first-contact MITM. Every message is sealed with a Double
Ratchet (per-message forward secrecy + post-compromise
recovery) whose asymmetric step is a hybrid PQ KEM. Groups re-key per epoch with
TreeKEM. Your long-term identity is an
ML-DSA-87 key that certifies your devices; you can
present it, stay pseudonymous, or rotate per conversation. It runs over a
Tor onion service with restricted discovery, and
your keys are held at the strongest custody tier your device
offers.