Technical documentation
For those who want to verify or reimplement. The full documents are in the code repository, in French and English.
Documents
| Document | Contents |
|---|---|
sources/PROTOCOL.en.md | The protocol: identity, contacts, messages, attachments, groups, multi-server, push, WebSocket transport. |
sources/ARCHITECTURE.en.md | Components, cryptography, encrypted storage, database schema, security model and known limits. |
state.en.md | Progress: what is done, tested, and what remains. |
sources/SERVER_INSTALLATION.en.md | Setting up your own relay server, public or private (ASP.NET Core 10, nginx, systemd). sources/DEPLOYMENT.en.md gives the concrete example. |
sources/ADMINISTRATION.en.md | Administering a relay or a push gateway without restarting: invitations, bans, sibling servers, logs, tracing. |
sources/DEPLOYMENT_PUSH.en.md | Setting up the push gateway (one key per relay, maintenance, limits). |
sources/CONSOLE_ADMIN.en.md | Web administration console (Pro edition): installation, roles, two-factor sign-in, audit. |
sources/diagrams/ | 14 explanatory diagrams, in French and English. |
Every document exists in French (.md) and English (.en.md), except the deployment guide, which is French only for now.
Cryptography at a glance
| Use | Primitive |
|---|---|
| Identity (keys derived from 3 phrases) | Argon2id (32 MiB, t = 3), then HKDF-SHA256 |
| Per-message key agreement | Ephemeral X25519, then HKDF-SHA256 |
| Encryption | ChaCha20-Poly1305 |
| Signature | Ed25519, bound to sender, recipient and message type |
| Groups | Shared key per epoch, renewed on every membership change |
| Attachments | 48 KiB chunks, SHA-256 Merkle tree |
| Local database | SQLite encrypted with SQLCipher, key derived from the phrases |
| Server to server | HMAC-SHA256 signed requests, 120 s window, single-use nonce |
Cryptography is implemented with BouncyCastle (managed code, portable to Android and iOS) and checked against fixed test vectors.
What the design protects, and what it does not
Protected
- Message and attachment contents are end-to-end encrypted and signed; servers never see them.
- The local database, private keys included, is encrypted at rest.
- Excluding a group member prevents them from reading what follows (key renewal).
- Every file chunk is checked against a hash an attacker cannot forge.
- A server cannot impersonate a user: registration requires proof of possession of the key.
Accepted limits
- Metadata: a server sees the sender, recipient, timestamps and connection times.
- No ratchet: the recipient's long-term key decrypts past traffic if stolen. Losing your phrases loses the identity; stealing them steals it.
- A dishonest group member can pass the current key to an excluded person, outside the protocol.
- "Delete for everyone" and "edit" are best-effort: a modified client can ignore them, and the recipient may have copied the message before.
- Received files are stored unencrypted in the app's protected space on the device.
- Stolen phone: the PIN protects the screen, not the encryption. Remote wipe destroys the phone's copy but does not revoke the identity.
Report a vulnerability: contact@rebisway.com.
Hosting your own server
A relay server is an ASP.NET Core 10 application behind nginx. It stores no messages. A private server needs no registration: put its address in your contact card. A public server can pair with other public servers by exchanging a shared secret (an allow-list managed by hand). A private server may also accept only the people it invited. The step-by-step guide is sources/SERVER_INSTALLATION.en.md; day-to-day administration is in sources/ADMINISTRATION.en.md.
Reference server: https://fs.rebisway.com (Settings → Servers → add).
Licence
FreeSpeech is free software. The code is published under the GNU AGPL v3 or later: you may study, modify and redistribute it under its terms. The server being a network service, anyone running a modified version must offer its source code to the users of that service. A separate commercial licence is available on request, to embed FreeSpeech in a product that cannot comply with the AGPL: contact@rebisway.com. The web administration console (Pro edition) is distributed separately; it only uses the servers' public admin APIs.
FreeSpeech