<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Bangze Han</title>
    <description>The latest articles on DEV Community by Bangze Han (@hbzsoft).</description>
    <link>https://dev.to/hbzsoft</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4012370%2Fa9760f28-ec4c-46b7-bfdb-f51a87d5a488.jpg</url>
      <title>DEV Community: Bangze Han</title>
      <link>https://dev.to/hbzsoft</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/hbzsoft"/>
    <language>en</language>
    <item>
      <title>KaleidoTalk 3.0: End‑to‑End Encryption + Cover Traffic – A Privacy Messenger That Hides Metadata</title>
      <dc:creator>Bangze Han</dc:creator>
      <pubDate>Tue, 04 Aug 2026 12:56:24 +0000</pubDate>
      <link>https://dev.to/hbzsoft/kaleidotalk-30-end-to-end-encryption-cover-traffic-a-privacy-messenger-that-hides-metadata-4b1h</link>
      <guid>https://dev.to/hbzsoft/kaleidotalk-30-end-to-end-encryption-cover-traffic-a-privacy-messenger-that-hides-metadata-4b1h</guid>
      <description>&lt;p&gt;I built an open‑source chat app that encrypts messages &lt;strong&gt;and&lt;/strong&gt; protects traffic patterns – fixed‑size packets, random padding, heartbeat jitter, automatic key rotation, and an irreversible account freeze. No CAs, no metadata leaks. &lt;a href="https://github.com/hbzsoft/KaleidoTalk" rel="noopener noreferrer"&gt;GitHub repo&lt;/a&gt;.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9hqtedmi4x3h8ndnkozw.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2F9hqtedmi4x3h8ndnkozw.png" alt="TOFU Trust Window" width="800" height="613"&gt;&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fn9hvypevmhkrkyw9rzw7.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fn9hvypevmhkrkyw9rzw7.png" alt="Chat Box" width="800" height="608"&gt;&lt;/a&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Why Another Secure Messenger?
&lt;/h2&gt;

&lt;p&gt;We all know the drill: &lt;em&gt;“Your messages are end‑to‑end encrypted”&lt;/em&gt; – but what about the &lt;strong&gt;metadata&lt;/strong&gt;? Packet sizes, timing, and frequency paint a detailed picture of your social graph, active hours, even relationships. Most apps don’t hide that.&lt;/p&gt;

&lt;p&gt;KaleidoTalk was built from the ground up with a simple manifesto:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Encryption is non‑negotiable.&lt;/li&gt;
&lt;li&gt;Source code must be public.&lt;/li&gt;
&lt;li&gt;Users – not certificate authorities – verify trust.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Traffic analysis must be defeated.&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Version 3.0 brings automatic key rotation, a modern GUI, and a unique account‑freeze mechanism. Let’s dive in.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Cryptographic Core
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Identity keys:&lt;/strong&gt; Ed25519 (long‑term, for signing).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Key exchange:&lt;/strong&gt; X25519 – &lt;strong&gt;ephemeral per message&lt;/strong&gt; (forward secrecy).&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Symmetric encryption:&lt;/strong&gt; AES‑256‑GCM with HKDF‑SHA256 key derivation.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Authentication:&lt;/strong&gt; Each message is signed with the sender’s identity key.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Every message uses a fresh ephemeral X25519 keypair. Even if your long‑term keys are compromised later, past messages remain safe.&lt;/p&gt;

&lt;h3&gt;
  
  
  Encryption Flow (simplified)
&lt;/h3&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight python"&gt;&lt;code&gt;&lt;span class="n"&gt;shared_secret&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;ECDH&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ephemeral_priv&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;recipient_x25519_pub&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;aes_key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;nonce&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;HKDF&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;shared_secret&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;salt&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;info&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="s"&gt;kaleido-msg&lt;/span&gt;&lt;span class="sh"&gt;"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;ciphertext&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;tag&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;AES_GCM_encrypt&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;aes_key&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;nonce&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;plaintext&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;signature&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="nc"&gt;Ed25519_sign&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;sender_priv&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;eph_pub&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;ciphertext&lt;/span&gt; &lt;span class="o"&gt;+&lt;/span&gt; &lt;span class="n"&gt;tag&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The server only sees opaque blobs – it cannot decrypt.&lt;/p&gt;




&lt;h2&gt;
  
  
  Cover Traffic: The Metadata Shield
&lt;/h2&gt;

&lt;p&gt;All traffic is wrapped in &lt;strong&gt;2048‑byte fixed‑length packets&lt;/strong&gt;. Every packet contains:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;A 1‑byte type (data, fragment, or pure padding)&lt;/li&gt;
&lt;li&gt;Length, sequence, total fragments&lt;/li&gt;
&lt;li&gt;Real payload (up to 2041 bytes)&lt;/li&gt;
&lt;li&gt;The rest is &lt;strong&gt;random padding&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Heartbeats
&lt;/h3&gt;

&lt;p&gt;Both client and server send padding packets at randomised intervals (5s ± 1.67s jitter). This means:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;An idle connection sends the same volume as an active one.&lt;/li&gt;
&lt;li&gt;An observer cannot tell if you’re typing, reading, or away.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;No more size‑based or timing‑based profiling.&lt;/strong&gt;&lt;/p&gt;




&lt;h2&gt;
  
  
  Trust Without Central Authorities
&lt;/h2&gt;

&lt;p&gt;KaleidoTalk uses &lt;strong&gt;Trust On First Use (TOFU)&lt;/strong&gt; for both TLS certificates and user public keys. Instead of ugly hex strings, fingerprints are displayed as &lt;strong&gt;six BIP39 words&lt;/strong&gt; – easy to read and compare out‑of‑band (e.g., in person).&lt;/p&gt;

&lt;p&gt;Once verified, the trust is stored locally with an HMAC‑protected database. If tampering is detected, all trust relationships reset.&lt;/p&gt;




&lt;h2&gt;
  
  
  Automatic Key Rotation (24‑hour cycle)
&lt;/h2&gt;

&lt;p&gt;X25519 keypairs are rotated automatically every 24 hours. The server keeps a list of recent public keys so messages sent with older keys can still be decrypted during the transition. This limits the window of compromise if a private key is leaked.&lt;/p&gt;




&lt;h2&gt;
  
  
  Account Freeze – Your Emergency Brake
&lt;/h2&gt;

&lt;p&gt;If your password is stolen or forgotten, &lt;strong&gt;there is no password reset via email/SMS&lt;/strong&gt; (which are attack vectors). Instead, during registration you generate an Ed25519 &lt;strong&gt;recovery certificate&lt;/strong&gt; stored locally.&lt;/p&gt;

&lt;p&gt;To freeze your account, you sign a message with that recovery key and send it to the server. The server verifies the signature and &lt;strong&gt;permanently&lt;/strong&gt; sets a &lt;code&gt;frozen&lt;/code&gt; flag – no login, no message delivery, active sessions killed. It is &lt;strong&gt;irreversible&lt;/strong&gt; (can’t be undone by the server admin) – this prevents social‑engineering recovery attacks.&lt;/p&gt;

&lt;p&gt;A standalone &lt;code&gt;freeze_account.py&lt;/code&gt; tool lets you freeze even without the full client.&lt;/p&gt;




&lt;h2&gt;
  
  
  Performance &amp;amp; Scalability
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;Idle bandwidth: ~310–620 bytes/s (thanks to heartbeats).&lt;/li&gt;
&lt;li&gt;Maximum efficiency: 99.66% for large messages (only 7‑byte header overhead).&lt;/li&gt;
&lt;li&gt;Current implementation: thread‑per‑client – fine for small to medium private teams. The protocol is concurrency‑agnostic, so an async version is straightforward if needed.&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Get Started in 3 Minutes
&lt;/h2&gt;



&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;git clone https://github.com/hbzsoft/KaleidoTalk
&lt;span class="nb"&gt;cd &lt;/span&gt;KaleidoTalk
pip &lt;span class="nb"&gt;install&lt;/span&gt; &lt;span class="nt"&gt;-r&lt;/span&gt; requirements.txt

&lt;span class="c"&gt;# Start server (auto‑generates TLS certs)&lt;/span&gt;
python run_server.py

&lt;span class="c"&gt;# In another terminal, start client&lt;/span&gt;
python run_client.py
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;ul&gt;
&lt;li&gt;Verify the TLS fingerprint (shown as BIP39 words) on first connect.&lt;/li&gt;
&lt;li&gt;Register, save your recovery key, and start chatting.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Admin tools and a standalone freeze tool are included.&lt;/p&gt;




&lt;h2&gt;
  
  
  What’s Next?
&lt;/h2&gt;

&lt;p&gt;I’m actively developing KaleidoTalk. Future plans:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Asynchronous server for higher concurrency.&lt;/li&gt;
&lt;li&gt;Mobile clients (Flutter/React Native).&lt;/li&gt;
&lt;li&gt;Optional Tor integration for IP‑level anonymity.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Try it out, star the repo, open issues, or submit PRs.&lt;/strong&gt; Every security review is welcome.&lt;/p&gt;

&lt;p&gt;👉 &lt;a href="https://github.com/hbzsoft/KaleidoTalk" rel="noopener noreferrer"&gt;GitHub Repository&lt;/a&gt;&lt;br&gt;&lt;br&gt;
👉 &lt;a href="https://kaleidotalk.hanbangze.tech/KaleidoTalk_Whitepaper.pdf" rel="noopener noreferrer"&gt;Full Whitepaper&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Let’s make private communication truly private – not just in content, but in pattern.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>python</category>
      <category>security</category>
      <category>privacy</category>
      <category>opensource</category>
    </item>
  </channel>
</rss>
