<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Methylrx</title>
    <description>The latest articles on DEV Community by Methylrx (@lmzx_7c04138e32289bf68ce3).</description>
    <link>https://dev.to/lmzx_7c04138e32289bf68ce3</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4061646%2Fcbd79c9e-257d-433b-9ff1-3948cf9357a4.png</url>
      <title>DEV Community: Methylrx</title>
      <link>https://dev.to/lmzx_7c04138e32289bf68ce3</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/lmzx_7c04138e32289bf68ce3"/>
    <language>en</language>
    <item>
      <title>MistClient: A Personal Project for Temporary Identity + End-to-End Encrypted Messaging</title>
      <dc:creator>Methylrx</dc:creator>
      <pubDate>Tue, 04 Aug 2026 04:29:27 +0000</pubDate>
      <link>https://dev.to/lmzx_7c04138e32289bf68ce3/mistclient-a-personal-project-for-temporary-identity-end-to-end-encrypted-messaging-1i4</link>
      <guid>https://dev.to/lmzx_7c04138e32289bf68ce3/mistclient-a-personal-project-for-temporary-identity-end-to-end-encrypted-messaging-1i4</guid>
      <description>&lt;p&gt;&lt;a href="https://pct.monster" rel="noopener noreferrer"&gt;https://pct.monster&lt;/a&gt;&lt;br&gt;
&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fo16ofku1ndw77edjqv32.jpg" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fo16ofku1ndw77edjqv32.jpg" alt=" " width="800" height="421"&gt;&lt;/a&gt;&lt;br&gt;
I’ve been working on a personal side project called MistClient for a while now. It’s a communication client built around temporary identities and end-to-end encrypted sessions.&lt;br&gt;
The core idea is simple:&lt;br&gt;
The client generates keys and handles all encryption/decryption locally. The server only deals with temporary identities, session signaling, encrypted message queues, and file relay. It never sees the plaintext.&lt;br&gt;
Here’s a summary of what’s currently implemented.&lt;br&gt;
Identity &amp;amp; Encryption&lt;/p&gt;

&lt;p&gt;A fresh X25519 key pair is generated every time the client starts&lt;br&gt;
Session keys are derived via X25519 and used with AES-256-GCM&lt;br&gt;
All text messages, session events, and file chunks travel in encrypted envelopes&lt;br&gt;
Envelopes include authentication and associated data (AAD) — tampering, wrong keys, or incorrect chunk indexes are rejected&lt;br&gt;
TOTP binding is supported (compatible with Ente Auth, Google Authenticator, etc.)&lt;br&gt;
QR code + Base32 manual key&lt;br&gt;
Standard 6-digit, 30-second codes&lt;br&gt;
The TOTP secret never leaves the client (DPAPI on Windows, 0600 file on Linux)&lt;/p&gt;

&lt;p&gt;The client shows a rotating MIST Live ID&lt;br&gt;
Each installation also stores a random device credential for stateful API calls&lt;/p&gt;

&lt;p&gt;Sessions&lt;/p&gt;

&lt;p&gt;Connect using the other person’s current Live ID&lt;br&gt;
Or generate a one-time key and exchange it offline&lt;br&gt;
Incoming connection requests can be accepted or declined&lt;br&gt;
Supports both one-shot sessions and persistent encrypted sessions&lt;br&gt;
Sessions can have time limits and message count limits&lt;br&gt;
Emergency stop is available (notifies the server to invalidate the current identity and related sessions)&lt;/p&gt;

&lt;p&gt;Messaging&lt;/p&gt;

&lt;p&gt;End-to-end encrypted text messages&lt;br&gt;
Read receipts&lt;br&gt;
Burn-after-reading messages (with configurable disappear timer)&lt;br&gt;
Normal messages stay until the user clears them or the session ends&lt;/p&gt;

&lt;p&gt;Encrypted File Transfer&lt;/p&gt;

&lt;p&gt;Sender creates a file offer inside an active session&lt;br&gt;
Receiver sees the filename and size before deciding whether to accept&lt;br&gt;
Files are split into 256 KiB chunks&lt;br&gt;
Each chunk is encrypted with AES-256-GCM and bound to the transfer ID + chunk index&lt;br&gt;
Downloads go to a temporary .part file and are only renamed after a full SHA-256 check&lt;br&gt;
Prefers direct P2P (LAN/VPN IPv4 and usable IPv6), falls back to encrypted server relay if needed&lt;/p&gt;

&lt;p&gt;Routing Modes (Qt client)&lt;/p&gt;

&lt;p&gt;P2P (default) — tries direct connection first, falls back to relay&lt;br&gt;
Relay — everything goes through the encrypted server relay&lt;br&gt;
Tor — routes through a local SOCKS5 Tor proxy (default 127.0.0.1:9050)&lt;/p&gt;

&lt;p&gt;Custom relay servers are also supported. You can point the client at your own relay instance, test the connection, and save the setting.&lt;br&gt;
Current Platform Status&lt;/p&gt;

&lt;p&gt;Windows: Qt GUI + native Win32 GUI + CLI&lt;br&gt;
Linux/Ubuntu: Qt GUI + GTK3 GUI + CLI&lt;br&gt;
Android: Qt client (Full and Lite flavors)&lt;br&gt;
macOS / iOS: Build support exists, formal signing and public release are not finished yet&lt;/p&gt;

&lt;p&gt;Honest Limitations&lt;/p&gt;

&lt;p&gt;No full ICE/STUN/TURN yet — current P2P only works with reachable addresses&lt;br&gt;
Tor requires you to run a SOCKS5 proxy yourself&lt;br&gt;
macOS notarization and iOS distribution are still incomplete&lt;br&gt;
Some of the newer features (custom relay UI, full routing options, update flow) are mainly in the Qt client&lt;/p&gt;

&lt;p&gt;This is still a personal, non-commercial project that I’m iterating on in my free time.&lt;br&gt;
If you’re interested in temporary identities, end-to-end encrypted messaging, or the current implementation, you can check it out here:&lt;br&gt;
&lt;a href="https://pct.monster" rel="noopener noreferrer"&gt;https://pct.monster&lt;/a&gt;&lt;br&gt;
Feedback, bug reports, and suggestions are very welcome.&lt;br&gt;
This project was originally designed for regulated regions such as China (PRC) btw.&lt;/p&gt;

</description>
      <category>privacy</category>
      <category>cpp</category>
      <category>security</category>
      <category>encryption</category>
    </item>
  </channel>
</rss>
