Hi everyone. I’m msd1shka, an indie developer.
I’m tired of hearing about "data safety" from companies that store terabytes of metadata. Servers hold all our contacts and chats; they know who talked to whom and when. And that "someone" can leak the database or sell you out completely.
I didn't set out to create another "super-secure messenger." Instead, I decided to make it so the data to leak physically doesn't exist.
Meet Delta-Time. It’s P2P on Tor Hidden Services v3. No servers, no registration, no phone numbers, no emails. Your identity is your local key generated only on your device: Ed25519. Messages are signed, routing goes through the onion network, and there are no intermediary servers, meaning there is nothing to hand over to authorities or hackers.
⚠️ Straight to the point: this is an alpha from a single indie developer. There has been no audit, there may be flaws, and please read the Threat Model. If you are a security researcher or just like digging through other people's code, I invite you to break this. Seriously, find a hole; I’ll be glad.
Why not Signal or Matrix?
(They seem similar)
- Signal = phone number + central server + AWS (a combo of metadata collection).
- Matrix = federation, but home-servers still leave logs. I needed a system where I don't have to trust anyone.
How it works:
(For those who will break it or are interested in the architecture)
Transport: Tor Hidden Services v3. Forget STUN/TURN. Each client spins up its own ephemeral hidden service. Exchange happens directly between onion addresses. IP never leaves the network. Yes, connection takes time (from seconds to a couple of minutes). That’s the price of anonymity, but the UI has statuses to indicate network state.
Identity: Ed25519. The private key never leaves the device. Public key = your ID. Lost the key? Goodbye account. No recovery because there is no user database.
TOFU: Trust On First Use. Just like SSH. On first connect, you get a fingerprint. Verify it against what you received personally or via another channel. Confirm without looking? That’s on you. Cancelled? Chat blocks. Security > UX.
Storage: Encryption at Rest. History is encrypted on disk. Stole the phone? Good luck with brute force.
Stack
Python + Flet. Yes, Python. Perfect for a desktop alpha.
Tor is either system or bundled.
Roadmap
Alpha: P2P on Tor v3, keys, signatures, disk encryption, TOFU.
Beta: Proper Win/Linux builds, Android via Orbot, audit (waiting for reviewers).
Later: Serverless groups, iOS, rewriting core in Rust/C++.
Reality
I recommend you not to believe words like "100% secure." Trust the code.
Cryptographers, network specialists, reverse engineers: jump into the repo. Look for metadata leaks during Tor errors, check TOFU, intercept traffic, write issues. This is the best help for developing such a project.
Why do this at all?
We are losing freedom of speech and privacy. Messengers have turned into surveillance tools. Delta-Time is an attempt to regain control. It is a tool for legal communication without overseers.
Privacy is a basic right, not a messenger feature.
you can try it there
git clone https://github.com/msd1shka/delta-time.git
cd delta-time
pip install -r requirements.txt
flet run or python main.py
Repository link: github.com/msd1shka/Delta-Time
Discussion / Issues: Telegram (here you can find out how to contact me or simply follow the app's development)
What would you improve in the TOFU UX?
Any specific attack vectors I should prioritize in the Threat Model?



Top comments (0)