#zeroknowledge — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #zeroknowledge, aggregated by home.social.
-
CryptPad is a free open source collaborative online office suite with the emphasis on privacy and "zero knowledge" encryption. You can find out more at:
You can follow the project at:
CryptPad can be self-hosted online, installation instructions are at:
🌱 https://docs.cryptpad.org/en/admin_guide/installation.html
It can also be self-hosted locally, instructions for local hosting are at:
🌱 https://docs.cryptpad.org/en/dev_guide/index.html#dev-guide
#SelfHosting #Privacy #Office #Encryption #ZeroKnowledge #FOSS
-
CryptPad is a free open source collaborative online office suite with the emphasis on privacy and "zero knowledge" encryption. You can find out more at:
You can follow the project at:
CryptPad can be self-hosted online, installation instructions are at:
🌱 https://docs.cryptpad.org/en/admin_guide/installation.html
It can also be self-hosted locally, instructions for local hosting are at:
🌱 https://docs.cryptpad.org/en/dev_guide/index.html#dev-guide
#SelfHosting #Privacy #Office #Encryption #ZeroKnowledge #FOSS
-
После прочтения сжечь. Как устроен zero-knowledge сервис, где сервер не видит ключ
Привет! Задача возникла банальная: нужно передать коллеге пароль, API-ключ или конфиг. Телега — не хочется, почта — тем более. Существующие решения от OneTimeSecret до PasswordPusher и прочих — либо закрытый код и доверяй на слово, либо требуют своего сервера. Одни требуют регистрации, другие — напичканные всем подряд комбайны. Захотелось сделать так: открытый код, шифрование в браузере, сервер физически не может прочитать содержимое и, разумеется, бесплатно. Так появился BurnAfterRead — self-destructing E2E encrypted drops на Cloudflare Workers. Полюбопытствовать
https://habr.com/ru/articles/1053686/
#информационная_безопасность #cloudflare #open_source #web_crypto_api #zeroknowledge #aesgcm #security #privacy
-
Privacy-focused users: Are you relying on AES-256 or just "hoping" for the best? Using a Password Manager with Zero-Knowledge encryption is the only way to ensure your keys stay local. Don't trust browser-based sync for your most sensitive data. I've mapped out the encryption standards you should look for before trusting a vault.
Read the technical breakdown:
https://securelylife.com/why-use-password-manager-for-every-account/ -
Как двухбуквенная технология проверяет трёхбуквенную организацию
Можно ли заставить трёхбуквенную контору отчитаться, не вынеся наружу ни одного секрета? Звучит невозможно — ровно как когда-то «доказать, что это настоящая боеголовка, не показав её устройства». Второе уже решили криптографы. Осталось собрать первое из готовых кусков — и посадить в кресло ревизора того, кого нельзя подкупить. Узнать, кто устережёт сторожей
https://habr.com/ru/articles/1049340/
#ИИ #нулевое_разглашение #zeroknowledge #TEE #верификация #секретность #надзор #криптография #OpenArx
-
WhatsApp Clone, but Decentralized with P2P Messaging
"Secure and private" is the general goal.
This is a technical/concept demo of a fairly unique approach using a browser-based, local-first and webrtc.
This is intended to introduce a new paradigm in client-side managed secure cryptography. We can avoid registration of any sort.
Features:
* P2P
* End to end encryption
* Signal protocol
* Post-Quantum cryptography
* File transfer
* Local-first
* No registration
* No installation
* No database
* TURN serverFeel free to reach out for clarity instead of diving into the docs/code.
IMPORTANT: While this is aiming to provide a secure experience, it isnt audited or reviewed. **Shared for testing, feedback and demo purposes only.** Please use responsibly.
#Privacy #OpenSource #P2P #WebRTC #Decentralization #DigitalSovereignty #CyberSecurity #FOSS #SelfHosted #NoCloud #AntiCorp #Encryption #WebDev #TechLiberty #PrivateMessaging #Networking #DataPrivacy #InternetFreedom #LocalFirst #SoftwareEngineering #WebApps #ZeroKnowledge #PrivacyTech #IndieDev #NoSignup #NoInstall #DecentralizedWeb #SecureMessaging #BrowserApp #TechEthics #P2P #WebRTC #PeerJS #ZeroData #EphemeralData #Encryption #E2EE #BrowserToBrowser #NoInstall #Privacy #Security #Decentralized #Messaging #VideoCall #NoTracking #PrivateMessaging #Prototype #Demo #WorkInProgress #CloseSource #OpenSource #WebDev #GitHub #TechDevelopment #WhatsApp #ChatApp #InstantMessaging #PWA
-
WhatsApp Clone, but Decentralized with P2P Messaging
"Secure and private" is the general goal.
This is a technical/concept demo of a fairly unique approach using a browser-based, local-first and webrtc.
This is intended to introduce a new paradigm in client-side managed secure cryptography. We can avoid registration of any sort.
Features:
* P2P
* End to end encryption
* Signal protocol
* Post-Quantum cryptography
* File transfer
* Local-first
* No registration
* No installation
* No database
* TURN serverFeel free to reach out for clarity instead of diving into the docs/code.
IMPORTANT: While this is aiming to provide a secure experience, it isnt audited or reviewed. **Shared for testing, feedback and demo purposes only.** Please use responsibly.
#Privacy #OpenSource #P2P #WebRTC #Decentralization #DigitalSovereignty #CyberSecurity #FOSS #SelfHosted #NoCloud #AntiCorp #Encryption #WebDev #TechLiberty #PrivateMessaging #Networking #DataPrivacy #InternetFreedom #LocalFirst #SoftwareEngineering #WebApps #ZeroKnowledge #PrivacyTech #IndieDev #NoSignup #NoInstall #DecentralizedWeb #SecureMessaging #BrowserApp #TechEthics #P2P #WebRTC #PeerJS #ZeroData #EphemeralData #Encryption #E2EE #BrowserToBrowser #NoInstall #Privacy #Security #Decentralized #Messaging #VideoCall #NoTracking #PrivateMessaging #Prototype #Demo #WorkInProgress #CloseSource #OpenSource #WebDev #GitHub #TechDevelopment #WhatsApp #ChatApp #InstantMessaging #PWA
-
Я не хотел, чтобы WeTransfer читал мои файлы, и написал хранилище, которое не доверяет само себе
Каждый раз, когда нужно передать кому-то файл или пароль, выбор бесит: WeTransfer и аналоги видят всё, почта и телеграм хранят файл в плейнтексте вечно, PrivateBin только для текста. Хотелось простого: бросил файл, получил ссылку, а сервер физически не может его прочитать. И чтобы сервер был мой. Так появился share·me, self-hosted сервис, который шифрует файлы и текст прямо в браузере (AES-256-GCM), а ключ кладёт в URL-фрагмент, который браузер никогда не отправляет на сервер. Внутри: Rust/axum, Next.js, потоковое шифрование больших файлов и пара граблей, на которых я споткнулся. Показать, как это устроено
https://habr.com/ru/articles/1045242/
#endtoend_encryption #шифрование #selfhosted #zeroknowledge #AES256GCM #Rust #Nextjs #обмен_файлами
-
Я открыл боевую базу своего clipboard-sync, чтобы показать, что он знает о вашем пароле. Ответ: ничего
Скопировали пароль от прода и синхронизировали его между ноутбуком и телефоном. Где он теперь лежит и кто может его прочитать? Я сделал сервис, где честный ответ — «нигде в открытом виде и никто, включая меня». И сейчас покажу строку из живой базы, чтобы это доказать. Это первая статья про Copy Sync — приватный кроссплатформенный обмен буфером обмена. Я не собираюсь его вам продавать. Я хочу разобрать одну инженерную задачу: как построить сервер, которому физически нечего у вас украсть , даже если им завладеет кто-то злой — включая меня самого. Весь крипто-код открыт, и проверить меня можно по ~70 строкам, а не по обещаниям.
https://habr.com/ru/articles/1044494/
#endtoend_шифрование #E2EE #zeroknowledge #X25519 #AESGCM #HKDF #Web_Crypto_API #синхронизация_буфера_обмена #NestJS #приватность
-
This is intended to introduce a unique approach in client-side managed secure cryptography. We can avoid registration of any sort.
Features:
PWA
P2P
End to end encryption
Signal protocol
Post-Quantum cryptography
Multimedia
File transfer
Video calls
Local-first
No registration
No installation
No database
TURN serverhttps://www.reddit.com/r/positive_intentions
#Privacy #OpenSource #P2P #WebRTC #Decentralization #DigitalSovereignty #CyberSecurity #FOSS #SelfHosted #NoCloud #AntiCorp #Encryption #WebDev #TechLiberty #PrivateMessaging #Networking #DataPrivacy #InternetFreedom #LocalFirst #SoftwareEngineering #WebApps #ZeroKnowledge #PrivacyTech #IndieDev #NoSignup #NoInstall #DecentralizedWeb #SecureMessaging #BrowserApp #TechEthics #P2P #WebRTC #PeerJS #ZeroData #EphemeralData #Encryption #E2EE #BrowserToBrowser #NoInstall #Privacy #Security #Decentralized #Messaging #VideoCall #NoTracking #PrivateMessaging #Prototype #Demo #WorkInProgress #CloseSource #OpenSource #WebDev #GitHub #TechDevelopment #WhatsApp #ChatApp #InstantMessaging #PWA
-
This is intended to introduce a unique approach in client-side managed secure cryptography. We can avoid registration of any sort.
Features:
PWA
P2P
End to end encryption
Signal protocol
Post-Quantum cryptography
Multimedia
File transfer
Video calls
Local-first
No registration
No installation
No database
TURN serverhttps://www.reddit.com/r/positive_intentions
#Privacy #OpenSource #P2P #WebRTC #Decentralization #DigitalSovereignty #CyberSecurity #FOSS #SelfHosted #NoCloud #AntiCorp #Encryption #WebDev #TechLiberty #PrivateMessaging #Networking #DataPrivacy #InternetFreedom #LocalFirst #SoftwareEngineering #WebApps #ZeroKnowledge #PrivacyTech #IndieDev #NoSignup #NoInstall #DecentralizedWeb #SecureMessaging #BrowserApp #TechEthics #P2P #WebRTC #PeerJS #ZeroData #EphemeralData #Encryption #E2EE #BrowserToBrowser #NoInstall #Privacy #Security #Decentralized #Messaging #VideoCall #NoTracking #PrivateMessaging #Prototype #Demo #WorkInProgress #CloseSource #OpenSource #WebDev #GitHub #TechDevelopment #WhatsApp #ChatApp #InstantMessaging #PWA
-
Because the devil's always in the details: #simulation paradigm has always been a comfortable and "natural" one, but eventually someone has leveraged it being a sufficient but not necessary condition for #zeroknowledge-ness: from @QuantaMagazine https://www.quantamagazine.org/how-unknowable-math-can-help-hide-secrets-20260511/ …hungry for follow-ups
-
Because the devil's always in the details: #simulation paradigm has always been a comfortable and "natural" one, but eventually someone has leveraged it being a sufficient but not necessary condition for #zeroknowledge-ness: from @QuantaMagazine https://www.quantamagazine.org/how-unknowable-math-can-help-hide-secrets-20260511/ …hungry for follow-ups
-
🔐 Strong passwords matter — but for teams, they’re not enough.
On World Password Day, we’re looking beyond password rules and at what really matters for secure collaboration: identity-based access, clear permissions, and zero-knowledge encryption.
Read more on the #Cryptomator blog: https://cryptomator.org/blog/2026/05/07/world-password-day-2026/?utm_source=mastodon&utm_medium=social&utm_campaign=world-password-day-2026
#WorldPasswordDay #Cybersecurity #ZeroKnowledge #Encryption #CryptomatorHub
-
🔐 Strong passwords matter — but for teams, they’re not enough.
On World Password Day, we’re looking beyond password rules and at what really matters for secure collaboration: identity-based access, clear permissions, and zero-knowledge encryption.
Read more on the #Cryptomator blog: https://cryptomator.org/blog/2026/05/07/world-password-day-2026/?utm_source=mastodon&utm_medium=social&utm_campaign=world-password-day-2026
#WorldPasswordDay #Cybersecurity #ZeroKnowledge #Encryption #CryptomatorHub
-
Приватные платежи на блокчейне Polygon: как ZK-доказательства стыкуются с регулятором
Приватные стейблкоин-платежи на Polygon: как ZK-доказательства стыкуются с регулятором 4 мая 2026 Polygon Labs объявил, что в Polygon Wallet добавлен пункт «Приватная отправка» (Privately Send) — отправка USDC и USDT с сокрытием отправителя, получателя и суммы транзакции. Технологический партнёр — Hinkal, протокол шифрованных пулов с верификацией через протокол доказательств с нулевым разглашением. Разбираемся, где слабые места в модели и почему этот паттерн важен далеко за пределами платежей — для RFQ-протоколов и опционов
https://habr.com/ru/articles/1031754/
#приватные_платежи #zk #zeroknowledge #polygon #платежи_на_блокчейне
-
Why we need more Zero-knowledge tools?
[Part 1 of 2]
Zero-knowledge tools (often called zero-knowledge encryption or zero-knowledge architecture services) are privacy-focused apps and platforms where the service provider has zero knowledge of the actual data. Even if they are subpoenaed, hacked, or compelled by authorities (relevant in India under DPDP [1] or other laws), they literally cannot access or hand over your readable content. This goes beyond basic End-to-End Encryption (E2EE). E2EE protects data in transit between users, but the provider might still hold keys or access metadata. Zero-knowledge ensures the provider is completely blind to the content [2].
Popular zero-knowledge tools are Proton mail, Tuta mail, Standard Notes, Notesnook, Proton Drive, Bitwarden, Filen.io, Simplex Chat, Threema (banned in India since May 2023) etc.
WhatsApp, with fully visible metadata to Meta, Gmail, Outlook, Telegram and Arattai are not zero knowledge tools. WhatsApp heavily advertise their E2EE features as sufficient for privacy, often misleading Indian users into believing basic E2EE equals full protection while downplaying metadata risks and provider access.
Signal prioritizes usable, strong E2EE with excellent metadata protection over pure zero-knowledge. It's "privacy by design + policy," is not absolute zero-knowledge. Many experts still call it the gold standard for messaging.
In India lack of awareness, network affect, convenience, habit, and zero cost keep WhatsApp, Gmail, and Google Drive dominant. Zero-knowledge tools offer stronger privacy but demand more effort and paid subscriptions or one time fee for comfortable and carefree usage in a price-sensitive market like India. This limits mass adoption and keeps strong privacy tools largely confined to tech-savvy or high-risk users.
1. Digital Personal Data Protection (DPDP) Rules, 2025 - https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190655®=3&lang=2
2. https://www.ghostvolt.com/blog/end-to-end-vs-zero-knowledge-encryption.html -
Why we need more Zero-knowledge tools?
[Part 1 of 2]
Zero-knowledge tools (often called zero-knowledge encryption or zero-knowledge architecture services) are privacy-focused apps and platforms where the service provider has zero knowledge of the actual data. Even if they are subpoenaed, hacked, or compelled by authorities (relevant in India under DPDP [1] or other laws), they literally cannot access or hand over your readable content. This goes beyond basic End-to-End Encryption (E2EE). E2EE protects data in transit between users, but the provider might still hold keys or access metadata. Zero-knowledge ensures the provider is completely blind to the content [2].
Popular zero-knowledge tools are Proton mail, Tuta mail, Standard Notes, Notesnook, Proton Drive, Bitwarden, Filen.io, Simplex Chat, Threema (banned in India since May 2023) etc.
WhatsApp, with fully visible metadata to Meta, Gmail, Outlook, Telegram and Arattai are not zero knowledge tools. WhatsApp heavily advertise their E2EE features as sufficient for privacy, often misleading Indian users into believing basic E2EE equals full protection while downplaying metadata risks and provider access.
Signal prioritizes usable, strong E2EE with excellent metadata protection over pure zero-knowledge. It's "privacy by design + policy," is not absolute zero-knowledge. Many experts still call it the gold standard for messaging.
In India lack of awareness, network affect, convenience, habit, and zero cost keep WhatsApp, Gmail, and Google Drive dominant. Zero-knowledge tools offer stronger privacy but demand more effort and paid subscriptions or one time fee for comfortable and carefree usage in a price-sensitive market like India. This limits mass adoption and keeps strong privacy tools largely confined to tech-savvy or high-risk users.
1. Digital Personal Data Protection (DPDP) Rules, 2025 - https://www.pib.gov.in/PressReleasePage.aspx?PRID=2190655®=3&lang=2
2. https://www.ghostvolt.com/blog/end-to-end-vs-zero-knowledge-encryption.html -
Do you prefer typing on a full keyboard while you work?
We completely understand. 💻🔒
Introducing the AmnyX Desktop Bridge!
You can securely sync your mobile AmnyX app with your desktop computer.
There’s no complex technical setup—just scan and sync.
Type faster, securely transfer files, and keep your P2P encrypted conversations flowing whether you’re at your desk or on the go.@AmnyX www.amnyx.com
#Privacy #ZeroKnowledge #desktop #secure #P2P -
Decentralized WhatsApp Clone - No Setup or Signup
https://positive-intentions.com
This is intended to introduce a new paradigm in client-side managed secure cryptography. We can avoid registration of any sort. A fairly unique offering for a messaging app.
No need for things like phone numbers or registering to any app stores. There are no databases to be hacked Allowing users to send E2EE messages; no cloud, no trace.
#Privacy #OpenSource #P2P #WebRTC #Decentralization #DigitalSovereignty #CyberSecurity #FOSS #SelfHosted #NoCloud #AntiCorp #Encryption #WebDev #TechLiberty #PrivateMessaging #Networking #DataPrivacy #InternetFreedom #LocalFirst #SoftwareEngineering #WebApps #ZeroKnowledge #PrivacyTech #IndieDev #NoSignup #NoInstall #DecentralizedWeb #SecureMessaging #BrowserApp #TechEthics
-
Decentralized WhatsApp Clone - No Setup or Signup
https://positive-intentions.com
This is intended to introduce a new paradigm in client-side managed secure cryptography. We can avoid registration of any sort. A fairly unique offering for a messaging app.
No need for things like phone numbers or registering to any app stores. There are no databases to be hacked Allowing users to send E2EE messages; no cloud, no trace.
#Privacy #OpenSource #P2P #WebRTC #Decentralization #DigitalSovereignty #CyberSecurity #FOSS #SelfHosted #NoCloud #AntiCorp #Encryption #WebDev #TechLiberty #PrivateMessaging #Networking #DataPrivacy #InternetFreedom #LocalFirst #SoftwareEngineering #WebApps #ZeroKnowledge #PrivacyTech #IndieDev #NoSignup #NoInstall #DecentralizedWeb #SecureMessaging #BrowserApp #TechEthics
-
‘Von der Leyen Announces the EU’s New Age Verification App Claiming it is “Completely Anonymous” & users “Cannot be Tracked”’ | …the EU is about to have its ‘Clipper’ moment
Who is going to be this generation’s Matt Blaze? 🙂
The Clipper Chip was announced on April 16, 1993, exactly 33 years ago, less one day:
https://www.reddit.com/r/europrivacy/comments/1sm1uoy/von_der_leyen_announces_the_eus_new_age/
#ageVerification #clipper #eu #oops #rofl #zeroKnowledge -
-
New breakthrough results for quantum attack resource estimates against 256-bit elliptic curves: most ECC-based applications including ECDSA and Bitcoin could be at risk way sooner than expected:
We estimate that these circuits can be executed on a superconducting qubit CRQC with fewer than 500,000 physical qubits in a few minutes [...] This is an approximately 20-fold reduction in the number of physical qubits required to solve ECDLP-256"
Interestingly, Google and friends did not release the blueprint for the attack circuit. In the name of "responsible disclosure", they only provided a zero-knowledge proof (ZKP) proving that the circuit works. This is, I think , a first in the realm of cryptanalysis disclosure.
The statement that our ZK proof demonstrates is the following: we possess a classical reversible circuit of a specified size which on most inputs correctly computes point addition on the elliptic curve secp256k. This is the primary bottleneck in Shor’s quantum algorithm
I have been saying this since the 2010s: quantum cryptanalysis is one of those non-linear technology progresses that will take everyone by surprise when it arrives. Qubits quality and numbers go up, error-correction and attacks improve, investments scale up accordingly. It's a perfect storm of compound factors. Folks didn't listen, now time is ticking.
More context at: https://gagliardoni.net/#20260331_new_quantum_estimates
#quantum #quantumcomputing #cryptography #security #cybersecurity #infosec #google #bitcoin #blockchain #ethereum #zkp #zeroknowledge
-
New breakthrough results for quantum attack resource estimates against 256-bit elliptic curves: most ECC-based applications including ECDSA and Bitcoin could be at risk way sooner than expected:
We estimate that these circuits can be executed on a superconducting qubit CRQC with fewer than 500,000 physical qubits in a few minutes [...] This is an approximately 20-fold reduction in the number of physical qubits required to solve ECDLP-256"
Interestingly, Google and friends did not release the blueprint for the attack circuit. In the name of "responsible disclosure", they only provided a zero-knowledge proof (ZKP) proving that the circuit works. This is, I think , a first in the realm of cryptanalysis disclosure.
The statement that our ZK proof demonstrates is the following: we possess a classical reversible circuit of a specified size which on most inputs correctly computes point addition on the elliptic curve secp256k. This is the primary bottleneck in Shor’s quantum algorithm
I have been saying this since the 2010s: quantum cryptanalysis is one of those non-linear technology progresses that will take everyone by surprise when it arrives. Qubits quality and numbers go up, error-correction and attacks improve, investments scale up accordingly. It's a perfect storm of compound factors. Folks didn't listen, now time is ticking.
More context at: https://gagliardoni.net/#20260331_new_quantum_estimates
#quantum #quantumcomputing #cryptography #security #cybersecurity #infosec #google #bitcoin #blockchain #ethereum #zkp #zeroknowledge
-
Tout le monde pense que « données protégées » = bonne politique interne. Faux.
Chez WIGGWIGG, nos ingénieurs voient que vous avez un compte. Ils voient des blocs chiffrés. Ils ne peuvent pas voir ce qu'il y a dedans.
AES-256-GCM. Clé dérivée de votre mot de passe. On ne l'a jamais.
wiggwigg.ca/fr/securite/securite-application/
#ZeroKnowledge #InfoSec #Privacy #Encryption #CanadianTech #PrivacyFirst #Fediverse
1/3
-
What does 'we protect your data' actually mean?
Most companies: a policy.
We literally cannot read yours: that's math, not a promise.Our engineers see encrypted blobs. Nothing more. AES-256-GCM, key never leaves your device.
https://wiggwigg.ca/en/security/application-security/
#ZeroKnowledge #Privacy #InfoSec #Fediverse #CanadianTech #PrivacyCanada #IndieWeb #PasswordManager #Encryption #AppSecurity
1/3
-
Imaginez un serrurier qui forge votre coffre-fort sans jamais garder la clé. C'est ça, la connaissance nulle : la clé de déchiffrement ne quitte jamais votre appareil. Nos serveurs conservent du charabia. Pas par politique. Mathématiquement.
https://wiggwigg.ca/fr/securite/zero-connaissance/
#InfoSec #Privacy #ZeroKnowledge #PasswordManager #CanadianTech #Encryption #PrivacyFirst #Fediverse #IndieWeb
1/3
-
Imagine hiring a locksmith who built your safe and still can't open it. Not because they forgot the combination. Because they never had it.
That's zero-knowledge. Your data encrypts before it leaves your device. We hold gibberish. Not a policy. Math.
https://wiggwigg.ca/en/security/zero-knowledge/
#ZeroKnowledge #Encryption #Privacy #InfoSec #Fediverse #PrivacyFirst #IndieWeb #CanadianTech
1/3
-
Would you like to play with audiovisual tools, join a great community, and support the Decentralized Web?
@ZFAVClub runs on small networks of people who help recordings survive and remain usable long after the event. 🎥
✨ Check out their open opportunities → https://zkav.club/opportunities/
#audio #video #production #videoProduction #ZkAvClub #zeroKnowledge #opportunity #volunteer