The messenger with no email, phone, or password to give
Hi PH π
I built LUME because "we can't read your messages" is a claim every messenger
makes and almost none of them let you check.
So the whole thing is built to be checkable:
There's no personal data because there are no columns for it. The user
table has nine columns: an id, a username you pick, four public keys, a push
token, and two timestamps. No email. No phone. No password hash. Not hidden or
encrypted β the fields don't exist. Your identity is 12 words that never leave
your device.
The encryption is a line you can read, not a badge. Encrypt, then send β
the server is handed a sealed blob. Every message gets its own key, so
compromising one doesn't open the conversation.
There's a test that would catch me lying. It runs against the production
server, sends a real message, fetches back what got stored, and fails if the
plaintext is in there. One command, in the repo.
What it is not, because you'd find out anyway:
Β· Not audited. No third-party security audit. There's been an internal
adversarial review β 33 findings, and whoever writes a fix can't close their
own β but that isn't the same thing and I won't pretend it is.
Β· Not anonymous. The server doesn't know who you are, but it sees that one
account messaged another and when. That's metadata, it's unavoidable, and it
exists here.
Β· Not open source. The licence lets you read and review the code, not use
or modify it. "Open to read" is the accurate phrase.
Β· The Android app is behind the web one β no settings screen, notifications,
attachments or groups yet.
If you want a battle-tested private messenger today, use Signal. It's older,
independently audited, and it's what I'd recommend to my family. LUME is a
different trade: no phone number required, and code you can actually read.
Happy to answer anything, including the awkward questions.
Replies