xxzoltanxx / Balvan-Chat

💬 A python E2E encrypted chat application.
MIT License
24 stars 0 forks source link

Security Audit #3

Open Urban-Hacker opened 3 weeks ago

Urban-Hacker commented 3 weeks ago

Hello,

I want to say kudos to you for attempting to create a secure messaging application. Your efforts in promoting privacy and security are highly appreciated. However, given the complexities of cybersecurity and encryption, the stakes can be incredibly high, particularly for users like journalists in totalitarian regimes, where any vulnerabilities can lead to severe consequences. Please add a disclaimer on this repository! Please add a disclaimer on this repository to highlight these risks.

With this context in mind, I have identified a few areas that need attention:

I recommend reviewing how the Signal protocol addresses these common issues. Additionally, please add a disclaimer stating that your app is a work in progress and should not be used for anything other than testing.

Please note, I am not a cryptographer, and there may be other weaknesses that I have not identified.

Let me know if you have any questions.

Urban

xxzoltanxx commented 3 weeks ago

Hi, Thank you very much for your contributions/analysis. They are wholly welcome. It's no issue adding a disclaimer right away that the app is a WIP currently. The other potential improvements will have to wait now, but I'm leaving the issue open to hold these improvements here.

Thanks and have a nice day.