Inspiration
Current secure messengers protect what you say, but they fail to protect the fact that you said anything at all. If an adversary wants to map a journalist's network, they do not need to break AES. They just need the metadata: who talked to whom, and when. I built Privex to solve this. The goal was to build a messenger that obeys four strict laws: the server cannot read content, the server cannot identify users, the server cannot trace relationships, and the network itself cannot confirm the app is being used.
What it does
Privex is a zero-knowledge, end-to-end encrypted messenger. It uses hybrid post-quantum cryptography (Kyber-1024 and Dilithium3) for all identity and key exchanges. It uses Sealed Sender, meaning the server only sees an encrypted blob and a recipient identifier, but never knows who sent it.
To defeat network observation, Privex routes traffic through the Nym mixnet and generates constant Poisson-distributed cover traffic. An ISP watching the connection only sees a steady stream of indistinguishable packets, making it impossible to tell when real messages are sent or received. It also features OPAQUE account recovery, allowing users to recover their cryptographic keys using just a password, without the server ever learning the password itself.
How I built it
The backend is written in Rust using Axum and Tokio, designed as a completely oblivious relay. It stores no IPs, no names, and uses PostgreSQL UNLOGGED tables so sensitive message queues never touch the disk write-ahead log (WAL).
The frontend is a React Progressive Web App. Because browsers lack direct access to hardware security modules, all heavy cryptography runs in WebAssembly. I compiled libsodium, libsignal, and liboqs from Rust to WASM. The app uses IndexedDB for encrypted local storage and WebCrypto for non-extractable master keys.
Challenges I ran into
The hardest part was building a zero-knowledge architecture in a browser. JavaScript garbage collection is insecure for key material, so I had to write a custom Rust-to-WASM bridge that explicitly zero-fills memory after cryptographic operations.
Integrating the Nym mixnet was another massive hurdle. Mixnets inherently add latency and packet shuffling to defeat timing attacks. Wiring this asynchronous, delayed delivery system into a real-time chat interface without breaking the Double Ratchet protocol required careful state management and custom message queuing.
Accomplishments that I'm proud of
I am most proud of replacing IP-based rate limiting with a privacy-preserving Proof-of-Work system. Instead of logging IPs to prevent spam registrations, Privex issues a dynamic SHA-256 and Argon2id hashcash challenge. The server scales difficulty based on aggregate network pressure without ever recording a single user identifier.
What I learned
I learned that applying cryptographic primitives is easy, but securely integrating them is incredibly hard. Building the OPAQUE protocol taught me how Oblivious Pseudorandom Functions (OPRFs) work in practice. I also learned a massive amount about network traffic analysis and how fixed packet sizes and cover traffic are the only real defenses against a passive network observer.
What's next for Privex
The next steps are completing the React Native mobile apps for Android and iOS, implementing the client-side CSAM protection circuit using Zero-Knowledge proofs, and securing funding for an independent security audit from a firm like Cure53 or Trail of Bits.
Built With
- axum
- dexie
- docker
- libsodium
- linux
- minio
- nym
- postgresql
- pwa
- react
- redis
- rust
- tailwindcss
- tokio
- typescript
- vite
- webassembly
Log in or sign up for Devpost to join the conversation.