First of all, thank you for taking your time to do this. I still wish you'd told me before so that I could help you understand a few points before publishing, but I totally get it, good effort. A bit unfortunate that your post got flagged and taken down
A few comments:
> chat keys are ever changed or when (forward secrecy)
Yes, this can be done anytime by any user. Chats -> Settings -> Renew RSA Keys
The Windows client doesn't include any chat capability, it's not just that it isn't E2EE, you simply can't send/receive messages on it. I plan on replacing the Windows client entirely with a web version, it's only there for some few users who really need it
>it's legal to have a directory of all registered users and email addresses accessible to all users
This is not the case. Users can only see other people's contact details when they are in the same "Group". Otherwise, both email address and name is hidden
>On Android, the standard `Random` is not entirely[5] based on current system time, but it does not seem like Codename One uses that. The documentation says it's purely time-based.
I think you may have missed that every message is encrypted with the ChatKey but also with a different IV each time. This ensures each message originates from a different seed
Don't know if you can update your post with this info? Anyway, thanks again and happy to discuss! I might have missed some points. Tbh the E2EE chat isn't really used by loads of people and in retrospective I should have made it non-E2E since most users use the app for its organigrams and not for secure comms. I just did it this way for fun
Edit: One last note
>If you're going to use a closed-source E2EE chat application, you might as well use WhatsApp
The problem with Whatsapp is backups. They kind of make E2E pointless
Edit 2: feel free to reply directly to javierantonf@hotmail.com I can't guarantee I will see your msg here
Edit 3: Isn't 2048 valid until 2023 and possibly beyond?
First of all, thank you for taking your time to do this. I still wish you'd told me before so that I could help you understand a few points before publishing, but I totally get it, good effort. A bit unfortunate that your post got flagged and taken down
A few comments:
> chat keys are ever changed or when (forward secrecy)
Yes, this can be done anytime by any user. Chats -> Settings -> Renew RSA Keys
The Windows client doesn't include any chat capability, it's not just that it isn't E2EE, you simply can't send/receive messages on it. I plan on replacing the Windows client entirely with a web version, it's only there for some few users who really need it
>it's legal to have a directory of all registered users and email addresses accessible to all users
This is not the case. Users can only see other people's contact details when they are in the same "Group". Otherwise, both email address and name is hidden
>On Android, the standard `Random` is not entirely[5] based on current system time, but it does not seem like Codename One uses that. The documentation says it's purely time-based.
I think you may have missed that every message is encrypted with the ChatKey but also with a different IV each time. This ensures each message originates from a different seed
Don't know if you can update your post with this info? Anyway, thanks again and happy to discuss! I might have missed some points. Tbh the E2EE chat isn't really used by loads of people and in retrospective I should have made it non-E2E since most users use the app for its organigrams and not for secure comms. I just did it this way for fun
Edit: One last note
>If you're going to use a closed-source E2EE chat application, you might as well use WhatsApp
The problem with Whatsapp is backups. They kind of make E2E pointless
Edit 2: feel free to reply directly to javierantonf@hotmail.com I can't guarantee I will see your msg here
Edit 3: Isn't 2048 valid until 2023 and possibly beyond?