How encryption works
How TACENZA Chat encrypts messages, files, profiles and your account on your device, which standard algorithms it uses, and how keys are shared and replaced.
TACENZA Chat encrypts everything on your device before it’s sent: messages, files, profiles, group names and your settings. The server relays and stores ciphertext, hashes and public keys. This page explains how, in enough detail to judge it for yourself.
Standard cryptography only
TACENZA uses the browser’s Web Crypto API and Argon2id. There are no home-made algorithms.
| Job | Algorithm |
|---|---|
| Encrypting data | AES-256-GCM |
| Deriving keys | HKDF-SHA-256 |
| Exchanging keys | ECDH on P-256 |
| Signing | ECDSA on P-256 |
| Stretching your password | Argon2id (64 MiB, 3 passes) |
Your account
- Password. Your device stretches your password with Argon2id and derives two things from it: a login proof and an encryption key. Only the login proof is sent. The server stores a hash of it, never the proof itself and never your password.
- Account key. Your private keys and your account data – contacts, blocked people, settings – are sealed with a random account key. Your password’s encryption key wraps that account key.
- Recovery key. A second, 256-bit key, made on your device and shown once, wraps the same account key. The server stores the wrapped copy and a check value, never the key. That’s why a recovery key can set a new password without losing any messages.
- Private keys are loaded as keys that can’t be read back out of the browser.
Messages
Each conversation has a key generation: a random 32-byte key.
- The key is sealed separately to each member’s public key, and signed by the member who made it. Members check the signature before using the key.
- For every message, a fresh key is derived from the generation key and a random salt.
- The message – including who sent it and when – is signed with the sender’s signing key and then encrypted. The sender and time are inside the ciphertext, so the server doesn’t know who wrote a message.
- Every encrypted object is padded to a power-of-two size, at least 256 bytes, so the server learns less about its length.
A message is shown only if it decrypts, belongs to this conversation, and its signature matches the sender’s pinned key. Otherwise the app shows “Can’t be unlocked or verified”.
New keys
A new key generation is made when members are added, removed or leave, when someone joins by link, and automatically after 50 messages in a group. New members can’t read earlier generations, and removed members can’t read later ones.
Private channels in a group have key generations of their own, given only to members who can view them.
Files and photos
Each attachment is encrypted with its own random key, which travels inside the encrypted message. Files are padded to the next multiple of 64 KiB first. Photos are re-encoded on your device, which strips hidden data such as GPS position.
Profiles
Your profile is sealed with a profile key that travels inside your messages and group info, so only people you talk to can read it. Parts for contacts only use a separate contact key. See Profiles.
Knowing who you talk to
The first time your app sees someone’s keys, it pins them. If the server ever hands out different keys, the chat locks until you compare safety numbers – 60 digits made from both people’s keys. See Safety numbers.
Other encrypted features
- Live location is encrypted with a key sent only to the people you chose.
- Push notifications are encrypted to your device and contain no sender or text.
- Reports, warnings and the audit log in groups are end-to-end encrypted messages.
- Tacenza News is public and not encrypted, but every post is signed with a key built into the app.
What encryption doesn’t cover
- There’s no forward secrecy within a key generation yet. Re-keying every 50 messages narrows the exposure; the Signal protocol and MLS are planned.
- The server sees who is in which conversation.
- A member can always read what’s sent to them, and anyone with a modified app can keep it.
See Known limits and What the server stores.