Verify the app you're running
Check that the TACENZA Chat code your browser runs matches the release hash published on GitHub, apart from our servers.
End-to-end encryption only protects you if the app doing the encrypting is the one we say it is. TACENZA Chat isn’t open source at the moment, so every release publishes the SHA-256 hash of the app’s JavaScript on GitHub, apart from the servers that run TACENZA. This page shows how to check that the code you’re running matches.
How releases are published
- When a release passes all its tests, the build pipeline publishes a file called
bundle-hash.txtto github.com/tacenza/releases, from the same build that gets deployed. - A published hash is never replaced. If the code on our servers ever changed without a release, the hashes would stop matching.
- The same hashes are shown on the security page, and Settings › Advanced › Diagnostics › Code fingerprint in the app links to it.
bundle-hash.txt has one line per JavaScript file, in the same format sha256sum uses: the hash, two spaces, then the file’s path.
Check the app
-
Open the latest release and open
bundle-hash.txt. Note each hash and file name, such asassets/index-abc123.js. -
Download the same file from TACENZA Chat and hash it:
curl -s https://chat.tacenza.app/assets/<file name> | sha256sum -
Compare the two hashes. They should be identical.
-
Repeat for each file listed in
bundle-hash.txt.
To check every file in one go, save bundle-hash.txt in an empty folder and run:
mkdir -p assets
cut -d' ' -f3 bundle-hash.txt | while read -r f; do
curl -s "https://chat.tacenza.app/$f" -o "$f"
done
sha256sum -c bundle-hash.txt
Each line should end in OK.
On Windows without a Bash shell, Get-FileHash -Algorithm SHA256 <file> in PowerShell gives the same hash, in capital letters.
Check what your browser loaded
curl fetches a fresh copy. To check the exact files your browser is running, open your browser’s developer tools, go to the Network tab, reload TACENZA Chat, and save the .js files from /assets/. Hash those files instead.
While you’re there, notice that every request goes to TACENZA. The app makes no requests to anyone else, apart from optional push notifications.
If the hashes don’t match
Don’t use the app for anything sensitive until it’s explained. Tell us through the channel in Reporting vulnerabilities.
What this check proves – and what it doesn’t
- It proves the JavaScript you have is the same as a published, tested release, and that the record lives outside our servers.
- It doesn’t prove the code is free of mistakes. The source isn’t public at the moment, and an independent security review is planned before version 1.0.
- It doesn’t cover the server. The server can’t read your messages, but see What the server stores for what it does see.