soc.octade.net is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
This week Microsoft and ReliaQuest reported attackers using hotel Wi-Fi across the US, India and Saudi Arabia to steal credentials and push malware onto travellers’ devices. Connect to the network and you’re the target.
This is exactly why the network you’re on shouldn’t be something you have to trust. Zerion routes everything over Tor, so a hostile Wi-Fi sees only encrypted traffic, no IP, no metadata, nothing to harvest or inject into.
zerion.chat
Tor Browser is a free, open-source browser from the nonprofit Tor Project. It routes everything through three volunteer relays: the first sees your IP but not the site, the last sees the site but not your IP. No single point knows both. Built to beat surveillance and censorship. Don't customize it — extensions or changed settings make you traceable. For everyday use Brave is enough; for real anonymity, Tor. torproject.org
Tor Browser is a free, open-source browser from the nonprofit Tor Project. It routes everything through three volunteer relays: the first sees your IP but not the site, the last sees the site but not your IP. No single point knows both. Built to beat surveillance and censorship. Don't customize it — extensions or changed settings make you traceable. For everyday use Brave is enough; for real anonymity, Tor. torproject.org
Zerion 3.0 is in its final stage before release. The dev branch, with the native protocol stack, I2P and the Bluetooth mesh, is now being tested by an external party before we ship it.
We don’t release security features on trust. They get checked first, and the whole thing is open source so you can read every line yourself while we do.
This is separate from the independent audit we’re still raising funds for. Both matter.
zerion.chat
Zerion 3.0 just landed two new transports in dev, on top of our native protocol stack.
I2P as an opt-in alternative to Tor, for people who want a different anonymity network. Tor stays the default.
And a Bluetooth mesh for communicating with no internet at all. Messages are carried encrypted from device to device, store-carry-forward, until they reach the recipient. Built for blackouts, protests, disasters, anywhere the network is down or cut.
zerion.chat
Privacy is evolving.
Zerion is an open-source, Tor-native messenger focused on modern cryptography and privacy-first communication.
🌐 https://zerion.chat
💻 https://github.com/zerionproject/Zerion
#OpenSource #Privacy #PostQuantum #Tor #Encryption #FOSS #Android
Zerion 3.0 is close. Our own protocol stack replacing the inherited Bramble layers: Tor-only, post-quantum on every message, constant-rate cover traffic so an observer can’t tell messages from noise.
In final testing now, two more transports:
I2P as an opt-in alternative to Tor. And a Bluetooth mesh for communicating with no internet at all, blackouts, protests, disasters.
Tor stays mandatory. The rest is additive.
zerion.chat
Super impressed by the brute force efforts of my fair city, Ashland, Ohio.
If we had time and effort to throw at it, it might be fun to hack the data being gathered by #Flock cameras and rebroadcast it all in real time.
I would probably need to figure out how to stream over #Tor.
https://www.instagram.com/reel/Da1KarqJcbA/?igsh=MWVxZjVuMXI3cmVkcw==I
#privacy #surveillance #FlockSafety #ALPRs #ALPR
#EFF #SurveillanceState #MassSurveillance
Briar just went into maintenance mode, and their update named the problems they couldn’t get past. Some of them we’ve already shipped: account backup, attachments, reliable contact adding, channels.
For 3.0 we’re going further, replacing the inherited Briar/Bramble layers with our own protocol stack. Transport, wire format, sync, message model, all ours. Bramble stays the origin, but stops being the foundation.
triple ratchet PQ
zerion.chat
I thought scaling Tor meant adding more relays.
What it actually meant was multiplying failure modes...
I now operate 24 Tor relays and bridges across 15 locations, 11 ASNs and 6 operating systems.
Every new relay brings another provider, firewall, IPv6 route, service manager, identity key, backup and recovery plan.
Some things I learned along the way:
🌍 More countries don’t automatically mean real diversity
🔑 The server is replaceable, the relay identity isn’t
🛠️ Linux, BSD and SunOS need the same outcomes, not the same commands
📊 What I configured isn’t always what the Tor network currently sees
A large fleet is easy to count. A resilient one is much harder to keep alive.
I wrote about what operating Tor across 15 locations actually taught me:
Briar is going into maintenance mode, only security fixes from here. Not for lack of skill. They had no funding and built it in their spare time for years.
Zerion runs on their Bramble protocol and we owe them for it. The gaps they listed as unsolved, account backup, attachments, reliably adding contacts, we’ve shipped. Our own protocol stack is next.
The foundation stays. The work keeps moving.
zerion.chat
An independent security audit is the single thing standing between “trust us” and “verified.” It’s also what Privacy Guides, journalists and security reviewers rightly ask for before recommending any messenger.
We’re raising funds to have Zerion audited by Radically Open Security. Every finding gets published, good or bad. That’s the deal.
If Zerion is useful to you, this is the most direct way to push it forward:
zerion.chat/donate.html
If you’ve been looking for a messenger with no phone number, no account, and no server that can be scanned or subpoenaed, that’s exactly what Zerion is.
Everything runs over Tor. Post-quantum encryption on every message. Hidden profiles and anti-forensics for people who need them. Free and open source, so you can verify all of it yourself.
We’ve grown to here on word of mouth alone. If it sounds useful, try it and tell one person who’d need it.
zerion.chat
Zerion 3.0 marks our transition to a fully independent protocol stack.
Briar has been an excellent foundation, but our goal is to be fully independent. We’re replacing the remaining Briar/Bramble protocols with our own transport, wire format, sync layer and message model.
One focus: resisting traffic analysis with constant-rate polling and cover traffic.
Apple says it would rather pull iMessage and FaceTime from the UK entirely than comply with new surveillance demands. Under the amended law, companies must clear security features with the government before release and scan encrypted messages on request.
Notice what makes that threat possible: Apple is a company with a headquarters, a server, and a product it can be forced to change or withdraw.
An app with none of those has nothing to weaken.
zerion.chat
Brave is a free browser built on Chromium that blocks ads, trackers, and fingerprinting scripts by default - no extensions needed. It includes private windows routed through the Tor network on desktop, and its own independent search engine that doesn't track searches.
Japan’s KDDI just disclosed a breach affecting up to 14.2 million email accounts across six providers. The detail that stands out: some passwords were stored in plain text, not even hashed.
This keeps happening because centralized services hold enormous pools of credentials, and one flaw in one vendor exposes all of them at once.
Zerion has no accounts, no passwords on any server, nothing pooled to steal. There’s simply no database to breach.
zerion.chat
@fdroidorg Please include the onion link in your post
http://fdroidorg6cooksyluodepej4erfctzk7rrjpjbbr6wx24jh3lqyfwyd.onion/2026/07/01/adv-malware.html.en
If this is the official f-droid floss.social account then I know you care about tor onion servers because the official fdroid website has an onion link
Tor onion links provide greater anonymity to tor users than simply accessing the clearweb site through tor
And the more people use tor and tor onion addresses for uncontroversial browsing the easier it becomes for people to hide in the traffic when it can be a matter of life or death what websites you are accessing
Canada’s Bill C-22 just passed third reading, rushed through with limited debate. It lets the government compel companies to build backdoors into encryption.
Signal and NordVPN have said they’ll leave Canada entirely if it passes. Apple and Meta are urging amendments.
Here’s what a backdoor mandate can’t touch: an app with no company to compel and no server to weaken. You can’t order a backdoor into something that has no door.
zerion.chat
Every week brings another breach, and a pattern underneath them: the more identity a system collects, the more there is to steal. Passports, fingerprints, phone numbers, all sitting in databases waiting to leak.
The fix isn’t better security on all that data. It’s not collecting it in the first place.
Zerion asks for nothing. No phone number, no email, no ID. Nothing to breach because nothing is stored.
zerion.chat
GitHub itself got breached this week. Around 4,000 code repositories taken, and the group behind it says they’ll sell the source rather than ask for ransom.
Even the platform that hosts the world’s code is a single point that can be hit.
It’s exactly why Zerion treats GitHub as a public mirror, not a dependency. The code is GPLv3 and can live anywhere. Nothing critical relies on it staying up.
zerion.chat
Next up, a #DEFCON #VPN service sounds awesome. Like with email there is plenty of expertise on how to build VPNs. Technically it is a realistic goal, so let's investigate!
To be attractive to a large customer base you need to offer a lot of locations with an ever changing pool of addresses for when some get blocked by someone in the world.
Those two things mean you need a pool of providers and great automation playbooks where you can easily spin up and provision "secure" VPN gateways all over the world.
Because of the reliance on 3rd parties, unlike with email, you now have to worry about the legal concept of the 3rd party doctrine, so have some more lawyers ready to do battle.
Then two things happened, I spoke with two different people with experience in the VPN game. First someone who served as a CTO to a large VPN provider.
They spent all their time trying to save money, automate more, and respond to non-stop customer complaints from over seas business people. Chine would block some VPN addresses and they could no longer connect to their company back home and they needed to do that RIGHT NOW. So a sort of daily fire drill. The increasing VPN competition meant they had to keep spending on advertising and cost control.
The second person put the final nail in the coffin. They explained as far as they could tell about half of all VPN providers had ties to intelligence services. Either as fronts or investors or super friendly "partners". Iran, Russia, China, North Korea, some Middle Eastern countries, all play in this space.
This means half of the VPN providers have a different business model than the other half. Their goal is maximum people at the least cost to cast as large a monitoring net as possible, and revenue from paying customers doesn't have to actually cover your operating costs.
Building a #VPN service the right way would mean we would be more expensive, in fewer locations, and support only the strongest technologies - all things that would reduce your pool of potential customers.
So, like the private email idea, it was interesting to investigate, we learned a lot, and we will never enter the VPN market.
Instead we run free #Tor relays and support @torproject Please support Tor and other privacy technologies.
Chat Control is back. This Monday, June 29, the EU holds its final negotiation on a regulation that could force messaging apps to scan your private messages before they’re encrypted, no warrant required.
Parliament rejected it by one vote in March. Now it’s being pushed through the back door.
Here’s the thing they can’t legislate around: you can’t scan what never touches a server. Zerion has no server to place a scanner on.
zerion.chat
Citizen Lab confirmed this week that Russian authorities used Cellebrite to extract a detained activist’s phone, then searched it for political contacts to build a prosecution.
This is the exact threat Zerion was built for. Forensic tool detection (Cellebrite, GrayKey, ADB) locks the app instantly. Hidden profiles keep separate identities behind separate passwords. Auto-wipe triggers on failed unlocks.
Encryption isn’t enough when they hold the device.
zerion.chat