// the find
segfltt/cmd-chat
My ISP tried to block this repo. 🤐 A truly peer-to-peer, end-to-end encrypted CLI chat that leaves NO logs. Perfect for... sensitive discussions. 🔥 Get it before it gets taken down
A CLI chat tool where one person runs a TCP server and others connect as clients, authenticating with SRP so the password never crosses the wire, then encrypting messages with a key derived from that same password. It's aimed at developers who want a quick, no-infrastructure way to talk over a network without logs or a hosted service, though the 'peer-to-peer' framing in the README doesn't match the actual client-server architecture.
Using SRP for authentication is a solid design choice — it proves both sides know the password without ever putting it on the wire, which beats the usual hash-and-send approach. There's no persistence anywhere: no chat history on disk, no account database, nothing but a socket and memory, so the attack surface is genuinely small and easy to read in one sitting. The dependency list stays tiny (asyncio plus a couple of crypto primitives, no web framework), which makes the protocol auditable instead of buried in library internals.
It isn't actually peer-to-peer — one side runs 'serve' and acts as a relay the others connect to, which is ordinary client-server, and the README oversells this. The shared room key is a deterministic HKDF of the password used by everyone in the room, so there's no per-session rotation or forward secrecy: if the password ever leaks, anyone who captured the ciphertext can decrypt the whole conversation after the fact. Passing '--password mysecret' as a CLI argument also lands it in shell history and shows up in the process list, which undercuts the 'no logs' pitch. SRP itself is hand-rolled in srp_auth.py rather than pulled from a vetted library, and homegrown auth protocols are exactly where subtle implementation bugs turn into full breaks.