ThreatScoopOnionChat Encrypted Messaging app for Android description
ThreadScoopOnionChat
This version is a fork from https://github.com/session-foundation/session-android, enfocado en la privacidad.
How Did ThreadScoopOnionChat Come About?
I have always been a fan of privacy and security in communications, and I am constantly researching potential security breaches in messaging applications. ThreadScoopOnionChat emerged after the analysis of this blog https://soatok.blog/2025/01/14/dont-use-session-signal-fork/, in which several aspects are described as to why using Session is not recommended, and I wondered how it is possible that a foundation focused on privacy—with the grants and support it receives—has not been able to improve this protocol. I still do not understand the answer, since my resources are much smaller than those of a foundation compared to that of a person who is simply a fan of privacy and security.
In this blog, certain problems were described:
- https://soatok.blog/2025/01/14/dont-use-session-signal-fork/#insufficient-entropy-ed25519
- https://soatok.blog/2025/01/14/dont-use-session-signal-fork/#in-band-negotiation
- https://soatok.blog/2025/01/14/dont-use-session-signal-fork/#public-keys-aes-gcm
This is a forked version privacy focussed from Session. Go Github to check all features implemented.