i took my files off the internet and started handing them to strangers.
sounds insane for about ten seconds, until you look at what happens to a file the second you upload it. i'd rather one person hold it for a day than a company hold it forever.
so that's HDMEx. a payment, a photo, a video, a message, it goes to someone already making the trip and they carry it. no server sees it.
the courier is not trusted and never was. the design assumes they copy what they're carrying on day one and sit on it for fifteen years waiting for the hardware to catch up.
so before the file leaves, it goes through an all-or-nothing transform, which scrambles it until every part depends on every other part. then 32 bytes come out and travel by a different route, sealed with a classical algorithm and a post-quantum one at the same time.
the courier carries the rest. the rest is not 99.99% of your file, it's noise. miss 32 bytes and you don't have most of it, you have nothing. which is the point: the person carrying your file can be anyone at all, including someone who badly wants to read it.
that's the road. the house is the other half.
your vault holds a seed and a colour. the seed never moves. the colour does, and it moves with what you actually do in the app. your key for a period comes from the two of them together, so a key that leaks is a key to one stretch of your life, not a key to you. that's why the mascot is a chameleon and not a padlock.
to be precise, since it's the first thing anyone competent asks. chroma guard is mine, i designed it. what it is not is a new cipher. the primitives underneath are the standard published ones, and what i invented sits above them, in how keys live and change. that layer is the one i expect to get shot at, and it should be.
now the part i care most about, and people usually mis-hear it. it is not "work replaces stake". voting power is the square root of your stake times the square root of your participation, so you need both, and neither one alone gets you anywhere. capital pushes, work decides.
participation isn't a count of deliveries either. recent work weighs more than old work, credit is capped per pair of counterparties so you can't farm it with a friend, and every delivery has to be counter-signed by the sender and the receiver. and to become a validator at all you have to have carried things. the bar is a number of completed courses and it rises as the network matures. you don't buy your way in.
the phone part is what i'm most pleased with. a phone can't be a BFT validator, it sleeps, it loses signal, the OS kills it. so phones don't sign blocks. they nominate, permanently, from 5G, holding their own keys, earning and voting with no uptime requirement at all. a separate rotating committee does the signing, opt-in, and never gets slashed for being offline. no proof of work anywhere.
to be clear, the chain still needs machines. every BFT chain does and mine is no exception. what it doesn't need is anywhere to put your files, and on a messaging network that's where nearly all the hardware normally goes.
and the honest limit, because it matters. none of that produces finality. block agreement runs on cometbft, boring and proven. my layer decides eligibility, weight, rewards and governance, and if i got it wrong the worst case is an unfair reward, never a broken chain. that separation was the first decision i made and the one i'd defend hardest.
i'm building it slowly and on purpose. no investors, and no deadline anyone else set. nobody in the room who can ask me to soften the ethics for a funding round. the chain is mine, written in C++. the scanner, the API and the web app in svelte, all mine. first early adopters at the end of 2026 or the start of 2027, with a beta. that's the only date i'm giving anyone.
a phone is a terrible 24/7 validator. it sleeps, loses signal, and the battery always gives up at the worst moment.
so in the chain i'm building it doesn't have to be one. the phone holds the keys, stakes and votes, even on 4G. signing blocks happens in a rotating committee you opt into, only during your slot, and being offline outside it never gets you slashed. finality comes from CometBFT.
no mining rigs and no proof-of-work. the couriers carrying the deliveries are the same people securing the chain.
@monero honest question from someone building with post-quantum seals: what's the plan for harvest-now-decrypt-later? the ledger stays public forever, and the privacy rests on curve math a future quantum machine could chew through. is that on the roadmap ?
@telegram good tip. the one the intern skipped: regular chats aren't end-to-end encrypted, only secret chats are, and those aren't on by default. hiding your number is nice, your messages still sit on telegram's servers ;-)
@EleanorTerrett@SECGov "self-custody in certain cases" is a funny way to describe holding your own keys. the chain i'm building starts from the opposite default: keys are created on the device and never leave it, and handing them to someone else would be the exception.
@Cointelegraph these ultimatums work more often than you'd expect. the same public trail that lets them find a hacker lets anyone find you too, most people just never have a reason to look.
@birdabo the hardest step on that list is quietly the google one. you can install arch alone, but your shared docs and group chats still live there with everyone else.
@MatiasBacklund@ProtonPrivacy true, and you never signed up for any of it. ask the neighbor where the footage ends up. best case a cloud server, worst case his wife's divorce lawyer ;-)
best explanation i've read of why bolting privacy onto an existing chain gets exotic so fast. it's part of why encryption sits in the base layer of the chain i'm building instead of coming later. fewer jetpacks, more boring plumbing. the socio-political part is the one i'd love to hear more about !
Why does adding private payments to Bitcoin seemingly require witness encryption, the cryptographic equivalent of a jetpack? Why is that awesome, impressive, and a bad idea? And how do you make a cryptocurrency like Bitcoin or Zcash private in the first place?
To answer that, we need to cover 1) why Bitcoin is public, 2) how you fix that, 3) the socio-political complications using that solution in Bitcoin, and 4) the cryptographic jetpack workaround.
@binance funny thread to get from an exchange, since the hottest wallet most people have is their binance account. the "use both" part is honest though. i'd only add that the cold one should be the one holding most of the money ;-)
the word doing all the damage there is "unencrypted". misconfigured servers happen to everyone sooner or later. what i care about in my own design is that when it happens, the server only ever had ciphertext to give away. nine months and nobody noticed, so nobody was looking either
@cvpayne the other thing people don't realize is how much of their own stuff sits in those buildings. every photo backup and chat log has a physical address, usually one they've never seen !
borrowing tens of billions at junk-adjacent rates to build buildings that need their own power plants. meanwhile what i'm building leans on phones people already own and charge every night anyway. obviously not the same workload as stargate, but i do wonder how many of those racks end up hosting stuff that never needed a data center ;-)
separating where the agreement lives from where the money settles is the right instinct. in the courier network i'm building, the file body and the piece that unlocks it never travel with the same carrier, and the transport refuses to build a delivery that breaks that rule. curious what enforces the separation on your side, contracts or code?
@crypto_banter@zachxbt this is the headline every privacy coin dreads, and it's also proof the pool works. worth remembering the part after: 3.8M in shielded ZEC is useless until it comes back out into something they can spend, and the exits are usually where these crews get caught.
@wallstreetbets funny how "privacy is for criminals" turned into "privacy is for institutions" the second someone's trading book showed up on etherscan. same tech, better suits. the real question is whether regular users get the same shielding or just the funds
new in WP 4.4, and the rule i care about most: a delivery where the file body and its missing fragment would travel with the same carrier doesn't get built. the transport rejects it before the package exists.
the body goes with one courier. the fragment, sealed for the recipient, goes either with a second courier or through the chain. on the two-courier route nothing goes online at all. the chain is more convenient, but the fragment then sits on a public ledger for good and only the seal protects it. i'd rather write that down than pretend both routes are equal.
and a fragment copied into another delivery won't open, it's bound to its own course.
'd push back a little. in a shielded pool, scale is the privacy. a pool with 200 users hides you among 200 people, and chain analysis loves small crowds. TPS matters mostly because it's how you get millions of people into the same pool. if tachyon does that from the base layer, the privacy argument gets stronger, not weaker.
"white van, spray paint" only works because every car that passed a camera for months is still in there. the AI just lets the archive answer questions in plain english. and misuse isn't hypothetical, a texas audit just found a dispatcher who ran the system 42 times on her own kid :-)