Threat model
The short version
- Private keys stay on your devices. The relay and the storage bucket never hold them, so a hacked or nosy server cannot forge your messages or read their contents.
- The server still sees metadata: who talks to whom, when, how big, and how files are organised and shared. Poweur does not hide it, and says so.
- For a hosted name, the operator of the domain controls where the name points. That is a real trust assumption, and the reason to use your own domain for anything long-lived.
- This has not had an external security review.
This page describes the model for the hosted service at poweur.net and for the software in general. It is a summary; the full security model is in the documentation, and the file-storage details are in the storage design.
Who can see and do what
| Who | Can see or do | Cannot |
|---|---|---|
| The relay (poweur.net) | Which IDs exist and their public keys; message routing metadata (sender, recipient, time, approximate size); file tree shape, padded sizes, timestamps, versions, authors and who a folder is shared with; your contacts and inbox policy; public folders; IP addresses and access patterns. It can drop or delay messages. | Read message contents or private file names and contents; forge a message from you; hold your identity private key. |
| Whoever controls the bucket or backups | The same stored metadata as the relay, and ciphertext. | Decrypt private files or names. |
| A network observer | That a connection to the relay happened, and its timing and volume (TLS hides the rest). | Read contents, which are end-to-end encrypted, or forge messages. |
| An app you sign in to | Your ID, and your name and photo if you allow it. | Your messages or files; it never receives a password. |
| The sign-in bridge (oauth.poweur.org) | Which applications you sign in to, and when, in its audit log. | Your messages or files. |
| Another person you share with | What you shared with them, including anything they cached. Revoking a share cannot erase copies or keys they already have. | Anything you did not share. |
Keys and devices
- Each ID has a long-lived signing key and encryption key, created on your device. They are wrapped by a secret only your passkey (or the phone's secure storage) can produce. The relay keeps an opaque encrypted copy so another device can be added or a cleared browser restored; it cannot open it.
- Messages use fresh ephemeral keys for each message (X25519, HKDF-SHA256, ChaCha20-Poly1305), so a later key compromise does not expose past messages whose ephemeral keys are gone. This is partial forward secrecy, not a full double ratchet.
- A recovery kit rebuilds your keys without any server. Whoever holds the kit is you. Store it like a password.
- A compromised, unlocked device can disclose keys and plaintext. Poweur cannot protect you from that.
The name is a trust assumption
Your keys are published in an identity document served from the name's own domain, and other people check messages against it. So whoever controls a domain's web server or DNS can change which keys a name points to.
- A name under poweur.net relies on the operator of poweur.net (today, one person). A compromised or dishonest operator could point a hosted name at different keys.
- A name on your own domain relies on you and your DNS provider. Enable DNSSEC and two-factor authentication on that account.
- Clients pin the key they first saw for a contact and warn when it changes, and the app shows a safety number you can compare out of band. That turns a silent swap into a visible one.
Files
Private file names, contents and the keys to them are encrypted on your device. The server sees the shape of what you store (see the table above). Signatures and authenticated encryption detect tampering and wrong authors. A malicious relay could still try to roll you back to an older state or show different devices different histories; clients keep the last version they saw and warn on regressions, but a brand-new device needs an independently trusted checkpoint to rule it out. Folders marked public are readable by anyone. Share links keep their key in the part of the address the server never receives; a link can still leak through browser history or copy-paste.
What Poweur does not claim
- No metadata privacy. Who talks to whom, and when, is visible to the relay. Hiding that would need mixnets or onion routing, which Poweur does not do. Sending through your home relay (CLI option
--via-home-relay) keeps your IP from the recipient's relay at the cost of an extra hop. - No proof of a legal identity. A Poweur ID proves control of a name and its keys, not that a person is who they say.
- No anonymity. Your IP address is visible to the relay you connect to.
- No guarantee of delivery. A relay can drop or delay messages; there is no proof of delivery beyond the recipient's read receipts.
- No audit yet. The design and the code are open for review. An independent review is planned but has not happened.
Telemetry
The website and the web app send anonymous page views, errors and speed measurements to our own servers (no third-party analytics). Your ID is attached only if you tick Include my ID in Settings → Diagnostics. The privacy policy has the full list.
Report a problem
Use GitHub's private vulnerability reporting or write to [email protected]. The security policy says what to expect.