Habr•October 10, 2026•🇷🇺Translated from Russian

ONYX 2.0 Removes Central Servers for Fully Decentralized Tor-Based Messaging and Calls

ONYX 2.0 has transitioned from a centralized model to a fully decentralized architecture that eliminates servers entirely. The update introduces a client-only design built around Tor, enabling direct peer-to-peer messaging and voice calls while preserving end-to-end encryption.

Account Model and Identity

Upon first launch, the application generates a cryptographic key pair that serves as the user account. Recovery on new devices is possible through a 12-word seed phrase. Each identity carries an Account ID and fingerprint that contacts can verify to confirm they are communicating with the intended party. Profile data remains local and syncs between a user’s own devices via WardLink.

Tor Integration and Network Design

The desktop versions bundle a Tor daemon, while Android uses tor-android. Every device receives its own onion address, and all traffic—including external groups and channels—routes exclusively through Tor. No fallback direct connections exist, preventing accidental IP exposure. A “View Circuit” screen displays the active Tor path for any conversation.

Contacts and Message Delivery

Contacts are added via QR code or onion address. Incoming requests may include a comment and can be accepted, rejected, or rejected with blocking. Until acceptance, the requester cannot view status or initiate calls. Without a central mailbox, undelivered messages stay on the sender’s device and retry automatically according to a configurable interval, with delivery status shown beneath each message.

Voice Calls

The standout feature is native voice calling that operates solely over Tor. A built-in local TURN server handles media relay without external infrastructure. Call quality remains acceptable despite 1–3 second latency, and call history is retained in the chat interface.

Trade-offs and Removed Features

Developers removed HTTP/SOCKS5 proxy support, link previews, and any server-dependent functions such as remote account deletion. Latency has increased due to Tor routing, and instant delivery is no longer guaranteed when recipients are offline. The changes represent a deliberate move toward decentralization.

The beta release aims to identify issues with unstable circuits, network switching, and multi-device behavior. The source and binaries are available on GitHub.

Related articles

Habr•Privacy & Surveillance

Privacy-Focused Browser Tool Compresses PDFs Locally Without Uploading Sensitive Documents

A developer created a PDF compression tool that runs entirely inside the browser to protect sensitive personal and professional documents from third-party servers. The solution addresses repeated situations where embassy submissions, financial presentations, contracts, and internal reports exceeded size limits, forcing users to choose between installing desktop software or risking data exposure through online services. The tool reduces scanned and photographic PDFs by 66 to 97 percent depending on quality settings while honestly reporting weaker performance on text-heavy files compared with Ghostscript. It works on both desktop and mobile platforms, including iPhone and Android, requires no installation, and continues functioning offline after the first page load. On mobile devices the application respects memory constraints by limiting images to four megapixels, preserving readability for A4 documents intended for printing. The project originated from a single evening script built around Ghostscript and evolved into a full web application after similar compression needs recurred across multiple devices and locations.

Habr•Privacy & Surveillance

Building Prizrak: How a Developer Created a Federated Messenger That Masks All Traffic as Legitimate HTTPS

A developer created Prizrak, a federated messenger with end-to-end encryption where all traffic, including calls, is indistinguishable from ordinary HTTPS connections. The project addresses three common limitations of existing messengers: centralized control points, mandatory phone numbers, and detectable encrypted traffic. It uses real TLS 1.3 handshakes to actual domains, multi-port listening, and a hidden token mechanism inside the encrypted channel. When servers cannot reach each other directly, messages are delivered through a network of storage nodes modeled after Ceph's RADOS system. Voice and video calls run on a native media stack with custom STUN-like functionality and careful UDP buffer sizing to avoid packet truncation. An integrated two-hop VPN reuses the same stealth transport while keeping messenger traffic outside the tunnel.

Habr•Privacy & Surveillance

GrapheneOS Setup Guide: Configuring Pixel Phones for Corporate Surveillance-Free Daily Use

This comprehensive engineering guide explains how to deploy GrapheneOS on supported Google Pixel devices to eliminate corporate telemetry collection. It follows three core principles: rejecting proprietary ecosystems, applying Zero Trust through cryptography and open-source audits, and enforcing strict compartmentalization via isolated user profiles. The tutorial covers official installation via the Web Installer, basic owner profile hardening with PIN shuffling and automatic reboot, and the use of Obtainium for direct FOSS app management from GitHub repositories. Detailed recommendations include privacy-focused tools such as KeePassDX, Aegis Authenticator, AmneziaVPN, Signal, and Fossify applications, along with VPN kill-switch configuration. Regional profiles are created for sandboxed Google Play, Aurora Store, RuStore, and Huawei AppGallery to safely run banking, marketplace, and social apps without cross-profile tracking.

Habr•Privacy & Surveillance

Following the White Rabbit: Developer Builds Custom Rust VPN PAYPHONE Using QUIC and Obfuscation to Evade Detection

A Russian developer has released PAYPHONE, an experimental IPv4 VPN written entirely in Rust that uses QUIC datagrams and optional TLS-over-TCP transport with custom obfuscation. The project aims to provide an alternative to AmneziaWG and Xray/VLESS+REALITY stacks that are commonly used to bypass Russian internet filtering. The article details the full packet path from TUN interface through a 16-byte PAYPHONE header, session management with Ed25519 tokens, and multiple post-launch bugs including MTU miscalculations, self-routing loops on macOS, and timer lifetime issues in Tokio. Key technical choices include RFC 9221 datagram support to avoid head-of-line blocking for multiplexed TCP flows and token-bucket rate limiting tied to subscription tokens. The author also describes route monitoring every 400 ms and interface-bound sockets to prevent the tunnel from swallowing its own control traffic.