惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - 司徒正美
The GitHub Blog
The GitHub Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Apple Machine Learning Research
Apple Machine Learning Research
L
LangChain Blog
GbyAI
GbyAI
博客园_首页
V
Visual Studio Blog
Martin Fowler
Martin Fowler
WordPress大学
WordPress大学
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 叶小钗
腾讯CDC
博客园 - Franky
IT之家
IT之家
Google DeepMind News
Google DeepMind News
Microsoft Azure Blog
Microsoft Azure Blog
D
Docker
大猫的无限游戏
大猫的无限游戏
Recent Announcements
Recent Announcements
小众软件
小众软件
博客园 - 三生石上(FineUI控件)
B
Blog
酷 壳 – CoolShell
酷 壳 – CoolShell

Hacker News: Show HN

PurrrrrFocus: Pomodoro Timer App - App Store Workflow Engine — Multi-Step Orchestration for Bun RapidPhoto: Pro Photo Editor App - App Store GitHub - DheerG/swarms: Achieve extraordinary results with claude code across a variety of tasks SPICE simulation → oscilloscope → verification with Claude Code — Lucas Gerads Show HN: VCoding – A 5 MB native Windows IDE with no dynamic dependencies Show HN: LLMs don't hallucinate because they're bad at math, it's the format GitHub - Agent-FM/agentfm-core: AgentFM is a peer-to-peer network that turns everyday computers into a decentralized AI supercomputer. AgentFM lets you run massive AI workloads directly across a global mesh of idle CPUs and GPUs. Show HN: Tracking Top US Science Olympiad Alumni over Last 25 Years GitHub - Potarix/agent-hub: One place to talk to all your agents Show HN: Runtime security for AI agents(injection,tool abuse, data exfiltration) GitHub - dubeyKartikay/lazyspotify: Terminal Spotify client for macOS and Linux GitHub - the-banana-tool/king-louie: Easy to use GUI Personal AI Assistant. Win/Linux/Mac. Show HN I made my vacation rental bookable by AI agents–no Airbnb, 0% commission GitHub - basteez/jsf-autoreload: maven plugin to enable hot reload on jsf projects uvm32/hosts/host-gdbstub at main · ringtailsoftware/uvm32 GitHub - labsai/EDDI: Config-driven engine that turns JSON into production-grade AI agents. Multi-agent orchestration, 12+ LLM providers, MCP/A2A protocols, RAG, persistent memory, and enterprise compliance (EU AI Act, GDPR, HIPAA). Built on Quarkus. GitHub - glitchnsec/fortyone-oss: AI Executive Assistant Platform Quickstart | Alien GitHub - muxshed/shed: One stream in, or many. Every destination, simultaneously. No cloud middleman, no per-channel fees, no limits. GitHub - ocrbase-hq/ocrbase: 📄 PDF/IMG ->.MD/JSON Document OCR API for PaddleOCR and GLMOCR. Self-hostable. GitHub - impactjo/home-memory: MCP server that lets your AI assistant remember everything about your home. GitHub - Sets88/dbcls: DbCls is a powerful terminal database client that supports various databases GitHub - neptun2000/heor-agent-mcp GitHub - SeanFDZ/macmind: Single-layer transformer in HyperTalk for the classic Macintosh RollQuation: Math Puzzles - Apps on Google Play GitHub - dropbox/witchcraft Show HN: Agent-cache – Multi-tier LLM/tool/session caching for Valkey and Redis GitHub - opentalon/opentalon: OpenTalon is an open-source platform built from the ground up in Go as a robust alternative to OpenClaw LinkedIn™ 职位抓取工具 - Chrome 应用商店
GitHub - VeilusDigital/PhantomChatCrypto: The cryptograph...
VeilusDigita · 2026-06-24 · via Hacker News: Show HN

Swift Tests

The cryptographic core of Phantom Chat (Veilus Digital), extracted verbatim from the iOS app so it can be read, compiled, and run by anyone — reviewers, journalists, security researchers — without taking our word for anything.

Source-available for review. You may read, build, and run this code to verify our claims. You may not reuse it in another product. See LICENSE.

The rest of the app and the backend remain closed-source; this package is the part where the security actually lives.

What's here

File What it is
Sources/PhantomChatCrypto/Kyber768.swift ML-KEM-768 (FIPS 203) — post-quantum KEM, pure Swift
Sources/PhantomChatCrypto/Keccak.swift Keccak-f[1600] + SHA3-256/512 + SHAKE128/256 (FIPS 202)
Sources/PhantomChatCrypto/PQXDHHybrid.swift Hybrid combiner: classical X3DH secret + Kyber secret → root key
Sources/PhantomChatCrypto/DoubleRatchet.swift Signal-protocol Double Ratchet (per-message keys, forward secrecy)

These files are byte-for-byte identical to the app's CryptoService.swift / DoubleRatchet.swift (only the import lines differ). The companion document phantom-chat-claim-audit.md maps each marketing claim to these files.

How to verify it yourself

That runs (all must pass):

  • FIPS 202 known-answer tests — SHA3-256/512 and SHAKE128/256 against the published NIST reference values.
  • NTT correctness — polynomial multiply checked against a schoolbook negacyclic convolution.
  • Reduction correctness — Barrett reduction checked congruent across the entire Int16 input range; canonical encoding verified.
  • ML-KEM-768 round-trips — KeyGen → Encaps → Decaps agree; tampered ciphertext triggers implicit rejection.
  • Double Ratchet — encrypt/decrypt round-trip.
  • PQXDH hybrid combiner — deterministic and transcript-bound.
  • FIPS-203 conformance vs Apple CryptoKit (FIPSInteropTests, requires macOS 26+): Phantom's Kyber and Apple's vetted MLKEM768 exchange shared secrets both directions, and for the same seed Phantom's public key is byte-identical to Apple's. This is the strongest possible evidence that this is genuinely standard ML-KEM-768, not a look-alike.

Honesty notes (the parts we want you to scrutinise)

  • This is a clean-room Swift implementation of published standards (FIPS 202, FIPS 203, Signal Double Ratchet/X3DH), not libsignal or liboqs. The algorithms are standard; the implementation is ours.
  • It has not had a paid third-party audit yet — that's on the roadmap. We're publishing it precisely so it can be reviewed.
  • The interop tests use Apple's CryptoKit as the reference oracle; they need macOS 26 or later to run (older OSes will skip them).
  • Found a problem? support@veilusdigital.co. We'd rather hear it from you.