惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
月光博客
月光博客
IT之家
IT之家
B
Blog RSS Feed
T
Tailwind CSS Blog
The GitHub Blog
The GitHub Blog
博客园 - 三生石上(FineUI控件)
MyScale Blog
MyScale Blog
J
Java Code Geeks
Stack Overflow Blog
Stack Overflow Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
博客园 - Franky
博客园 - 叶小钗
阮一峰的网络日志
阮一峰的网络日志
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
U
Unit 42
博客园_首页
B
Blog
V
V2EX
腾讯CDC
Vercel News
Vercel News
量子位
Microsoft Security Blog
Microsoft Security Blog

Show HN

GitHub - astefanutti/shaderbang: Shebang for Shaders Show HN: AI agents for UK GDAD PCF roles and their skills The Two Pillars: Mixer Mode and Meta-Software in the Reorganization of Software Work After AI GitHub - JaiCode08/teleport-env What 1,000+ Harness Experiments Taught Me About Self-Improving Agents Show HN: Liiists, a Markdown-first, iOS and CLI list app SwiperTab – Get this Extension for 🦊 Firefox (en-US) GitHub - kouhxp/fftext: Summarize, explain, fact-check, or translate any text, URL, or file. No GPU. No cloud. One command GitHub - sweetpad-dev/sweetpad: Develop Swift/iOS projects using VSCode GitHub - dogmaticdev/IRON: IRON a.k.a. Intermediate Representation Object Notation is a Interpreter/Database that is used to create Programming Languages. GitHub - sjhalani7/vaen: Package your AI coding harness into a portable .agent file, and share it across repos, teams, & the community without ever having to copy-paste instructions, skills, MCP config, or secrets. Show HN: Gandalf the Grader Show HN: Citadeld – replay any CI failure locally from a single file GitHub - tdortman/cuSBF: High-Performance GPU Super Bloom Filter coral-ai/claude-code-token-xray at main · Coral-Bricks-AI/coral-ai GitHub - ulyssestenn/funes: Funes is a Git-based framework for LLM-managed knowledge work: an AI Librarian ingests raw sources, builds an interlinked Markdown knowledge base, and uses it to produce cited reports, analyses, and other outputs. GitHub - ThatXliner/gah: Git Add Hunk, built for agents to use GitHub - harmont-dev/harmont-cli: Command-line client for the Harmont CI platform GitHub - brooksmcmillin/mcp-authflow: OAuth 2.0 Authorization Server framework for MCP servers GitHub - javaid-codes/audit-supply-chain-agents GitHub - amorey/gochan: A small library of common channel architectures for Go, inspired by Rust GitHub - arifozgun/OpenGem: Free, Open-Source AI API Gateway with Gemini, OpenAI & Anthropic Compatibility in 1 file GitHub - Pranesh950/BioPetals: 🌸 Run BIOxAI models at home, BitTorrent-style. Fine-tuning and inference up to 10x faster than offloading GitHub - cnguyen14/bounty-doctor: Diagnose a GitHub bounty issue before you waste hours: detects honeypot scam repos, AI-bot attempt swarms, and stale contests. Show HN: CoreMCP – MCP Server for On-Prem DBs Show HN: KittyHTML – Render HTML/CSS as an inline image in your terminal GitHub - bingud/filemat: Web-based file manager Show HN: TruthLens – Free multi-signal deepfake image detector GitHub - apexlocal-jz/claude-usage-tray: Windows system-tray app showing your Claude Code rate-limit usage at a glance. Zero deps, ~300 lines of PowerShell. Cross-IDE (works regardless of VS Code, Cursor, plain terminal). Release v0.1.2.1 · kouhxp/yapsnap
GitHub - VeilusDigital/PhantomChatCrypto: The cryptograph...
VeilusDigita · 2026-06-24 · via Show HN

Swift Tests

The cryptographic core of Phantom Chat (Veilus Digital), extracted verbatim from the iOS app so it can be read, compiled, and run by anyone — reviewers, journalists, security researchers — without taking our word for anything.

Source-available for review. You may read, build, and run this code to verify our claims. You may not reuse it in another product. See LICENSE.

The rest of the app and the backend remain closed-source; this package is the part where the security actually lives.

What's here

File What it is
Sources/PhantomChatCrypto/Kyber768.swift ML-KEM-768 (FIPS 203) — post-quantum KEM, pure Swift
Sources/PhantomChatCrypto/Keccak.swift Keccak-f[1600] + SHA3-256/512 + SHAKE128/256 (FIPS 202)
Sources/PhantomChatCrypto/PQXDHHybrid.swift Hybrid combiner: classical X3DH secret + Kyber secret → root key
Sources/PhantomChatCrypto/DoubleRatchet.swift Signal-protocol Double Ratchet (per-message keys, forward secrecy)

These files are byte-for-byte identical to the app's CryptoService.swift / DoubleRatchet.swift (only the import lines differ). The companion document phantom-chat-claim-audit.md maps each marketing claim to these files.

How to verify it yourself

That runs (all must pass):

  • FIPS 202 known-answer tests — SHA3-256/512 and SHAKE128/256 against the published NIST reference values.
  • NTT correctness — polynomial multiply checked against a schoolbook negacyclic convolution.
  • Reduction correctness — Barrett reduction checked congruent across the entire Int16 input range; canonical encoding verified.
  • ML-KEM-768 round-trips — KeyGen → Encaps → Decaps agree; tampered ciphertext triggers implicit rejection.
  • Double Ratchet — encrypt/decrypt round-trip.
  • PQXDH hybrid combiner — deterministic and transcript-bound.
  • FIPS-203 conformance vs Apple CryptoKit (FIPSInteropTests, requires macOS 26+): Phantom's Kyber and Apple's vetted MLKEM768 exchange shared secrets both directions, and for the same seed Phantom's public key is byte-identical to Apple's. This is the strongest possible evidence that this is genuinely standard ML-KEM-768, not a look-alike.

Honesty notes (the parts we want you to scrutinise)

  • This is a clean-room Swift implementation of published standards (FIPS 202, FIPS 203, Signal Double Ratchet/X3DH), not libsignal or liboqs. The algorithms are standard; the implementation is ours.
  • It has not had a paid third-party audit yet — that's on the roadmap. We're publishing it precisely so it can be reviewed.
  • The interop tests use Apple's CryptoKit as the reference oracle; they need macOS 26 or later to run (older OSes will skip them).
  • Found a problem? support@veilusdigital.co. We'd rather hear it from you.