惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
The Last Watchdog
The Last Watchdog
C
Check Point Blog
Y
Y Combinator Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
云风的 BLOG
云风的 BLOG
Google DeepMind News
Google DeepMind News
K
Kaspersky official blog
P
Proofpoint News Feed
Security Latest
Security Latest
The Hacker News
The Hacker News
Simon Willison's Weblog
Simon Willison's Weblog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Security Blog
Microsoft Security Blog
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
C
CXSECURITY Database RSS Feed - CXSecurity.com
T
Threatpost
WordPress大学
WordPress大学
Project Zero
Project Zero
A
Arctic Wolf
C
Cyber Attacks, Cyber Crime and Cyber Security
L
Lohrmann on Cybersecurity
C
Cybersecurity and Infrastructure Security Agency CISA
I
Intezer
G
GRAHAM CLULEY
A
About on SuperTechFans
S
Securelist
P
Palo Alto Networks Blog
T
Tor Project blog
罗磊的独立博客
C
Cisco Blogs
Microsoft Azure Blog
Microsoft Azure Blog
Know Your Adversary
Know Your Adversary
NISL@THU
NISL@THU
Latest news
Latest news
博客园 - 叶小钗
C
CERT Recently Published Vulnerability Notes
U
Unit 42
AWS News Blog
AWS News Blog
J
Java Code Geeks
小众软件
小众软件
D
Docker
The Cloudflare Blog
Cisco Talos Blog
Cisco Talos Blog
B
Blog
V
Vulnerabilities – Threatpost
V
V2EX
GbyAI
GbyAI
博客园_首页

DEV Community

Authentication Security Deep Dive: From Brute Force to Salted Hashing (With Java Examples) Why AI Systems Don’t Fail — They Drift Spilling beans for how i learn for exam😁"Reinforcement Learning Cheat Sheet" I Replaced Chrome with Safari for AI Browser Automation. Here's What Broke (and What Finally Worked) How Python Borrows Other People's Work The $40 Architecture: Processing 1 Billion API Requests with 99.99% Uptime Vibe Coding: A Workflow Guide (From Zero to SaaS) Most webhook security guides protect the wrong side. The scary part is delivery. Headless CMS for TanStack Start: Build a Blog with Cosmic EU Age Verification App "Hacked in 2 Minutes" — What Actually Happened Comfy Cloud’s delete function does not actually remove files Running AI Models on GPU Cloud Servers: A Beginner Guide Event-driven media intelligence with AWS Step Functions and Bedrock I scored 500 AI prompts across 8 quality dimensions — here's what broke How to Call Google Gemini API from Next.js (Free Tier, No Backend Needed) The Portal Protocol: Reclaiming Human Connection in the Age of AI How to Fix Your Team's Scattered Knowledge Problem With a Self-Hosted Forum Intro to tc Cloud Functors: A Graph-First Mental Model for the Modern Cloud Designing Multi-Tenant Backends With Both Ownership and Team Access I Built a Neumorphic CSS Library with 77+ Components — Here's What I Learned PostgreSQL Performance Optimization: Why Connection Pooling Is Critical at Scale Cómo construí un SaaS multi-rubro para gestionar expensas en Argentina con FastAPI + Vue 3 🚀 I Built an Ethical Hacking Scanner Tool – Open Source Project I Replaced /usage and /context in Claude Code With a Single Statusline A Pythonic Way to Handle Emails (IMAP/SMTP) with Auto-Discovery and AI-Ready Design I Collected 8.9 Million Polymarket Price Points — Here's What I Found About How Markets Really Move EcoTrack AI — Carbon Footprint Tracker & Dashboard Everyone's Using AI. No One Agrees How. 5 self-hosted ebook managers worth trying in 2026 Building Your First AI Agent with LangChain: From Chatbot to Autonomous Assistant Common SOC 2 Failures (Real World) Stop Vibe-Checking Your AI App: A Practical Guide to Evals How to Use SonarQube and SonarScanner Locally to Level Up Your Code Quality Your Next To-Do App Is Dead — I Replaced Mine with an OpenClaw AI Sign a Nostr event in 60 lines of Python using coincurve — no nostr-sdk, no nbxplorer, no rust toolchain ITGC Audit Explained Like You’re in Big 4 Patch Tuesday abril 2026: Microsoft parcha 163 vulnerabilidades y un zero-day en SharePoint Stop scraping everything: a better way to track competitor price changes Listing on MCPize + the Official MCP Registry while routing payments OUTSIDE the marketplace — how I kept 100% of my x402 revenue Building an AI-Powered Risk Intelligence System Using Serverless Architecture Why We Ripped Function Overloading Out of Our AI Toolchain Testing AI-Generated Code: How to Actually Know If It Works SaaS Churn Is Killing Your Business. Here Is What to Do About It (Without a Support Team) The Speed of AI Is No Longer Linear - And Self-Improving Models Are Why How to Implement RBAC for MCP Tools: A Practical Guide for Engineering Teams From Standard Quote to Persuasive Proposal: AI Automation for Arborists I built a CLI that scaffolds complete multi-tenant SaaS apps Axios CVE-2025–62718: The Silent SSRF Bug That Could Be Hiding in Your Node.js App Right Now The dashboard that ended our friendship Data Pipelines Explained Simply (and How to Build Them with Python) The Hidden Cost of AI Systems Nobody Talks About. undefined vs undeclared, and how typeof behaves Switching from file-based jobs to NATS/Kafka in Rust without changing code io_uring Adventures: Rust Servers That Love Syscalls Why Agentic AI is Killing the Traditional Database The POUR principles of web accessibility for developers and designers Quantum Neural Network 3D — A Deep Dive into Interactive WebGL Visualization How To Install Caveman In Codex On macOS And Windows Automation Pipeline Reliability: Why Your Workflow Breaks When Nobody Is Watching I Built an 'Open World' AI Coding Agent — It Works From ANY Folder From Freelancing to Product: A Tech Service Company's SaaS Transformation China's AI Giants: Adding Tencent Hunyuan & ByteDance Doubao to AI University (74 Providers) On the Vibe Coders and Their Lies clerk: Auto-Summarize Your Claude Code Sessions AI Weekly — 2026/04/10–04/17 | The Model Lockdown Is Here, but the Toolchain Is the Real Battleground AI 週報 — 2026/04/10–2026/04/17 模型封鎖潮來了,但工具鏈才是真戰場 Maybe this is how Open-Source apps are born... 🚀 Fine-Tune LLMs with LoRA and QLoRA: 2026 Guide tRPC v11 + Next.js App Router: End-to-End Type Safety Without the Boilerplate ShadCN UI in 2026: Why I Stopped Installing Component Libraries and Started Owning My Components SaaS Billing in React Server Components: Stripe + Supabase Without a Single `useEffect` Join our DEV Weekend Challenge — $1,000 in Prizes Across TEN winners! Submissions Due April 20 at 6:59 AM UTC. Implementing FSRS Spaced Repetition in Flutter + Supabase — Adding Memory Science to an AI Learning App "I Texted My Localhost From the Train — Claude Code Fixed the Bug Before I Got Home" I Built a Sales Prep AI and It Went Deeper Than Expected Design to Code #2: One JSON, Eleven Outputs Solving the 100M-Row Problem: A Summary Table Pattern for High-Volume Push Notification Logs Flutter Web With Wasm: What Actually Changes For Developers I Built 50 Royalty-Free Soundtracks for My Side Project in a Weekend Using AI Music Generation The Vibe Coding Security Checklist: 7 Things to Check Before You Ship Stop Letting Googlebot Guess Fix Your React App's SEO Right Desconstruindo o Streaming do LinkedIn: Como Criar um Engine de Extração de Vídeo de Alta Performance com HLS e FFmpeg (EDA Part-1) EDA (Exploratory Data Analysis) Explained With Real Life — Why Looking at Your Data Is the Most Important Step in Machine Learning Brand Relationship Management at Scale: Our 4-Touch Outreach System for 200+ Brands Why String.fromEnvironment() Might Return an Empty String in Dart JGuardrails 1.0.0 — Hardening Java LLM Apps Against Jailbreaks, Toxicity, and Prompt Injection Plan and Schedule a Full Week of Threads Content From One Claude Conversation Coding Cat Oran Ep3, Five Tables Changed Everything Updated: BFF Pattern I'm done watching freelancers get buried by 200 proposals. So I'm building the alternative. This is my first post BFS Algorithm in Java Step by Step Tutorial with Examples Tracking LLM Pricing Monthly: An Open Dataset for 22 AI Models How We Measure Content ROI on a Comparison Site: Revenue Attribution Without Perfect Data Introducing Nova AI Ops: The AI-Native Operating System for SRE Teams I built a free desktop video downloader for Windows — Grabbit How Talkie OCR Helps Vision-Impaired & Dyslexic Users Read the World Around Them VRCFaceTracking安装和iPhone面捕配置教程,有bug Even CrowdStrike Can't See Your Agents The Automation Gold Rush: What n8n Workflows and Claude Are Opening Up for Developers Right Now
Why I Built Abolitus: The Retrospective of a Zero-Trust AI Client
abolitus · 2026-05-18 · via DEV Community


Quick Takeaways from the Dev Log

  • The Big Tech Harvest: Why I hate the idea of centralized companies sitting on my private logs.
  • BYOK: Bypassing the host model model entirely to avoid handling your plaintext keys.
  • Scrambled Data: Slicing and encrypting vault snapshots before pushing them to a dumb Supabase backend.
  • Zero Telemetry: No Google Analytics, no session replays, and no email signups.
  • Immunized Against Banks: Going crypto-only to escape the constant payment processor bans that kill adult projects overnight.
  • PWA & Relays: Connecting local LLMs from PC to mobile without spending three hours on ngrok configurations.

A screen capture of the Abolitus user interface showcasing the clean, minimalist dark brutalist design system and high-fidelity chat experience.


1. The Big Tech Harvest: Why Centralized AI Is Never Safe

Look, everyone knows ChatGPT, Gemini, and Claude are logging your chat history. It is not some hidden conspiracy; it is right there in the terms of service. They need the data to train their next model, and your chat logs are the fuel.

If I am asking a model for a quick python script or a butterscotch pie recipe, who cares? Let them log it.

But when it comes to AI roleplay—where your chats read like a deeply personal diary, raw creative writing, or intensely intimate fantasies—the idea of those plaintext transcripts sitting on an AWS bucket somewhere makes my skin crawl.

Most platforms try to hide this with slick corporate messaging and paragraphs of vague legal jargon. They promise "encryption in transit" (which just means the packet is safe on the way to their server, where they promptly decrypt it and read it anyway).

But as long as the model runs on their hardware, they hold the keys to the kingdom.

A stark, high-contrast, black and white minimalist photograph of an endless grid of identical concrete pillars stretching into the distance under a harsh, clinical overhead light, casting deep, sharp shadows.

I wanted to build something different. I envisioned a system that rejected developer trust and corporate promises entirely. Privacy should be a mathematical certainty—never a marketing slogan.

That is why I built Abolitus.


2. BYOK: Bypassing the GPU Bill Liability

If you build an AI chat startup, the standard playbook is simple: host the models yourself, mark up the API costs, bill users per token, and act as the middleman.

But that setup has a massive structural flaw.

To run the model on my own servers, your chats have to hit my backend in plaintext. I have to process them, buffer them, and pay massive GPU hosting bills. That means I have to audit usage, monitor for "compliance," and constantly worry about getting shut down by my server hosts.

We decided to walk away from that headache. We chose BYOK (Bring Your Own Key).

We do not host the AI. We do not touch your plaintext prompts.

Instead, the Abolitus client talks directly from your browser to major API routers like OpenRouter, privacy-focused setups like NanoGPT, or a local GPU running on your machine via Ollama or LM Studio.

[ Your Browser ] --------( Direct Fetch )--------> [ LLM Provider ]
       |
  (No Plaintext Chats Ever Hit My Servers)
       |
       v
[ Abolitus Server ] (Only holds encrypted, scrambled blobs)

Enter fullscreen mode Exit fullscreen mode

By keeping the interface client-side, the API keys stay in your browser. If someone breaches my database tomorrow, they will not find a single plaintext prompt or API key. There is literally nothing to steal.


3. E2EE Cloud Sync: The Zero-Knowledge Scrambler

Since we do not run a traditional database backend, syncing your chats across devices was a puzzle. I did not want your history on my server, but you still wanted to jump from your desktop to your phone.

So we built a zero-knowledge cloud sync system.

When you create an account, your master encryption key is derived directly inside your browser from your password using the Web Crypto API. That key stays on your local machine and never touches the internet.

Before any message or character card leaves your device:

  1. The browser encrypts the payload using AES-256-GCM.
  2. It slices the data into discrete, formless blobs.
  3. It strips away all identifying metadata.
  4. Your account identifier itself is stored as a secure, one-way hash.

To my backend, your account looks like a pile of randomized noise.

Plaintext Chat ---> [ Browser AES-256-GCM ] ---> Scrambled Blobs ---> [ Dumb Blob Store ]

If you lose your password, by the way, your data is gone forever. I cannot recover it for you. There is no "forgot password" button that emails you a magic link, because I literally do not have your decryption key. That is the price of actual privacy.


4. Zero Surveillance: Why We Don't Know Who You Are

Most modern websites are instrumented like surveillance cameras. They run Google Analytics, record session replays via Hotjar, track your IP on every click, and demand an email address before you can even see the landing page.

I hate this stuff. So I banned all of it.

  • No Email Addresses: You do not register with an email. We do not want your email, because we do not want a bridge between your real-world identity and your chat files.
  • Zero App-Level IP Mapping: While HTTP requests must naturally hit CDN edge servers (like Vercel or Supabase) to route network traffic, our application and database layers do not log, persist, or map your IP address to your vault slots. We keep our application logs strictly clean of any tracking metadata.
  • No Google Analytics or Telemetry: No behavioral tracking, no cookies, no third-party scripts watching your mouse move.

I write minimal database uptime logs to make sure the sync services do not crash, but this operational metadata is mathematically isolated. It cannot touch your chat plaintext, your vault keys, or your LLM API tokens.


5. Under the Hood: The Cryptographic Details

I wanted the security model of Abolitus to be completely transparent. If you are interested in the raw mechanics, you can read the full details in our Security Model Whitepaper.

Here is a quick look at the tech behind the curtain:

Non-Extractable Local Key Custody

Your master vault key is derived from a BIP-39 mnemonic phrase and a local salt.

Once loaded in the browser, we import it as a non-extractable CryptoKey via the WebCrypto API. This means JavaScript can use the key to encrypt and decrypt data in memory, but the raw key bytes can never be extracted or read back out of the browser runtime by malicious scripts or shady browser extensions.

1 KB Boundary Padding

If you edit a character card, standard sync systems upload an object of that exact size. A packet sniffer watching your connection could look at the size of your ciphertext packets and correlate them to specific card sizes or typing rhythm.

To stop this metadata leak, Abolitus automatically pads all serialized vault data to strict 1 KB boundaries before encrypting. Whether you typed "Hi" or updated a massive 30KB character card, it looks identical to a network observer.

Storage Write Tokens

How does the server let you update your database sync slot if it does not know who you are?

We derive a secondary storage write token from the sync slot and the vault key. This acts as a cryptographic signature. The server verifies this token, allows the database write, and remains completely blind to the actual vault decryption key.


6. Defying the Credit Card Censors: Why We Went Crypto-Only

Privacy on the web is dying, and the executioners are payment processors.

If you have watched recent web history—like the massive DL-Site censorship waves—you know credit card networks actively police what adults do online. They threaten, freeze merchant accounts, and block payments to platforms that allow unfiltered self-expression.

This payment blockade is a massive source of anxiety for developers and users. Over the years, I have watched dozens of excellent NSFW-friendly services, character repositories, and developers suddenly get blacklisted by Visa or Mastercard. They are forced to shut down their servers, restrict access, or delete user creations overnight. You spend months building a personal creative workspace, only to watch it vanish because a bank executive got squeamish.

We wanted to build a fortress.

To bypass this threat entirely, we went crypto-only.

[ Traditional Setup ] -> Real Name -> Credit Card -> Bank Records -> Platform Identity

[ Abolitus Setup ] -> Anonymized Wallet -> Direct Blockchain Sync

Instead of forcing you onto a single chain, we support a compact, multi-chain engine with instant verification:

  • USDC & USDT Networks: Solana, TRON (TRC-20), Base, Arbitrum, Polygon, Ethereum, and BSC.
  • Native Gas Tokens: SOL (Solana), POL (Polygon), ETH (Base, Arbitrum, Ethereum), and BNB (BSC).

By going crypto-only, we protected your identity and immunized our infrastructure. We have zero reliance on credit card networks. They cannot threaten us, they cannot audit our transactions, and they can never force us to shut down or compromise our features. There is zero risk of Abolitus disappearing overnight due to payment processor crackdowns.

Yes, our conversion rates took a massive nosedive because we do not have a credit card button. Yes, we make way less money. But we do not care. We would rather build a tiny, fiercely private refuge for those who value their autonomy than compromise for a fiat gateway.


7. PC-to-Mobile Tunneling: Local LLMs in Your Pocket

Anyone who has run a massive 70B parameter local model on a powerful home gaming rig has wanted the same thing: to lie in bed and chat with that model on a smartphone.

Historically, setting this up was a nightmare. You had to fiddle with port forwarding on your router, sign up for dynamic DNS services, or run complex CLI tunneling tools like Cloudflare Tunnels or ngrok. It took hours of debugging terminal commands and exposed your home PC to the open internet.

I got tired of the friction, so I decided to fix it.

A common question is: “Wait, do I need to download a heavy native desktop client to do this?”

No. Abolitus runs entirely inside your browser. You can even install it as an offline-first PWA (Progressive Web App) on both your desktop and smartphone.

Because the client runs client-side in the browser sandbox, we built the tunneling layer to coordinate directly through the browser.

With zero configuration, you can pair your desktop PWA to your mobile phone in seconds. Under the hood, the session is coordinated and relayed through our central server. But just like our cloud sync, every byte of this traffic is end-to-end encrypted (E2EE). Our server acts as a dumb, blind proxy to bridge your devices—it possesses zero ability to decrypt or inspect the prompts and response tokens traveling between your desktop and phone.

You get to leverage the raw power of your local gaming PC’s LLM from your couch, phone, or tablet with zero setup, all while keeping your data strictly inside your personal encrypted envelope.


8. UI/UX: Power Without the Homework

Open-source local clients like SillyTavern are legendary projects. The community is brilliant, the feature set is vast, and they paved the way for local AI.

But getting them running feels like configuring a Linux system. You have to install Node, download extension systems, hunt for character card v2/v3 converters, and wire up third-party TTS servers. It is a lot of homework.

Abolitus was built for the user who wants power without the friction.

We built in everything natively:

  • Character Card Portability: Native support for SillyTavern character cards out of the box.
  • Intelligent Gestures: Swipe navigation to cycle model responses.
  • Built-in TTS & Extensions: Integrated text-to-speech engines that work immediately.
  • Brutalist Design System: No messy layouts, no cheap gradients, and no unnecessary bloat. A sharp, dark-themed, ultra-premium interface built for focus.

The Blunt Conclusion

We built Abolitus to prove that you do not have to trade your privacy for intelligence. You should never have to let big tech companies catalog your private thoughts to enjoy state-of-the-art AI—especially in an ecosystem flooded with generic chatbot wrappers.

We built a premium, fast, zero-knowledge sanctuary.

If you want an AI client that treats your thoughts as your property, welcome to the other side.

Ready to reclaim your private chats? Start running today at Abolitus.