A chat app with MTProto 2.0-style message encryption on the server and an end-to-end encrypted secret chat in the browser.
The goal was to build the message-protection pieces of Telegram's MTProto 2.0 by hand inside a working chat app, instead of calling a library that hides them: message keys, key derivation, per-message metadata and an end-to-end encrypted secret chat.
Accounts
Sign-up and login with one-time codes by SMS or email, stored through SQLAlchemy with migrations.
Keys and message metadata
Each user gets a 256-byte auth key, and every message carries a random salt, session ID, message ID and sequence number.
Message key and KDF
The message key is taken from a SHA-256 hash of the auth key and the payload, and the AES key and IV come from MTProto 2.0's SHA-256 derivation.
Encryption
AES-256 encrypts each message on the server before it's stored or relayed.
Transport
HTTP routes plus Socket.IO for live messages.
Secret chat
The two browsers run a Diffie-Hellman exchange with a fresh key per chat and encrypt with AES-GCM through WebCrypto. The server only relays public keys.
Writing this up honestly means listing what a real implementation would do differently:
Each of these is a known gap from building it as a course project, and each is where I'd start if I took it further.
Next project
rag-redteamAn open-source scanner that attacks your RAG pipeline for prompt injection and document leakage, and fails CI the moment it gets more exploitable.