Three things you can check in TACENZA Chat yourself
TACENZA Chat's code isn't open source, so here are three things you can check yourself – the app's hash, where it connects, and safety numbers.
TACENZA Chat encrypts everything on your device before it’s sent. But a web app is code the server hands you every time you open it, and our code isn’t open source. So you shouldn’t have to take our word for what it does. This post covers three things you can check on your own: that everyone gets the same app, that it talks to nobody else, and that nobody is in the middle of your conversations.
Everyone gets the same app
The risk with any web app is that the server could quietly give one person different code from everyone else. To make that visible, every release of the TACENZA web app is recorded with the SHA-256 hash of its JavaScript.
- Where the record lives. The hashes are published in tacenza/releases on GitHub, kept apart from the servers that run TACENZA.
- Who publishes it. Our build pipeline publishes it automatically, after all tests pass, from the same build that gets deployed.
- What it means. If the code at chat.tacenza.app ever changed without a release, the hashes there would no longer match.
Check it yourself
-
Open the latest release and note the hash and file name in
bundle-hash.txt. -
Hash the file chat.tacenza.app serves you:
curl -s https://chat.tacenza.app/assets/<file from bundle-hash.txt> | sha256sum -
Compare the two. They should be identical. The same steps are on our security page.
The Windows app loads the same code, so the same hash applies there.
If the hashes don’t match, please tell us. How to reach us is in security.txt.
For a step-by-step version, see Verify the app in the docs.
Nothing goes to anyone else
TACENZA makes no requests to anyone but itself. There are no analytics, fonts or scripts from third parties – the fonts are hosted by us too.
You can see this for yourself:
- Open your browser’s developer tools and go to the Network tab.
- Use TACENZA as you normally would: open chats, send a message, look at a profile.
- Look at where each request goes. Every one goes to TACENZA itself.
There are two exceptions, and both are off until you turn them on. Push notifications go through your browser maker’s push service, and the notice is encrypted and has no content. Email notifications are sent through a mail provider, and only say you have new messages. The Privacy Policy says exactly what each one reveals.
Nobody is in the middle
End-to-end encryption only protects you if your messages are encrypted to the right people. If someone could swap in their own keys, they could read along. Safety numbers let you check.
- Compare safety numbers with the people you write to, in person or on a call. Every contact has one.
- If they match, your messages are encrypted to them and nobody else.
- If someone’s keys ever change, the chat locks until you’ve checked again.
This is the check that doesn’t depend on us at all.
What these checks don’t cover
Being honest about limits matters as much as the checks themselves.
- The hash tells you that you got the same code as everyone else. It doesn’t tell you what that code does. Without open source code, you can’t read it for yourself.
- A web page can’t block screenshots. The desktop app can, so by default protected chats can only be read there.
- The server knows who is in which group, because it has to enforce roles and permissions. It can’t read names, messages or profiles.
- Forward secrecy isn’t there yet. The Signal protocol and MLS are planned for after 1.0. Until then, groups get a new key after 50 messages and on every membership change.
We’ll keep adding to what you can check. If you find something that doesn’t match what we say, we want to hear about it.