Prototypes ZibaldoneP26 · Zibaldone chat
Opening the chatThe messages are decrypted on this device with the key in the link.

↵ to send, ⇧↵ for a new line

New channel

Lower case letters, numbers and dashes.

Members
New message

Choose one person for a direct message, or more for a group.

Settings

Writing

Send withEnter sends and ⇧Enter makes a new line, or ⌘Enter sends and Enter makes a new line.
DensityHow close the messages sit.

Privacy

Read receiptsOthers see when you have read their messages, and you see when they have read yours. Off, neither side sees it.
Link previewsWhen you send an address, your device asks this site’s Worker for the page’s title, text and picture, and they go in the signed message, so the readers never contact the site. The Worker sees the address at that moment and keeps nothing. Off, messages go without a preview.

Devices

Notifications

SoundA short sound when a message comes in another conversation.
Desktop notificationsThe browser asks first. A muted conversation only notifies when it mentions you.

Your status

StatusThe others see it beside your name.
Link a device

The new browser shows it when it opens the chat under your name.

Link this browser
Keyboard shortcuts
Message info
Remove from the workspace

Share a document

These are your documents in Writing on this device. The link to the document, with its key, goes inside the encrypted message, so only the people in this conversation can open it.

Show it

Live shows the document as it is now, and follows its edits while the chat is open.

Forward a message
↑↓ to move↵ to openEsc to close
How Zibaldone is built
  1. Channels, direct messages, threads, reactions, pins and who has read what are one Yjs document, encrypted in the browser with AES-GCM and a key that is only in the link after the #. P14’s relay keeps and passes on the ciphertext and cannot read a message; it sees the name each device connects with. Everyone with the link can decrypt the whole workspace: a direct message is left out of the others’ lists and is encrypted with the same key as the rest.
  2. Each device makes its own Ed25519 key in the browser and signs every message, edit, deletion and reaction. The other side checks the signature and keeps the first key it sees for each name. A message under someone’s name with another key is shown struck through with a warning, a line in the conversation shows that the key changed, and a message changed after it was signed is marked the same way. The sample history is signed with keys made for it and thrown away, which Message info shows.
  3. A person can use several browsers. Each person’s devices are signed records in the document: the first device signs its own record, and a device counts only when a device that already counts for the same name signed its record. A new browser under a name that has devices shows a code of eight digits and a QR code of a link with the code in it. On a browser that counts, Settings, Devices, Link a device takes the code; the request and the answer travel in the encrypted document, both screens show 15 digits made from both keys and the code, and when the person confirms, the old browser signs the record. Settings lists the devices with names guessed from the browser, and Remove signs a removal that lists the ids of what the device had sent, as the removing browser holds them; afterwards a message from that key counts only when its id is in the list, whatever time it claims, and Message info shows why one is marked. Message info names the device that signed a message.
  4. Zibaldone’s safety number (SHA-512 iterated 5,200 times, 60 digits) is made from each person’s first device, so linking another device does not change it. It is shown for each pair of people in Details with the number of devices, and a switch marks it verified once the digits have been compared.
  5. Messages from one person within five minutes are grouped, with dividers for each day and one New line where you left off. Jump to latest counts what came below. Text can be bold, italic, struck, code, a code block, a quote or a list; addresses become links and @names and #channels are marked. The text is escaped before it is shown, so markup in a message shows as text.
  6. The message box grows with the text. @ suggests people, # channels and the work (a paragraph of P23’s brief or a task of P24’s plan), : emoji, and / the commands /topic, /mute, /unmute and /remind me. Drafts are kept on the device for each conversation and thread. ↑ in an empty box edits your last message. For five seconds after sending, Undo takes the message back before it leaves the device. A scheduled message is signed on the device, made into a Yjs update on a copy of the document with a client id of its own, and sealed with the workspace key. The relay keeps the sealed update with its time, up to 31 days ahead, and a hash of a cancel token, until it is released or taken back; and at that time a Durable Object alarm adds it to the document’s log and passes it to the devices online, so it leaves when the chat is closed too. The device keeps the text, the time and the token, so the Scheduled list can edit and cancel. When the relay does not take it, the message is kept on the device and sent while the chat is open, and the list shows that.
  7. Photos are made smaller in the browser, and files and voice messages are kept in the encrypted document, up to 150 KB each and 450 KB in a workspace, because the relay passes the whole document. Photos chosen together go as one album of up to four tiles with one caption, each made smaller so the album stays under 300 KB. A PDF gets its first page as a small picture, drawn on the sender’s device with P20’s pdf.js (Apache-2.0), which loads only when a PDF is added. The photo viewer moves through every photo in the conversation with the arrows, the keys or a swipe, and has Reply, Forward and Download. Details lists the conversation’s photos by month, its links and its documents.
  8. A voice message is recorded with MediaRecorder: hold the button and let go to send, slide up to lock it and get Stop and Send, slide left to delete; a click starts it locked. The sender works out 40 peaks from the recording with Web Audio and they go with the message, so the others draw them without decoding it. The speed (1×, 1.5×, 2×) is kept on the device. Who has played a voice message is kept in the document beside the read positions, and the sender’s mark turns to the accent color when someone has. Voice messages from others play one after another. The page plays sound from blob: addresses only.
  9. When a message has an address, the sender’s device asks this site’s Worker (/api/p26/unfurl) for the page’s Open Graph and Twitter tags and its title. The Worker sees the address at that moment, reads at most 512 KB for 4 seconds, refuses private and local addresses and any redirect to one, and keeps and logs nothing. The page’s picture comes through the same route and is made small in the browser. Title, text and picture go into the signed message, so the readers never contact the site or the Worker. You can turn previews off in Settings.
  10. A document from Writing (P23) is shared as a card from Writing’s Share menu, the workspace’s Discuss or the attach menu. Its link, with the key, goes only inside the encrypted message. A live card opens the document read only through a second sync with the document’s own key, which keeps nothing on the device, sends no presence and never writes; the relay sees that this device asks for that document’s id. A pinned card shows the document as it was, marked with the time. Open opens it in Writing, in P27’s frame when the chat is in the workspace.
  11. Removing someone from the workspace makes one new key for all of it, as P13 turns its key after a removal. Each device publishes an X25519 key in a record it signs itself. The remover’s device writes a line in each channel and makes a new workspace key. It copies the chat, the writing, the plan and the notes into new documents made from that key, and each Writing document shared in the chat into a new document whose key is made from it with HKDF. Then it writes one record, signed with its Ed25519 key, into every old document, with an envelope for each remaining device: a key pair made for it, X25519 with the device’s key, HKDF-SHA-256 bound to both chat document ids and the device, and AES-GCM. Each tool reads the record from its own document, on the workspace’s page or its own, opens this device’s envelope, checks that the key makes the named document id, and moves, with its place. The new documents are made by applying the old documents’ Yjs state, so they hold the same items: a device that moves applies the items its own Yjs client ids (kept on the device for each document) inserted that the new document lacks, so its edits made after the copy, offline or before it saw the change, merge once, and nothing the removed person writes or deletes in the old documents reaches the new ones. Yjs cannot say who deleted something, so no deletion is carried: text deleted offline during the change stays in the new document. Edits that waited on a device while it was offline are not sent to the old document once its log shows the change. The removed person keeps what they had, cannot decrypt anything written after, and each tool says who removed them. A device that never published an X25519 key gets no envelope and must be linked again.
  12. Held messages move with the key. The remover’s device takes its held messages back from the old chat document and holds them again for the new one, at the same time. A device marks the old chat document moved by sending the whole SHA-256 of the prefix and the old key, whose first half is the document id. The relay checks it against a hash of that value, which the first device to open the document left when it connected, so only someone with the key can mark a document. The relay sends nothing more into a moved chat document, so a held message of another person waits until that person’s device opens the chat; the device then does the same, and its Scheduled list shows that until it has.
  13. On a phone, a message swiped right is quoted in a reply, with the reply icon under the finger and a short vibration; a long press opens the reactions and the menu together; a conversation swiped left shows Archive and More, and swiped right is marked read or unread. These read pointer events from touch and pen; a mouse keeps the hover tools and the right click.
  14. A thread opens beside the conversation, and a reply can also go to the conversation. In a channel or a group, Reply privately opens the direct conversation with the sender and quotes the message. Reactions are signed like messages. A message can be pinned for everyone, saved for yourself, forwarded, quoted, edited (the earlier versions are kept) and deleted for everyone or only for you. Turn into a task sends it to P24’s plan when the chat is open in P27’s workspace.
  15. Who is here and who is typing go through Yjs awareness, encrypted the same way. Each person’s delivered and read positions are kept in the document, and read receipts can be turned off, for both sides.
  16. A conversation can end new messages after 1, 7 or 30 days. Each message has its end time in its signed record, and the first device to see it past that time takes it out of the document, where Yjs drops its content.
  17. Zibaldone’s key ring and relay, and Wire’s servers. Wire’s own mention parser and disappearing-message resolver (RAMTT’s wire-core) are bundled from the source.