Une communication éphémère sans boîte de réception permanente.
Un système de communication individuel dans le navigateur, fondé sur des invitations brèves, un WebRTC direct vérifié et des états de repli explicites.
- Publié
- Mis à jour
Périmètre du projet
ACTUEL / PRODUIT EXPÉRIMENTAL
Product and protocol engineering
- Session model
- Temporary one-to-one invitations
- Preferred path
- Verified direct WebRTC
- Current status
- Experimental; not independently security-certified
Thèmes
A private session without a permanent inbox
Orylin starts from a deliberately small product model: create a temporary invitation, bring one peer into the same session, communicate, and let the session expire or be ended. Accounts, contact discovery and server-side conversation history are not the centre of the design.
The smaller lifecycle makes important state visible. Invitation age, peer authentication, directness and expiry are product concepts rather than invisible infrastructure details.
Directness is a user-visible property
The system prefers a verified direct WebRTC path. If that path is unavailable, an explicitly labelled volunteer-browser ciphertext relay may support bounded messaging or file traffic, while the current rescue path is message-only.
Direct, relay and rescue are not synonyms. The interface needs to show which path is active because the path changes latency, availability and the trust story the user is relying on.
Application protection is separate from transport
The current runtime uses invitation-bound material to bootstrap an encrypted application channel with directional AES-GCM keys, counters and replay rejection. The Cloudflare edge coordinates sessions but is not intended to become a conversation mailbox or payload store.
That is a concrete current-product boundary. Future post-quantum and media-security designs remain candidate work until their own providers, vectors, browser paths and review gates are complete.
Security claims have a version boundary
A privacy product is easier to trust when it says exactly which runtime is being described. Current messaging, bounded file transfer and Direct-only voice are separate from future PQ profiles and from stronger claims about anonymity or traffic analysis.
The engineering lesson is simple: do not let a roadmap diagram silently become a production guarantee.
Limite de l'évidence publique
The current runtime should not be described as PQ1, a continuous ratchet, a global-anonymity system or independent security certification. Direct, volunteer-relay and rescue paths are distinct runtime states and must remain labelled as such.
Ces pages publient un périmètre d'ingénierie et un raisonnement vérifiables ; les preuves de projet sont ajoutées lorsqu'elles sont prêtes à être partagées.
Voir tous les projets d'ingénierie