SMarTrTalk, ein Messenger, der niemanden kennt

SMarTrTalk ist ein Android-Messenger, in dem Kontakte ausschließlich dadurch entstehen, dass zwei Menschen ihre Telefone zusammenhalten. Keine Telefonnummer …

SMarTrTalk, a messenger that knows nobody

SMarTrTalk is an Android messenger where contacts come into being only when two people hold their phones together. No phone number, no address book, no …

SMarTrTalk ist ein Android-Messenger, in dem Kontakte ausschließlich dadurch entstehen, dass zwei Menschen ihre Telefone zusammenhalten. Keine Telefonnummer, kein Adressbuch, keine Suche nach Menschen, kein Standort. Die erste Beta ist da.

Titelbild SMarTrTalk: Wortmarke, der Satz Ein Messenger, der niemanden kennt, und ein QR-Punktraster in Firmenblau

Die Sache in einem Absatz

Jeder Messenger, den du kennst, will zuerst wissen, wer du bist. Eine Telefonnummer, eine Mailadresse, am liebsten gleich dein ganzes Adressbuch. Aus diesen Daten entsteht das, was dich am Ende verwundbar macht: eine Karte deiner Beziehungen, die jemand anderem gehört. SMarTrTalk geht den umgekehrten Weg. Es fragt nichts. Es kennt dich nicht, und es kennt deine Kontakte nicht. Wer sich schreiben will, hält einmal die Telefone zusammen und scannt den Code des anderen direkt vom Bildschirm.

Warum der Scan

Weil Anwesenheit sich nicht fälschen lässt. Der Code auf dem Bildschirm erneuert sich jede Minute und trägt eine frische Zufallszahl. Ein Foto davon ist nach kurzer Zeit wertlos, ein Ausdruck sowieso. Es gibt keinen Link zum Weiterschicken und keinen Import aus der Galerie. Der Regelweg hinein führt darüber, dass zwei Menschen im selben Raum stehen.

Weil dann niemand dazwischen passt. Beim Scan macht deine Kamera ein Bild und legt es verschlüsselt ab, versiegelt mit einem Schlüssel, der das Telefon nie verlässt. Dieses Bild ist der Kontakteintrag. Später kommt jeder Schlüssel, mit dem geprüft wird, aus deinem eigenen Bestand, nie aus einer eingehenden Nachricht. Der Server kann darum niemanden unterschieben.

Weil der Server nichts wissen soll. Er sieht Postfach-Kennungen, Signaturen und verschlüsselte Pakete. Er weiß nicht, wer mit wem redet, wie die Gruppen heißen oder wer in ihnen ist. Gruppen leben vollständig auf den Geräten; jede Verwaltungsaktion reist einzeln signiert über die normalen Kanäle.

Was diese Beta kann

Schreiben, Ende zu Ende. Der Chat läuft über das Signal-Protokoll, also über dieselbe geprüfte Bibliothek, die auch Signal selbst verwendet. Wir bauen keine eigene Verschlüsselung, niemals. Der Sitzungsaufbau nutzt zusätzlich ein Kyber-Verfahren, damit auch jemand, der heute mitschneidet und in vielen Jahren einen Quantenrechner hat, nichts davon hat.

Einladen, ohne den Scan aufzuweichen. Du kannst jemandem aus deiner Liste eine Einladung schicken. Diese Person zeigt sie auf ihrem Bildschirm, und die dritte Person scannt sie live. Die Einladung gilt einmal und 72 Stunden. Auch hier steht am Ende ein Scan, nur eben nicht deiner.

Gruppen, die dem Server verborgen bleiben. Wer einladen darf, entscheidet ihr bei der Gründung. Ein berechtigtes Mitglied zeigt einen Gruppen-Code, das Gegenüber scannt ihn und ist drin. Auch dieser Code ist an genau den Bildschirm gebunden, der ihn gezeigt hat.

Schreiben in Gruppen nur, wenn beide wollen. Zwei Menschen, die sich nur aus einer Gruppe kennen, können einander nicht einfach anschreiben. Es gibt eine Anfrage ohne Freitextfeld, und erst wenn beide zugestimmt haben, entsteht ein Kontakt. Sagt jemand nein, erfährt die andere Seite nur, dass die Anfrage nicht mehr offen ist, und sieben Tage lang kommt keine neue durch. Ein Nein soll ein Nein bleiben dürfen, ohne Erklärung.

Und ein Weg für alle, die sich nicht treffen können. Es gibt genau eine Ausnahme von der Scan-Regel, und wir sagen offen, was sie kostet: die Einladungskarte. Du kannst sie verschicken oder ausdrucken, einmal gültig oder dauerhaft. Wer sie in die Hand bekommt, kann sie einlösen, auch wenn sie nicht für ihn gedacht war. Deshalb hat jede Karte eine Frist und eine Höchstzahl, deshalb fragt dich deine App vor jedem neuen Kontakt, und deshalb bleibt ein so entstandener Kontakt dauerhaft als solcher gekennzeichnet. Wer die Karte nicht braucht, merkt nichts von ihr.

Alles verschlossen auf dem Gerät. Die Datenbank ist mit AES-256 verschlüsselt, Dateien liegen in einem eigenen Tresor mit einem Schlüssel je Datei. Davor liegt eine PIN, deren Wartezeit sich bei jedem Fehlversuch verdoppelt, und die App sperrt sich selbst, sobald sie in den Hintergrund geht.

Was die App verlangt

Internet, Netzstatus, Kamera, Biometrie. Das ist die vollständige Liste. Kein Standort, keine Kontakte, kein Speicherzugriff, kein Telefonstatus. Wer das nachprüfen will, kann es nachprüfen: Der Quelltext ist offen.

Ehrlich gesagt

Das hier ist eine Beta, und wir nennen sie so, weil sie eine ist. Sie ist gebaut, automatisiert geprüft und signiert, aber sie ist noch auf keinem Telefon im Alltag gelaufen. Die offenen Punkte stehen in der Testmatrix im Quelltext, nachlesbar, ohne dass jemand nachfragen muss.

Es fehlt auch noch etwas. Gruppen-Chat gibt es noch nicht; die Verwaltung steht vollständig, die Nachrichten folgen. Anrufe und Dateien im Chat kommen später. Guthaben aufladen geht noch nicht, deshalb starten Beta-Installationen mit einem großzügigen Startguthaben, und Empfangen kostet grundsätzlich nichts.

Und der ehrlichste Satz zuletzt: Ein Messenger, der beim Einrichten verlangt, dass ihr euch trefft, ist unbequemer als einer, der einfach dein Adressbuch liest. Genau das ist der Punkt. Wer Bequemlichkeit sucht, ist woanders besser aufgehoben, und das sagen wir lieber vorher.

Ausprobieren

Die Beta kommt als Datei, nicht aus dem Play Store. Dein Telefon fragt beim ersten Mal nach, ob es aus dieser Quelle installieren darf, und das ist richtig so. Neben der Datei liegt eine Prüfsumme; wer sie nicht vergleicht, hat die Datei nicht geprüft. Beim ersten Start gibt es kein Konto und keine Anmeldung, die Identität entsteht auf dem Gerät.

Wo es die Datei gibt und was sich mit jeder Fassung ändert, steht in unserem Kanal t.me/smartragents. Sicherheitsbefunde bitte an [email protected] statt in ein öffentliches Ticket, damit wir sie erst schließen und dann darüber reden.


SMarTrTalk ist ein Projekt von smartragents.ai. Quelltext offen unter MIT.

Impressum · Datenschutz · AGB · Widerruf

SMarTrTalk is an Android messenger where contacts come into being only when two people hold their phones together. No phone number, no address book, no people search, no location. The first beta is out.

Cover image SMarTrTalk: wordmark, the line a messenger that knows nobody, and a QR dot pattern in brand blue

The short version

Every messenger you know wants to know who you are first. A phone number, an email address, ideally your whole address book. Out of that data grows the thing that makes you vulnerable in the end: a map of your relationships that belongs to somebody else. SMarTrTalk goes the other way. It asks for nothing. It does not know you and it does not know your contacts. Two people who want to write to each other hold their phones together once and scan the other code straight off the screen.

Why the scan

Because being there cannot be faked. The code on screen refreshes every minute and carries fresh randomness. A photo of it is worthless shortly after, a printout even more so. There is no link to forward and no import from the gallery. The regular way in runs through two people standing in the same room.

Because then nobody fits in between. During the scan your camera takes a picture and stores it encrypted, sealed with a key that never leaves the phone. That picture is the contact entry. From then on every key used for checking comes from your own records, never from an incoming message. The server therefore cannot slip anyone in.

Because the server is meant to know nothing. It sees mailbox identifiers, signatures and encrypted packets. It does not know who talks to whom, what the groups are called or who is in them. Groups live entirely on the devices; every administrative action travels individually signed over the ordinary channels.

What this beta does

Writing, end to end. The chat runs on the Signal protocol, the same audited library Signal itself uses. We do not build our own encryption, ever. The session setup adds a Kyber scheme, so that anyone recording today and holding a quantum computer in many years still gets nothing out of it.

Inviting without softening the scan. You can send an invitation to someone on your list. That person shows it on their screen, and the third person scans it live. The invitation is valid once and for 72 hours. Here too there is a scan at the end, just not yours.

Groups the server cannot see. Who may invite is decided when the group is founded. A permitted member shows a group code, the other person scans it and is in. That code too is bound to exactly the screen that displayed it.

Writing in groups only if both want it. Two people who know each other only from a group cannot simply message one another. There is a request with no free text field, and a contact comes into being only once both have agreed. If somebody says no, the other side only learns that the request is no longer open, and for seven days no new one gets through. A no should be allowed to stay a no, without an explanation.

And one way for people who cannot meet. There is exactly one exception to the scan rule, and we say plainly what it costs: the invitation card. You can send it or print it, valid once or ongoing. Anyone who gets hold of it can redeem it, even if it was not meant for them. That is why every card has an expiry and a limit, why your app asks you before every new contact, and why a contact made this way stays marked as such. If you do not need the card, you will never notice it.

Everything locked on the device. The database is encrypted with AES-256, files sit in their own vault with one key per file. In front of that is a PIN whose waiting time doubles with every wrong attempt, and the app locks itself as soon as it goes to the background.

What the app asks for

Internet, network state, camera, biometrics. That is the complete list. No location, no contacts, no storage access, no phone state. Anyone who wants to verify that can verify it: the source is open.

Honestly

This is a beta, and we call it that because it is one. It is built, checked by automated tests and signed, but it has not yet run a day on a real phone. The open items are listed in the test matrix in the source, readable without anyone having to ask.

Things are missing, too. There is no group chat yet; the administration is complete, the messages follow. Calls and files in chat come later. Topping up credit is not possible yet, which is why beta installations start with a generous balance, and receiving never costs anything.

And the most honest sentence last: a messenger that asks you to meet in person before you can write is less convenient than one that just reads your address book. That is precisely the point. Anyone looking for convenience is better served elsewhere, and we would rather say so up front.

Trying it

The beta comes as a file, not from the Play Store. Your phone asks the first time whether it may install from this source, and that is exactly right. Next to the file there is a checksum; anyone who does not compare it has not checked the file. On first start there is no account and no sign-in, the identity is created on the device.

Where to get the file and what changes with each build is posted in our channel t.me/smartragents. Security findings go to [email protected] rather than into a public ticket, so we can close them first and talk afterwards.


SMarTrTalk is a project by smartragents.ai. Source open under MIT.

Imprint · Privacy · Terms · Right of withdrawal