Blog

Sept. 17, 2026

Dead Drop: a note that is read once — even in a browser

A one-time encrypted note behind a link: the key never reaches a server, a chat app's link preview can't burn it, and the recipient doesn't need our app. How it works, and the two things a browser can't promise.

Sept. 17, 2026

The decoy was deniable on day one. We measured day ninety.

Hidden-volume deniability is usually argued at setup. We simulated months of use and attacked our own decoy the way a forensic examiner would — copies of storage and a stopwatch. It failed. Here is what failed, what we changed, what the re-measurement shows, and what is still open.

Sept. 10, 2026

We removed the location lock

YGOOW used to let you seal a message so it only opened near a place. We took the feature out, because reading such a message made your phone ask Google where it was — outside Tor. What we found, why it mattered more than it looked, and what it says about every other feature.

Sept. 10, 2026

Measured, not assumed

Six weeks of measuring our own code on the phone it runs on — timing of every primitive, the size and rhythm of every frame, the strength meter, the backup file. What leaked, what we fixed, what we still haven't, and three claims on this site that the numbers overturned.

July 30, 2026

Post-quantum without a prekey server

Going post-quantum usually means parking one-time keys on a server. Our relay is forbidden from holding anything — so the post-quantum key rides in your identity instead. How YGOOW's X25519 + ML-KEM-768 hybrid works, and what it costs.

June 25, 2026

They broke the metadata, not the cipher: the Ricochet lesson

In 2024 German investigators deanonymised a Ricochet user without breaking Tor or the cipher — they timed the network and made the ISP name the subscriber. The reason it worked, and the one design choice that removes the anchor the attack needed.

June 25, 2026

They broke the content, not the cipher: the EncroChat lesson

In 2020 police read tens of thousands of EncroChat users' messages without breaking the encryption — they owned one central system and harvested everyone at once. Here is what actually happened, and the single architectural choice that turns that dragnet back into per-target work.

June 24, 2026

Encryption was the easy part

The cipher is the solved problem. The leaks live in the margins — the traffic a deaf relay still sees, and the phone someone can take from your hand. Two new defenses: shaped metadata, and a decoy profile for when you're forced to unlock.

June 20, 2026

Why YGOOW won't pick your security for you

Every other messenger chooses a default and hopes you never ask. YGOOW refuses: you pick how each conversation is protected, or you don't chat. Here is why that bluntness is the feature.

June 20, 2026

Five locks, and every one is your choice

A message in YGOOW passes through up to five independent layers — transport, Tor, the end-to-end channel, locked content, and a lifetime. What each one does, in plain terms, and why they are separate on purpose.

June 19, 2026

No oracle: why every locked message looks the same

A wrong key, a missing key, and a message that was never yours all produce the same locked block — no error, no hint, no oracle. How YGOOW's 'Variant C' trial-decryption works, and where it ends.

June 19, 2026

Why we are building YGOOW

Why a twenty-year-old idea — anonymous, account-free data sharing — is finally shipping as an encrypted messenger.

RSS