You cannot select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
Comrad/README.md

211 lines
10 KiB
Markdown

# Comrad
4 years ago
4 years ago
Comrad is a social*ist* network: encrypted, insurveillable, unmontizeable, and self-governing. Meet fellow comrades and message them securely, organize safely into self-moderated groups, plan demonstrations secretly and spontaneously and help fight back against the police state and surveillance capitalism, both online and off.
4 years ago
4 years ago
## Why another social network?
4 years ago
Is a 'socialist network' possible? Although the internet began with anarchic design principles, it quickly consolidated into the hands of a few of the largest corporations in the world. It has effectively recreated the capitalist mode of production within itself: the means of content production (social media platforms) are privatized while the work of production (posting) remains socially distributed. Exploitation inheres in that relation, whether in the industrial factory or the digital platform, because the value you produce is taken from you, concentrated and privatized.
4 years ago
4 years ago
But a digital network can be redesigned. The technology behind these social media platforms is actually quite simple. We can easily build our own social network, one which is secure, insurveillable, and unmonetizable—one which would give people the security they need to communicate about whatever they want, including protesting against capital and the state.
4 years ago
4 years ago
## Core principles
4 years ago
4 years ago
### Confidential
4 years ago
4 years ago
All of your data are strongly encrypted end-to-end: only you and those you write to can decrypt and read it. To anyone without the right decryption 'key', the data is nonsense.
4 years ago
4 years ago
### Untraceable
4 years ago
All network traffic is routed through Tor, a "deep web" of computers so dense even the FBI can't follow you through it. Comrad's "Operator" or central server is accessible only from Tor. It's impossible to tell who is sending what to whom, or even who is using the app at all.
4 years ago
### Unmonetizable
What's untraceable is also unmonetizable: your data can't be harvested by technology companies and used for advertising algorithms. You're protected from both surveillance capitalism and the surveillance state.
4 years ago
4 years ago
### Democratized
4 years ago
4 years ago
Group accounts or 'collectives', like @portland or @socialists, grow as existing members 'vouch for' new ones, forming webs of trust. In order to join a group, at least one member must vouch for you; this minimum (or 'quorum') may grow as the group grows, or in accordance with a 'constitution' which the group votes upon.
4 years ago
4 years ago
### (Semi-)decentralized
4 years ago
Data is deleted as soon as possible from Comrad. Comrad's "Operator" simply sorts and holds the mail temporarily: as soon as users log in to download their mail, the messages are deleted from the server and network forever.
4 years ago
4 years ago
### Open-source
Information wants to be communist.
4 years ago
### Anti-profit
4 years ago
4 years ago
Not just non-profit, we're anti-profit.
4 years ago
4 years ago
4 years ago
## Social media features
4 years ago
4 years ago
We present a simplified set of social media features drawn from everything that's out there:
4 years ago
4 years ago
#### Profile
4 years ago
* Curate a profile with photo and posts (~Twitter)
* Show profile to world (~Twitter)
* Show profile only to those you trust (~Facebook)
4 years ago
4 years ago
#### Posting
* Post up to 1 image and/or 1000 characters
4 years ago
* Post to the entire world (~Twitter) ✔
* Post to those you trust (~Facebook)
* Post to self-moderating groups (~Facebook)
* Anonymously up-vote or down-vote posts (~Reddit)
* Post with encrypted data over untraceable connection (~new?) ✔
4 years ago
4 years ago
#### Organizing
4 years ago
* Host events and invite others (~Facebook)
* Host events like protests anonymously (~new?)
* Anonymously pin on a map sites of danger, like police (~Waze)
4 years ago
4 years ago
#### Messaging
4 years ago
* Message securely with encrypted contents (~Signal) ✔
* Message over untraceable connection (~[Briar](https://briarproject.org/)/new?) ✔
4 years ago
## How is this different from ...?
4 years ago
See ["Comparison of alternative social networks" on the wiki](https://github.com/ComradOrg/Comrad/wiki/Comparison-of-alternative-social-networks) for an attempt at a systematic comparison. (And please help edit, if you can! The data there is a little incomplete and probably a little inaccurate.) But here are some imagined differences:
4 years ago
* **It's not (fully) decentralized.** Who's afraid of a little central planning? In contrast to [Secure Scuttlebutt](https://scuttlebutt.nz/) and [Cabal Chat](https://cabal.chat/), which are 100% decentralized, subsisting only through peer-to-peer connections, Comrad sticks with the old, client/server model. Why?
4 years ago
4 years ago
* **It *is* anonymous.** Because P2P networks almost always expose your IP address: they privilege decentralization over anonymity -- and, potentially, safety. By contrast, lying hidden within the deep web of Tor, accessible only from this application and its built-in Tor client, Comrad will never reveal who is accessing it and its encrypted information. This is important for comrades organizing protests against the surveillance state, and to protect our social media traffic from being harvested and monetized by surveillance capitalism.
4 years ago
4 years ago
* **It's 100% end-to-end encrypted.** Unlike [Mastodon](https://joinmastodon.org/) or [Diaspora](https://diasporafoundation.org/), direct messages between users and within groups remain encrypted 1:1 end-to-end among users. Posts to the public are encrypted to @Comrades, a special account which automatically re-encrypts its messages back to any key-registered requester of them.
4 years ago
4 years ago
* **It verifies identities.** Comrad's server, "The Operator", keeps a permanent record of one thing only: every comrad's name and public key, and requires that new comrades choose a unique name. Whenever you send or receive mail, the Operator will make sure that the name and public key on the letter matches what it has on file, verifying the identity of both parties.
4 years ago
4 years ago
* **It's (semi-)ephemeral.** Data, like all natural things, should not last forever. Direct messages auto-delete from the server as soon as they are downloaded. Group messages are sent as direct messages through the "web of trust" of the group membership network. Posts to the world auto-delete in however many days you specify. By contrast, data on both [SSB](https://scuttlebutt.nz/) and [Matrix](https://matrix.org/) is undeletable.
4 years ago
4 years ago
* **It's easy to use.** No invitation or server is needed on startup, unlike [SSB](https://scuttlebutt.nz/), [Mastodon](https://joinmastodon.org/), [Diaspora](https://diasporafoundation.org/), or [Briar](https://briarproject.org/). It's basically a Twitter clone, but one where you can also post to a universal feed shared by the entire world (@Comrades), so that you can make yourself known, participate in general discussions, find new contacts, and organize new groups.
4 years ago
4 years ago
## Progress
4 years ago
### Animations from mobile/desktop app
4 years ago
4 years ago
#### Registering and connecting through Tor
<img src="comrad/app/assets/comrad-screen-preview-2020-09-27.gif" alt="GIF animation" height="600" />
4 years ago
#### Navigating posts
<img src="comrad/app/assets/comrad-screen-preview-2020-08-23.gif" alt="GIF animation" height="600" />
4 years ago
### Animations from terminal app
#### Connecting through Tor
<img src="comrad/app/assets/comrad-terminal-preview--2020-09-20--tor.gif" alt="GIF animation of Tor connection" />
4 years ago
#### "Meeting" (exchanging public keys)
<img src="comrad/app/assets/comrad-terminal-preview--2020-09-16--meet.gif" alt="GIF animation of meeting process" />
4 years ago
#### Messaging
<img src="comrad/app/assets/comrad-terminal-preview--2020-09-16--msg.gif" alt="GIF animation of messaging" />
4 years ago
### Posting
<img src="comrad/app/assets/comrad-terminal-preview--2020-09-19--posting.gif" alt="GIF animation of posting" />
4 years ago
4 years ago
4 years ago
## Usage
4 years ago
4 years ago
### Install
4 years ago
4 years ago
#### ...on Mac OSX
4 years ago
4 years ago
Download and run [this installer](https://github.com/ComradOrg/Comrad/raw/master/script/InstallComrad.app.zip).
4 years ago
4 years ago
#### ...on Linux
4 years ago
4 years ago
Open a terminal in Linux, and copy and paste the following line into it:
4 years ago
```
bash <(curl -s https://comrad.app/run)
4 years ago
```
4 years ago
[That](https://comrad.app/run)'s a shortcut to [this auto-installer script](https://github.com/ComradOrg/Comrad/blob/master/script/install). It installs Comrad in a virtual Python environment in the folder "comrad" in your home directory.
4 years ago
4 years ago
#### ...on Windows
4 years ago
Unfortunately, Windows is not yet supported. We tried and tried, but cannot get everything to install correctly on either Mingw64 or Cygwin; and we also haven't yet been able to package a complete binary release with pyinstaller. If you are a developer, please lend a hand to support Windows. The current attempt at a windows installation is located [here](https://github.com/ComradOrg/Comrad/blob/master/script/install-windows.sh).
4 years ago
4 years ago
### Run
4 years ago
4 years ago
#### ...on Mac OSX
4 years ago
4 years ago
Install [as above](#on-mac-osx).
4 years ago
Run "Comrad.app" in your Applications folder.
4 years ago
4 years ago
#### ...on Linux
4 years ago
4 years ago
Open a terminal in Linux, and type:
4 years ago
```
comrad-app
4 years ago
```
4 years ago
If that doesn't work, try:
```
~/comrad/code/bin/comrad-app
4 years ago
```
#### Running terminal client
4 years ago
For the terminal client (which may be broken at the moment), run:
```
comrad-cli # or: ~/comrad/code/bin/comrad-cli
4 years ago
```
#### Running server (development only)
To run The Operator server (for development purposes only), run:
```
comrad-op # or: ~/comrad/code/bin/comrad-op
4 years ago
```
4 years ago
## Details
4 years ago
4 years ago
### Frontend
4 years ago
4 years ago
#### Mobile/desktop
4 years ago
The mobile/desktop app is made with [KivyMD](https://github.com/kivymd/KivyMD), a variant of [Kivy](https://kivy.org/), a cross-platform app development framework in Python. Python is an easy and versatile progamming language to learn, which keeps the code accessible to as many people as possible. Code for the app is in [comrad/app](comrad/app).
4 years ago
4 years ago
#### Terminal app
4 years ago
Vanilla Python. Code is in [comrad/cli](comrad/cli).
4 years ago
### Backend
4 years ago
#### API
4 years ago
Plain old object-oriented code in Python. The root entity is a "Keymaker": anyone from @Telephone, to @Operator, to users, to groups, who has a public/private key pair. The database uses a simple file-based key-value store using the Redis protocol: [rlite](https://github.com/seppo0010/rlite), via its [rlite-py](https://github.com/seppo0010/rlite-py) Python bindings. All code for backend/API is in [comrad/backend](comrad/backend).
4 years ago
#### Cryptography
4 years ago
We are using [Themis](https://github.com/cossacklabs/themis), a high-level cross-platform cryptography library, for all cryptographic functions, rather than handling any primitives ourselves. Installing it from packages is tricky, so right now the [auto-installer](#install) builds it from sources.
4 years ago
4 years ago
Crypto-related code is primarily in:
4 years ago
* [comrad/backend/keymaker.py](comrad/backend/keymaker.py)
4 years ago
4 years ago
* [comrad/backend/comrades.py](comrad/backend/comrades.py)
4 years ago
* [comrad/backend/phonelines.py](comrad/backend/phonelines.py)
4 years ago