Peer-to-peer group chat that routes all traffic through the Tor network.
No accounts. No logs. No persistent keys. When the session ends, nothing remains.
Every architectural decision in Haze is made to protect your identity and communications.
No usernames stored, no accounts, no registration. Your identity exists only for the duration of a session.
All traffic enters and exits through the Tor network via ephemeral hidden services. Your IP is never revealed.
X25519 ECDH key exchange, ChaCha20-Poly1305 cipher, HKDF-SHA256 key derivation with per-message nonces.
Session keys are generated fresh each run and never written to disk. When the session ends, nothing persists.
One click wipes session keys, terminates all connections, and forces immediate exit via os._exit(0) — bypassing all cleanup handlers.
English and Turkish interface support. Native desktop UI with animated Tor circuit visualizer.
Anonymous peer-to-peer communication through layered encryption and Tor routing.
The host launches a Tor ephemeral hidden service. A .onion address appears in the title bar — share it through a separate secure channel.
Each client performs a one-pass X25519 key exchange. The session key is wrapped under a per-connection derived key — plaintext keys never appear on the wire.
All messages are encrypted with ChaCha20-Poly1305 using per-message random 12-byte nonces and framed with a 4-byte length prefix.
When the session ends, the ephemeral hidden service is removed, keys are wiped, and the Tor data directory is deleted. No trace.
A rigorous security model with cryptographic guarantees at each level.
| Property | Implementation | Status |
|---|---|---|
| Transport Anonymity | Tor onion routing; client IP never revealed to host | Verified |
| Message Confidentiality | ChaCha20-Poly1305 with per-message nonces | Verified |
| Forward Secrecy | Ephemeral session keys; new key per session | Verified |
| Key Exchange | X25519 ECDH with HKDF-SHA256 derivation | Verified |
| Persistent Storage | None — no database, no files, no cookies | Zero |
| Panic Wipe | os._exit(0) — bypasses all Python cleanup handlers |
Verified |
| Hidden Service Key | Never written to disk; held in Tor process memory only | Verified |
Desktop app and mobile client. Every pixel designed for operational security.
Choose to host a new session or join an existing one with a .onion address.
Real-time group messaging with OLED-black interface. Panic button always within reach.
Animated circuit diagram showing real-time Tor routing status and encryption parameters.
Full-featured mobile client with the same zero-identity architecture.
Connect to an existing session or host a new one — all routed through Tor.
Real-time group messaging with a dark mobile interface. Panic button at the ready.
Animated Tor circuit visualizer showing real-time routing and encryption details.
Install Haze on your preferred platform — Linux desktop or Android mobile.
paru -S haze
yay -S haze
Available on the Arch User Repository (AUR). Dependencies including Tor are installed automatically.
# Install Tor
sudo apt install tor
# Clone and install Haze
git clone https://github.com/berk-kucuk/Haze
cd haze
bash installer/install.sh
# Install Tor
sudo dnf install tor
# Clone and install Haze
git clone https://github.com/berk-kucuk/Haze
cd haze
bash installer/install.sh
# Create virtual environment
python -m venv .venv
source .venv/bin/activate
# Install dependencies
pip install -e .
# Launch
haze
Full-featured mobile client. Tor bundled, zero config. Requires Android 8.0+.
Verify your download with the SHA-256 checksum from the GitHub releases page.
Haze is provided for research and educational purposes. It demonstrates privacy-preserving communication techniques. Tor provides strong anonymity at the network layer but does not protect against endpoint compromise, a malicious host, or physical device access. Users are responsible for understanding the legal implications of using anonymity tools in their jurisdiction.