Security
How Qurb protects your files and keys today — and, just as plainly, what it doesn’t protect against yet.
Your key
Each person has one root key: 256 random bits from the operating system, which are your 24-word recovery phrase. Every other key is derived from it, one for each purpose. All your devices hold it; nobody else ever does, so if you lose the words and every device, your files can’t be recovered by anyone.
On a computer you choose how it’s kept: in a file only you can read, in the system keystore, or behind a passphrase. On Android it’s kept in the Android Keystore, where only Qurb on that phone can use it.
Your files
- Between devices, everything is encrypted, over QUIC. Each device has its own certificate, and pairing carries its full fingerprint across the room — by a code you scan or type — so a device only ever talks to devices you added.
- On a device, the files in your Qurb folder are ordinary files, protected the way the rest of your disk is. What Qurb keeps in its own store — copies held for your other devices, the parts of files not in the folder — is compressed and encrypted with XChaCha20-Poly1305.
- Anything a peer sends is checked before it is written: content is named by its BLAKE3 hash and verified against it, and a path that tries to leave the folder or reach Qurb’s own store is refused.
The services
The service that introduces devices across networks learns their network addresses and that they want to meet, under identifiers it can’t link to a person — never a filename, a file or a key. A relay, where one is used, forwards encrypted traffic it cannot read. If you set up push, Google learns that a phone was woken, and when — nothing about why. You run both services yourself; Qurb runs neither.
What it doesn’t protect against yet
- Your devices share one key. A file in one device’s Private Vault is private from devices that don’t hold its bytes, not cryptographically private from one that does.
- Removing a device doesn’t take its key away. It stops being trusted at once, and keeps what it already has. Changing the key is not built yet.
- Nobody outside the project has reviewed it. Everything above is tested, including against hostile peers and crashes, but it has not been audited.
The reasoning behind each of these is written down: keys and recovery, device identity, what the introduction service learns. Found something? Report it privately.