Hush 2
Private, local-first chat at https://hush.maculab.dev. Source: https://maculab.dev/admin/hush.
Community forum: public questions, project sharing, and discussions about Maculab, Hush, and HushAnon. Use a Maculab account to post. The Community forum link inside Hush preserves your current web, Tor, or I2P network.
HushAnon: https://hushanon.maculab.dev uses a random account key instead of Maculab sign-in, with a separate public @handle that changes every 30 minutes. Existing chats and the account key keep working. Both editions share the same encryption and device approval. Tor and I2P addresses and setup are available for Maculab, Hush, and HushAnon.
Find a friend by @username, accept the invitation, and chat through an encrypted relay. Hush reconnects automatically while the tab stays unlocked and queues ciphertext when a recipient is offline. Readable history lives in each device's encrypted browser storage.
- Proteus Double Ratchet direct messages and MLS private groups (2–10 people).
- Independent device keys, signed device approval, revocation and safety numbers.
- Four-day direct-message session renewal plus per-message ratcheting; group refreshes use the controller device.
- Replies, reactions, edits, deletion requests, local search, @mentions and encrypted files up to 8 MiB each.
- Passkeys, Maculab sign-in, encrypted local vaults, explicit encrypted backup/history transfer.
- Optional presence, typing, receipts and disappearing messages. These sharing options start off.
- VPS relay only: no peer-to-peer connection or WebRTC/ICE. Participants do not receive each other's IP addresses.
- Device-local appearance: light/dark themes, colors, fonts, spacing, sidebar/message widths, avatars, timestamps, wallpaper and theme import/export.
Privacy boundary: the gateway/network provider can see connection IPs and routing metadata. A compromised web host can deliver a malicious client. Hush is an early release with no independent integration audit. Read the threat model and protocol, including group-controller and offline-retention limits.
Layout
Browser: apps/web + packages/crypto
→ HTTPS/WSS gateway (Cloudflare Tunnel + private nginx)
→ apps/server + server (account authentication / encrypted relay)
→ PostgreSQL: metadata + short-lived ciphertext
→ Redis: ephemeral presence / rate limits / challenges
→ private S3-compatible Garage: encrypted attachments
All backend/storage listeners bind loopback on the public VPS. The browser connects only to the Hush origin. Public source does not include production credentials.
Run and test
Requires Node.js 24, PostgreSQL 15+, Redis 7+, and a private S3-compatible bucket (a private local ciphertext spool is available for development). Use npm ci, then copy deploy/messenger.example.json to a protected configuration file outside the repository and set HUSH_MESSENGER_CONFIG to its absolute path. Set HUSH_DATA, HUSH_ORIGIN, HUSH_PORT; optionally HUSH_MACULAB_CONFIG. Never commit those files.
npm ci
npm run build
npm run start:hosted
npm test
For browser/integration tests, use only a separate PostgreSQL database whose name ends in _staging. Set HUSH_TEST_BACKEND_CONFIG to its protected config, install Playwright Chromium (npx playwright install chromium), then run npm run test:browser. The staging fixture binds ports 4184/4186 and uses synthetic users. Relay integration tests skip without a test backend; release validation must run them with a real backend and verify zero skips.
Production units, gateway example and metadata-backup script are in deploy/. Operations describes migration, backups and recovery. Contributing describes review expectations. License: GPL-3.0-only; see third-party notices.
For a separate key-only deployment, set HUSH_ACCOUNT_MODE=key, omit HUSH_MACULAB_CONFIG, and use independent PostgreSQL, Redis and data directories. Set HUSH_ANON_TEST_URL to an isolated key-only staging service to run tests/v2-anonymous.spec.js. See private network operations before enabling alternate origins.