← Back to this site

MACULAB · HUSH · HUSHANON

Choose your connection.

These addresses reach the same services through Tor or I2P. Chat messages remain end-to-end encrypted. Neither network is a replacement for encryption on your device.

Loading the address directory…

Using Tor

  1. Open Tor Browser and connect to Tor.
  2. Paste the onion address for the site you want. Check that the full address matches this directory.
  3. Hush needs JavaScript and WebAssembly for encryption. Tor Browser’s Standard security level supports these features.

The onion connection is encrypted and authenticated by Tor, even though its URL begins with HTTP. Use Tor Browser; a regular browser with a SOCKS proxy may not provide the secure browser context Hush needs.

Using I2P

  1. Run an I2P router and configure a dedicated Firefox profile using the official browser instructions. Route both HTTP and HTTPS through your local I2P proxy; disable direct fallback.
  2. Open the HTTPS I2P address. These long, self-authenticating addresses use a site-specific certificate because public certificate authorities do not issue certificates for .i2p names.
  3. Inspect the certificate in the browser’s warning and compare its SHA-256 fingerprint with the value below the site’s address. Obtain this directory through an already trusted connection, such as the normal HTTPS site or its verified onion address.
  4. Only if the fingerprint matches, save an exception for that exact site in your I2P browser profile. Keep HTTPS enabled. Never disable certificate checking globally or install an unknown root certificate.

HTTPS enables the secure browser features Hush uses for local encryption and device coordination. An HTTP-only I2P connection cannot run Hush correctly.

What stays private

Hush and HushAnon keep readable chat history and message keys on your devices. The relay temporarily queues encrypted messages and sees account and routing metadata. Connecting through Tor or I2P hides your direct connection IP from the site; normal HTTPS connections still expose it to the gateway and its hosting provider.

Hush uses your Maculab account. HushAnon uses a randomly generated account key, with separate accounts and no email address. Save that key privately: there is no email reset. An account key does not recover lost local message history.

Each web, Tor, and I2P address has separate browser storage. Changing addresses creates a new device session; approve it from an existing trusted device. Your local appearance settings and history do not automatically move between addresses. Logging into the same account still links those sessions to that account.

These are alternative routes to the services on our VPS. They are not a VPN, and they do not hide account relationships from the service. Network delays can be longer; Hush reconnects automatically while the tab is open.