Fixxx
Moder
- Joined
- 20.08.24
- Messages
- 1,195
- Reaction score
- 4,884
- Points
- 113

I want to examine a messenger that few people know about, even though its architecture offers a level of anonymity unattainable by most popular apps - including those commonly considered "secure".
The problem even good messengers don’t solve
Signal encrypts the contents of messages end to end - which is excellent. But Signal’s servers still know who is communicating with whom, when and how often. The metadata remains visible even if the message text cannot be read. Session and similar messengers that do not require a phone number address part of this problem by routing traffic through their own network of nodes, but they still rely on infrastructure - servers and nodes through which the traffic passes. Ricochet Refresh takes things further: it removes the server from the equation entirely.
Architecture: peer-to-peer communication over Tor, with no central server
Instead of sending messages through intermediary infrastructure, Ricochet establishes a direct connection between two people through a Tor onion service. Each Ricochet user effectively becomes their own server in the form of an onion address. The message travels directly from one onion address to another, bypassing any third party. This is fundamentally different from the architecture of any messenger with a centralized server. There is no company that can hand over logs. There is no database containing metadata about who contacted whom. There is no physical point that can be served with a legal request, because there is nothing to seize - the conversation is stored nowhere except on the participant's own devices.
What it looks like in practice
When Ricochet is installed, it generates a unique onion address. This address is your identifier - not a phone number, not an email address and not a username tied to a server, but a cryptographically generated address. To add someone, you exchange onion addresses by any available method (personally or through another secure channel) and add the address to your contacts. When you send a message, the app connects directly to the recipient’s onion address through Tor. If the recipient is offline, the message is not delivered at all, because there is no server that can hold it in a queue until the recipient comes back online.
What this means for metadata specifically
With ordinary messengers, even when message contents are fully encrypted, the server can still see the IP addresses of connections (or at least the fact that a connection occurred) the times of activity, the frequency of messages between specific pairs of users and the amount of data transferred. With enough analysis, this metadata can be used to reconstruct a social graph (who communicates with whom) without reading a single message. With Ricochet, there is physically nowhere for this metadata to accumulate. The connection exists only while the message is being transmitted, directly between two onion addresses through Tor and disappears immediately afterward. There is no intermediary node that can see both ends of the conversation at the same time.
Why this works specifically because of Tor onion-service architecture
Each onion address is routed through the Tor network in such a way that no single node along the path simultaneously knows both the sender and the recipient. This is a built-in property of the Tor protocol on which Ricochet is based. The application doesn't simply add an extra layer of anonymity on top of an ordinary network - it uses the anonymity provided architecturally by Tor to enable direct peer-to-peer communication instead of the usual client-server model.
Honest limitations: this is not a messenger for everyday use
Both participants must be online at the same time for a message to be delivered. There is no cloud-based message queue like the one used by Telegram or WhatsApp, where you can send a message and the recipient can read it later when they turn on their phone. There is no synchronization between devices. The entire identity (your onion address and keys) exists on the specific device where Ricochet is installed. If you lose that device, you lose your identity and must start over with a new address, exchanging it with all your contacts again. There are no conventional group chats. The architecture is designed specifically for private one-to-one conversations, not for coordinating large groups. Both participants also need to be technically prepared to keep the application running continuously in order to receive messages. This is inconvenient for the average user, but for people who genuinely need maximum anonymity for a particular conversation, it is a deliberate trade-off.
Who can actually benefit from it
Ricochet is not intended for everyday conversations with friends. For those, Signal or Session is more convenient and generally sufficient. Ricochet makes sense specifically for conversations where the absence of metadata matters more than convenience - for example, one-off sensitive discussions or coordination between people who need to make it architecturally impossible to link their communications after the fact.
Conclusion
Ricochet Refresh does not try to be a messenger for everyone. It is a highly specialized tool designed for a specific purpose: having a conversation whose very existence should be known to no one except the two participants. The price is convenience: there is no offline delivery, no synchronization and no group messaging. But in the rare situations where this level of protection is genuinely necessary, there is arguably no messenger with a stronger anonymity-focused architecture.