new bitchat in app store: https://apps.apple.com/us/app/bitchat-mesh/id6748219622

Reply to this note

Please Login to reply.

Discussion

Nice 👍

Now just need more plebs

At least I’m not the only one with this problem 😅

heads-up: we looked for a lightning address on your profile but could not find one... u can get a free one at https://rizful.com ... and then reply back to this comment so we can zap you.

Bitchat on coolr.chat 🤙🫂🎨

Bitchat might not work as intended though, and here is why.

Bluetooth communication can be captured using specialized hardware and software tools designed for packet sniffing and man-in-the-middle (MITM) attacks.

nRF Sniffer for Bluetooth LE, Ubertooth, or Gattacker can be used to monitor and capture traffic between devices. It's definitely more secure and depends on the Bluetooth version and encryption, but it's not immune.

So as the app and its code have not undergone external security review, and the project's own developers explicitly warn against using it for production or high-risk communications, its security is still under review.

A major flaw allows attackers to impersonate trusted contacts by exploiting the "Favorites" function, and a potential buffer overflow bug has been reported.

For here and there, it’s awesome to use. But for the world that needs it (I.e Iran’s authoritarianist regime shutting off internet), these vulnerabilities make a huge impact.

PS- would appreciate a reply back in the DMs lol

Looking for the android version, i see the playstore version is distributed by "Verse Communication PBC". While on the app store it says "Jack Dorsey"

On the web there are about 3k pages that offer APK downloads for it. All looking more or less scammy.

Are any of the android versions legit?

it's the verse one.

Many thanks, Jack!

I've just installed the Android version. But unfortunately there is no one near me - Budapest, Hungary - who uses it. 😢

I hope someone or someones will be there soon.

Put up a poster about it in the stairway of your building! :D

Wow, the offline world rulez! :-)

Now it works!

I've tried it with my college. But a bit messy regarding the channel function

Is Android version available?

Yeap. Come join the very many that speak to the void until someone else appears! Not giving up 😂

Our voice must be heard 😂

✊🏽

It's on zapstore

Thank you, will check

Being the oñly còme òñ!

Ĺove need to rèaçh now!

nostr:nprofile1qqsgssmk5x8sd4jc57h7r3pqdlesmdyscqu0l0xm55nc8n4874mcndgpzemhxue69uhhyetvv9ujumn0wd68ytnzv9hxgqg5waehxw309aex2mrp0yhxgctdw4eju6t07qwfcx

💜🔥

Love it nostr:nprofile1qqsgydql3q4ka27d9wnlrmus4tvkrnc8ftc4h8h5fgyln54gl0a7dgspp4mhxue69uhkummn9ekx7mqpz4mhxue69uhhyetvv9ujumt0wd68ytnsw43qgmzvsy 🗽✨🙏🙏🙏

Bitchat ✊

Excellent!

Will the BTC offline payment function be added some time soon?

Wooow … look at the spam here too… nostr is getting more mainstream i guess :)

Join us at the deep sea "21m".

nostr:nprofile1qqsgydql3q4ka27d9wnlrmus4tvkrnc8ftc4h8h5fgyln54gl0a7dgspxdmhxue69uhkuamr9ec8y6tdv9kzumn9wshkz7tkdfkx26tvd4urqctvxa4ryur3wsergut9vsch5dmp8pesz9nhwden5te0wfjkccte9ehx7uewwdhkx6tpdswfvru5 nostr:npub1luh5e4uxus45xgm5njg4zlk8htezmlgrtdapqxl2swmw9096e52sgjlqgz

nostr:nevent1qqsdtpytt3y5am2gd0zgt54k73exdas2vyawkg6uwrvkdahs3fv0jygpzemhxue69uhhyetvv9ujuurjd9kkzmpwdejhg7mhdpt

Cool I just downloaded

GM! ☀️ ☕ 🍳 🥓 Started... let's spread in the neighbourhood...

🧡

Great job jack 🫡

I slapped my collegue with a large trout 🐟 using "/slap" command.

This is like curing the "Lubbermatosis" at the movie short titled "So you want to be a Pirate!"

At least one dev surely have seen this movie. 😁

https://m.youtube.com/watch?v=dkFIb0GDpcY&pp=ygUNTHViYmVybWF0b3Npcw%3D%3D

Downloaded, I just starting to use it! Nice thing 👏

When you initially released bitchat on the App Store and I downloaded it, I was immediately able to find the command. Now I can’t find it anymore. I guess I’ve lost my bitchat intuition. Is it because I’m alone (slapping myself silly)? Pls help. Also, could we possibly slap others with other types of fishes such as snapper or tuna? Maybe salmon. Thanks.

ist this verse communications stuff the original legit project on android? https://play.google.com/store/apps/details?id=com.bitchat.droid

on github i only read about direct apk file based installation no link to google playstore? yet?

When will you stop pushing unsafe tech?

New Vulnerabilities: In 2025, several new vulnerabilities have been reported, including:

CVE-2025-32875: Insufficient authentication during Bluetooth binding, allowing unauthorized devices to connect during initial setup.

CVE-2025-32876: Weakness in the encryption process during Bluetooth handshakes, particularly in certain Android environments.

CVE-2025-44559: A Denial of Service (DoS) vulnerability in the Bluetooth Low Energy (BLE) stack, allowing attackers to disrupt services by sending crafted packets.

You should sign the Android apk on nostr:nprofile1qqs83nn04fezvsu89p8xg7axjwye2u67errat3dx2um725fs7qnrqlgpzamhxue69uhhyetvv9ujumn0wd68ytnzv9hxgtcsrhspy with your npub, live in the future, no more relaying on big corporate app store.

nostr:nprofile1qqs83nn04fezvsu89p8xg7axjwye2u67errat3dx2um725fs7qnrqlgpzdmhxue69uhhwmm59e6hg7r09ehkuef0a2g9gl

Which Bitchat do we grab from Zapstore?

com.bitchat.android

or

com.bitchat.droid

I have not the slightest idea

Maybe the App ID changed?

I think .android was the original one, but nostr:nprofile1qqs9pk20ctv9srrg9vr354p03v0rrgsqkpggh2u45va77zz4mu5p6ccpzemhxue69uhk2er9dchxummnw3ezumrpdejz7qgkwaehxw309a5xjum59ehx7um5wghxcctwvshszrnhwden5te0dehhxtnvdakz7qrxnfk had to change the App ID to .droid due to some 'ptoblems' publishing the app on the Play Store.

🫂

Sigh

I come here for this thing , just uninstalled bitchat since 0.9.0 DOES NOT MISMATCH IDS and zapstore install a new app, very bad practices , you can clarify what's going on? nostr:nprofile1qqs9pk20ctv9srrg9vr354p03v0rrgsqkpggh2u45va77zz4mu5p6ccpzemhxue69uhk2er9dchxummnw3ezumrpdejz7qgkwaehxw309a5xjum59ehx7um5wghxcctwvshszrnhwden5te0dehhxtnvdakz7qrxnfk nostr:nprofile1qqsgydql3q4ka27d9wnlrmus4tvkrnc8ftc4h8h5fgyln54gl0a7dgsppemhxue69uhkummn9ekx7mp0qythwumn8ghj7un9d3shjtnswf5k6ctv9ehx2ap0qyt8wumn8ghj7un9d3shjtnddaehgu3wwp6kytc79p4zh

Found 8 humans 🫡💜🫂

New update for android is not out?

you're wild for this one

nostr:npub1ghcetnluhryhynhuyj8s2pazldjm27wl40nu6dfeskvpv09twcnsneygat

I already downloaded it but don’t see any reason to use it right now

We were in there with Ryan YODL and Pitufo

Was it a party? 😭

2 separate parties

One after the other. Now at second location

The ⭕️ parties hard even without the whole squad

This is true

Grazie mille from Florence 🇮🇹🔥❤️🇮🇹

Geohash: 666

It would be super cool if you had the balls to say something about what is going on with girls and cameras and bcis and how I can never have anything in my life for Arielle to have fun with my body and life at my own expense around the country and above the law in constant isolation because she’s psychotic psychotically obsessed with women and trying to start a mass shooting and ditch town nostr:npub1sg6plzptd64u62a878hep2kev88swjh3tw00gjsfl8f237lmu63q0uf63m

I asked 5 Thinking (rarely use) bout spam optimal solution, it’s funny cause it goes through your GitHub stuff when reasoning that is way over my head. Cute that it does that. This is what it said:

Today(no code)

-use password channels for real conversations (interesting but like I’m sure spam will keep getting access to unless changed daily, maybe tire it out :)

-Use built-in/block @name for obvious spam and keep local blocklists.

Building tomorrow

-layer 1: simple flood & duplicate control with token-bucket rate limits and as mesh already uses TTL routing, in busy venues, reduce hop TTL to shrink the attack surface.

Layer 2:

-Require tiny POW per public message.

Layer3:

-Per-key trust scores, new keys start in probation(slow rate) and include relay policy where nodes deprioritise or refuse to forward from low-reputation keys (oof hope that’s not my key)

Layer 4

-First-time posters must complete in-room handshake 🤝 like your QR idea or get a trust reaction from non-newbie before normal rates apply.

-Invite links for channels with password + short-lived QR code for events.

Layer 5

-ship a tiny Core ML text model to score spammy patterns which works for offline damping of bots (be interesting if you can get this embedded into iOS bitchat app)

How to geohash without doxxing:

-Channel geofence where rooms require senders to be inside target geohash cell (e.g., precision 6 ≈ ~1km, 7 ≈ ~150-200 m)

-witness attestations from nearby devices with truncated geohash, not raw coordinates.

-pop-up room with rotating QR or 6 digit code as proximity ticket, first time posters scan or enter, afterward post for grace period 24hr.

Ok, well that’s it from me, hope it helps.

P.S. I swear I am not spam.

Cc nostr:npub12rv5lskctqxxs2c8rf2zlzc7xx3qpvzs3w4etgemauy9thegr43sf485vg

the only decentralized anti-spam measure that is long term workable:

1 make identity costly (no the per message cost is retarded)

2 get blocked before full propagation if you spam

this is very hard to implement well, especially point 2

thank you im so down