The most private nojs forum powered by PGP and Spasm, based on direct signing of all events, without any legacy bs like accounts and cookies. Dark Forum features self-custody, immutable events, censorship-resistance, and interoperability.
Find a file
2026-07-30 01:56:16 +01:00
.gitignore git: add gitignore 2026-07-18 17:06:07 +01:00
LICENSE docs: add license 2026-07-17 09:38:07 +01:00
README.md docs: add architecture 2026-07-30 01:56:16 +01:00

Dark Forum

Mirrors: Forgejo Codeberg Github

This is a proposal for the most private nojs forum powered by PGP and Spasm, based on direct signing of all events, without any legacy bs like accounts and cookies. Dark Forum features self-custody, immutable events, censorship-resistance, and interoperability.

Intro

The privacy web runs on slave tech. All privacy forums, including those that use PGP signatures instead of passwords, have the same account-based legacy architecture, which means:

  • Cookies
  • Centralization
  • No self-custody
  • Users can be censored and deplatformed
  • Forums are walled gardens that compete with each other
  • All events are unsigned and can be tampered with
  • Admins can impersonate users
  • Messages don't propagate through any network
  • Bad privacy (requires direct submission)
  • Highly exploitable

Features

Dark Forum has a modern architecture based on direct signing and is powered by PGP and Spasm, which means:

  • Self-custody
  • Censorship-resistance
  • Immutable events that cannot be tampered with
  • Federated network
  • Supports PGP
  • Optional support for Nostr, Ethereum
  • Highly customizable
  • No cookies
  • Administration/moderation via direct signing
  • Virtually unexploitable (read below)

Unexploitable

Slave tech forums rely on unsigned events, so changing records in the database can have catastrophic consequences. It's virtually imposable to keep a database protected forever, meaning that exploits are unavoidable.

Dark Forum relies on signed events and the database is public, so there is nothing to exploit. A blackhat agent can obviously crash a server or even get a root access by chaining a few zero-days, but he won't be able to inflict any significant damage since there are no accounts, passwords, etc.

In the worst case scenario, a bad actor can serve a malicious frontend, but since all actions are directly signed, users should recognize that they were served with malicious content. Besides, PGP and Nostr private keys are not used to manage funds, while modern Ethereum wallets have safety measures, which will warn a user if he tries to sign a malicious transaction.

Stack

  • Spasm.js (TypeScript, PGP, Spasm, Nostr, Ethereum, DMP, RSS)
  • Spasm-forum-server (TypeScript, Node.js, PostgreSQL)
  • Dark-forum (nojs frontend)
Spasm.js

The npm library already supports multiple protocols (Spasm, Nostr, DMP, RSS) and private keys (Nostr, Ethereum) and it has the most advanced architecture to date. It will be required to create a new event structure and add support for PGP private keys in order to enable Dark Forum features.

Spasm-forum-server

The backend implementation of a Spasm forum already supports multiple protocols and private keys, but it will require adjustments to support PGP keys and a new event structure.

Dark-forum

A completely new nojs frontend will be required since the current Spasm-forum-web implementation relies on JavaScript to facilitate direct signing of all events. The exact stack will be determined after integrating PGP into Spasm.js and adding new API.

Architecture

┌─────────────────────────────────────────────────────┐
│                     dark-forum                      │
│ ┌──────────┐ ┌───────────┐ ┌──────────┐ ┌─────────┐ │
│ │   Feed   │ │  Filters  │ │ Comments │ │  Admin  │ │
│ └──────────┘ └───────────┘ └──────────┘ └─────────┘ │
│  Receive events                    Submit events    │
│          │                               │          │
│          └─────────── wrapper ───────────┘          │
└─────────────────────────┬───────────────────────────┘
                          │
┌─────────────────────────▼───────────────────────────┐
│                     spasm.js                        │
│ ┌──────────┐ ┌──────────┐ ┌──────────┐ ┌──────────┐ │
│ │ PGP      │ │ Nostr    │ │ Ethereum │ │ Events:  │ │
│ │ keys     │ │ keys     │ │ keys     │ │ - Spasm  │ │
│ └────┬─────┘ └────┬─────┘ └─────┬────┘ │ - PGP    │ │
│      │            │             │      │ - Nostr  │ │
│ ┌────▼────────────▼─────────────▼────┐ │ - DMP    │ │
│ │  SpasmEventV2 (universal wrapper)  │ │ - RSS    │ │
│ └────────────────────────────────────┘ └──────────┘ │
└─────────┬────────────────┬─────────────────┬────────┘
          │                │                 │
┌─────────▼──────┐ ┌───────▼───────┐ ┌───────▼────────┐
│ Local database │ │ Spasm Network │ │ Nostr Network  │
│ (postgres)     │ │ (federation)  │ │ (nostr relays) │
└────────────────┘ └───────────────┘ └────────────────┘

Why me

I developed the most advanced generation of decentralized social media with a fully agnostic architecture that supports multiple private keys, protocols, networks, and introduces various groundbreaking innovations like multisigning with different key types and protocols, and moderation/administration based on direct signing of all events without any cookies and other outdated bs.

This is not some marketing bs. This stuff simply doesn't exist anywhere else and you can verify that by watching this 12-min detailed video which explains why Spasm is the endgame of social media and it's the only truly open ecosystem unlike all major walled gardens like Nostr, Bluesky, Mastodon, Lemmy, Lens, Ethcomments, etc.

Why fundraising

I've developed Spasm for over half a decade without any funding and I received many feature requests in these years, most of which were implemented, but I never got paid for that, and, frankly, many of these features ended up not being used.

For example, I spent a few months working on multisigning with different key types and protocols, which is an absolutely groundbreaking feature that doesn't exist anywhere on the web. It went live in 2024, but probably less than ten users actually used it.

This time we'll do things differently. I received many requests to add PGP support and create a nojs version. Well, if the community really wants a private nojs forum with self-custody, immutable events, censorship-resistance, and interoperability, then it can easily donate a few thousand for the MVP version.

I've proved my dedication to restoring freedom of speech by working on Spasm full-time for five years with zero funding. Let me emphasize that again: five years, zero funding. We did launched a token after four years, though, in attempt to grow the ecosystem, which actually helped us get new instances, but the token has no utility or governance power at the moment. In other words, it's a pure memecoin like Bitcoin, and we didn't push it onto users, so there is almost no liquidity. Thus, I haven't received a penny from it.

Basically, I'm clearly the best person to deliver this project since I'm a highly ideologically-motivated unbanked cypherpunk who's always been censored on slave tech. I'm also a senior full-stack developer and the top expert in decentralized social media. Finally, I don't do tech holy wars, so I attend various conferences, research different tech, and I've been using Monero, Bitcoin, Ethereum and other crypto for a decade.

In other words, I can deliver, and I will deliver. There are many ways to grow the Spasm ecosystem and Dark Forum is one of them. I'd like to work on the project, but this time I need at least some commitment from the privacy community and a small donation is a pretty good start.

Milestones

I have a rough architecture in mind, but it'll probably take at least a few weeks to finalize it since I'll need to do more research and testing.

Then I'll have to integrate PGP into Spasm, which can easily take a few weeks or more. It's not just some legacy boring project that can be vibecoded with a few prompts.

I then will have to update backend to support PGP, which can take a few weeks more.

Finally, I'll have to rewrite the frontend from scratch since it should work without JS and support PGP. This will probably be the hardest task. The current frontend is fully dependent on JS since all events are signed with web3 or Nostr wallets.

And let's clarify one more time. It's fairly easy to implement a legacy account-based walled garden with "log in with PGP", but Dark Forum will have a much more complex architecture based on direct signing and without accounts, cookies, and other legacy bs.

Basically, we are looking at the minimum of 3 months of work, probably more.

Thus, a few thousand in donations is almost "free".

Sponsorship

Additionally, feel free to reach out if you manage a freedom-focused project, which would like to sponsor Dark Forum. We can feature your brand name with banners and links on a website and in a git repo.

Donate

BTC: bc1ql42pcl509k5qzzdty8hlx8ul2d54d9h24mfnsg
ETH: 0xF5b56722Aa3347c2b7A333Ae781Ea42CF966B941
SOL: FyQJfREE3HyMhC7eiUebyJ4SLW52Tf5ww3Lo63oAtMF6
XMR: 87n1PSRxE52KZXRypNsq1tbAK2jHy1kBAcHLS437Yhuj3WHaboCPWuGNTk4Lvh1j6x23gN7tN7rpDanVTNu6Y5NM98nfif3

FAQ

Q: What if I run away with the money?

A: That would be ridiculous.