The Book of Rhizo Go back home

Open Questions

Every chapter up to here has explained the measures we take to protect people and data, but there is always more to be done.

This chapter talks about the remaining risks, open questions, and any gaps and mitigation strategies, as well as where we currently need help from contributors and supporters.

Audit status

The application and protocols has not yet been through an external security audit. This means the implementation can still be wrong in ways that aren’t easy to catch. Using the software before an audit means doing so at your own risk, and we do not recommend it for sensitive use cases.

An audit of this scale will be a considerable financial effort, and we’re exploring grants and self-funding to achieve it in the future.

Post-quantum

As of 2026, the open-mls library we use does not yet support post-quantum key exchange, and we don’t have any post-quantum layer of our own. We use ChaCha20-Poly1305 until post-quantum support lands upstream in open-mls, at which point we are ready to switch.

Post-quantum cryptography

Most cryptographic algorithms in use rely on it being difficult to solve mathematical challenges using the computers we have today. Given the development of quantum computers, all of these problems could be easily solved on a sufficiently powerful quantum computer.

As quantum computing threatens to break traditional encryption algorithms, organizations are beginning to explore post-quantum cryptography techniques to future-proof their infrastructure.

What we’re still working on

We are still working on topics in a few areas:

  • Hardening Rhizo to the attacks coming from the inside. While MLS protocol already gives us strong assurances when it comes who can join what groups, we still rely on trusting admins. This reliance can be possibly reduced with some gossip between members.
  • Routing the network traffic through Tor or P2P as a way to prevent leaking metadata through network analysis.
  • Limiting the number of VOPRF tokens minted to prevent server abuse.
  • Mitigating (or deciding not to mitigate) the potential server invite correlation gap.

If you have experience and would like to help with any of these areas, see how you can get in touch below.

How to contribute

Rhizo and this book are open-source projects. If you want to contribute something, create a new pull request or a new issue on Codeberg while being mindful of community and contribution guidelines.

Got ideas or suggestions? Come talk to us on IRC or on the fediverse.