Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
op4 — Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable authentication, and OS-level hardening via seccomp-bpf and mlockall. | Kitploit
Tools/GitHubGitHub/opfour/op4
Authentication & AuthorizationDefensive ToolsEncryption/Decryption ToolsCryptographyPrivacyAuthentication
GitHubopfour/op4

op4

Terminal-based encrypted messenger with post-quantum cryptography, Double Ratchet protocol, and Tor anonymity. Features duress passphrase, deniable authentication, and OS-level hardening via seccomp-bpf and mlockall.

View Repository
68411 days agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share


op4 — Secure Terminal Messenger

Op4 is a terminal-based encrypted messaging application written in Rust. It provides end-to-end encrypted private messaging with post-quantum cryptography, routed entirely through the Tor network so that neither the content of your messages nor your IP address is exposed to anyone — not even the person you are talking to.






Table of Contents

  1. What op4 Does
  2. Installation
  3. Connecting to Another User
  4. Security Model
  5. Architecture Overview
  6. Project Layout
  7. Current Status

What op4 Does

op4 lets two people exchange private messages without either party revealing their IP address or real identity. Every message is:

  • End-to-end encrypted using a Double Ratchet protocol — the same fundamental design used by Signal.
  • Post-quantum hardened — the key exchange layer combines classical X25519 with ML-KEM-768 (NIST-standardised lattice-based KEM), so a future quantum computer cannot retroactively decrypt recorded traffic.
  • Anonymised — all traffic travels over Tor hidden services (.onion addresses). Your IP address is never exposed to your contact or to any network observer.
  • Stored locally — there is no server. Your messages and contacts live in an encrypted vault file on your own machine, and nowhere else.

op4 runs entirely in the terminal. It has no GUI, no browser component, and no cloud account. The only external process it contacts is the Tor daemon running on your own machine.


Installation

All download options — AppImage, source tarball, clone & build, and automated installer — are documented in the Downloads & Install guide. The latest release is available on the Releases page.

Debian / Ubuntu (automated)

On Debian and Ubuntu, install/setup.sh handles everything in one command: Rust toolchain, build dependencies, Tor, control port configuration, binary compilation, system user, data directory, and AppArmor profile.

git clone https://github.com/Opfour/op4.git
cd op4
sudo bash install/setup.sh

After the script finishes, you must log out and log back in before running op4. The installer adds your user to the debian-tor group so it can read the Tor cookie file. Linux does not apply group changes to already-open sessions — a fresh login is required.

Skipping this step will cause op4 to fail at startup with: Permission denied reading /run/tor/control.authcookie

Then verify the source hash printed by the script matches the published release hash for your version before trusting the binary.

Release hash verification

When op4 starts it prints a source hash covering all Rust source files, Cargo.toml, Cargo.lock, and build.rs. Compare it against the value below for the version you installed.

VersionSource hash
0.3.080820cb41a63575d2c139dadd425d13d1e87e62a9d60200ae7b894ae2e9ad8ed
0.3.148115efb12747fa78b627ddbf7a56c46169f59e777d7d7508941bf89e4fe7521
0.2.0-dev35740577f6c4a4f19c5a08fe85b1f78a10347f2ba9dd7642d126552266bfa5a5
0.1.0e1a94761c7d3fa589ba892b47d5295aa417f95aee126809d51a7e7fb7e78982c

You can also check it without launching the full app:

op4 --print-hash

If the hash does not match, do not use the binary — it was either built from a different commit or has been tampered with.

Fedora / Arch / other distros (manual)

Install dependencies first, then run the script:

Rust toolchain (pinned to 1.89.0 via rust-toolchain.toml):

curl --proto '=https' --tlsv1.2 -sSf https://sh.rustup.rs | sh
source "$HOME/.cargo/env"

Tor and build dependencies:

# Fedora
sudo dnf install tor gcc pkg-config openssl-devel

# Arch
sudo pacman -S tor base-devel pkg-config openssl

Configure Tor control port — add to /etc/tor/torrc:

ControlPort 9051
CookieAuthentication 1
sudo systemctl restart tor

Add your user to the Tor group:

sudo usermod -aG tor $USER        # Fedora / Arch

You must log out and log back in after this step. Group membership changes are not applied to active sessions. Until you do, op4 will fail with Permission denied reading /run/tor/control.authcookie.

To apply the change without a full logout, run:

newgrp tor

Build and install:

git clone https://github.com/Opfour/op4.git
cd op4
cargo build --release
sudo bash install/setup.sh

Run

op4
# or, without system install:
./target/release/op4

On first launch op4 will guide you through setting a normal passphrase and a duress passphrase, then generate your identity keys. Your vault is stored at ~/.local/share/op4/vault.op4.

Supported platforms

DistroStatus
Ubuntu 22.04 / 24.04Supported
Debian 12Supported
Fedora 39+Supported
Arch Linux (current)Supported
Tails OSSupported (setup guide)
macOS / Windows / WSL1Not supported

Minimum kernel: 4.15 (5.4+ recommended). Architecture: x86-64 (aarch64 should work but is untested).


Connecting to Another User

Two people each need op4 installed, Tor running, and their vault unlocked. The exchange is asymmetric: one person sends their contact code first, the other adds it, then sends their first message, which arrives as a pending request that the first person accepts.

Step 1 — First launch

On first run op4 prompts for a normal passphrase and a duress passphrase, then generates your identity keys. This only happens once. Your vault is stored at ~/.local/share/op4/vault.op4.

$ op4

Step 2 — Get your contact code

Your contact code contains your full public key bundle and your .onion address. The other person needs this to reach you.

  1. Navigate to the Contacts tab (press 2 or →)
  2. Press e to export your contact code
  3. Your code appears on screen — it is a long Base58 string starting with op4:
  4. Copy it and send it to the other person out of band (Signal, email, in person, etc.)

Your contact code is not secret. It is safe to share publicly. It contains only your public keys and onion address — no private material.

Step 3 — Add the other person as a contact

Once you have their contact code:

  1. In the Contacts tab, press a to add a contact
  2. Paste their op4: contact code and press Enter
  3. Give them a name and press Enter

Step 4 — Send your first message

  1. Select the contact from your contacts list (use ↑/↓, then Enter)
  2. Switch to the Messages tab (press 3 or →)
  3. Type your message and press Enter

This first message initiates the encrypted handshake and is delivered to their .onion address over Tor. They will see it as a pending contact request.

Step 5 — Accept an incoming request

When someone sends you a first message, a badge appears on the Contacts tab showing how many requests are waiting.

  1. Go to the Contacts tab (press 2)
  2. Press p to review pending requests
  3. You will see the sender's fingerprint and their first message
  4. Type a name for this contact and press Enter to accept (press Esc to reject and discard)

Once accepted, the Double Ratchet is initialised and the conversation is immediately available in the Messages tab.

Download Tool