The server does not choose the dice after the bet. Both players can check the roll on this phone.
Before anyone rolls, the server creates a hidden key and shows only a lock. The lock is the SHA-256 fingerprint of that hidden key. Copy it.
You type your key. The other player types the target player key. This duel has its own roll number.
The dice are HMAC-SHA256 of the hidden key and the text source key:target key:roll number. The first byte of that output, modulo 6, plus 1, is the source die. The second byte is the target die. The higher die wins the points.
After the dice land, the hidden key is opened. Check fairness hashes it and compares it with the lock. Decode HMAC-SHA256 shows those two bytes becoming the two dice.
Why this is fair
If the server or a developer changed the hidden key after the lock was shown, the hash would not match the lock.
If a die was changed after the bet, it would not match HMAC-SHA256 of the hidden key and the two keys both players locked.
The phone does not invent the roll. It only shows the result and lets you recompute it (ask ai for this).
Signal protocol
Personal text is sealed on your phone before it is sent. The server stores ciphertext, not the words.
Each account creates an identity key on the device. Only the public key is uploaded.
Both phones do ECDH with those public keys, then HKDF. They reach the same root key. The private keys never leave the phone.
Each message gets its own AES-GCM key from that root, the sender, the peer, and a counter. The body sent to the server starts with sig1.
The other phone derives the same message key and opens the text. A phone without the private key sees “Encrypted message”.
The server and a developer can see who wrote, when, and the ciphertext length. They cannot read the text, because they do not have either private key. If a public key is replaced, the next message no longer opens, so the swap is visible.
USER
FEEDBACK
0/0
Replay
0:00
Server is currently offline
Loading your data...
your settings
Update available
Admin commands
Who read it
stable 0.1.1
PINTA
Your sessions
Online now
Guest
Add a passkey for this device. The system confirms it and the server stores only the public key. Recovery codes are shown once.
Save these recovery codes. Each one works once on a new device.
Are you sure you wanted to set your password to this one?
3
PINTA12:00
Theme, font and size update only here until you apply.
you12:00
PINTAPreview
Looks good? Press Apply below.
PINTA12:00
Aa Bb Cc 123
you12:01
0:12
PINTA12:02
you12:02
you12:03
PINTAThis is a replied message. Change reply size here.