Privacy Messaging App Briar Enters Maintenance Mode: What Should Users Do Next?
Privacy Messaging App Briar Enters Mai…
Briar enters maintenance mode, raising concerns about long-term security and highlighting open-source privacy tool sustainability issues.
Briar, the decentralized P2P encrypted messaging app known for its offline mesh networking and Tor-based communication, has entered maintenance mode — meaning no new features and uncertain long-term security support. This reflects a broader structural challenge facing open-source privacy projects that rely on cyclical grants rather than sustainable funding. Users, especially high-risk individuals like journalists and activists, should evaluate alternatives such as Signal, Session, or Matrix-based clients based on their specific threat model.
What It Means for Briar to Enter Maintenance Mode
Briar, a decentralized instant messaging app built around privacy and censorship resistance, recently announced it is entering "Maintenance Mode." The news sparked discussion on Hacker News and is a signal worth paying attention to for anyone who follows encrypted communications and the privacy tools ecosystem.
"Maintenance Mode" typically means the project team is no longer investing resources in new feature development — only basic bug fixes and security patches will be maintained, and even those may become difficult to sustain due to limited staffing. For a security communications tool, stagnant development is often more dangerous than stagnant features: fixing security vulnerabilities requires long-term, continuous investment.
What Is Briar?
Briar is an open-source, peer-to-peer encrypted instant messaging app primarily aimed at journalists, activists, and users living under high-pressure censorship environments. Its biggest technical differentiator is that it doesn't rely on centralized servers: messages are transmitted via the Tor network, and even when internet connectivity is completely cut off, devices can sync directly over local networks via Bluetooth or Wi-Fi.
Tor (The Onion Router) hides users' real IP addresses through multi-layer encryption and multi-hop relay nodes, and is one of the most mature anonymous communication infrastructures available today, maintained by the nonprofit Tor Project. Briar's Mesh Network capability is even more distinctive — when the internet is unavailable, devices can establish direct encrypted connections via Bluetooth or Wi-Fi Direct, forming a local communications network that requires no internet infrastructure whatsoever. This design attracted widespread attention during the 2019 Hong Kong protests, when the use of similar offline communication apps saw a significant spike.
For this reason, Briar has long enjoyed a strong reputation in the privacy community. When governments block the internet or surveil communications infrastructure, this local mesh network capability can theoretically sustain basic communications, giving Briar a unique value in extreme censorship scenarios.
Why Open-Source Privacy Projects Struggle to Survive
Briar entering maintenance mode reflects a long-standing challenge across the entire open-source privacy tools ecosystem. These projects are often maintained by small teams or volunteers and lack a sustainable business model.
The Dual Pressure of Funding and Manpower
Developing and maintaining security software is extremely expensive. Cryptographic implementation, protocol audits, cross-platform compatibility, timely vulnerability response — each of these requires specialized talent and ongoing investment. The chronic underfunding of open-source security infrastructure is a well-known problem: OpenSSL, the foundational library powering HTTPS encryption worldwide, had only one core maintainer and less than two thousand dollars in annual donations before the Heartbleed vulnerability was disclosed in 2014. That incident directly led to the creation of the Linux Foundation's Core Infrastructure Initiative (now OpenSSF), dedicated to funding critical open-source security infrastructure. However, end-user privacy communication tools typically don't hold the same infrastructure status, making it much harder for them to receive systematic support.
Unlike Signal — backed by the Signal Foundation, which was established in 2018 with a $50 million investment from WhatsApp co-founder Brian Acton, and whose Signal Protocol has been widely adopted by mainstream applications like WhatsApp and Google Messages, forming a solid reputational foundation — Briar has long relied on project-based grants from organizations like the European Human Rights Foundation and the Open Technology Fund. This type of funding is cyclical and struggles to support a team's long-term stable operations, a structural challenge shared by many niche privacy projects. Once a core developer leaves for personal reasons or a funding source dries up, a project can easily fall into stagnation.
Briar's situation is not unique. In recent years, many once-celebrated privacy tools have experienced similar fates: either acquired by commercial companies and redirected, or gradually abandoned due to lack of funding. This serves as a reminder that "open source" does not equal "permanent" — the sustainability of community support has always been the soft underbelly of decentralized communication projects like this.
What Maintenance Mode Means for Users
For users still on Briar, the most immediate impact of maintenance mode is that new feature development has stopped — and more critically, long-term security is in question. The value of encrypted communication tools is built on a continuous ability to respond to threats; once maintenance efforts diminish, potential vulnerabilities may go unpatched for extended periods.
For high-risk users such as journalists and activists, this warrants especially careful consideration. Before making a migration decision, it's worth closely monitoring the project's official statements to understand what security commitments remain under maintenance mode, and whether any clear alternatives or follow-up plans have been announced.
Possible Alternatives
When choosing an alternative, your threat model should be the primary framework — that is, systematically evaluating your security needs based on the specific adversaries you face, the attack methods involved, and your protection objectives. Current mainstream encrypted communication alternatives include:
- Signal: Centralized architecture, but thoroughly security-audited; the Signal Protocol has become an industry standard, and the foundation's operations are relatively stable. Suitable for most users who don't have extreme anonymity requirements.
- Session: Decentralized design based on the Oxen service node network; no phone number required for registration, with stronger metadata protection. Suitable for high-risk users who need to resist state-level censorship.
- Matrix protocol clients (such as Element): Open federated architecture that allows users or organizations to self-host servers (homeservers). Suitable for technically capable teams that want to control their own data sovereignty.
It's worth emphasizing that Briar's offline mesh network and censorship-resistance capabilities are fairly unique — the scenario of achieving local encrypted communications in a completely offline environment has almost no equivalent implementation among the mainstream alternatives listed above. Users should weigh their migration decisions against their own threat model, rather than simply "finding a roughly similar replacement."
The Sustainability of Privacy Tools: An Unsolved Problem
Briar entering maintenance mode is another reminder to pay attention to the overall health of the privacy tools ecosystem. Donation models (such as crowdfunding platforms), foundation stewardship, and dedicated grants from governments or human rights organizations are currently the three most common survival paths for such projects — but all come with instability. No matter how technically excellent a project is, without sustainable funding and human resources, decline is ultimately inevitable.
For the broader community, how to establish more robust support mechanisms for privacy infrastructure that has public value but lacks commercial returns remains an urgent, unsolved problem. For users, staying informed about the maintenance status of the tools they depend on and planning backup options in advance is always essential homework for protecting your own communications security.
Key Takeaways
Related articles

The Truth Behind Codex 'Build a Website in 5 Minutes': AI Isn't Creating Sites—It's Helping You Copy Them
Exposing the truth behind viral Codex 5-minute website videos: creators aren't building original sites with AI—they're copying shared prompts or scraping others' work. Learn AI coding tools' real limits.

Getting Started with AI Agent Development: A Complete Guide from Concept to Practice
A comprehensive guide to AI Agent architecture and development, covering automated marketing, intelligent customer service, and investment analysis scenarios with single and multi-agent collaboration.

The Truth Behind Codex 'Build a Website in 5 Minutes': AI Isn't Creating Sites — It's Helping You Copy Them
Exposing the truth behind viral Codex 5-minute website videos: creators aren't building original sites with AI — they're copying shared prompts or scraping others' work.