Building Stiger
How I came up with Stiger.
PART I: Where the idea came from
They say that when you start a project, scratch your own itch. Build something you’d actually use — that you’d reach for if it existed, or if the existing thing were any good.
Like a lot of people in 2025–2026, I sat at my laptop, thinking. Luck had it that I didn’t need an AI wrapper, a finance tracker, or a meditation timer. So what does pull me in? What do I actually need?…
time for a lyrical aside
Here’s the thing: four years ago I emigrated. Where I’m from, Russia, what’s on your phone can matter. Roughly: if the wrong thing turns up in a phone check, you’ve got a problem. An access key, a saved article, a subscription to the wrong channel, the wrong app…
OK, that’s a starting point — but what can I actually do about it?…
I’d been hooked on the idea of steganography since I was a kid.
Steganography (/ˌstɛɡəˈnɒɡrəfi/ STEG-ə-NOG-rə-fee) is the practice of representing information within another message or physical object, in such a manner that the presence of the concealed information would not be evident to an unsuspecting person’s examination.
—https://en.wikipedia.org/wiki/Steganography
I think I picked it up from the Russian magazine ”][акер” (“Hacker”). I remember a clever little utility going around at some point that bundled a rar archive with a jpeg image, letting you do this:
- You’d download an image — say, “cat.jpeg”. Just some random cat picture from the internet.
- You’d rename “cat.jpeg” to “cat.rar” and… extract it as an archive.
Cool, right? Cool.
What I loved about it: the recipient didn’t need any special tools. As long as they had a common archive program — WinRAR or whatever — they were ready to receive. You could plant Easter eggs all over the internet (back when image hosts didn’t usually recompress), have a laugh, and… that was about it, really.
For regular users, steganography effectively doesn’t exist. For the slightly more technical crowd, it stays in the realm of an academic concept: you read the description, run the tool a couple of times, admire the elegance, and shelve it. Because for it to be useful as actual communication, the other person has to know this kind of thing exists in the first place — and they have to be technical enough to use it.
A quick look at the category bears this out: the developers in this space, dazzled by the academic beauty, focus on the algorithms way more than on the interface or the actual usage flow. Steganography tools tend to be standalone apps that don’t (or barely) plug into anyone’s day-to-day. In most flows, the user is told to install the app, import the photo, add the secret, export the image, and send it as an attachment. Often as a file rather than an image — no thumbnail preview, so the secret doesn’t get lost to compression. To read it on the other end, you do the whole thing in reverse: download the attachment, install the app, import the image…
There’s another category of tool that hides messages in invisible whitespace characters instead of images. But a “Hello!” stuffed with hidden spaces is essentially signing your name to the use of steganography. Anyone who copy-pastes it, or flips on “show invisible characters”, will spot it immediately. And those hidden characters get indexed by the device’s text search just like ordinary chat text — unlike binary image files.
Fine for cypherpunks, maybe. Not for everyone else. Not for talking to your friends, or your parents.
And it’s a shame, because… you know… IT’S BEAUTIFUL.
But programmers wouldn’t be programmers if they gave up that easily. Time to actually test things, with the user in mind.
PART II: Testing the idea
OK, here’s where I’m at:
- The main thing is UI/UX and a simple story for the user to follow. Without that, the moment the app ships it goes straight to the software graveyard, along with every other tool that starts with “Steg-”.
- Technical details have to be available — for the geeks, who care. But normal people need a friendly, legible front, a user story that answers “why do I want this?” — or, even better, doesn’t make the question come up at all and just has them go “huh, neat.”
What’s the friction for someone who wants to use steganography — or, more accurately, for someone who doesn’t yet know they want to?
- Which picture to use
- How it slots into the chat
- …that’s it.
A regular user doesn’t need fancy tools or the gory details of the embedding protocol. It has to be steganography at your fingertips. As close to the keyboard as you can get. Which sounds like: a prototype custom keyboard with image search built in, and a place to type the secret. Or even simpler — an image gallery plus a text input.
OK, what do we send from a keyboard?
On Twitter/X there’s an organically integrated GIF search. Nobody really uses it, but the shape is right. Except — steganography inside a GIF? Hmm. What else do people send? Memes? (Do people still send memes, or is that like telling jokes — extinct?) OK, prototype: a meme catalog. Format? PNG is probably the way for clean graphics. Skim the literature on hiding payloads in PNG, pick a method, throw together a custom keyboard-gallery that inserts a test image with a secret, and run it through…
…And it doesn’t work in Telegram. Doesn’t work in WhatsApp. The PNG doesn’t survive forwarding intact — the messengers transcode the image, and the secret is gone. While we’re at it, another problem surfaces: if your project is a keyboard-gallery and the user needs to type their own text (the actual secret), you can’t summon the system keyboard from inside another keyboard (which, fair). Which means… we need to build the keyboard ourselves.
Bottom line: the PoC doesn’t work. Reasons, in order:
- A custom keyboard-gallery can’t pop up the system keyboard for text input — and entering the secret needs the system keyboard. So a “keyboard-gallery” suddenly becomes “a keyboard plus a gallery”. The keyboard half alone is a horror story (every language, every layout type — picture the matrix). And on top of that, you can’t really build a half-decent custom keyboard on iOS. Anyone who’s ever installed a third-party keyboard knows the feeling.
- A custom keyboard needs “Full Access”, which raises immediate questions about data privacy.
- But the real killer: the image — the PNG with a hidden payload, the whole point of this — doesn’t work in the most popular messengers. And even if it worked in one of them, how do you explain to the user “it works here, doesn’t work there”?… Worse, Telegram, WhatsApp, and many of the other plausible transports (which I didn’t even bother to check — Discord, Viber, Skype for Business, MS Teams, Snapchat, Threema, WeChat, Signal, Facebook Messenger, you name it) are blocked or restricted in the country I came from anyway.
By the end of all this it’s clear: instead of a keyboard that works everywhere, the right move is to embed inside one specific messenger — somewhere with a transport you can rely on.
But which messenger? And how?
PART III: iMessage
I’ve spent all 15-plus years of my career in web — iOS is new territory for me. Swift feels broadly familiar coming from TypeScript, my main language, and mobile screens are second nature from years of mobile web. But the iOS ecosystem itself I’d only ever seen from the outside, as a user.
Sitting with the bleak results, I noticed an Xcode target labeled “iMessage extension”…
Quick context: iMessage is huge in English-speaking countries and barely used in Russia. So unpopular there that, as of mid-2026, it had not been blocked. One guess why: blocking iMessage at the network layer would arguably break the iPhone outright. Either way, I sent a PNG through iMessage as a test — and lo and behold, the image came through intact. The secret read back fine.
From there I went all-in on iMessage. It checked all the boxes from Part I:
- A transport that ferries a PNG end-to-end without breaking the payload — green light for steganography.
- It’s everywhere. On every iPhone, even when the owner doesn’t realize it’s there.
- It’s exclusive. An iMessage extension, unlike a custom keyboard, only runs inside the Messages app — there’s no way for the user to accidentally send a stego image through some other transport that won’t carry it.
- And the iMessage extension gives me all the UI primitives I need. Building a sticker gallery is straightforward; so is a text input. The standard system keyboard handles typing — no need to ask for the sketchy “Full Access” in settings.
That’s pretty much how Stiger came into existence. After that came prototypes, an MVP, testing. A few rounds of iteration. You can see what came of it for yourself if your iPhone is on iOS 15 or up.
Once installed, all the core features are yours — minus encryption. That’s enough for more than just kicking the tires: if you don’t need encryption for what you’re sending, go ahead — pass jokes around, chat with friends. No trial, no time limit. Just know that without encryption, any other Stiger user can read what’s inside your stickers. Encryption, along with a few other advanced features, comes with the subscription. Subscription plus the sticker store — that’s the monetization model.
I went from a universal meme keyboard, through a few iterations, to an iMessage Extension with stickers. The original idea of copy-pasting stickers eventually gave way to a friendlier drag-and-drop.
I’ll admit it: there were stretches where it was hard to stop thinking like a programmer and let the interface stay simple and clean. But in the end I worked out a stack of meaning, simple-to-complex, that kept the balance:
- A simple, friendly iMessage Extension. All the steganography happens here, and the most complicated thing the user runs into is the password field and the drag-and-drop gesture.
- The Stiger.app companion app stays out of the steganography itself, but it carries the advanced security settings and an interactive widget I call the paranoia guide — it walks through each setting and helps you pick a usage strategy that fits your threat model.
- And finally, THREAT_MODEL.md plus the open protocol description on GitHub at github.com/axlerk/stiger-protocol — with reference implementations in Python and TypeScript. The whole thing is there for specialists who need to decide whether Stiger is worth trusting with their data.
Put it all together: Stiger’s interface aims at a broad audience, the app icon is deliberately on-brand for “security through obscurity by design”, but behind the surface there’s actual privacy-tool architecture and design choices that — I hope — keep your messages, and mine, well enough protected. Encryption, hiding and reading all happen on your device. No analytics.
Given that many messengers are restricted in Russia, plus the simple fact that you basically can’t pay for App Store purchases there, I decided to give encryption away free to anyone whose device language is set to Russian. I hope it helps people in Russia get information through, and stay in touch with the people they care about.