Kasumi

霞かすみ

Japanese for haze — the thin mist that softens a landscape until its outlines dissolve. You can tell something is there, but there is no sharp edge to fix on.

That is what the protocol is built to be on the wire. Its contents are encrypted from the very first byte, and its shape is deliberately formless: no TLS handshake to fingerprint, no HTTP to imitate, no constant prefix or fixed length for a classifier to key on. A name is a small thing to get right, but this one is the whole design brief.

One engine sits behind all of it — the same rule set, the same fake-IP routing, the same connection tracking — with a native client on each platform rather than a shared one that feels at home on none.

Clients

macOS
Apple silicon and Intel · macOS 13 or later
Download
brew install --cask owo-network/brew/kasumi

Written in Objective-C and AppKit.

Installed copies update themselves through Sparkle.

Server

Linux
systemd · x86-64 and arm64
bash <(curl -fsSL https://s.ee/kasu)

Written in Go — the same engine the clients embed.

Run it as root. It picks a port, generates a key, opens the firewall, and prints a client config and a kasumi:// share link with its QR code — which the clients above read directly.