Viber adds end-to-end encryption
31–40 of 114 posts
Re: Viber adds end-to-end encryption
#32Earlier quoted context omitted.
That's just an utterly ridiculous proposition. By that logic the entire application would need to be open source, because nobody would start out by targeting the crypto if they wanted to spy on someone.
Ideally it would be possible to use third party clients to connect, and so anyone could use a fully open source solution if they wanted.
But you need far more than just the crypto code to create a client, I think open source protocol specs would already achieve this.
And my main complaint was with the claim that open sourcing their crypto code would somehow make a meaningful difference to the security of these applications to the extent where you could consider all applications that haven't done so "insecure".
Re: Viber adds end-to-end encryption
#33End-to-end (E2E) code needs to be open source and venders that don't agree to an audit should be considered insecure; holds true for What's App, which declined to allow their E2E code to be audited. Also, message metadata is still being leaked by all of these E2E implementations and needs to be fixed.
Would open sourcing the Whatsapp client hurt Whatsapp in any significant way? I mean, sure, there could be "Whatsapp clones" (aren't there already?!), but wouldn't Whatsapp still benefit from the phone number user base it has, thus maintaining a certain lock-in on its users from which it already benefits?
Re: Viber adds end-to-end encryption
#34Earlier quoted context omitted.
Would open sourcing the Whatsapp client hurt Whatsapp in any significant way? I mean, sure, there could be "Whatsapp clones" (aren't there already?!), but wouldn't Whatsapp still benefit from the phone number user base it has, thus maintaining a certain lock-in on its users from which it already benefits?
> I mean, sure, there could be "Whatsapp clones" (aren't there already?!) Sounds funny if you consider that Whatsapp itself is just a branded deployment of FOSS XMPP server Ejabberd, with feature of federation taken away. Plus a client app implementation, of course.
Re: Viber adds end-to-end encryption
#35Earlier quoted context omitted.
Open source client and reproducible builds. Signal already does that. It's not a high bar.
That's a completely different from just wanting the e2e crypto source, which is useless by itself. https://www.bishopfox.com/blog/2016/04/if-you-cant-break-cry...
So, my point that the E2E should be open source is that that code should never be the basis for a business model, so to me, it being open source makes sense. As larger system, that's why I'm saying there needs to be an audit.
Also, you mentioned ATP and I agree, which is why to me it is troubling Signal instead of guarding metadata, actively collects it.
Please let me know I have missed anything you'd like me to address. And I really would be interested in your thought on the question above in as much detail as you're able to share. Thanks!
Re: Viber adds end-to-end encryption
#36What really impresses me about Viber is the way they went all out and splurged with an honest to god penultimate "e" before the final "r". Most dot-com companies would have settled for "Vibr", but they went the distance and bought an authentic luxurious vowel, precisely where it was called for, without going overboard and throwing in a sometimes-vowel "y" in place of the "i". Very bold and straightforward spelling, I…
Re: Viber adds end-to-end encryption
#37What really impresses me about Viber is the way they went all out and splurged with an honest to god penultimate "e" before the final "r". Most dot-com companies would have settled for "Vibr", but they went the distance and bought an authentic luxurious vowel, precisely where it was called for, without going overboard and throwing in a sometimes-vowel "y" in place of the "i". Very bold and straightforward spelling, I…
Viber is an Israeli company, don't be so judgmental of their poor startup spelling skills.
Re: Viber adds end-to-end encryption
#38What really impresses me about Viber is the way they went all out and splurged with an honest to god penultimate "e" before the final "r". Most dot-com companies would have settled for "Vibr", but they went the distance and bought an authentic luxurious vowel, precisely where it was called for, without going overboard and throwing in a sometimes-vowel "y" in place of the "i". Very bold and straightforward spelling, I…
Viber is an Israeli company, don't be so judgmental of their poor startup spelling skills.
Re: Viber adds end-to-end encryption
#39Earlier quoted context omitted.
Viber is an Israeli company, don't be so judgmental of their poor startup spelling skills.
No, you misunderstand: I am truly and earnestly impressed by their good spelling, not criticizing any bad grammar. If they'd named it "Vybr," it would have come off like Steve Buscemie holding a skateboard over his shoulder wearing a MUSIC BAND t-shirt, desperately trying to appeal to the youth demographic.
Re: Viber adds end-to-end encryption
#40Earlier quoted context omitted.
What do you mean by "user's rights" and by "sent"? Why shouldn't it be possible? If the TOS and app allow and enable it, it can be done. This sounds no different from, say, Snapchat, except that the deletion is triggered by the sender instead of by a timer.
It's the same thing people complain about wrt unfree software, e.g. Kindle deleting purchased books remotely if they were uploaded by someone without the rights to the book. The difference with snapshot is that their whole gimmick was the deleting thing. You had no expectation of permanency. But I'm sure many use Viber with the expectation that they'll be able to access old communications; after all, it's on their ow…
The comparison to Amazon is not apt. That was Amazon, not the seller of the book, that chose to delete it (in that case because the seller didn't have a right to sell, though given it was 1984 it was rather amusing/ironic). If, for instance, Amazon's digital platform allowed sellers to remove their content from Amazon's listings AND from "buyers'" devices, then 1) no one should be too surprised when it happens, 2) no one should use that platform.