Live data from Hacker News

Moxie Marlinspike Makes Encryption for Everyone

popsci.com

11–20 of 144 posts

Re: Moxie Marlinspike Makes Encryption for Everyone

#11

Oh the irony of an article about encryption on a site sans encryption.

Its incredibly hard for publishers to do https, where main revenue is from serving third party content embedded inside.

Wired has nice article about their efforts going https https://www.wired.com/2016/04/wired-launching-https-security...

Re: Moxie Marlinspike Makes Encryption for Everyone

#13
post #6

Earlier quoted context omitted.

> Not for everyone, their crypto is GPL only and GPL can't be deployed everywhere. GPL code can be used anywhere; GPL code cannot be made proprietary.

Well, no. You could have a situation where there's a policy in place forbidding installing GPL-licensed products. (I don't have any info about it, but I wouldn't be surprised if that was the case at Microsoft a while ago.) EDIT: I'm getting downvotes and don't understand why. I'm seriously interested, can someone explain the reason?

That's the fault of the people making that policy, not the fault of the people licensing the code under GPL.

Re: Moxie Marlinspike Makes Encryption for Everyone

#14
post #6

Earlier quoted context omitted.

> Not for everyone, their crypto is GPL only and GPL can't be deployed everywhere. GPL code can be used anywhere; GPL code cannot be made proprietary.

Well, no. You could have a situation where there's a policy in place forbidding installing GPL-licensed products. (I don't have any info about it, but I wouldn't be surprised if that was the case at Microsoft a while ago.) EDIT: I'm getting downvotes and don't understand why. I'm seriously interested, can someone explain the reason?

> You could have a situation where there's a policy in place forbidding installing GPL-licensed products.

You might have situation with policies forbidding anything. Like, MS Windows. Or Macs. Or smartphones. Rarely, yes, but I'm surprised GPL looks that unique regarding this matter.

Re: Moxie Marlinspike Makes Encryption for Everyone

#15

Not for people who don't want Google on their device. He only wants distribution via Google, and even went as far to demand that free/libre Play-alternative F-droid removed their build of TextSecure. See: https://fdroid.eutopia.cz/

Huge deal breaker for me, regrettably.

You might want to try this then:

https://github.com/Spark-Innovations/SC4

Re: Moxie Marlinspike Makes Encryption for Everyone

#16
post #11

Oh the irony of an article about encryption on a site sans encryption.

Its incredibly hard for publishers to do https, where main revenue is from serving third party content embedded inside. Wired has nice article about their efforts going https https://www.wired.com/2016/04/wired-launching-https-security...

Nice article. Thanks, dbalan!

Re: Moxie Marlinspike Makes Encryption for Everyone

#17
post #9

Not for people who don't want Google on their device. He only wants distribution via Google, and even went as far to demand that free/libre Play-alternative F-droid removed their build of TextSecure. See: https://fdroid.eutopia.cz/

Here is moxie's reply in that matter https://news.ycombinator.com/item?id=10665520

I don't buy his arguments. It's one thing to say we have to be on Google Play Store or we have to use phone numbers despite the privacy implications because that is what people use. But ignoring much of the developing countries (see whatsapp), China or the people who are your strongest user base by saying "you can just" isn't pragmatic at all.

Nor is it actually reasonable that we should expect to or rely on a few people to secure something that should be a fundamental and a fundamental right of communication. Not to rant to much, but it feels like going to parties (conferences) and talking about how much good you do and then being dismissive in the real world is how much of the security industry operates and that Signal has just become the latest excuse to why nothing has to be fixed.

I'll give him credit for the whatsapp integration though. More people in the field should consider working with companies where they can have a lot of impact.

Re: Moxie Marlinspike Makes Encryption for Everyone

#18
post #9

Not for people who don't want Google on their device. He only wants distribution via Google, and even went as far to demand that free/libre Play-alternative F-droid removed their build of TextSecure. See: https://fdroid.eutopia.cz/

Here is moxie's reply in that matter https://news.ycombinator.com/item?id=10665520

I can understand that he sets his own priorities. But in this case someone else took the sourcecode, built the app and published it to F-Droid.

The only thing Moxie had to do was not threaten them with legal action.

Re: Moxie Marlinspike Makes Encryption for Everyone

#19

Oh the irony of an article about encryption on a site sans encryption.

Huh? I'm connecting over HTTPS right now. Have you tried it?

When I try, I get a certificate that expired 5 months ago.

www.popsci.com uses an invalid security certificate. The certificate expired on 12/10/2015 05:59 PM. The current time is 05/11/2016 01:39 AM. Error code: SEC_ERROR_EXPIRED_CERTIFICATE

Re: Moxie Marlinspike Makes Encryption for Everyone

#20

Oh the irony of an article about encryption on a site sans encryption.

Huh? I'm connecting over HTTPS right now. Have you tried it?

I don't get HTTPS :( http://i.imgur.com/TByP8XM.png?1

dbalan's explanation is quite legit. Hope they get there.

Post reply on HN