Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

41–50 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#41

To me it seems like Open Whisper Systems are accepting a lot of concessions in order to have Signal included into products. The trust I once had for moxie is quickly dissipating. * Privacy is only provided in Allo in a secondary mode. Not by default. * Federation of the Signal protocol has been rejected for non-technical reasons. Also, on a personal note, the desktop client requiring chrome is pretty awful.

WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages, no real ability for the servers to do anything smart, no real search functionality, desktop client that requires the phone to be on, etc.

An incognito mode allows the default mode to have more functionality, and matches their approach with Chrome. It's not a bad tradeoff.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#42
post #23
post #2

This is fantastic news. The two largest messaging platforms on the Internet will both be using Signal protocol. I could ask for more: E2E could be the default for Allo, and it isn't. That's not great. But the E2E you get when you ask for it will apparently be best-in-class.

Skype is the last major messaging platform to not have end-to-end encryption in any way.

No, only WhatsApp has it. Facebook Messenger doesn't, SMS doesn't.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#43
post #33

To me it seems like Open Whisper Systems are accepting a lot of concessions in order to have Signal included into products. The trust I once had for moxie is quickly dissipating. * Privacy is only provided in Allo in a secondary mode. Not by default. * Federation of the Signal protocol has been rejected for non-technical reasons. Also, on a personal note, the desktop client requiring chrome is pretty awful.

> on a personal note, the desktop client requiring chrome is pretty awful. Why? I haven't had any issues with it. I even have a shortcut on linux for dmenu, typing "signal" opens the chrome extension URL, opening the app in a new popup window (not a full browser, just the app in a chromeless window). So it functions just like a normal app to me. This is the `signal` bash script: #!/usr/bin/dash /opt/google/chrome-uns…

To me it is personally annoying because so many people and esp developers seems to want Chrome to become the new IE: a subpar (yeah, until google give you nested vertical tabs ;-) browser that web developers have fallen in love with to the point where they forget anything else.

Anything that reinforces this automatically qualifies as bad (and I'm only partially joking here ;-)

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#44
post #15

What I'm curious about, and think would be really neat, is if one could take advantage of the shared Signal Protocol to send messages cross-platform. Specifically, sending an encrypted message to a Whatsapp user from Allo. Or to a Signal user from Whatsapp. Or any combination/permutation really.

My understanding is that the Signal protocol isn't an IM protocol like XMPP, but a messaging protocol like OTR. Just like you can use OTR with XMPP, Signal can work be used inside IM protocols like Matrix and XMPP. Or with proprietary ones like WhatsApp, Allo, and Signal itself. The former provides federation, the latter do not.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#45
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

Moxie replied in this Forbes article: http://www.forbes.com/sites/thomasbrewster/2016/05/11/wire-s...

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#46
post #32

To me it seems like Open Whisper Systems are accepting a lot of concessions in order to have Signal included into products. The trust I once had for moxie is quickly dissipating. * Privacy is only provided in Allo in a secondary mode. Not by default. * Federation of the Signal protocol has been rejected for non-technical reasons. Also, on a personal note, the desktop client requiring chrome is pretty awful.

Matrix uses the same encryption protocol but is also federated, which is nice.

Matrix uses an encryption protocol of their own devising that employs the double ratchet, which is one component of Signal Protocol. But it's not Signal Protocol, it's their own thing.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#47
post #45
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

Moxie replied in this Forbes article: http://www.forbes.com/sites/thomasbrewster/2016/05/11/wire-s...

[deleted]

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#49
post #45
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

Moxie replied in this Forbes article: http://www.forbes.com/sites/thomasbrewster/2016/05/11/wire-s...

That isn't quite a reply. It's a second hand account of Moxie denying that he asked for money. This story seems very troubling. The Wire guys made very specific claims (where did they get the >$2M figure from ... and why would they simply invent such a figure). If their implementation is in Rust then it cannot be the same as OWS' code.

It would be good if OWS could publicly clarify that reimplementing the Signal Protocol/Axoltl does not trigger any copyright claims by OWS even if doing so involved reading the GPLd version.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#50

To me it seems like Open Whisper Systems are accepting a lot of concessions in order to have Signal included into products. The trust I once had for moxie is quickly dissipating. * Privacy is only provided in Allo in a secondary mode. Not by default. * Federation of the Signal protocol has been rejected for non-technical reasons. Also, on a personal note, the desktop client requiring chrome is pretty awful.

WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages, no real ability for the servers to do anything smart, no real search functionality, desktop client that requires the phone to be on, etc. An incognito mode allows the default mode to have more functionality, and matches their approach with Chrome. It's not a bad tradeoff.

I don't get why encryption and incognito (not leaving a trace on the device) go together. I should be able to have one without the other.
Post reply on HN