Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

51–60 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#51
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

[deleted]

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#52
post #37
post #34

Earlier quoted context omitted.

Because some of us don't want to use Chrome? How is vendor lock-in at the browser level any better than at the OS or device level?

The script above basically acts like a wrapper script, launching in a small square chromeless window. So you don't even need to use Chrome, just launch that at startup so it runs in the background. Small software companies have to make platform decisions. They chose the most popular browser (and notably most secure browser), allowing the app to work on all OSes.

I don't think you completely get how some of us feel about chrome.

Chrome is a good, modern browser but this constant pushing by google (telling me to download a "better browser" when I'm visiting their site in Firefox) as well as every lazy web developer annoys me (seriously, at least consider if you should test basic functionality in all major browsers even if you aren't directly paid for it) .

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#53
post #50

Earlier quoted context omitted.

WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages, no real ability for the servers to do anything smart, no real search functionality, desktop client that requires the phone to be on, etc. An incognito mode allows the default mode to have more functionality, and matches their approach with Chrome. It's not a bad tradeoff.

I don't get why encryption and incognito (not leaving a trace on the device) go together. I should be able to have one without the other.

Did you watch what Allo does? In its normal mode it couldn't possibly function with end-to-end encryption. They also have encryption to and from the server in the middle when you aren't in that mode.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#54
post #45

Earlier quoted context omitted.

Moxie replied in this Forbes article: http://www.forbes.com/sites/thomasbrewster/2016/05/11/wire-s...

That isn't quite a reply. It's a second hand account of Moxie denying that he asked for money. This story seems very troubling. The Wire guys made very specific claims (where did they get the >$2M figure from ... and why would they simply invent such a figure). If their implementation is in Rust then it cannot be the same as OWS' code. It would be good if OWS could publicly clarify that reimplementing the Signal Prot…

So, https://github.com/WhisperSystems/libsignal-protocol-c is GPL3.

If I implement haskell-signal and consult documentation and the code to understand the protocol but do not copy code, it's not clean room, but Open Whisper wants to see the protocol spread, so it's in their interest to more clearly state how someone is allowed to reimplement Signal in Common Lisp or FORTH, if one were so inclined, and release it under MIT.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#55
post #32

Earlier quoted context omitted.

Matrix uses the same encryption protocol but is also federated, which is nice.

And interesting enough, Matrix faces a different problem than Signal: It doesn't have many good clients at all (at least, last I had checked a few months back). I will agree it would be very nice if Matrix was the dominant messaging protocol that everyone needed to speak with their friends. However, that's not feasible until somebody makes an easy-to-use, beautiful Android and iOS client that doesn't require the user…

I have no experience with iOS anything, but at least the Matrix Console Android client is pretty good for what I use it for. It even supports multiple simultaneous accounts which I really appreciate. I believe the iOS version of it is very similar.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#56
post #50

Earlier quoted context omitted.

I don't get why encryption and incognito (not leaving a trace on the device) go together. I should be able to have one without the other.

Did you watch what Allo does? In its normal mode it couldn't possibly function with end-to-end encryption. They also have encryption to and from the server in the middle when you aren't in that mode.

Incognito is a useful feature. E2E encryption is a useful feature.

There's no reason to only allow those two features to be used together. You could have them both turned off by default, and have three modes, one which turns on E2E and one which turns on incognito.

Also, the incognito decision should be made by each side independently. Just because I want to delete my traces doesn't mean my partner does.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#59
post #23

Earlier quoted context omitted.

Skype is the last major messaging platform to not have end-to-end encryption in any way.

No, only WhatsApp has it. Facebook Messenger doesn't, SMS doesn't.

There's an option for SMS: https://silence.im/

(Yup, that's a TextSecure fork before Moxie had dropped encrypted SMS support.)

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#60
post #38

I really wonder what the people of allo.im are thinking now.

Whoa, I wonder what the story is there. Did Google know this allo.im existed before naming their thing?

I suspect they don't care. And I'm guessing allo.im will get booted from the Play Store for using the same name as a Google product.
Post reply on HN