Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

61–70 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#61
post #50

Earlier quoted context omitted.

WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages, no real ability for the servers to do anything smart, no real search functionality, desktop client that requires the phone to be on, etc. An incognito mode allows the default mode to have more functionality, and matches their approach with Chrome. It's not a bad tradeoff.

I don't get why encryption and incognito (not leaving a trace on the device) go together. I should be able to have one without the other.

They wouldn't be able to insert a chat bot to all of your conversations if they were all end to end encrypted. I agree it's a good trade-off

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#62
post #18

Why didn't Google just develop this in house? It almost feels like they're admitting to having no credibility on privacy without an external partner.

I'd distinctly trust it more because Google didn't create it.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#63
post #56

Earlier quoted context omitted.

Did you watch what Allo does? In its normal mode it couldn't possibly function with end-to-end encryption. They also have encryption to and from the server in the middle when you aren't in that mode.

Incognito is a useful feature. E2E encryption is a useful feature. There's no reason to only allow those two features to be used together. You could have them both turned off by default, and have three modes, one which turns on E2E and one which turns on incognito. Also, the incognito decision should be made by each side independently. Just because I want to delete my traces doesn't mean my partner does.

I think this is a terminology issue - from what's been said elsewhere the only two differences in incognito mode is that it is E2E and doesn't show messages on your lockscreen.

It's not ephemeral messaging like Snapchat or something, although they are discussing it as a future feature.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#64
post #56

Earlier quoted context omitted.

Incognito is a useful feature. E2E encryption is a useful feature. There's no reason to only allow those two features to be used together. You could have them both turned off by default, and have three modes, one which turns on E2E and one which turns on incognito. Also, the incognito decision should be made by each side independently. Just because I want to delete my traces doesn't mean my partner does.

I think this is a terminology issue - from what's been said elsewhere the only two differences in incognito mode is that it is E2E and doesn't show messages on your lockscreen. It's not ephemeral messaging like Snapchat or something, although they are discussing it as a future feature.

I followed the arstechnica liveblog. http://live.arstechnica.com/google-io-2016-keynote/#post-885...

>Incognito also offers message expiration. When you close incognito mode, your message is gone forever.

I assumed that was accurate. Did they misrepresent it somehow?

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#65
post #50

Earlier quoted context omitted.

I don't get why encryption and incognito (not leaving a trace on the device) go together. I should be able to have one without the other.

They wouldn't be able to insert a chat bot to all of your conversations if they were all end to end encrypted. I agree it's a good trade-off

But why not allow E2E without incognito? Have both as separate options.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#66
post #65

Earlier quoted context omitted.

They wouldn't be able to insert a chat bot to all of your conversations if they were all end to end encrypted. I agree it's a good trade-off

But why not allow E2E without incognito? Have both as separate options.

Probably because proliferation of options is bad for UX for most user types and bad for uptake, and "incognito" is what they've named the package of privacy-related options, including E2E.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#67
post #56

Earlier quoted context omitted.

Did you watch what Allo does? In its normal mode it couldn't possibly function with end-to-end encryption. They also have encryption to and from the server in the middle when you aren't in that mode.

Incognito is a useful feature. E2E encryption is a useful feature. There's no reason to only allow those two features to be used together. You could have them both turned off by default, and have three modes, one which turns on E2E and one which turns on incognito. Also, the incognito decision should be made by each side independently. Just because I want to delete my traces doesn't mean my partner does.

> There's no reason to only allow those two features to be used together.

UX simplicity is, in fact, a reason.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#68
post #45

Earlier quoted context omitted.

Moxie replied in this Forbes article: http://www.forbes.com/sites/thomasbrewster/2016/05/11/wire-s...

That isn't quite a reply. It's a second hand account of Moxie denying that he asked for money. This story seems very troubling. The Wire guys made very specific claims (where did they get the >$2M figure from ... and why would they simply invent such a figure). If their implementation is in Rust then it cannot be the same as OWS' code. It would be good if OWS could publicly clarify that reimplementing the Signal Prot…

https://twitter.com/moxie/status/730230490653851648

https://twitter.com/moxie/status/730230320553828352

The Wire guys also withdrew the complaint.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#69
post #56

Earlier quoted context omitted.

Incognito is a useful feature. E2E encryption is a useful feature. There's no reason to only allow those two features to be used together. You could have them both turned off by default, and have three modes, one which turns on E2E and one which turns on incognito. Also, the incognito decision should be made by each side independently. Just because I want to delete my traces doesn't mean my partner does.

> There's no reason to only allow those two features to be used together. UX simplicity is, in fact, a reason.

Then have the default incognito be as described, with an option in settings to separate the two features.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#70
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

You have this story backwards and you should correct your post. Moxie and OWS didn't threaten to sue Wire. Wire sued Open Whisper Systems. That suit made, but did not substantiate, a claim that OWS asked for money. OWS denies that. I believe OWS, and not Wire.

The genesis of this claim comes from Wire having used GPL'd OWS code, apparently for the Signal protocol, without complying with the GPL. OWS demanded that Wire comply with the GPL.

Apparently, upon being told that they would be required to comply with the GPL, they inquired instead about dual-licensing. That's standard practice when a company adopts GPL code for their own product but doesn't want to comply with the GPL: they instead have to pay for a private license.

Instead of paying for a private license, Wire has apparently chosen to comply with the GPL instead, and withdrawn their complaint. I think that was the right choice.

The knives are definitely out for Signal now that its importance is being recognized by a wider audience. Complaints about Signal are, unsurprisingly, getting dumber and more venomous. For instance, last week, Nadim Kobeissi (the author of Cryptocat, a competing secure messaging system that I think you should avoid) was on Twitter talking about how impossible a GPL violation could have been given that Wire's Signal implementation is in Rust.

Post reply on HN