Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

71–80 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#71
post #54

Earlier quoted context omitted.

That isn't quite a reply. It's a second hand account of Moxie denying that he asked for money. This story seems very troubling. The Wire guys made very specific claims (where did they get the >$2M figure from ... and why would they simply invent such a figure). If their implementation is in Rust then it cannot be the same as OWS' code. It would be good if OWS could publicly clarify that reimplementing the Signal Prot…

So, https://github.com/WhisperSystems/libsignal-protocol-c is GPL3. If I implement haskell-signal and consult documentation and the code to understand the protocol but do not copy code, it's not clean room, but Open Whisper wants to see the protocol spread, so it's in their interest to more clearly state how someone is allowed to reimplement Signal in Common Lisp or FORTH, if one were so inclined, and release it unde…

That's not what happened. Wire didn't consult OWS documentation. They used the code itself, and (apparently) baked it into a closed-source product. How much sympathy am I meant to have for those people?

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#72
post #45

Earlier quoted context omitted.

Moxie replied in this Forbes article: http://www.forbes.com/sites/thomasbrewster/2016/05/11/wire-s...

That isn't quite a reply. It's a second hand account of Moxie denying that he asked for money. This story seems very troubling. The Wire guys made very specific claims (where did they get the >$2M figure from ... and why would they simply invent such a figure). If their implementation is in Rust then it cannot be the same as OWS' code. It would be good if OWS could publicly clarify that reimplementing the Signal Prot…

Here's an article including first hand account and quotes from Moxie: http://news.softpedia.com/news/wire-drops-lawsuit-alleging-e...

IMHO, no credence should be given to lawsuits and accusations made without proof and right before OWS integrates with two huge partners. The accuser even filed a voluntary notice of dismissal with prejudice. Accusations without proof are just mudslinging.

Moxie has a great track record; the burden of proof is on the accuser, not the defendant.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#73
post #45

Earlier quoted context omitted.

Moxie replied in this Forbes article: http://www.forbes.com/sites/thomasbrewster/2016/05/11/wire-s...

That isn't quite a reply. It's a second hand account of Moxie denying that he asked for money. This story seems very troubling. The Wire guys made very specific claims (where did they get the >$2M figure from ... and why would they simply invent such a figure). If their implementation is in Rust then it cannot be the same as OWS' code. It would be good if OWS could publicly clarify that reimplementing the Signal Prot…

> The Wire guys made very specific claims (where did they get the >$2M figure from ... and why would they simply invent such a figure).

Their court filing[0] says the license fee was "unspecified" and the $2 million figure was based on "information and belief" which is legal terminology used to dodge perjury[1]. If they had really been told that, they wouldn't be using terms that mean "I heard that from somewhere second-hand and think it might be true".

[0] https://www.scribd.com/doc/311974670/Wire-Swiss-GmbH-v-Quiet...

[1] https://www.law.cornell.edu/wex/information_and_belief

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#74

I really wonder what the people of allo.im are thinking now.

That app didn't exist until May 15th, and all the reviews for it are incredibly poor (as in, had zero functionality at all). I'd bet someone got an early leak of the name for Google's new messaging product, and tried to make a quick product and domain registration, so they can get tossed a few bucks when Google needs to buy the domain.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#75
post #64

Earlier quoted context omitted.

I think this is a terminology issue - from what's been said elsewhere the only two differences in incognito mode is that it is E2E and doesn't show messages on your lockscreen. It's not ephemeral messaging like Snapchat or something, although they are discussing it as a future feature.

I followed the arstechnica liveblog. http://live.arstechnica.com/google-io-2016-keynote/#post-885... >Incognito also offers message expiration. When you close incognito mode, your message is gone forever. I assumed that was accurate. Did they misrepresent it somehow?

Possibly - the two sites I've seen with "hands-ons" do not mention this anywhere.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#76
post #70
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

You have this story backwards and you should correct your post. Moxie and OWS didn't threaten to sue Wire. Wire sued Open Whisper Systems . That suit made, but did not substantiate, a claim that OWS asked for money. OWS denies that. I believe OWS, and not Wire. The genesis of this claim comes from Wire having used GPL'd OWS code, apparently for the Signal protocol, without complying with the GPL . OWS demanded that W…

Thanks, amended my post.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#77
post #71
post #54

Earlier quoted context omitted.

So, https://github.com/WhisperSystems/libsignal-protocol-c is GPL3. If I implement haskell-signal and consult documentation and the code to understand the protocol but do not copy code, it's not clean room, but Open Whisper wants to see the protocol spread, so it's in their interest to more clearly state how someone is allowed to reimplement Signal in Common Lisp or FORTH, if one were so inclined, and release it unde…

That's not what happened. Wire didn't consult OWS documentation. They used the code itself, and (apparently) baked it into a closed-source product. How much sympathy am I meant to have for those people?

You kinda repeat yourself here, and it's not really a response to my post here.

I found the answer from a sibling post: https://twitter.com/moxie/status/730289041493483520

Moxie should use this incident to prominently make it clear in the protocol documentation that independent implementations are welcome. That's our best bet until there's an IETF RFC based on Axolotol everyone can implement instead.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#78
post #33

Earlier quoted context omitted.

> on a personal note, the desktop client requiring chrome is pretty awful. Why? I haven't had any issues with it. I even have a shortcut on linux for dmenu, typing "signal" opens the chrome extension URL, opening the app in a new popup window (not a full browser, just the app in a chromeless window). So it functions just like a normal app to me. This is the `signal` bash script: #!/usr/bin/dash /opt/google/chrome-uns…

I don't use chrome for a number of reasons, the main one being I can't imagine using a browser which doesn't support the blocking of ads, and on Android there are no plugins at all, and given that I use firefox on multiple desktops, all syncing passwords, tabs etc, I'm not about to make an exception for this or that chrome-only feature. I have no idea why chrome doesn't support plugins on Android; they said they'd do…

Why would you have to use Chrome? You just need Chrome as a platform to launch your chrome app...

I don't get it

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#79
post #64

Earlier quoted context omitted.

I followed the arstechnica liveblog. http://live.arstechnica.com/google-io-2016-keynote/#post-885... >Incognito also offers message expiration. When you close incognito mode, your message is gone forever. I assumed that was accurate. Did they misrepresent it somehow?

Possibly - the two sites I've seen with "hands-ons" do not mention this anywhere.

http://www.wsj.com/articles/google-takes-on-apple-facebook-w... (https://archive.is/ELitC for paywall)

>All chats will be encrypted, but a special incognito mode will have an end-to-end encryption, and expiring chats that are permanently deleted once you leave them.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#80

To me it seems like Open Whisper Systems are accepting a lot of concessions in order to have Signal included into products. The trust I once had for moxie is quickly dissipating. * Privacy is only provided in Allo in a secondary mode. Not by default. * Federation of the Signal protocol has been rejected for non-technical reasons. Also, on a personal note, the desktop client requiring chrome is pretty awful.

I lament the fact that we're moving more and more to closed chat protocols. Shortly, nothing will work with Pidgin/Adium any more, and it's a shame because it's by far the best way to chat.
Post reply on HN