Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

81–90 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#81
post #70
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

You have this story backwards and you should correct your post. Moxie and OWS didn't threaten to sue Wire. Wire sued Open Whisper Systems . That suit made, but did not substantiate, a claim that OWS asked for money. OWS denies that. I believe OWS, and not Wire. The genesis of this claim comes from Wire having used GPL'd OWS code, apparently for the Signal protocol, without complying with the GPL . OWS demanded that W…

> Complaints about Signal are, unsurprisingly, getting dumber and more venomous. For instance, last week, Nadim Kobeissi (the author of Cryptocat, a competing secure messaging system that I think you should avoid) was on Twitter talking about how impossible a GPL violation could have been given that Wire's Signal implementation is in Rust.

Given that I'm mentioned by name (and tied to a bunch of exaggerated claims), I'd like to clarify a few points.

1. I never claimed that a GPL violation was impossible because of different programming languages. I merely questioned whether this was the case with Wire's Rust codebase [0], given that its data structures, namespacing etc. are substantially different from the OWS Java code [1]. To me, different code organization + different implementation style + different programming language don't exactly amount to a line-by-line conversion from Java to Rust as OWS seems to be claiming.

2. Cryptocat does not compete with Signal: it's a desktop XMPP client that focuses on synchronous messaging (that I write in my free time and with no funding or business plan, to boot), and does not at all target the mobile space. I was very happy to adopt a variant of Signal Protocol into Cryptocat and consider Signal's contributions to the field of secure messaging to be highly valuable. I'm not sure why tptacek brings up Cryptocat (completely unrelated to this discussion) but by all means, don't avoid it! The recent rewrite is pretty good, actually.

Overall, this situation just struck me as very ugly. Moxie seemed at some point to be reticent to allow fully independent implementations of the protocol, and Wire's lawsuit was pretty aggressive. Both parties locked in a catfight and then (apparently?) realized their approaches were counterproductive and gave it up.

The best resolution here, in my view, would have been for Moxie to publish a public-domain reference specification document of Signal Protocol that's independent of the code, and for Wire to be allowed to write a Rust implementation of it without any party causing drama.

[0] https://github.com/wireapp/proteus

[1] https://github.com/WhisperSystems/libsignal-protocol-java

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#82
post #70
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

You have this story backwards and you should correct your post. Moxie and OWS didn't threaten to sue Wire. Wire sued Open Whisper Systems . That suit made, but did not substantiate, a claim that OWS asked for money. OWS denies that. I believe OWS, and not Wire. The genesis of this claim comes from Wire having used GPL'd OWS code, apparently for the Signal protocol, without complying with the GPL . OWS demanded that W…

I'd like to learn some possible reasons why one should avoid cryptocat, is there any material you could link for further reading?

Thank you

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#83
post #69

Earlier quoted context omitted.

> There's no reason to only allow those two features to be used together. UX simplicity is, in fact, a reason.

Then have the default incognito be as described, with an option in settings to separate the two features.

I don't think you've thought this through.

If one side enabled this "use E2E encryption for everything" feature, then the other side would presumably no longer have access to any of the smart assistant features. And it would not be obvious why.

Additionally, it would be hard to explain why you'd ever want to enable such a feature which means nobody would do it. I suspect you want default E2E encryption for political reasons. Such things don't work unless it's on by default.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#84
post #70

Earlier quoted context omitted.

You have this story backwards and you should correct your post. Moxie and OWS didn't threaten to sue Wire. Wire sued Open Whisper Systems . That suit made, but did not substantiate, a claim that OWS asked for money. OWS denies that. I believe OWS, and not Wire. The genesis of this claim comes from Wire having used GPL'd OWS code, apparently for the Signal protocol, without complying with the GPL . OWS demanded that W…

> Complaints about Signal are, unsurprisingly, getting dumber and more venomous. For instance, last week, Nadim Kobeissi (the author of Cryptocat, a competing secure messaging system that I think you should avoid) was on Twitter talking about how impossible a GPL violation could have been given that Wire's Signal implementation is in Rust. Given that I'm mentioned by name (and tied to a bunch of exaggerated claims),…

You're the author of a secure messaging system who is, to put it lightly, notorious for throwing shade on other people's secure messaging projects. This comment is a perfect example: OWS demanded that Wire comply with the GPL, and you've declared that "drama", and suggested that Wire was somehow "not allowed" to port it to Rust.

Your messages on Twitter are right there for everyone to read.

Here's a helpful starting point:

https://twitter.com/kaepora/status/730165751240364033

The preceding link where you referred, unbidden, to Moxie's last post about their take on federation for their own implementation of Signal as a "dishonest rant" is left as an exercise for the reader.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#85
post #77
post #71

Earlier quoted context omitted.

That's not what happened. Wire didn't consult OWS documentation. They used the code itself, and (apparently) baked it into a closed-source product. How much sympathy am I meant to have for those people?

You kinda repeat yourself here, and it's not really a response to my post here. I found the answer from a sibling post: https://twitter.com/moxie/status/730289041493483520 Moxie should use this incident to prominently make it clear in the protocol documentation that independent implementations are welcome. That's our best bet until there's an IETF RFC based on Axolotol everyone can implement instead.

Since nobody has provided any evidence that OWS ever suggested that using their documentation was improper, you might just as well suggest Moxie use this "incident" as an opportunity to announce that he's stopped beating his wife.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#86
post #17
post #15

What I'm curious about, and think would be really neat, is if one could take advantage of the shared Signal Protocol to send messages cross-platform. Specifically, sending an encrypted message to a Whatsapp user from Allo. Or to a Signal user from Whatsapp. Or any combination/permutation really.

Moxie's on the record as being opposed to federated services. https://whispersystems.org/blog/the-ecosystem-is-moving/

I don't think he's opposed to it, he just recognises that in practice federation and open protocols impose large hidden costs that are typically undiscussed and unrecognised.

Federation between WhatsApp and Allo would face some obvious problems: features that don't work the same way or don't work at all, for instance. Moxie's point is that federation is just less important than it once was because there's no real lockin due to the pervasive use of phone numbers as identities. There's no real reason to use Allo to send message to a WhatsApp user or vice versa given you can just install both apps for free anyway.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#87
post #69

Earlier quoted context omitted.

Then have the default incognito be as described, with an option in settings to separate the two features.

I don't think you've thought this through. If one side enabled this "use E2E encryption for everything" feature, then the other side would presumably no longer have access to any of the smart assistant features. And it would not be obvious why. Additionally, it would be hard to explain why you'd ever want to enable such a feature which means nobody would do it. I suspect you want default E2E encryption for political…

>If one side enabled this "use E2E encryption for everything" feature

That's not what I'm suggesting. I want E2E to be separate from the "delete chats when I'm finished" feature.

Wanting an E2E chat that stays on my device when I'm done should be fine.

I'm fine with having E2E require a separate mode, but that shouldn't be bundled with the incognito feature of not remembering history.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#88
post #70
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

You have this story backwards and you should correct your post. Moxie and OWS didn't threaten to sue Wire. Wire sued Open Whisper Systems . That suit made, but did not substantiate, a claim that OWS asked for money. OWS denies that. I believe OWS, and not Wire. The genesis of this claim comes from Wire having used GPL'd OWS code, apparently for the Signal protocol, without complying with the GPL . OWS demanded that W…

"Impossible" is a tough standard to meet. But given how different idiomatic Java code and idiomatic Rust code are, it does seem kind of unlikely. I'd expect nothing at all would carry over from one codebase to the other even if you were making as straight a port as possible. Or alternatively one program would look like total garbage, like someone mechanically translating Lisp to C.

And indeed, with a quick browse through the Wire [0] and OWS [1] repositories I just can't find any kind of commonalities at all. Not in the structure, not in the comments, not in naming, not in the data structures, etc. Am I missing something, is there anything at all in the code itself that suggests the two codebases are related in any way at all? Or is the "GPL's OWS code" you refer to something else entirely?

[0] https://github.com/wireapp/proteus/tree/develop/src/intern

[1] https://github.com/WhisperSystems/libsignal-protocol-java/tr...

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#89
post #70

Earlier quoted context omitted.

You have this story backwards and you should correct your post. Moxie and OWS didn't threaten to sue Wire. Wire sued Open Whisper Systems . That suit made, but did not substantiate, a claim that OWS asked for money. OWS denies that. I believe OWS, and not Wire. The genesis of this claim comes from Wire having used GPL'd OWS code, apparently for the Signal protocol, without complying with the GPL . OWS demanded that W…

I'd like to learn some possible reasons why one should avoid cryptocat, is there any material you could link for further reading? Thank you

I am the original author of the software you refer to. Before its complete rewrite (released two months ago), Cryptocat was based on a codebase that I wrote starting in my early undergrad and that was notorious for containing many high-severity vulnerabilities. The most important was "Decryptocat", documented by Steve Thomas [0] but we also had:

* AES-CTR counter-reuse (2012)

* Biased Fortuna CSPRNG implementation [1] (2013)

To be sure, Cryptocat's substandard reputation was well-deserved; but all the same, I think that every vulnerability that did pop up was addressed responsibly and with full disclosure.

Since then, there has been a major rewrite that I am conversely quite happy with.

[0] https://tobtu.com/decryptocat.php

[1] https://nakedsecurity.sophos.com/2013/07/09/anatomy-of-a-pse...

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#90
post #88
post #70

Earlier quoted context omitted.

You have this story backwards and you should correct your post. Moxie and OWS didn't threaten to sue Wire. Wire sued Open Whisper Systems . That suit made, but did not substantiate, a claim that OWS asked for money. OWS denies that. I believe OWS, and not Wire. The genesis of this claim comes from Wire having used GPL'd OWS code, apparently for the Signal protocol, without complying with the GPL . OWS demanded that W…

"Impossible" is a tough standard to meet. But given how different idiomatic Java code and idiomatic Rust code are, it does seem kind of unlikely. I'd expect nothing at all would carry over from one codebase to the other even if you were making as straight a port as possible. Or alternatively one program would look like total garbage, like someone mechanically translating Lisp to C. And indeed, with a quick browse thr…

The very code you linked to settles this:

// Based on libsignal-protocol-java by Open Whisper Systems

Post reply on HN