Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

111–120 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#111
post #106

Earlier quoted context omitted.

This cultural reference I get even less than the first one, but I'll just ignore the references. I'm not sure if you're missing the context. This branch of the thread forked off me asking the same thing as another poster, namely the likelihood of being bothered by IP or Copyright claims for a real, proper clean room implementation of the protocol, zero code copied, assuming there is sufficient documentation available…

Sorry, I'm just eager to deploy Frinkiac. I simply disagree with you that Moxie Marlinspike is in any way accountable for what Oracle does with Java. I also take exception to the argument that Open Whisper Systems needs to do something to mitigate your false impression that they've disallowed developers from using their documentation. They have not, nobody has credibly claimed otherwise, even the Wire people, and so…

> accountable for what Oracle does with Java

Maybe my English is imprecise, but that's not what I tried to express. We may have to disagree that the OracleVsGoogle fallout is relevant in the hypothetical case of Axolotl IP, but as we're both not lawyers, it's moot to continue that debate.

> I don't think it's proper to suggest

It wouldn't cost Moxie anything to clear such concerns, even if it's just a handful of HN reader (including me), in light of this public event and would increase the positive profile of the protocol. You make it seem like by documenting that clearly Moxie would admit to doing something, but that's wrong and a curious way to look at things, especially as you're confident of there being no problem like that.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#112
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

According to https://twitter.com/moxie/status/730289041493483520 Moxie is fine with reimplementations.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#113
post #38

Earlier quoted context omitted.

Whoa, I wonder what the story is there. Did Google know this allo.im existed before naming their thing?

I suspect they don't care. And I'm guessing allo.im will get booted from the Play Store for using the same name as a Google product.

It's not in the US playstore, so it obviously doesn't exist.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#114
post #84

Earlier quoted context omitted.

> Complaints about Signal are, unsurprisingly, getting dumber and more venomous. For instance, last week, Nadim Kobeissi (the author of Cryptocat, a competing secure messaging system that I think you should avoid) was on Twitter talking about how impossible a GPL violation could have been given that Wire's Signal implementation is in Rust. Given that I'm mentioned by name (and tied to a bunch of exaggerated claims),…

You're the author of a secure messaging system who is, to put it lightly, notorious for throwing shade on other people's secure messaging projects. This comment is a perfect example: OWS demanded that Wire comply with the GPL, and you've declared that "drama", and suggested that Wire was somehow "not allowed" to port it to Rust. Your messages on Twitter are right there for everyone to read. Here's a helpful starting…

These kinds of arguments may have force on Reddit, but they're verboten on HN. You need to engage the argument itself and not try to dredge things up about the arguer.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#115
post #65

Earlier quoted context omitted.

They wouldn't be able to insert a chat bot to all of your conversations if they were all end to end encrypted. I agree it's a good trade-off

But why not allow E2E without incognito? Have both as separate options.

It seems to me that it's simpler to understand. If you really want to keep something a secret, it's probably not a good idea to keep a copy on your (or their) phone.

Providing separate options would make it easier to make mistakes.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#116
post #2

This is fantastic news. The two largest messaging platforms on the Internet will both be using Signal protocol. I could ask for more: E2E could be the default for Allo, and it isn't. That's not great. But the E2E you get when you ask for it will apparently be best-in-class.

WhatsApp is pretty big, but I doubt Google is even now second before Facebook, WeChat or QQ. Unless you include e-mail, but that isn't being encrypted as I understand.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#117
post #65

Earlier quoted context omitted.

But why not allow E2E without incognito? Have both as separate options.

It seems to me that it's simpler to understand. If you really want to keep something a secret, it's probably not a good idea to keep a copy on your (or their) phone. Providing separate options would make it easier to make mistakes.

Pretty much no other E2E app feels the same way, and certainly doesn't enforce that.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#118
post #85
post #77

Earlier quoted context omitted.

You kinda repeat yourself here, and it's not really a response to my post here. I found the answer from a sibling post: https://twitter.com/moxie/status/730289041493483520 Moxie should use this incident to prominently make it clear in the protocol documentation that independent implementations are welcome. That's our best bet until there's an IETF RFC based on Axolotol everyone can implement instead.

Since nobody has provided any evidence that OWS ever suggested that using their documentation was improper, you might just as well suggest Moxie use this "incident" as an opportunity to announce that he's stopped beating his wife.

I've been pretty quiet about this, but over the last couple of months I have been trying to negotiate with Moxie a way to distribute the GPL licensed AxolotlKit on the iOS App Store in ChatSecure (which is open source). After being denied a license, I was told by Moxie that I would be unable to write a non-GPL AxolotlV3 implementation because there is not publicly available documentation, and that any re-implementation will necessarily be a derivative work because the source code must be consulted. You may notice the AxolotlV2 documentation has been removed... and there was never documentation for AxolotlV3. The only public spec is the original double ratchet, and a few blog posts, which don't include things like signed prekeys and 4-way DH.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#119
post #90
post #88

Earlier quoted context omitted.

"Impossible" is a tough standard to meet. But given how different idiomatic Java code and idiomatic Rust code are, it does seem kind of unlikely. I'd expect nothing at all would carry over from one codebase to the other even if you were making as straight a port as possible. Or alternatively one program would look like total garbage, like someone mechanically translating Lisp to C. And indeed, with a quick browse thr…

The very code you linked to settles this: // Based on libsignal-protocol-java by Open Whisper Systems

[deleted]

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#120
post #46
post #32

Earlier quoted context omitted.

Matrix uses the same encryption protocol but is also federated, which is nice.

Matrix uses an encryption protocol of their own devising that employs the double ratchet, which is one component of Signal Protocol. But it's not Signal Protocol, it's their own thing.

Yup, just to reinforce from the Matrix side: Olm is an independent E2E protocol which happens to implement the double ratchet (formerly known as the axolotl ratchet), but it's not Signal Protocol and it's increasingly divergent from Signal, and it's completely independent of Open Whisper Systems. For instance, we're defining different behaviour for group chat ratchets, called Megolm, following our own design at http://matrix.org/speculator/spec/drafts%2Fe2e/client_server....

That said, we've tried to architect it such that we could implement compatibility with Signal if Moxie and OWS were ever open to it. But it looks like we'll need to first prove that Matrix can support a rapidly evolving yet federated ecosystem without compromising UX or privacy :)

Post reply on HN