Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

151–160 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#151

Earlier quoted context omitted.

Nadim had a legitimate and reasonable question. For those who don't know, here was Thomas Ptacek recently joking about Nadim's penis: https://mobile.twitter.com/tqbf/status/705825790529662976 Here he is telling Nadim "go fuck yourself, forever": https://mobile.twitter.com/tqbf/status/705900243313758208 This is unprofessional. That kind of bullying is especially unacceptable coming from someone who has a lot of money…

> I think Hacker News should be better than this. I don't think it should. I think us pretending that we are some group of regal statesmen is a bunch of pretentious bullshit. Being civil is preferable, but not if it means being fake. People aren't any less "mean" on HN, they're just good at bullying in more subtle ways, and we are all worse off for it.

Being civil is preferable, but not if it means being fake.

I don't understand this. Everything is fake to some degree. Being civil is a good thing.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#152
post #65

Earlier quoted context omitted.

They wouldn't be able to insert a chat bot to all of your conversations if they were all end to end encrypted. I agree it's a good trade-off

But why not allow E2E without incognito? Have both as separate options.

What use-case does E2E without incognito address?

* Sharing naked pics on a monitored work network? No - there is at least some chance that your company owns your device, so therefore you want it to disappear from that

* Sharing politically outlawed content? No - you can be compelled to give up your device.

Wanting it "just because" is fine, but simplifying the UI is a pretty valid counter argument too.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#153
post #70

Earlier quoted context omitted.

You have this story backwards and you should correct your post. Moxie and OWS didn't threaten to sue Wire. Wire sued Open Whisper Systems . That suit made, but did not substantiate, a claim that OWS asked for money. OWS denies that. I believe OWS, and not Wire. The genesis of this claim comes from Wire having used GPL'd OWS code, apparently for the Signal protocol, without complying with the GPL . OWS demanded that W…

Nadim had a legitimate and reasonable question. For those who don't know, here was Thomas Ptacek recently joking about Nadim's penis: https://mobile.twitter.com/tqbf/status/705825790529662976 Here he is telling Nadim "go fuck yourself, forever": https://mobile.twitter.com/tqbf/status/705900243313758208 This is unprofessional. That kind of bullying is especially unacceptable coming from someone who has a lot of money…

> I think Hacker News should be better than this.

I'm not sure how linking to twitter supports your comment that HN needs to improve. If he'd said that on HN he'd have been (I assume) banned. dang is constantly asking people not to be mean or dumb, or banning people for being mean.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#154

Earlier quoted context omitted.

Ugh, I hate this phone number as identify business. My pone number changes every time I move and I have to keep paying to have it. I see the benefit to a number that I can easily share but I don't like tying it to the telephone system. I'll keep using something like hangouts that allows me to keep my contacts when I move as well as a number of other benefits.

Why does it change? In my experience most people keep their first cell phone number for their entire lives. Area codes are indicative of nothing, except where you lived in 2005 [1]. [1] https://xkcd.com/1129/

If you move internally within a country, sure. But when you actually move country, you'll need to get a new sim (or be charged roaming fees).

I live in Europe, and I've had 4 different phone numbers in the past 3 years.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#155

Earlier quoted context omitted.

Ugh, I hate this phone number as identify business. My pone number changes every time I move and I have to keep paying to have it. I see the benefit to a number that I can easily share but I don't like tying it to the telephone system. I'll keep using something like hangouts that allows me to keep my contacts when I move as well as a number of other benefits.

Why does it change? In my experience most people keep their first cell phone number for their entire lives. Area codes are indicative of nothing, except where you lived in 2005 [1]. [1] https://xkcd.com/1129/

Changing counties comes to mind.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#156
post #37

Earlier quoted context omitted.

The script above basically acts like a wrapper script, launching in a small square chromeless window. So you don't even need to use Chrome, just launch that at startup so it runs in the background. Small software companies have to make platform decisions. They chose the most popular browser (and notably most secure browser), allowing the app to work on all OSes.

I don't think you completely get how some of us feel about chrome. Chrome is a good, modern browser but this constant pushing by google (telling me to download a "better browser" when I'm visiting their site in Firefox) as well as every lazy web developer annoys me (seriously, at least consider if you should test basic functionality in all major browsers even if you aren't directly paid for it) .

Wish I could remove the "lazy" part, my apologies webdevs!

Still: wish less companies would be fine with shipping web apps that break in one or more of modern browsers.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#157
Come on Nadim. Just shut up. seriously. go whining about ptacek treating you badly again.. because your behaviour isn't any better:

You've been bashing on TextSecure/Signal and it's authors on Twitter and other mediums since you started your own, insecure, javascript IM a few years back. Always promoting your own product along some rather dubious arguments. There has even been a best-of on tumblr of your self-righteous flood of twitter messages, unfortunately it was taken down. Please leave people that are busy working on securing strong crypto-systems alone with your idiot-commentary.

This is getting annoying (for a lot of people). Ignoring you on twitter doesn't seem to be enough.

I'd never work on nor recommend crypto.cat, but if you feel your time is spent well coding on that crap, please do so instead of spreading accusations on twitter on OWS and others all of the time.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#158
post #157

Come on Nadim. Just shut up. seriously. go whining about ptacek treating you badly again.. because your behaviour isn't any better: You've been bashing on TextSecure/Signal and it's authors on Twitter and other mediums since you started your own, insecure, javascript IM a few years back. Always promoting your own product along some rather dubious arguments. There has even been a best-of on tumblr of your self-righteo…

Wow.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#159
post #157

Come on Nadim. Just shut up. seriously. go whining about ptacek treating you badly again.. because your behaviour isn't any better: You've been bashing on TextSecure/Signal and it's authors on Twitter and other mediums since you started your own, insecure, javascript IM a few years back. Always promoting your own product along some rather dubious arguments. There has even been a best-of on tumblr of your self-righteo…

Wow.

[deleted]

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#160
post #112
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

According to https://twitter.com/moxie/status/730289041493483520 Moxie is fine with reimplementations.

Unfortunately, if I read https://news.ycombinator.com/item?id=11727870 right, Moxie formulated that more clearly by saying they would only approve of copyleft reimplementations. Unless I'm misreading things, this confirms the concerns and turns it more into something like the Java conformance testing case which the Apache folks ran into. I do get why they want protocol conformance, but expecting everyone to publish their implementation as copyleft is unreasonable and unrealistic. The only acceptable solution, if they want to see widespread use of the protocol, is to have a shared, no strings attached testing framework everyone can use to check their protocol implementation doesn't deviate. We have such things for web standards, why not for a secure chat solution? Their aim is good, but the solution is unacceptable for an industry standard to be.

Quoting

    If you'd like to do the work of developing a strong copyleft
    version of the GPL that you feel is appropriate for use in the
    app store, and get it OSI approved, we'd certainly look at
    using that.

    We'd like to get this better documented [...] It's a priority [...]
    hopefully we'll have more to publish this year.

    We haven't patented any of the concepts here, and we've done a
    lot to explain and popularize them. We're happy for people to
    use these concepts to build their own implementations of similar
    protocols, but we don't want people slapping things together and
    calling that Signal Protocol.
Post reply on HN