Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

161–170 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#161
post #122

Earlier quoted context omitted.

> the desktop client requiring chrome is pretty awful That's rubbish. They are a small company with not enough person-time to develop native versions for all OS. Would you prefer only to have a windows version available? Developing with Chrome/NW.js/Electron allows you to have an app that runs on 3 OS's from the start. I think it's pretty awesome. Plus you only need chrome installed, it doesn't have to run if I under…

I've used NW and electron based applications and don't have chrome installed. Why is Chrome needed at all for those to work?

To add to what rtkwe said, I assume the Signal client is a Chrome plugin because as far as I know you can't use GCM push messages with Chromium/NW/Electron, but only in Android and Google Chrome.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#162

Earlier quoted context omitted.

Ugh, I hate this phone number as identify business. My pone number changes every time I move and I have to keep paying to have it. I see the benefit to a number that I can easily share but I don't like tying it to the telephone system. I'll keep using something like hangouts that allows me to keep my contacts when I move as well as a number of other benefits.

Why does it change? In my experience most people keep their first cell phone number for their entire lives. Area codes are indicative of nothing, except where you lived in 2005 [1]. [1] https://xkcd.com/1129/

Over here (Germany) it commonly costs 30 bucks to transfer a phone number to another provider, at least if you are on cheap plans.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#163
post #124

Earlier quoted context omitted.

I lament the fact that we're moving more and more to closed chat protocols. Shortly, nothing will work with Pidgin/Adium any more, and it's a shame because it's by far the best way to chat.

Moving to closed protocols isn't the whole problem. Everyone used to use AIM, ICQ, MSN Messenger, Yahoo! Messenger, which were all* closed protocols. And yet, the developers of gAIM (now Pidgin) and Trillian both developed clients that interoperated with all of these services and others. Sure, we had five years when everyone was on XMPP. But given that rich history of protocol investigation, what's surprising to me i…

Most people use whatever is dominant. People who have contacts on more than one 'app' simply install those apps and mope about it a bit (but accept it nontheless). In the Netherlands (and a lot of other countries), the dominant player is Whatsapp, although some countries have their own dominant player, such as Kakao Talk in South Korea.

Of course there is call for unified messaging; it just isn't in the interest of the companies behind the currently dominant messing apps to facilitate it. To monetize their product, they need you to use their software, on (or through) an operating system approved by them, following their rules (e.g., Whatsapp's requirement of a relatively high-value personal identifier in the form a phone number). Using anything else to access their protocol causes a devaluation of their product — whatever their eventual business model will be after the make-sure-everyone-uses-us phase will be (advertising, user tracking/marketing profiles, freemium model), users will need to interact with them on their terms, with their software.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#164
post #70

Earlier quoted context omitted.

You have this story backwards and you should correct your post. Moxie and OWS didn't threaten to sue Wire. Wire sued Open Whisper Systems . That suit made, but did not substantiate, a claim that OWS asked for money. OWS denies that. I believe OWS, and not Wire. The genesis of this claim comes from Wire having used GPL'd OWS code, apparently for the Signal protocol, without complying with the GPL . OWS demanded that W…

I'd like to learn some possible reasons why one should avoid cryptocat, is there any material you could link for further reading? Thank you

The authors have been incompetent. Cryptocat has had several severe bugs that demonstrate cluelessness around fairly simple cryptographic stuff.

Here's one walkthrough of their broken PRNG: https://nakedsecurity.sophos.com/2013/07/09/anatomy-of-a-pse...

Decryptocat lists some of the other bugs: https://tobtu.com/decryptocat.php

The response - "bugs happen, we'll fix them" is okay for most other software, but probably not for cryptography. Especially not if you're marketing your software to people at risk of being murdered by their governments.

Here's a snippet from their blog, there are plenty of others:

> In working with young and middle-aged professionals in the Middle East region, we have discovered that desktop OTR clients suffer from serious usability issues which are sometimes further exacerbated due to language differences and lack of cultural integration (the technology was frequently described as foreign). In one case, an activist who was fully trained to use Pidgin-OTR neglected to do so citing usability difficulties, and as a direct consequence encountered a life-threatening situation at the hands of a national military in the Middle East and North Africa region.

They're the victims of being over hyped. There's some discussion to be had around how much they generated that hype. http://paranoia.dubfire.net/2012/07/tech-journalists-stop-hy...

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#165
post #125

Earlier quoted context omitted.

That's nonsense. In-house proprietary encryption is not peer reviewed and untrustworthy by definition and if you're going to work in the open, especially for a new proprietary chat app, it makes better sense to build on an open platform that's already proven and is handled by people that really know their stuff. More secure and probably cheaper as well.

Being open source or closed source doesn't make code more secure. What make code more secure is making it more secure. Have you audited the code?

It is possible for anyone to audit open source software though, unlike proprietary software.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#166
post #6

Earlier quoted context omitted.

Uh, where are you defining Allo as one of the largest messaging platforms on the internet? It literally just launched. It might do well, but it could also easily be a flop (as many other social initiatives from Google have been). Either way it's a long ways from catching up to WeChat, Viber, or even Facebook Messenger.

It's going to end up on a lot of Android phones. If it's any good, it will catch on. Hangouts hasn't caught on that much because, imho, it has bad UI.

The UI is awful (even as a very tech-savvy person I find it confusing!), and the web version only work properly on chrome/chromium.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#167
post #23
post #2

This is fantastic news. The two largest messaging platforms on the Internet will both be using Signal protocol. I could ask for more: E2E could be the default for Allo, and it isn't. That's not great. But the E2E you get when you ask for it will apparently be best-in-class.

Skype is the last major messaging platform to not have end-to-end encryption in any way.

Is Skype actually still considered a "MAJOR messaging platform"?

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#168

Does this require a phone number like the rest of Open Whisper Systems products?

Ugh, how did this EVER catch on so much!?

Lost your phone? Got mugged? Now you've lost you only identifier on every major IM network out there. You need to contact everyone you know out-of-band and have them update your number.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#169

Earlier quoted context omitted.

Ugh, I hate this phone number as identify business. My pone number changes every time I move and I have to keep paying to have it. I see the benefit to a number that I can easily share but I don't like tying it to the telephone system. I'll keep using something like hangouts that allows me to keep my contacts when I move as well as a number of other benefits.

Why does it change? In my experience most people keep their first cell phone number for their entire lives. Area codes are indicative of nothing, except where you lived in 2005 [1]. [1] https://xkcd.com/1129/

Not everyone lives in the US. Here's how this affects me:

* If I lose my phone, I've permanently lost my number. * Long-distance calls are a lot more expensive (about 5-10x as much). * Switch companies? Number lost again.

I've had about 5-6 mobile numbers since during the last decade.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#170
post #125

Earlier quoted context omitted.

That's nonsense. In-house proprietary encryption is not peer reviewed and untrustworthy by definition and if you're going to work in the open, especially for a new proprietary chat app, it makes better sense to build on an open platform that's already proven and is handled by people that really know their stuff. More secure and probably cheaper as well.

Being open source or closed source doesn't make code more secure. What make code more secure is making it more secure. Have you audited the code?

Open vs closed sources makes a difference in how much I TRUST its security level, not security itself.
Post reply on HN