Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

181–190 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#181

That is awesome - now we also need to kill metadata collection. Is this feasible? Oh and off-the-record was there on Hangouts/Gtalk before - I used it but the chats were replicated across clients (e.g. Pidgin vs gmail.com) - so not really off-the-record (i.e. they lied).

Metadata-free chat exists already on the desktop with Ricochet (https://ricochet.im) and it will soon exist on mobile with Briar (https://briarproject.org). Both work through Tor hidden services - Briar also allows to exchange messages over Bluetooth and direct wifi.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#182

I'm not sure I got it right. Is Google going to be scanning all my conversations to give me suggestions on what to say next? Really? I understand the price of things like Gmail, where I get a robust email system in exchange of scanning my emails and mining my data. I got something very good from Google, they got my data. Not the best of the deals I ever made, but it has (had?) a strong appeal. On the other hand I don…

Saving time and hand movement typing "LOL=)" could be quite an appeal, depending on how many times a day you're doing it.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#183
post #50

Earlier quoted context omitted.

I don't get why encryption and incognito (not leaving a trace on the device) go together. I should be able to have one without the other.

Did you watch what Allo does? In its normal mode it couldn't possibly function with end-to-end encryption. They also have encryption to and from the server in the middle when you aren't in that mode.

I think it could if the AI was done locally, but don't expect Google to do that anytime soon, even if it becomes technically feasible and cheap to do. Didn't Apple already employ some client-side AI for photos and gave the reason that this is for privacy? I don't recall what the feature was exactly though.

As a sign of good faith, Google could also stop data-mining Hangouts now, since they have Allo for that, and make Hangouts end-to-end encrypted by default.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#184
post #152
post #65

Earlier quoted context omitted.

But why not allow E2E without incognito? Have both as separate options.

What use-case does E2E without incognito address? * Sharing naked pics on a monitored work network? No - there is at least some chance that your company owns your device, so therefore you want it to disappear from that * Sharing politically outlawed content? No - you can be compelled to give up your device. Wanting it "just because" is fine, but simplifying the UI is a pretty valid counter argument too.

Combined with full disk encryption it ensures nobody can get it.

Or maybe you want to use an open WiFi hotspot without letting anyone get your data. (Https solves this, though.)

Or maybe you don't want Google to have your messages for targeting purposes.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#185
post #109

Earlier quoted context omitted.

Are you assuming that all storage ends up on Google's servers (because that's what hangouts does, maybe)? Why can't it store E2E chats locally and never upload to google, or even encrypt with a passphrase like Chrome sync does?

Congrats, you have dug it down to the core. Google just doesn't need chats that it can't mine for useful data.

Then why build E2E at all?

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#186
post #153

Earlier quoted context omitted.

Nadim had a legitimate and reasonable question. For those who don't know, here was Thomas Ptacek recently joking about Nadim's penis: https://mobile.twitter.com/tqbf/status/705825790529662976 Here he is telling Nadim "go fuck yourself, forever": https://mobile.twitter.com/tqbf/status/705900243313758208 This is unprofessional. That kind of bullying is especially unacceptable coming from someone who has a lot of money…

> I think Hacker News should be better than this. I'm not sure how linking to twitter supports your comment that HN needs to improve. If he'd said that on HN he'd have been (I assume) banned. dang is constantly asking people not to be mean or dumb, or banning people for being mean.

>If he'd said that on HN he'd have been (I assume) banned

No he wouldn't.

https://news.ycombinator.com/item?id=5883501

https://news.ycombinator.com/item?id=6098474

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#187
post #56

Earlier quoted context omitted.

Did you watch what Allo does? In its normal mode it couldn't possibly function with end-to-end encryption. They also have encryption to and from the server in the middle when you aren't in that mode.

Incognito is a useful feature. E2E encryption is a useful feature. There's no reason to only allow those two features to be used together. You could have them both turned off by default, and have three modes, one which turns on E2E and one which turns on incognito. Also, the incognito decision should be made by each side independently. Just because I want to delete my traces doesn't mean my partner does.

I don't mind the two being used together. I've been using OTR in Gtalk/Hangouts for a long time, too (yes, I know Google actually keeps those messages anyway).

However, I would like an option to make the Incognito mode the default (always-on), just like Firefox can make Private Mode the default.

If Google wants people to believe it cares about their privacy (which is probably the reason they're even doing this in the first place), then it should not just offer the feature to them in an obscure way, but it should make it easy for them to use it if that's what they want.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#188

Earlier quoted context omitted.

Ugh, I hate this phone number as identify business. My pone number changes every time I move and I have to keep paying to have it. I see the benefit to a number that I can easily share but I don't like tying it to the telephone system. I'll keep using something like hangouts that allows me to keep my contacts when I move as well as a number of other benefits.

Why does it change? In my experience most people keep their first cell phone number for their entire lives. Area codes are indicative of nothing, except where you lived in 2005 [1]. [1] https://xkcd.com/1129/

I went to school and got a new number because a lot of my friends didn't have free province-wide calling and I'm about to move from Canada to Europe. So for me this is a particular concern at the moment.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#189
post #87

Earlier quoted context omitted.

I don't think you've thought this through. If one side enabled this "use E2E encryption for everything" feature, then the other side would presumably no longer have access to any of the smart assistant features. And it would not be obvious why. Additionally, it would be hard to explain why you'd ever want to enable such a feature which means nobody would do it. I suspect you want default E2E encryption for political…

>If one side enabled this "use E2E encryption for everything" feature That's not what I'm suggesting. I want E2E to be separate from the "delete chats when I'm finished" feature. Wanting an E2E chat that stays on my device when I'm done should be fine. I'm fine with having E2E require a separate mode, but that shouldn't be bundled with the incognito feature of not remembering history.

Wanting an E2E chat that stays on my device when I'm done should be fine.

Only if all other participants in that chat are fine with it. So you'd end up with an implementation that only allows saving to disk if all parties allow saving. That's a lot more complexity than simply a separate checkbox.

I still agree with you, there is value in allowing the features to be controlled separately.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#190

Earlier quoted context omitted.

You know what? It's not part of my argument that I'm above all the vitriol and venom in amateur secure messaging. You're doing a fine job of positioning yourself right in the middle of it as well. As long as the typical HN reader leaves this thread understanding how much bullshit drama is attached to this field, I don't really care one way or the other what their opinion of me is. The knives are out for Signal. It's…

I think perhaps the worst thing you've done here is deprive the viewers at home of their closure to the question of whether or not kaepora knows what his ultimate transgression was, or if he is feigning ignorance to elicit sympathy from the audience. What did he do? Does he know what he did? Do we ever get to find out? The people want answers.

fa9c5885a129a3dd5faf1b55bfdaf2d3e3a3de442bf6c817724febaa2b01bc71

Nadim has enough information to know what that hash corresponds to. Maybe he'll tell you. I won't. Not until I'm ready.

Post reply on HN