Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

191–200 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#191
post #189
post #87

Earlier quoted context omitted.

>If one side enabled this "use E2E encryption for everything" feature That's not what I'm suggesting. I want E2E to be separate from the "delete chats when I'm finished" feature. Wanting an E2E chat that stays on my device when I'm done should be fine. I'm fine with having E2E require a separate mode, but that shouldn't be bundled with the incognito feature of not remembering history.

Wanting an E2E chat that stays on my device when I'm done should be fine. Only if all other participants in that chat are fine with it. So you'd end up with an implementation that only allows saving to disk if all parties allow saving. That's a lot more complexity than simply a separate checkbox. I still agree with you, there is value in allowing the features to be controlled separately.

Why? I could always screenshot it, there's never a guarantee when you send information that it won't be retained by others with access. Letting me keep it without screenshotting is just a local convenience feature.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#192
post #185

Earlier quoted context omitted.

Congrats, you have dug it down to the core. Google just doesn't need chats that it can't mine for useful data.

Then why build E2E at all?

To stay competitive (or perceived so).

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#193
post #185

Earlier quoted context omitted.

Then why build E2E at all?

To stay competitive (or perceived so).

So you're suggesting Google crippled the feature so it doesn't get used? This seems unlikely.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#194

Earlier quoted context omitted.

Why would you have to use Chrome? You just need Chrome as a platform to launch your chrome app... I don't get it

Why would I want to use a browser to do non broswery things? It's bad enough that we have to use browsers in the first place. Wouldn't we be better starting from scratch and developing a secure, standards-friendly way of deploying text, images and video rather than taking something which was designed to display just text and try and make it useful?

Any ideas?

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#195
post #161

Earlier quoted context omitted.

I've used NW and electron based applications and don't have chrome installed. Why is Chrome needed at all for those to work?

To add to what rtkwe said, I assume the Signal client is a Chrome plugin because as far as I know you can't use GCM push messages with Chromium/NW/Electron, but only in Android and Google Chrome.

Signal Desktop does not use GCM. You can use the extension with Chromium or any Chromium-based browser.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#196

To me it seems like Open Whisper Systems are accepting a lot of concessions in order to have Signal included into products. The trust I once had for moxie is quickly dissipating. * Privacy is only provided in Allo in a secondary mode. Not by default. * Federation of the Signal protocol has been rejected for non-technical reasons. Also, on a personal note, the desktop client requiring chrome is pretty awful.

WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages, no real ability for the servers to do anything smart, no real search functionality, desktop client that requires the phone to be on, etc. An incognito mode allows the default mode to have more functionality, and matches their approach with Chrome. It's not a bad tradeoff.

Didn't WhatsApp Web require the phone to be on, before they got encryption?

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#197

Earlier quoted context omitted.

I think perhaps the worst thing you've done here is deprive the viewers at home of their closure to the question of whether or not kaepora knows what his ultimate transgression was, or if he is feigning ignorance to elicit sympathy from the audience. What did he do? Does he know what he did? Do we ever get to find out? The people want answers.

fa9c5885a129a3dd5faf1b55bfdaf2d3e3a3de442bf6c817724febaa2b01bc71 Nadim has enough information to know what that hash corresponds to. Maybe he'll tell you. I won't. Not until I'm ready.

I have no idea what that hash corresponds to and haven't even seen it before. Also, to be clear. I have absolutely not the slightest idea what kind of issue tptacek seems to be referring to in general. Honest. I'd swear under oath if I could.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#198
post #45

Earlier quoted context omitted.

Moxie replied in this Forbes article: http://www.forbes.com/sites/thomasbrewster/2016/05/11/wire-s...

That isn't quite a reply. It's a second hand account of Moxie denying that he asked for money. This story seems very troubling. The Wire guys made very specific claims (where did they get the >$2M figure from ... and why would they simply invent such a figure). If their implementation is in Rust then it cannot be the same as OWS' code. It would be good if OWS could publicly clarify that reimplementing the Signal Prot…

> does not trigger any copyright claims by OWS even if doing so involved reading the GPLd version.

I'm pretty sure having GPLed code open, reading it and writing some new software counts as a "derived work", and the GPL would apply. That's what most people who release FLOSS want to happen.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#199
post #135

Earlier quoted context omitted.

Hey Chris, as you know, we have no problem with you distributing our GPL software through the app store. Most of your communication has centered around asking us to change the license on our source base to something other than the GPL. We like the GPL for the quality control that it provides. If someone publicly says that they're using our software, we want to see if they've made any changes, and whether they're usin…

It looks like you can publish GPL apps in the App Store if you are the author. If you want to use someone's GPL lib in your app, then you might have a problem...

And what would be the reasoning for that?! It doesn't seem to make sense. It seems like another one of Apple's arbitrary rules.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#200
post #135

Earlier quoted context omitted.

Hey Chris, as you know, we have no problem with you distributing our GPL software through the app store. Most of your communication has centered around asking us to change the license on our source base to something other than the GPL. We like the GPL for the quality control that it provides. If someone publicly says that they're using our software, we want to see if they've made any changes, and whether they're usin…

It looks like you can publish GPL apps in the App Store if you are the author. If you want to use someone's GPL lib in your app, then you might have a problem...

When you're the author, you can publish your code under whatever license you want.

To publish in the App Store some app you've been distributing under GPL, you basically have to give a separate, more permissive, license to Apple.

Post reply on HN