Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

211–220 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#211
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

Wire doesn't even encrypt chats and images, only calls.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#212

Does this require a phone number like the rest of Open Whisper Systems products?

Ugh, how did this EVER catch on so much!? Lost your phone? Got mugged? Now you've lost you only identifier on every major IM network out there. You need to contact everyone you know out-of-band and have them update your number.

[deleted]

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#213
post #196

Earlier quoted context omitted.

WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages, no real ability for the servers to do anything smart, no real search functionality, desktop client that requires the phone to be on, etc. An incognito mode allows the default mode to have more functionality, and matches their approach with Chrome. It's not a bad tradeoff.

Didn't WhatsApp Web require the phone to be on, before they got encryption?

It still does

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#214

Earlier quoted context omitted.

WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages, no real ability for the servers to do anything smart, no real search functionality, desktop client that requires the phone to be on, etc. An incognito mode allows the default mode to have more functionality, and matches their approach with Chrome. It's not a bad tradeoff.

> WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages Small clarification: WhatsApp actually does seem to have a backup feature, at least on my Android phone. I was prompted by the application to enable it just this morning.

Message backup is there on iOS too.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#215

To me it seems like Open Whisper Systems are accepting a lot of concessions in order to have Signal included into products. The trust I once had for moxie is quickly dissipating. * Privacy is only provided in Allo in a secondary mode. Not by default. * Federation of the Signal protocol has been rejected for non-technical reasons. Also, on a personal note, the desktop client requiring chrome is pretty awful.

Making someone else's crypto not suck is not the same as endorsing their product.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#216
post #124

Earlier quoted context omitted.

Moving to closed protocols isn't the whole problem. Everyone used to use AIM, ICQ, MSN Messenger, Yahoo! Messenger, which were all* closed protocols. And yet, the developers of gAIM (now Pidgin) and Trillian both developed clients that interoperated with all of these services and others. Sure, we had five years when everyone was on XMPP. But given that rich history of protocol investigation, what's surprising to me i…

I think federation has largely moved to the device. I do most of my messaging on my phone, where which app I'm using isn't invisible, but it's also not really a hassle to switch (mostly it involves dragging down my notification shade and tapping on the message I received). Not perfect, but also not really requiring the cognitive overhead that switching between desktop clients seemed to have. My phone federates my con…

Your phone federates your contacts, email, calendars, etc because those are all open protocols.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#217
post #124

Earlier quoted context omitted.

Moving to closed protocols isn't the whole problem. Everyone used to use AIM, ICQ, MSN Messenger, Yahoo! Messenger, which were all* closed protocols. And yet, the developers of gAIM (now Pidgin) and Trillian both developed clients that interoperated with all of these services and others. Sure, we had five years when everyone was on XMPP. But given that rich history of protocol investigation, what's surprising to me i…

Most people use whatever is dominant. People who have contacts on more than one 'app' simply install those apps and mope about it a bit (but accept it nontheless). In the Netherlands (and a lot of other countries), the dominant player is Whatsapp, although some countries have their own dominant player, such as Kakao Talk in South Korea. Of course there is call for unified messaging; it just isn't in the interest of t…

That was always the case, though. The problem with making a WhatsApp Pidgin adapter, for example, is that WhatsApp only allows a single client. I'm not sure why nobody has tried to make one that talks to the phone, like WhatsApp Web does (although that also only allows a single browser).

Generally, we've taken a big step backwards where chat is concerned.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#218
post #157

Come on Nadim. Just shut up. seriously. go whining about ptacek treating you badly again.. because your behaviour isn't any better: You've been bashing on TextSecure/Signal and it's authors on Twitter and other mediums since you started your own, insecure, javascript IM a few years back. Always promoting your own product along some rather dubious arguments. There has even been a best-of on tumblr of your self-righteo…

Please don't do this. Personal attacks are not ok on HN, regardless of how wrong or annoying someone is.

We detached this subthread from https://news.ycombinator.com/item?id=11728339 and marked it off-topic.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#219
post #145
post #135

Earlier quoted context omitted.

Hey Chris, as you know, we have no problem with you distributing our GPL software through the app store. Most of your communication has centered around asking us to change the license on our source base to something other than the GPL. We like the GPL for the quality control that it provides. If someone publicly says that they're using our software, we want to see if they've made any changes, and whether they're usin…

The FSF and SFLC take the position that the GPL is incompatible with the iOS App Store restrictions, since it forbids adding additional restrictions. However, GPL3 has official support for "additional permissions" and it's still FSF / OSI approved with those added. It permits dropping the additional permissions and using the software as pure GPL3. So that seems like the best approach, but Apple's restrictions are pro…

When the author say "we have no problem with you distributing our software through the app store", then I would just get that in some more official writing that include you, apple, and more detailed description on what permission is exactly given. The primary purpose of any software license is to shield the downstream distributor against being charged under copyright infringement, but a personal permission is equally fine in a legal sense so long you don't intend that downstream from you should also be able to distribute your version.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#220
post #31

Has anyone given this https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 more thought and whether one should avoid Signal and work with a more friendly project that doesn't seemingly fail at its desire to have widespread use of the protocol and actually tried to sue WireApp? WireApp's now approved as a non-infringing implementation in Rust, so that's great for reliability. Edit: The suing part was initiated…

Wire doesn't even encrypt chats and images, only calls.

That was true when Wire launched in December 2014 but not any more.

On March 10, 2016 Wire rolled out end-to-end encryption and from that on everything (chat, photos, files, video messages, all calls) are end-to-end encrypted. More + security whitepaper at wire.com/privacy

Post reply on HN