Live data from Hacker News

License update

whispersystems.org

21–30 of 71 posts

Re: License update

#21
post #5

Please be aware that you may not use this code to interact with OWS servers or in an app containing "signal" in the name [0]. [0] https://github.com/LibreSignal/LibreSignal/issues/37#issueco...

Yep, the rest of the world has moved on. Olm already provides what Signal protocol did and the app itself is now useless to many.

Signal app itself still can't run on Android Open Source, because it forces centralised metadata collection on the user via Google Play Store and GCM. Installing Google privacy-invading bloatware, is a prerequisite, which also further requires you to destroy your phone's security model because all non-vendor GCM options currently require you to patch a nasty hack into the kernel or otherwise prevent you using a secure, verified bootloader.

But like 'blame Apple', 'blame Google', because Signal won't provide or permit a WebSocket fallback (to do exactly the same as desktop client) - the one major thing LibreSignal wanted and were threatened legal action with if they did. Oh, that and using a trustworthy (FDroid), not just trusted, app store that doesn't require bloat, metadata leaks & GSF battery drain.

So, if your operating system can't support GCM (for good security reasons), or you just don't want to give up your data (kind of the point of Signal), then you're out in the cold.

You may think "It's open source, I'll run my own server". Nope. It's not just that they won't allow others to federate with their servers. Even if you were willing to give up your entire network of Signal contacts (that you've been building because you THOUGHT they were Open as they always painted themselves) - you can't. 'Open' Whisper aren't open sourcing their server. The voice side is locked up. Don't forget, you didn't choose GCM. Signal took the SMS option away after you'd built your network, plus convinced all your friends to drop XMPP alternatives and install Signal.

This license is too little, too late.

Matrix.org is providing a secure, viable modern, open alternative to IRC and XMPP, that also federates with them. With clients like Vector.IM that'll soon be non-GCM too. It already provides better functionality than Signal app and with Olm protocol (being merged within weeks) is equivalent to Signal encryption anyway.

Conversations.IM already works beautifully without Signal (plus is merging with the resources of ChatSecure). They've proven very well that you CAN in fact have an awesome (and secure) user experience based on XMPP.

The thing that really annoys me, is that while we spent all these years just backing Signal, singing their praises - thinking they were open (yeah, more fool us) - we were also diverting attention, installs and sentiment/resources from genuinely open protocols & projects for the web. Now those networks are gone, they're hard to get back.

The good news is that Matrix is technically good enough to win, so I hope they do.

Why have Signal Protocol chosen now to open the license up a little? Well, I can't help but wonder if it's because Olm is finally ready, done and merging for public release.

Re: License update

#22
post #14
post #8

Earlier quoted context omitted.

Tough crowd! That's what we used to do, but some extremely vocal people weren't satisfied, so we've done this to integrate our intentions into the license itself.

Oh, I totally missed that the MPL makes you deliver source with binaries. I think I had it confused in my head with the Apache License 2.0 somehow. OK, I'll admit that this is in fact clearer than the Mosh approach. (My main confusion was whether you expected me to offer source if the only binary I distributed was an iOS app; the Mosh waiver is very clear about that.)

"Provided that you are otherwise in compliance with the GPLv3 for each covered work you convey (including without limitation making the Corresponding Source available in compliance with Section 6 of the GPLv3)..."

Yes, the expectation is that you still have to comply with the GPLv3 (including making the corresponding source for your derivative work available), at which point you have the additional freedom to distribute the app through the app store.

Re: License update

#23
post #9

Earlier quoted context omitted.

The GPL is an amazing license to gag developers while looking like a good person in the process. Not saying that is happening here but I have seen this before where questionable motivations where the driving force behind the license choice.

The GPL is an amazing license to prevent devs from profiting off others' work without also providing access to their own. Some might call that a "gag" because they're prevented from using the code without opening their own code as well, so it's closed to them for all practical purposes. Is that the kind of gag that you're talking about, or did you mean something different?

> Is that the kind of gag that you're talking about, or did you mean something different?

I meant that the GPL as a license can be used to gag others while keeping a positive image as a person yourself. There are many licenses that can be used like this (the CDDL in particular was used for that purpose). That in itself has nothing to do with the GPL, more that you as a copyright holder have the ability to do things that are not available for others.

Re: License update

#24

Thank you Moxie! Although we personally trusted and would've moved forward with Moxie's informal permission to distribute SignalProtocol within ChatSecure on the App Store, our funder required us to get the legal details squared away or we'd lose our funding. This announcement is an amazing gift for us, and for other GPL compatible Mac/iOS apps. This announcement also more broadly benefits the copyleft community. The…

Apple could always do what Google does, to state that in the case of copyleft licenses their term take precedence over the ToS (neutralizing restrictive terms like the redistribution ban on everything you download from the store).

Re: License update

#25

This is probably partially in response to some of the issues that were discussed here: https://github.com/LibreSignal/LibreSignal/issues/37

It's a little depressing Moxie believes federated protocols can't compete with unfederated/proprietary ones. I don't like the idea of all future innovation taking place in the Slacks and WhatsApps rather than the IRCs and SMTPs. Are there any recent counter examples of successful federated protocols? It would be an interesting thought experiment to design a protocol that started with the basic features of IRC and inc…

That thought experiment lives today in the form of Matrix.org :)

Re: License update

#26
post #6

Earlier quoted context omitted.

How does the GPL gag developers?

The GPL does not but it can be used as a vehicle that does.

Can you provide a concrete example? I've seen three messages from you, and I still have no idea what you're talking about.

Do you have an example of what you mean by "gag", in context of copyright?

Do you have an example of how GPL or other licenses allows you to do something negative while maintaining a positive image?

Re: License update

#27
post #5

Please be aware that you may not use this code to interact with OWS servers or in an app containing "signal" in the name [0]. [0] https://github.com/LibreSignal/LibreSignal/issues/37#issueco...

Yep, the rest of the world has moved on. Olm already provides what Signal protocol did and the app itself is now useless to many. Signal app itself still can't run on Android Open Source, because it forces centralised metadata collection on the user via Google Play Store and GCM. Installing Google privacy-invading bloatware, is a prerequisite, which also further requires you to destroy your phone's security model bec…

Just a few clarifications:

* Olm isn't a replacement for 'Signal protocol' - it's just an independent (Apache license) implementation of the same 'double ratchet' cryptographic ratchet that Signal protocol uses under the hood for generating message keys.

* Megolm provides the higher layer semantics for using Olm for group conversations in Matrix, and diverges significantly from Signal Protocol as far as I know.

* There's already an experimental FDroid ready build of Vector Android (following the HN discussion on Friday) at https://matrix.org/jenkins/job/VectorAndroidDevelop/lastSucc... - feedback welcome on just how badly the polling-based push mechanism performs on your hardware & network. We're looking at alternative push mechanisms like microG - or just using a more efficient push transport for Matrix to provide notifs.

Re: License update

#28
post #5

Please be aware that you may not use this code to interact with OWS servers or in an app containing "signal" in the name [0]. [0] https://github.com/LibreSignal/LibreSignal/issues/37#issueco...

Yep, the rest of the world has moved on. Olm already provides what Signal protocol did and the app itself is now useless to many. Signal app itself still can't run on Android Open Source, because it forces centralised metadata collection on the user via Google Play Store and GCM. Installing Google privacy-invading bloatware, is a prerequisite, which also further requires you to destroy your phone's security model bec…

> Yep, the rest of the world has moved on. Olm already provides what Signal protocol did and the app itself is now useless to many.

Olm/Megolm is not Signal Protocol. It is an entirely different protocol that has made different choices, and those choices have received less study and scrutiny. It hasn't been deployed anywhere that I know of. It's fine if you want to explore those choices, but I would caution against calling it the same thing.

> the one major thing LibreSignal wanted and were threatened legal action with if they did

I understand that because we have what you consider to be unpopular opinions, it's easy to believe that we're somehow single-handedly responsible for everything bad in the world. However, you can't just make shit up. Legal action? Could you cite that?

The entirety of our exchange is in the top of that issue. They asked for permission, and I said we'd prefer for them to use their own servers and their own name. The same thing we say to everyone. Many people do set up their own servers for their own products, these people chose not to. We didn't threaten anyone with anything, legal or otherwise.

> 'Open' Whisper aren't open sourcing their server. The voice side is locked up.

https://github.com/whispersystems/textsecure-server https://github.com/whispersystems/pushserver https://github.com/whispersystems/websocket-resources https://github.com/whispersystems/dropwizard-simpleauth

By "the voice side," do you mean a TURN server? Plenty of options for you out there. Or are you just more interested in having something to blame us for?

And LibreSignal already doesn't support voice, even with our servers, so your complaint doesn't make much sense.

> Why have Signal Protocol chosen now to open the license up a little? Well, I can't help but wonder if it's because Olm is finally ready, done and merging for public release.

The conspiracy theories never stop. We haven't changed anything, this has been what we said our policy was all along, but people thought that was some kind of conspiracy. Of course, now that we've made it an explicit license term instead, that's also suspicious somehow. Why would anyone ever want to be involved in this community you think we're not appropriately considering?

Re: License update

#29
post #9

Earlier quoted context omitted.

The GPL is an amazing license to prevent devs from profiting off others' work without also providing access to their own. Some might call that a "gag" because they're prevented from using the code without opening their own code as well, so it's closed to them for all practical purposes. Is that the kind of gag that you're talking about, or did you mean something different?

> Is that the kind of gag that you're talking about, or did you mean something different? I meant that the GPL as a license can be used to gag others while keeping a positive image as a person yourself. There are many licenses that can be used like this (the CDDL in particular was used for that purpose). That in itself has nothing to do with the GPL, more that you as a copyright holder have the ability to do things t…

I don't understand what you mean by "gag" and "positive image".

The GPL is a very good license, because it has one benefit that almost all other licenses don't: it restricts use of your code to free software. If you care about software freedom, or want to live in a world where proprietary software is a thing of the past, then that should be reason enough to use it. Positive image is not a clause in the GPL, so I really don't know what you mean.

Re: License update

#30
post #4

The license change is from GPLv3 to, uh, dual GPLv3/MPL-on-the-App-Store-or-something? > Additional Permissions For Submission to Apple App Store: Provided that you are otherwise in compliance with the GPLv3 for each covered work you convey (including without limitation making the Corresponding Source available in compliance with Section 6 of the GPLv3), Open Whisper Systems also grants you the additional permission…

> This seems less straightforward than what e.g. Mosh has. https://github.com/mobile-shell/mosh/blob/master/COPYING.iOS

From my perspective as a developer, that is quite scary. While I love mosh, I don't trust anyone in this world enough to hand them a loaded gun labeled "GPL violation that was excused informally".

Still, IMO we just shouldn't support devices that don't allow you to distribute canonical free software freely.

Post reply on HN