Live data from Hacker News

Messaging done right. No phone number. No Email. No sign up required

welcome.dklo.co

31–40 of 51 posts

Re: Messaging done right. No phone number. No Email. No sign up required

#31
post #30

Earlier quoted context omitted.

We saved the encrypted version to enable password reset. When you reset your password we send an activation code to the email you signed up with (We don’t save that email ). To reset your password you need to enter that email. We encrypt the value on the client and compare it we the value we have on our server. To make sure it s really you But at any time we don’t have user emails stored on our system. So If someone…

Okay and how do you choose the key for the encryption? If it is the same for all users (which from what you said it kind of has to be?) you could just decrypt it?

A hash of the email stored then compared to a hash of the email sent during reset

Re: Messaging done right. No phone number. No Email. No sign up required

#32

Earlier quoted context omitted.

Name is meh, but the url is worse. Why not dikalo.net? or dikalo.co? Also, "messaging done right" is a bad tagline as it doesn't tell me anything.

We will offer alternative domains. dikalo.net and dikalo.co beeing one of those. Also the landing page will have more infos soon. With messaging done right we mean Messaging without you giving up any private infos. No email, no phone nr, no sign up required. In fact you can use Dikalo without ever opening an account. The reason we started with dklo.co is because we wanted people to type as little as possible.

Correct me if I'm wrong:

Most links are sent via text (email, messaging, social networks) where they're automatically turned into hyperlinks. Length isn't an issue here.

When they are spoken, vowels help a lot. It's not fun to spell out D-K-L-O-DOT-CO, no not COM, CO.

In the end though, I don't think it matters that much either way, just bikeshedding.

Re: Messaging done right. No phone number. No Email. No sign up required

#33
post #30

Earlier quoted context omitted.

We saved the encrypted version to enable password reset. When you reset your password we send an activation code to the email you signed up with (We don’t save that email ). To reset your password you need to enter that email. We encrypt the value on the client and compare it we the value we have on our server. To make sure it s really you But at any time we don’t have user emails stored on our system. So If someone…

Okay and how do you choose the key for the encryption? If it is the same for all users (which from what you said it kind of has to be?) you could just decrypt it?

[deleted]

Re: Messaging done right. No phone number. No Email. No sign up required

#34
post #26

Earlier quoted context omitted.

and what are you doing with the random text per user (i.e. the encrypted emails)? Why do you need them? If they are encrypted by the user, how can you verify their email then? This does not add up.

We saved the encrypted version to enable password reset. When you reset your password we send an activation code to the email you signed up with (We don’t save that email ). To reset your password you need to enter that email. We encrypt the value on the client and compare it we the value we have on our server. To make sure it s really you But at any time we don’t have user emails stored on our system. So If someone…

Informations we store [...] Hashed value of your email

okay, so you can easily make a rainbow-table and thus your users are not anonymous anymore + if someone has your database and want to know if email@email.com has an account one can easily find that out, even without the need to bruteforce all emails. Btw. in this case it makes absolutely no difference if you or the client computes the hash ;)

Re: Messaging done right. No phone number. No Email. No sign up required

#35
post #30

Earlier quoted context omitted.

Okay and how do you choose the key for the encryption? If it is the same for all users (which from what you said it kind of has to be?) you could just decrypt it?

A hash of the email stored then compared to a hash of the email sent during reset

Exactly. This is the main idea behind Dikalo. Your private stuff belong to you. We are only interested in sending your messages. This is why you can use Dikalo without even siging up

Re: Messaging done right. No phone number. No Email. No sign up required

#36
post #32

Earlier quoted context omitted.

We will offer alternative domains. dikalo.net and dikalo.co beeing one of those. Also the landing page will have more infos soon. With messaging done right we mean Messaging without you giving up any private infos. No email, no phone nr, no sign up required. In fact you can use Dikalo without ever opening an account. The reason we started with dklo.co is because we wanted people to type as little as possible.

Correct me if I'm wrong: Most links are sent via text (email, messaging, social networks) where they're automatically turned into hyperlinks. Length isn't an issue here. When they are spoken, vowels help a lot. It's not fun to spell out D-K-L-O-DOT-CO, no not COM, CO. In the end though, I don't think it matters that much either way, just bikeshedding.

:) I think once you use the service you will get used to the name :)

Re: Messaging done right. No phone number. No Email. No sign up required

#37
From the Terms of Service:

>Terms of Use

>Last updated September November 1st, 2016

... >The Terms are governed by German law.

...

> To the extent permitted by law, these Terms and the actions performed under them are governed by and construed in accordance with the law of France, without regard to any choice of law principles which would require the application of a different jurisdiction’s law. The United Nations Convention on the International Sales of Goods shall not apply hereto.

To the extent permitted by law, you consent to the jurisdiction of the courts of Paris with appropriate subject matter jurisdiction.

???

Re: Messaging done right. No phone number. No Email. No sign up required

#38
post #34

Earlier quoted context omitted.

We saved the encrypted version to enable password reset. When you reset your password we send an activation code to the email you signed up with (We don’t save that email ). To reset your password you need to enter that email. We encrypt the value on the client and compare it we the value we have on our server. To make sure it s really you But at any time we don’t have user emails stored on our system. So If someone…

Informations we store [...] Hashed value of your email okay, so you can easily make a rainbow-table and thus your users are not anonymous anymore + if someone has your database and want to know if email@email.com has an account one can easily find that out, even without the need to bruteforce all emails. Btw. in this case it makes absolutely no difference if you or the client computes the hash ;)

You are assuming a lack of salt when the client hashes the password.

Re: Messaging done right. No phone number. No Email. No sign up required

#39
post #32

Earlier quoted context omitted.

Correct me if I'm wrong: Most links are sent via text (email, messaging, social networks) where they're automatically turned into hyperlinks. Length isn't an issue here. When they are spoken, vowels help a lot. It's not fun to spell out D-K-L-O-DOT-CO, no not COM, CO. In the end though, I don't think it matters that much either way, just bikeshedding.

:) I think once you use the service you will get used to the name :)

I think you are lowering your conversion rate. My guess is if you do A/B testing with invitation emails, more people will use the service with a 'respectable' looking URL rather than one that looks 'dodgy'.

Sure, have a short name once people are converted, but make a good first impression.

Re: Messaging done right. No phone number. No Email. No sign up required

#40

Earlier quoted context omitted.

Thx :). Whats wrong with the name ? :)

Name is meh, but the url is worse. Why not dikalo.net? or dikalo.co? Also, "messaging done right" is a bad tagline as it doesn't tell me anything.

I live in Germany. I read the domain name as d'Klo. As some kind of reference to "Klo" - the toilet.
Post reply on HN