Live data from Hacker News

On Privacy versus Freedom

matrix.org

51–60 of 209 posts

Re: On Privacy versus Freedom

#51
post #14

When i asked if i could use his libraries in ios/android apps Moxie refused. He licensed them under GPL that prohibits distributing of software via app stores. Quite a strange for a guy who claim that he wants to spread encryption. Sure, but only on your own platform. Fastforward he sold such rights for a whatsapp. Just simple business, nothing about privacy itself.

Why would GPL prevent distribution via app stores? I think I have at least one GPL app installed that way.

Re: On Privacy versus Freedom

#53
post #35

Earlier quoted context omitted.

Telegram is GPL, I think it would be worth it to see how they use it, because it honestly is absolutely incredible.

Telegram server is closed.

Yes but the implementation of the notification handling is impressive on the client side. The server side software as far as this is concerned should be easily deducible and isn't the interesting part.

Re: On Privacy versus Freedom

#54

Earlier quoted context omitted.

Building monoliths (like Signal) is easy and that's a core take-away point of Matthew's response in the blog post. Building Matrix is not and has not ever been a small task, but the effort gives us the freedom to run our own services and still be able to talk with our friends. Matrix is the "long game".

And it's a worthwhile pursuit. Moxie's points simply don't make sense, and are infuriating / disrespectful to those who are working on solving decentralization's issues. _Of course_ it will be difficult. But the same argument could be made for building a completely unencrypted messenger app. You won't have to worry about managing keys, obfuscating metadata, or anything like that. At the end of the day, it's about rea…

He's been anti-complexity for awhile. the matrix ecosystem is far more complex than signal.

Re: On Privacy versus Freedom

#55
post #45

Earlier quoted context omitted.

Wire seemed like a decent alternative where you're not required a number, I think only an email. Also you can delete your account.

I read on a privacy-oriented website that Wire was purchased by an American company not trusted for its record on privacy (or perhaps it was that since the company is American, their data can be read by the US govt.). I can't find it now though. There isn't anything mentioning it on the website of `www.privacytools.io`: https://www.privacytools.io/software/real-time-communication...

I never continued with Wire cause... nobody uses it, even less people use it than Signal. I think Keybase is the next best thing to some extent.

Re: On Privacy versus Freedom

#56

I think the timing makes Moxie's point very well without him saying a thing. All these years later Matrix only has... The ambition to some day try to offer the core privacy features Signal already delivered back then. Some of the most basic stuff is, you believe, almost kinda sorta done. This is, to be clear, much better than just sitting back insisting you were right but not lifting a finger. But for an actual user…

>All these years later Matrix only has... The ambition to some day try to offer the core privacy features Signal already delivered back then. E2E on Matrix works, plus key verification is easier than on Signal. Managing metadata is hard, but my Matrix homeserver doesn't have my phone number (unlike Signal) and does not require Google Cloud Messaging. I can even run it on a PinePhone or Pocket CHIP! >But for an actual…

bruh did you honestly just say home server.... might as well just say use "tor and pgp".

Re: On Privacy versus Freedom

#57
post #24

Earlier quoted context omitted.

Can you explain how GPL prohibits distribution via app stores?

Some people argue that the GPL2's clause "You may not impose any further restrictions on the recipients' exercise of the rights granted herein." is violated because you need to agree to additional terms from Apple to use the apps. https://www.fsf.org/news/2010-05-app-store-compliance In this case however, the code is under the GPLv3, which is far more problematic. It contains a "anti-tivoization" clause, which says y…

> In this case however, the code is under the GPLv3, which is far more problematic. It contains a "anti-tivoization" clause, which says you cannot require any "methods, procedures, authorization keys, or other information required to install and execute modified versions".

That doesn't actually apply to the Apple app store. The "anti-tivoization" clause is narrowly written to only cover what Tivo did. Namely, providing hardware with locked down firmware.

This is the trigger for the "anti-tivoization" clause:

> If you convey an object code work under this section in, or with, or specifically for use in, a User Product, and the conveying occurs as part of a transaction in which the right of possession and use of the User Product is transferred to the recipient in perpetuity or for a fixed term (regardless of how the transaction is characterized), the Corresponding Source conveyed under this section must be accompanied by the Installation Information.

A "User Product" is:

> either (1) a “consumer product”, which means any tangible personal property which is normally used for personal, family, or household purposes, or (2) anything designed or sold for incorporation into a dwelling.

When someone downloads an app from the Apple app store for their iPhone, the iPhone is the "User Product", and the transaction is not one in which "the right of possession and use of the User Product is transferred to the recipient", and so the "anti-tivoization" does not apply.

Re: On Privacy versus Freedom

#58
post #31

One frustrating thing about Moxie's original post is that Signal derives huge amounts of value by piggybacking on an existing distributed federated network: the phone system. If phone numbers weren't an existing working identifiers that people had regardless of what OS, carrier, or messaging app, Signal as designed wouldn't work. People should think harder about how to replicate that experience, instead of how to app…

>People should think harder about how to replicate that experience, instead of how to appropriate it and then abandon it.

That's great and all, but because Signal takes advantage of that existing network of identifiers, it is able to deliver usable private messaging to many users today. Replacing phone numbers as identifiers is a much harder problem than what Signal has done so far. We shouldn't wait to solve this at some unknown point in the future before offering "huge amounts of value" to users.

Re: On Privacy versus Freedom

#59
post #25

I saw Moxie Marlinspike's talk when it was posted on CCC's official channel [1] and was disgusted by it. The talk has been now censored and video was made private. It was one of the most defeatist talks I've ever come across when it comes to messaging and privacy. His message was basically that anything you do is pointless and that his and WhatsApp/Facebook's way is the right one. I've used Signal on few occasions in…

I think if Moxie had framed this from a perspective of "centralization has some advantages, so how can we make a centralized service as safe as possible" the outcry would be much less. Because signal is genuinely doing some very great stuff in that area. But the framing as a dismissal of decentralized solutions as unworthwhile is very frustrating, especially when it so transparently overlaps with his business interests.

Re: On Privacy versus Freedom

#60
post #18

> Moxie didn’t want the 36C3 talk recorded Curious why. Anyway it's there: https://peertube.co.uk/videos/watch/12be5396-2a25-4ec8-a92a-...

Here's his reasoning: https://twitter.com/moxie/status/1211443530335281153

This seems kind of silly to me because:

1. Does the same thing not also apply to the blog post he authored, which contains the exact same points?

2. Is a talk where you get a big stage to preach your opinion from and take two questions at the end really the best way to do this? As opposed to say, a panel discussion or similar.

Post reply on HN