Live data from Hacker News

Briar Project

briarproject.org

11–20 of 189 posts

Re: Briar Project

#11

Now that I think about it, why aren't most messaging apps peer to peer? Shouldn't that be the standard? I mean it's literally the point of messages: sending from one person to another.

Because: a) Often the intended recipient isn't online when the message is sent, and it may happen that there is never a time when both sender and recipient are online simultaneously (e.g. sender's device only turns on to send the occasional message, receiver's device is usually off but turns on occasionally to check if there are messages) b) Often one or both devices can only connect to, but can't be connected to (be…

In before someone suggests storing encrypted messages in a public blockchain. This is a really good overview of the challenges with these messaging systems. Store and forward has been our MO since email and Usenet were invented because always on always connected devices that aren’t restricted by some network obstacle are not really feasible or even desirable most of the time. I do wonder what alternatives we have to something like a trusted online service to store and forward messages or a public blockchain. Some kind of crypto based system where nobody but the owner of a private key can even locate the message? A decentralized system where multiple copies of multiple fragments of your message are stored so nobody can piece together your (encrypted) message without controlling the majority of the nodes?

Re: Briar Project

#12

Earlier quoted context omitted.

Because: a) Often the intended recipient isn't online when the message is sent, and it may happen that there is never a time when both sender and recipient are online simultaneously (e.g. sender's device only turns on to send the occasional message, receiver's device is usually off but turns on occasionally to check if there are messages) b) Often one or both devices can only connect to, but can't be connected to (be…

In before someone suggests storing encrypted messages in a public blockchain. This is a really good overview of the challenges with these messaging systems. Store and forward has been our MO since email and Usenet were invented because always on always connected devices that aren’t restricted by some network obstacle are not really feasible or even desirable most of the time. I do wonder what alternatives we have to…

Do you have an opinion on Skype like centralised coordinator that then sets up P2P connections?

Re: Briar Project

#13

Now that I think about it, why aren't most messaging apps peer to peer? Shouldn't that be the standard? I mean it's literally the point of messages: sending from one person to another.

Because: a) Often the intended recipient isn't online when the message is sent, and it may happen that there is never a time when both sender and recipient are online simultaneously (e.g. sender's device only turns on to send the occasional message, receiver's device is usually off but turns on occasionally to check if there are messages) b) Often one or both devices can only connect to, but can't be connected to (be…

Is IPv6 likely to be a practical solution to the router/NAT issue? Are routers assigning globally-routable IPs to their clients, is that already a thing?

Re: Briar Project

#14
post #7
post #6

I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…

Have you looked at 'threema'? I recently installed it and I'm actually pleasantly surprised. However, all of these bloody messengers mean that my contacts list is spread across a multitude of programs: we need the iOS/Android equivalent of pidgin.

Pidgin is exactly what we need.. and each messenger needs to be a pluggable module. Then we dont need to hound friends and family to switch messenger apps they just use pidgin.

Re: Briar Project

#15

Now that I think about it, why aren't most messaging apps peer to peer? Shouldn't that be the standard? I mean it's literally the point of messages: sending from one person to another.

> why aren't most messaging apps peer to peer [...] it's literally the point of messages: sending from one person to another.

Messaging apps are more like postal services — "please deliver this message to $person" — you're describing driving across town to drop something in a mailbox directly. A peer-to-peer messaging system wouldn't have many benefits over an E2E-encrypted one (in a centralized E2E-encrypted service you already enjoy technical guarantees that the courier can't peek inside the metaphorical envelope), but would have several usability drawbacks that would drive away casual users, which the sibling comments mention.

Driving away casual users has its own problems: you might drive them away to insecure services ("ah fuck it, this thing doesn't work, I'll just DM them on Twitter"), and the lack of casual users will make your remaining users stand out in traffic analysis (e.g. state agency says "hmm, askxnakjsn is using SuperEncryptoP2PMessenger, better go make sure they aren't a dissident").

Re: Briar Project

#16
post #7
post #6

I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…

Have you looked at 'threema'? I recently installed it and I'm actually pleasantly surprised. However, all of these bloody messengers mean that my contacts list is spread across a multitude of programs: we need the iOS/Android equivalent of pidgin.

Threema is closed source which is something I don't really like when it comes to security as there are no independent audits.

Edit: Generally, Threema seems interesting feature-wise, but I think the price (4€) will prevent my contacts from using it...

Re: Briar Project

#17
post #14
post #7

Earlier quoted context omitted.

Have you looked at 'threema'? I recently installed it and I'm actually pleasantly surprised. However, all of these bloody messengers mean that my contacts list is spread across a multitude of programs: we need the iOS/Android equivalent of pidgin.

Pidgin is exactly what we need.. and each messenger needs to be a pluggable module. Then we dont need to hound friends and family to switch messenger apps they just use pidgin.

But why would something like Facebook open up their walled garden? Does it even count as a walled garden when you have 2 billion people on the platform?

Re: Briar Project

#18
post #6

I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…

FWIW, I think you can just get a Google Voice or other short-term burner number to sign up for Signal, and then never worry about it again. Signal's an order of magnitude more trustworthy than the other messaging players and have built out a good base of features at this point. (telegram specifically is a joke... proprietary closed-source encryption is a recipe for disaster.)

I would strongly advise against picking a tiny new-comer without some serious research beforehand... They're not battle-hardened, so will typically be less reliable than any of the existing larger players.

Re: Briar Project

#19
post #7
post #6

I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…

Have you looked at 'threema'? I recently installed it and I'm actually pleasantly surprised. However, all of these bloody messengers mean that my contacts list is spread across a multitude of programs: we need the iOS/Android equivalent of pidgin.

threema claims no having no identificable information yet the account IDs are just the unsalted hashes of your telephone number.

Re: Briar Project

#20

Earlier quoted context omitted.

Because: a) Often the intended recipient isn't online when the message is sent, and it may happen that there is never a time when both sender and recipient are online simultaneously (e.g. sender's device only turns on to send the occasional message, receiver's device is usually off but turns on occasionally to check if there are messages) b) Often one or both devices can only connect to, but can't be connected to (be…

In before someone suggests storing encrypted messages in a public blockchain. This is a really good overview of the challenges with these messaging systems. Store and forward has been our MO since email and Usenet were invented because always on always connected devices that aren’t restricted by some network obstacle are not really feasible or even desirable most of the time. I do wonder what alternatives we have to…

It seems like this might be the eventual intent of the Scuttlebutt protocol, and so far that's also the furthest along in approaching such a solution.
Post reply on HN