Live data from Hacker News

Briar Project

briarproject.org

81–90 of 189 posts

Re: Briar Project

#81
post #74

Earlier this year, I finally took the time to revisit the state of instant messaging services. My requirements: - open source - cross-platform (linux, mac, windows, ios, android) - group chats - end-to-end encryption - well-understood crypto ciphers & protocols - mature enough for a reasonable expectation of security & privacy - easy enough for most computer users - some way to protect metadata (e.g. self-hosting) -…

Did you look into Status?

https://status.im/

https://github.com/status-im/status-react

https://github.com/status-im/nim-status-client

Re: Briar Project

#83
Support for a TEMPEST mode of communication would be a killer feature. Perhaps vibrate mode on one phone being picked up by the accelerometer of another?

In our hypothetical dystopian future The Regime will probably jam 2Ghz to 5Ghz in public spaces. TEMPEST mode would also force them to install vibrators into all coffee shop tables.

Re: Briar Project

#84

Support for a TEMPEST mode of communication would be a killer feature. Perhaps vibrate mode on one phone being picked up by the accelerometer of another? In our hypothetical dystopian future The Regime will probably jam 2Ghz to 5Ghz in public spaces. TEMPEST mode would also force them to install vibrators into all coffee shop tables.

What’s TEMPEST? Something that communicates by vibrating a table?

In my dystopian future theory, the government that has no issue jamming 2 and 5 ghz channels to keep people from talking would probably notice two people on on a table continually picking up And dropping their phones. Why wouldn’t they simply whisper to each other in that scenario?

Re: Briar Project

#85
post #6

I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…

The project is no longer maintained but Oversec had a cool concept of hiding your own encrypted text as non-printing chars in Android text fields in any other app, like e.g. WhatsApp.

https://github.com/oversecio/oversec

Re: Briar Project

#86
post #70

I don’t have an answer, but a slightly different perspective. Many different segments have a deep interest in using highly secure encrypted communications: politicians working on deals within/between governments (that should be auditable, but many try to avoid that), whistleblowers, organizers operating in adverse governments, dissidents, terrorists, pedophiles with a lot to lose (similar to Epstein’s network), healt…

This is the same way of thinking many politicians subscribe to: "There has been one terrorist attack, which killed 20 people, quickly now, surveilance everyone and everything! Think of the dangers!"

Throwing out the baby with the bathing water (does this proverb exist in English?) is not going to do society much good. Just because there some bad actors, one does not need to discard the whole idea of encryption.

Also the dehumanized way of checking for bad content will not help. Bad actors can pre-encrypt or disguise content, whatever you do. Furthermore when the bots have the key to decryption, then the backdoor is built into the system. Bad actors and politicians will try to make use of that.

Re: Briar Project

#87

Earlier quoted context omitted.

Oh indeed it is. I spent years reading apple reports and my conclusion was that they want the data for themselves so they can sell it. Devices don't make much profit when you factor in how much is spent buying up almost all old devices that hit the market.

None of the big tech companies sell user data.

Idk if you consider Twitter a big tech company, but they do: https://developer.twitter.com/en/pricing. I don't believe Google or FB does though.

Re: Briar Project

#88

Earlier quoted context omitted.

They target ads to your interests, default on: "Ads that are delivered by Apple’s advertising platform may appear in Apple News and in the App Store. If you do not wish to receive ads targeted to your interests from Apple's advertising platform, you can choose to enable Limit Ad Tracking, which will opt your Apple ID out of receiving such ads regardless of what device you are using. If you enable Limit Ad Tracking on…

A third party being able to list ads on apples ad platform that target some collection of desired user data is not the same thing as said third party obtaining user data. Third parties are buying ad listings, not user data. They have no way to extract user data from the ad platform, unless there's some kind of data leak. If you think Apple is harvesting data off of bought back phones to improve their ad targeting tha…

Unless those ads contain anything, that is loaded from the ad creating company, whichis then loaded in the user browser. Of course, no platform would allow requests to a third party …

Re: Briar Project

#89

Earlier quoted context omitted.

It is, alongside limiting what you can do with their leased equipment that people think they bought.

This made me jump. You make one excellent point, with appropriately shocking language: When I can’t do what I want with my phone, I may as well be leasing it. Hmmm. But I don’t believe Apple’s business model is to spy on me.

> But I don’t believe Apple’s business model is to spy on me.

Apple business is not spying on you, but Apple business is much easier to do if they do spy on you. Meaning they do it anyway, don't worry.

Re: Briar Project

#90

Earlier quoted context omitted.

Signal is working on getting rid of the cell # requirement, but it'll take a while.

It can't happen soon enough. I installed Signal a few years ago, and the first thing it did was notify a bunch of people I had in my contacts, that I was now using Signal... ...Including the unstable frenemy-guy who was only in my contacts so I'd recognize the number if he called and I'd know not to answer... ....who immediately PM'd me on Signal to push his latest delusion and make sure I didn't disagree. Great, jus…

I agree. I found that behaviour disgusting, and that's why I avoid Signal.

Anyone who says Signal has good privacy is just wrong. When Signal say they have good privacy, that's false advertising.

Of course, Telegram does the same thing. I have Telegram installed, and I use it, but it wasn't really a choice. I needed to access a forum which is only on Telegram :/ Unfortunately that meant I had no choice but to have people who know me notified that I installed it. Someone messaged me about 30 seconds after I installed it to say hi. I'm not comfortable about this, but as I say, I didn't really have a choice.

Then there's WhatsApp. I was surprised to read an article which recommended that, of the three, WhatsApp is probably the most privacy-respecting of the apps. I have WhatsApp installed after a long period of avoiding it, because of all people recruiters started expecting it. Hmph. I still refuse to grant it access to my contact list, because I'm not handing that over to Facebook. Which means every message is associated with a raw phone number only, and I have to guess who it is from the content :-)

You can tell WhatsApp doesn't reveal so much, by the people who have sent WhatsApp messages without being told that the recipient doesn't have WhatsApp installed and won't see the message. I've known a few people this happened to. One installed WhatsApp and found they'd been sent a message a year earlier, from someone they thought wasn't talking to them. They were talking, but the sender assumed of course the recipient would have WhatsApp.

Post reply on HN