Live data from Hacker News

Briar Project

briarproject.org

91–100 of 189 posts

Re: Briar Project

#91

Support for a TEMPEST mode of communication would be a killer feature. Perhaps vibrate mode on one phone being picked up by the accelerometer of another? In our hypothetical dystopian future The Regime will probably jam 2Ghz to 5Ghz in public spaces. TEMPEST mode would also force them to install vibrators into all coffee shop tables.

What’s TEMPEST? Something that communicates by vibrating a table? In my dystopian future theory, the government that has no issue jamming 2 and 5 ghz channels to keep people from talking would probably notice two people on on a table continually picking up And dropping their phones. Why wouldn’t they simply whisper to each other in that scenario?

TEMPEST is a generic term for extracting data that emanates from channels which were are not supposed to carry data. It’s usually an attack, used to spy on people.

The classic example is pointing a high speed camera at an office window across the street and recording the brightness of the walls. Even if the office computer is hidden out of sight the attacker can reconstruct what’s on screen by analysing subtle changes in brightness reflected off the wall.

Re: Briar Project

#92
post #70

I don’t have an answer, but a slightly different perspective. Many different segments have a deep interest in using highly secure encrypted communications: politicians working on deals within/between governments (that should be auditable, but many try to avoid that), whistleblowers, organizers operating in adverse governments, dissidents, terrorists, pedophiles with a lot to lose (similar to Epstein’s network), healt…

As much as I don't like Epstein's network, it is better for him to go free than to live in an authoritarian state with locked down protocols which control what someone can and can't do.

Someone like Epstein could easily communicate with coded messages. Or send someone to convey messages in person.

Re: Briar Project

#93
post #35

In an authoritarian regime with large masses of human and technological resources determined to have control over its population, nothing is really secure. Sending a message that can't be read by a third party? You're suspect. Have an illegal app installed on your registered "report to big brother" phone? Expect an unfriendly visit by big brother police. Don't have a "big brother" phone? There are various ways of sni…

Authoritarian regimes are often far less technologically advanced than free countries. They will often import technology from free countries and be constrained by whatever freedom respecting decisions they've made.

Re: Briar Project

#94
post #6

I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…

> Telegram isn't very secure

Can someone elaborate?

Re: Briar Project

#95
post #6

I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…

Have you tried Jabber with Conversations or Pix-Art android app? It has end to end encryption (OMEMO), support for sharing media, voice and video calling, multitude of desktop clients, (a less secure) web client etc.

Most importantly, you can host the server yourself without cutting off from the network.

Re: Briar Project

#96

Earlier quoted context omitted.

What’s TEMPEST? Something that communicates by vibrating a table? In my dystopian future theory, the government that has no issue jamming 2 and 5 ghz channels to keep people from talking would probably notice two people on on a table continually picking up And dropping their phones. Why wouldn’t they simply whisper to each other in that scenario?

TEMPEST is a generic term for extracting data that emanates from channels which were are not supposed to carry data. It’s usually an attack, used to spy on people. The classic example is pointing a high speed camera at an office window across the street and recording the brightness of the walls. Even if the office computer is hidden out of sight the attacker can reconstruct what’s on screen by analysing subtle change…

> The classic example is pointing a high speed camera at an office window across the street and recording the brightness of the walls. Even if the office computer is hidden out of sight the attacker can reconstruct what’s on screen by analysing subtle changes in brightness reflected off the wall.

Is this feasible now?

Re: Briar Project

#97
post #35

In an authoritarian regime with large masses of human and technological resources determined to have control over its population, nothing is really secure. Sending a message that can't be read by a third party? You're suspect. Have an illegal app installed on your registered "report to big brother" phone? Expect an unfriendly visit by big brother police. Don't have a "big brother" phone? There are various ways of sni…

This is precisely why it's important to make these tools (protocols/applications) part of the core layer of how businesses operate consumer-facing services online; it's only true if the ratio of "interesting" communication over these channels is high enough.

In an alternative timeline where ISPs where more strictly regulated and trusted and everything was cleartext HTTP, I'm certain that HTTPS/TLS would face pushback from regulators. There's no way it can be banned today, though. Similarly, you won't be marked as suspicious just from opening an encrypted TLS connecting over port 443 to an arbitrary endpoint.

I don't think it's too late. There is a significant probability that today's centralized incumbents will Myspace at some point in the future. These federated, decentralized and secure solutions could be the next iteration after that.

Re: Briar Project

#98
post #87

Earlier quoted context omitted.

None of the big tech companies sell user data.

Idk if you consider Twitter a big tech company, but they do: https://developer.twitter.com/en/pricing . I don't believe Google or FB does though.

That isn't selling user data. All that is on the site itself, they are just making it easier to access. I'm talking about their click streams and other things that are invisible to the public. That data no one sells because it is how they target their ads.

Re: Briar Project

#99
post #93
post #35

In an authoritarian regime with large masses of human and technological resources determined to have control over its population, nothing is really secure. Sending a message that can't be read by a third party? You're suspect. Have an illegal app installed on your registered "report to big brother" phone? Expect an unfriendly visit by big brother police. Don't have a "big brother" phone? There are various ways of sni…

Authoritarian regimes are often far less technologically advanced than free countries. They will often import technology from free countries and be constrained by whatever freedom respecting decisions they've made.

China is an authoritarian regime that is as technologically advanced as the US and Western Europe, and they will gladly export freedom restricting technology.

Re: Briar Project

#100
post #74

Earlier this year, I finally took the time to revisit the state of instant messaging services. My requirements: - open source - cross-platform (linux, mac, windows, ios, android) - group chats - end-to-end encryption - well-understood crypto ciphers & protocols - mature enough for a reasonable expectation of security & privacy - easy enough for most computer users - some way to protect metadata (e.g. self-hosting) -…

Did you look into Status? https://status.im/ https://github.com/status-im/status-react https://github.com/status-im/nim-status-client

I've been out of the loop a bit on Status recently; do you know if it's currently utilizing Matrix protocol or if it's on the roadmap? I take their partnership and $5M investment into New Vector in 2018 as an indication of such intentions. Or perhaps they're intending to just bridge Whisper and Matrix.

https://matrix.org/blog/2018/01/29/status-partners-up-with-n...

Post reply on HN