Live data from Hacker News

Briar Project

briarproject.org

111–120 of 189 posts

Re: Briar Project

#111
post #87

Earlier quoted context omitted.

Idk if you consider Twitter a big tech company, but they do: https://developer.twitter.com/en/pricing . I don't believe Google or FB does though.

That isn't selling user data. All that is on the site itself, they are just making it easier to access. I'm talking about their click streams and other things that are invisible to the public. That data no one sells because it is how they target their ads.

Twitter is literally selling data (tweets) that users generate via API.

Re: Briar Project

#112

Earlier quoted context omitted.

This is precisely why it's important to make these tools (protocols/applications) part of the core layer of how businesses operate consumer-facing services online; it's only true if the ratio of "interesting" communication over these channels is high enough. In an alternative timeline where ISPs where more strictly regulated and trusted and everything was cleartext HTTP, I'm certain that HTTPS/TLS would face pushback…

Oppressors can (and I think some already do) subvert HTTPS by mandating installation of government-issued certs so they can do their MITM.

I know there have been attempts (was it Iran and Kazakhstan that was in the news last year?), but is anyone aware of this actually being done in practice today? My understanding is that they were forced to roll back for practical reasons (which highlights my point).

Re: Briar Project

#113
post #96

Earlier quoted context omitted.

TEMPEST is a generic term for extracting data that emanates from channels which were are not supposed to carry data. It’s usually an attack, used to spy on people. The classic example is pointing a high speed camera at an office window across the street and recording the brightness of the walls. Even if the office computer is hidden out of sight the attacker can reconstruct what’s on screen by analysing subtle change…

> The classic example is pointing a high speed camera at an office window across the street and recording the brightness of the walls. Even if the office computer is hidden out of sight the attacker can reconstruct what’s on screen by analysing subtle changes in brightness reflected off the wall. Is this feasible now?

Yep

https://www.nassiben.com/lamphone

Re: Briar Project

#114
post #68

Earlier quoted context omitted.

I understand your frustration, but Signal didn't notify your contacts because you installed it. It notified the other person, because he had your phone number. Your local Signal installation regularly checks if any of your contacts (with the phone numbers you have of them) are registered at the Signal servers - and then lets you know it, such that you can text this contact securely.

The technical details do not really matter. Many people might have my phone number, possibly from a long ago. But the number itself is pretty safe -- there is no way to tell if this phone is in use or not. Signal breaks that assumption -- it immediately tells every other user that this number is alive, valid, and can be contacted right now. This is a terrible idea to do by default, especially if one cannot disable it…

Although it lacks a notification in WhatsApp it's just as easy to check a phone number for 'aliveness'. When you select 'new conversation' you get a list of your contacts with a name (from your address book) and a picture and tagline.

This is all based on your address-book so it doesn't matter if the other party knows your number or not.

Re: Briar Project

#115
post #16
post #7

Earlier quoted context omitted.

Have you looked at 'threema'? I recently installed it and I'm actually pleasantly surprised. However, all of these bloody messengers mean that my contacts list is spread across a multitude of programs: we need the iOS/Android equivalent of pidgin.

Threema is closed source which is something I don't really like when it comes to security as there are no independent audits. Edit: Generally, Threema seems interesting feature-wise, but I think the price (4€) will prevent my contacts from using it...

Interesting thought experiment though; if you’re not paying for the development and hosting- who is?

Re: Briar Project

#116
post #35

In an authoritarian regime with large masses of human and technological resources determined to have control over its population, nothing is really secure. Sending a message that can't be read by a third party? You're suspect. Have an illegal app installed on your registered "report to big brother" phone? Expect an unfriendly visit by big brother police. Don't have a "big brother" phone? There are various ways of sni…

When someone reads the above comment and thinks 'Oh well, it is a risk the user is willing to take by using these apps in an Authoritarian regime' should think again.

Targeting users who rely upon secure apps is becoming common in flawed democracies as well and more countries are eager to join that list. Several people, including minors were arrested in Kashmir when police found VPN app on their mobile during routine checks[0]. Government's logic being 'Why use VPN, if you are not a terrorist?'

At the same time journalists, activists are heavily dependent upon secure apps like this to make their voice heard outside, all the more reason for all of us who are lucky to not have gestapo knocking our doors because we used a VPN to watch PornHub to make usage of such secure apps (messaging, email, VPN etc.) very common.

[0]https://scroll.in/article/954711/in-kashmir-a-spree-of-arres...

Re: Briar Project

#117
post #94
post #6

I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…

> Telegram isn't very secure Can someone elaborate?

There are different aspects to this. The first and the easily verifiable one is that they default to client-server-client connections, not end-to-end encryption. If you want to have an end-to-end encrypted channel, you have to explicitly open a "secret chat". However, this removes the convenience of cross device syncing.

The second one is more difficult to evaluate. If you use the above mentioned "secret chat" feature, Telegram employs their own closed-source encryption scheme. That's usually an indicator to be cautious from the get-go. Since it's closed source, it can't really be trusted.

See [Wikipedia](https://en.wikipedia.org/wiki/Telegram_(software)#Security) for a timeline in regards to the security.

Re: Briar Project

#118
post #30

Earlier quoted context omitted.

Which requires you to trust your neighbours. To which you might say: aha! Just use end to end encryption! And sure, you can. But at that point, what benefits are you getting over using E2E with a centralised system? Very few. And you’re getting a bunch of drawbacks in terms of reliability too.

I dunno, a centralized server means a centralized off-switch, that's a pretty huge drawback in terms of reliability.

which is why centralized/peer-to-peer is a false dichotomy the solution to many of the problems of both of them is (forkable) federated networks

Re: Briar Project

#119
post #94

Earlier quoted context omitted.

> Telegram isn't very secure Can someone elaborate?

There are different aspects to this. The first and the easily verifiable one is that they default to client-server-client connections, not end-to-end encryption. If you want to have an end-to-end encrypted channel, you have to explicitly open a "secret chat". However, this removes the convenience of cross device syncing. The second one is more difficult to evaluate. If you use the above mentioned "secret chat" featur…

Telegram clients are open source. I downloaded and built MacOS version recently - it was very straightforward.

https://telegram.org/apps#source-code

Encryption for secret chats doesn't involve server, so technically it can be analyzed.

It's a pity Telegram decided to roll their own encryption scheme. I use Telegram a lot for daily business because it's superior desktop messenger product. I would gladly participate if somebody started a crowd-funding for Telegram's security and encryption audit.

Re: Briar Project

#120
post #93

Earlier quoted context omitted.

Authoritarian regimes are often far less technologically advanced than free countries. They will often import technology from free countries and be constrained by whatever freedom respecting decisions they've made.

This is like saying that the weapons advanced countries sell to less advanced countries are more "life-respecting".

Imagine a world where a gun sold is by the US to a poor wartorn nation. When the trigger is pulled, it does facial recognition to figure out who it is aimed at, and if it detects someone friendly to US interests, it will refuse to hit them.
Post reply on HN