Live data from Hacker News

Briar Project

briarproject.org

131–140 of 189 posts

Re: Briar Project

#131

Support for a TEMPEST mode of communication would be a killer feature. Perhaps vibrate mode on one phone being picked up by the accelerometer of another? In our hypothetical dystopian future The Regime will probably jam 2Ghz to 5Ghz in public spaces. TEMPEST mode would also force them to install vibrators into all coffee shop tables.

> Support for a TEMPEST mode of communication would be a killer feature.

You are misusing the term. TEMPEST is an attack.

> Perhaps vibrate mode on one phone being picked up by the accelerometer of another?

At very close distance vibrating our vocal cords and eardrums would be much easier and works without battery.

Re: Briar Project

#132
Briar Project (and other projects like Signal and Tor) are funded by Open Technology Fund.

OTF is being killed by the current US government and this will affect all projects!

https://en.wikipedia.org/wiki/Open_Technology_Fund

https://saveinternetfreedom.tech/

https://saveinternetfreedom.tech/updates/

Re: Briar Project

#133
many of my friends are activists, and i'm hesitant to disclose to them which technologies they could use. 95% chance they're going to use it for getting drugs, or avoid monitoring to organize gatherings, which, without law enforcement protection always have potential to turn violent. i just don't want to take responsibility for these actions.

then you have heavy stuff, people trafficking, bomb threats, suicide threats, organ trade, child abuse, and crypto seriously limits the options for a response. as long as we're talking about functioning democracies, it does more bad than good.

Re: Briar Project

#134

Earlier quoted context omitted.

Guess it depends on your circles. For my group, everyone has an iPhone or a Mac. For the outliers, everyone has cell phones, and iMessage supports SMS.

>iMessage supports SMS. Which isn't end to end encrypted which defeats the whole point in terms of this conversation.

Thank you for identifying that.

Re: Briar Project

#135
post #90

Earlier quoted context omitted.

I agree. I found that behaviour disgusting, and that's why I avoid Signal. Anyone who says Signal has good privacy is just wrong. When Signal say they have good privacy, that's false advertising. Of course, Telegram does the same thing. I have Telegram installed, and I use it, but it wasn't really a choice. I needed to access a forum which is only on Telegram :/ Unfortunately that meant I had no choice but to have pe…

You might want to read Whatsapp terms of service, in particular the part where they claim copyright and even the right to make derivative works on anything you transmit over their platform.

Oh don't get me wrong. I don't want to use WhatsApp. I'm only on it at all because I need to speak with people who are using it without antagonising them. I still haven't granted it access to my contacts DB.

All three of Signal, Telegram and WhatsApp make me a bit off about using them for various reasons. None of them are what you'd call "user's privacy first".

As it is, I'm currently having occasional confidential chats (at someone else's request) on Telegram secret chats, and at least that probably is what it says it is.

I don't think any of these three apps are awful.

They are pretty slick, and useful.

I don't feel too bad actually using them, any more then using say MSN, Yahoo or Freenode.

They just don't meet the advertised bar of respecting individual privacy first. And I find that really misleading in the case of Signal and Telegram in particular, which emphasise the privacy angle, and then without letting you know, sprays everyone you ever interacted with outside Signal with a notification, including professional contacts, customer service agents, people you don't like, spammers, etc.

Re: Briar Project

#136
post #6

I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…

FWIW, I think you can just get a Google Voice or other short-term burner number to sign up for Signal, and then never worry about it again. Signal's an order of magnitude more trustworthy than the other messaging players and have built out a good base of features at this point. (telegram specifically is a joke... proprietary closed-source encryption is a recipe for disaster.) I would strongly advise against picking a…

I don't think never worry about it again is quit correct

  What if someone registers with my old number? 
  If someone were to register with your old number on a new phone, then they will have an empty message history. Your contacts will also be made aware of a safety number change if they start messaging with the old number.

https://support.signal.org/hc/en-us/articles/360007062012-Ne...

Re: Briar Project

#137

Earlier quoted context omitted.

What’s TEMPEST? Something that communicates by vibrating a table? In my dystopian future theory, the government that has no issue jamming 2 and 5 ghz channels to keep people from talking would probably notice two people on on a table continually picking up And dropping their phones. Why wouldn’t they simply whisper to each other in that scenario?

TEMPEST is a generic term for extracting data that emanates from channels which were are not supposed to carry data. It’s usually an attack, used to spy on people. The classic example is pointing a high speed camera at an office window across the street and recording the brightness of the walls. Even if the office computer is hidden out of sight the attacker can reconstruct what’s on screen by analysing subtle change…

The more classic example is display cables like VGA, DVI and HDMI emanate signals that can be used to reconstruct the image displayed. Doesn't work for newer high speed HDMI though.

Old BBC documentary on the topic

https://www.youtube.com/watch?v=mcV6izFG3vQ

Re: Briar Project

#138
post #74

Earlier this year, I finally took the time to revisit the state of instant messaging services. My requirements: - open source - cross-platform (linux, mac, windows, ios, android) - group chats - end-to-end encryption - well-understood crypto ciphers & protocols - mature enough for a reasonable expectation of security & privacy - easy enough for most computer users - some way to protect metadata (e.g. self-hosting) -…

"some way to protect metadata (e.g. self-hosting)"

From whom are you trying to protect metadata? Briar distinguishes itself as a platform that doesn't leak it to anyone. Matrix always has at least one central point for metadata eavesdropping, and that's the device the entities interested in your communication will hack first. Or maybe the threat of the group is in the inside -- John, the creepy IT-guy of the peer network who has a crush on Karen and is jealously eavesdropping on her every action, including content when E2EE is disabled for some chats.

Thanks but no thanks. I'd much rather just centralize the trust to a known crypto anarchist like Moxie who doesn't know me in person, and if I can't trust anyone I'll just use Briar despite lack of offline-messages. It's not like my phone isn't on 24/7 anyway.

Wrt. Session, it's not at all clear how anonymous their onion routing network is, if there's enough nodes etc.

Re: Briar Project

#139
post #106

Earlier quoted context omitted.

No, that investment was for establishing good relationship. There were no attempts or discussions to marry or bridge protocols.

Huh. They do mention this as "potential obvious advantage" in the post I linked: > Bridging between Matrix and Whisper (Ethereum's own real-time communication protocol) - exposing all of the Matrix ecosystem into Ethereum and vice versa But maybe this is just meaningless marketing fluff and something that's effectively left to "the community".

Quick unrelated comment from the peanut gallery:

Every time any crypto-currency related messaging app is published, I think it should be mandatory to immediately explain what the currency and/or blockchain brings to the table. Is it a paid app? Does it store ciphertexts indenfinitely to the blockchain? Or public keys?

Re: Briar Project

#140
post #48

Criminal conspiracy as a service. I don’t think I’d invest my money. Edit: to clarify their marketing is transparently targeting organizers of street violence. I have no problem with encryption and don’t think government forbidding it is a good idea.

No it's being marketed to protesters, it's not helping violent people in any more ways than oxygen is. Let's ban oxygen from street thugs too? The cops are already doing great job on that.

Also, privacy this app helps to protect is a fucking human right too. You're not welcome here, please leave.

Post reply on HN