Live data from Hacker News

Briar Project

briarproject.org

151–160 of 189 posts

Re: Briar Project

#151

Earlier quoted context omitted.

Signal is working on getting rid of the cell # requirement, but it'll take a while.

It can't happen soon enough. I installed Signal a few years ago, and the first thing it did was notify a bunch of people I had in my contacts, that I was now using Signal... ...Including the unstable frenemy-guy who was only in my contacts so I'd recognize the number if he called and I'd know not to answer... ....who immediately PM'd me on Signal to push his latest delusion and make sure I didn't disagree. Great, jus…

Signal can't fix social problems. Sounds like you probably ought to cut the toxic person out of your life. Or if that's too confrontational, there's always the old, "Sorry, I just got this number, don't know who you're talking about."

Re: Briar Project

#152
post #70

I don’t have an answer, but a slightly different perspective. Many different segments have a deep interest in using highly secure encrypted communications: politicians working on deals within/between governments (that should be auditable, but many try to avoid that), whistleblowers, organizers operating in adverse governments, dissidents, terrorists, pedophiles with a lot to lose (similar to Epstein’s network), healt…

This is the same way of thinking many politicians subscribe to: "There has been one terrorist attack, which killed 20 people, quickly now, surveilance everyone and everything! Think of the dangers!" Throwing out the baby with the bathing water (does this proverb exist in English?) is not going to do society much good. Just because there some bad actors, one does not need to discard the whole idea of encryption. Also…

The English idiom is precisely "throwing out the baby with the bath water." So, as they say, you "hit the nail on the head."

Re: Briar Project

#153

Earlier quoted context omitted.

It seems like this might be the eventual intent of the Scuttlebutt protocol, and so far that's also the furthest along in approaching such a solution.

I'm really intrigued by the Scuttlebutt protocol, but in practice it's super hard to get plugged into the community because, as a new user, nobody follows you. I haven't figured out how to just engage people in conversation -- I reply to their posts but nobody sees my replies. If there are other applications that can run over the protocol, I'm interested in learning about them.

The dealbreaker with Scuttlebutt for me was the inability to delete messages.

Re: Briar Project

#154

Support for a TEMPEST mode of communication would be a killer feature. Perhaps vibrate mode on one phone being picked up by the accelerometer of another? In our hypothetical dystopian future The Regime will probably jam 2Ghz to 5Ghz in public spaces. TEMPEST mode would also force them to install vibrators into all coffee shop tables.

> Support for a TEMPEST mode of communication would be a killer feature. You are misusing the term. TEMPEST is an attack. > Perhaps vibrate mode on one phone being picked up by the accelerometer of another? At very close distance vibrating our vocal cords and eardrums would be much easier and works without battery.

I can't exactly modulate my vocal chords to send a file. But I think you're right, using some sort of high-frequency beacon tone like what they use for the creeping tracking identifiers might be an option.

Re: Briar Project

#155

Earlier quoted context omitted.

Signal is working on getting rid of the cell # requirement, but it'll take a while.

It can't happen soon enough. I installed Signal a few years ago, and the first thing it did was notify a bunch of people I had in my contacts, that I was now using Signal... ...Including the unstable frenemy-guy who was only in my contacts so I'd recognize the number if he called and I'd know not to answer... ....who immediately PM'd me on Signal to push his latest delusion and make sure I didn't disagree. Great, jus…

That's because most privacy design is done by nerds who think "CIA/NSA/GCHQ/Mossad/FSB etc. might secretly whisk me away to Gitmo for my thoughtcrimes" is a far more pressing problem in people's lives than "my partner is a coercive, controlling domestic abuser", or "my employer might fire me for trying to set up a union"...

Re: Briar Project

#156
post #48

Criminal conspiracy as a service. I don’t think I’d invest my money. Edit: to clarify their marketing is transparently targeting organizers of street violence. I have no problem with encryption and don’t think government forbidding it is a good idea.

> their marketing is transparently targeting organizers of street violence.

The cops already have radios.

Re: Briar Project

#157
post #111

Earlier quoted context omitted.

That isn't selling user data. All that is on the site itself, they are just making it easier to access. I'm talking about their click streams and other things that are invisible to the public. That data no one sells because it is how they target their ads.

Twitter is literally selling data (tweets) that users generate via API.

The data is public and available to everyone. They are selling an API to it.

Re: Briar Project

#158
post #74

Earlier this year, I finally took the time to revisit the state of instant messaging services. My requirements: - open source - cross-platform (linux, mac, windows, ios, android) - group chats - end-to-end encryption - well-understood crypto ciphers & protocols - mature enough for a reasonable expectation of security & privacy - easy enough for most computer users - some way to protect metadata (e.g. self-hosting) -…

Just installed it. How do direct messages work? Is it just a room with two people in it?

Yep. There's some work to help clearly differentiate these from group rooms that allow for some more guarantees underway: https://github.com/matrix-org/matrix-doc/pull/2199

But at the core, yes it's just a group room with two people.

Re: Briar Project

#159
What I don't understand about Briar is how it can scale. Surely it can't know ahead of time which users are going to "travel to another part of town" and should therefore have messages pre-loaded onto their devices. Therefore to me this seems like it must use some kind of broadcast delivery model and so would be vulnerable to flooding attacks.

Edit: seems there are some thoughts about this already https://code.briarproject.org/briar/briar/-/issues/511

Re: Briar Project

#160
post #148

Earlier quoted context omitted.

Isn’t matrix basically all that’s needed? It even has out-of-band verification of your friend’s keys.

If only the ecosystem had been built to use E2EE by default, always. They fucked up with the design allowing bridges and bots, left E2EE for later, and now they're in the vicious circle of downgrade attacks until all major clients switch to E2EE with no insecure fall-back option.

there aren't downgrade attacks. we turned on E2EE by default in May for private rooms, and there's no negotiation involved. if you're on a client that supports E2EE (i.e. almost all major ones, now) and you try to DM someone, they simply won't be able to read you unless they support E2EE. i.e. they can't downgrade the convo.
Post reply on HN