Live data from Hacker News

Briar Project

briarproject.org

161–170 of 189 posts

Re: Briar Project

#161
post #148

Earlier quoted context omitted.

If only the ecosystem had been built to use E2EE by default, always. They fucked up with the design allowing bridges and bots, left E2EE for later, and now they're in the vicious circle of downgrade attacks until all major clients switch to E2EE with no insecure fall-back option.

there aren't downgrade attacks. we turned on E2EE by default in May for private rooms, and there's no negotiation involved. if you're on a client that supports E2EE (i.e. almost all major ones, now) and you try to DM someone, they simply won't be able to read you unless they support E2EE. i.e. they can't downgrade the convo.

Yeah, I really like the ability to have an unencrypted channel: easy bots and bridges are one of the main advantages for me of matrix vs. IRC.

My only big issue is that the iOS client doesn’t support multiple simultaneous identities.

Re: Briar Project

#162
post #70

I don’t have an answer, but a slightly different perspective. Many different segments have a deep interest in using highly secure encrypted communications: politicians working on deals within/between governments (that should be auditable, but many try to avoid that), whistleblowers, organizers operating in adverse governments, dissidents, terrorists, pedophiles with a lot to lose (similar to Epstein’s network), healt…

The ideal solution will not throw away encryption, but enable self-policing. It's the difference between HN and 4Chan. AI with safety vs Pure AI unleashed.

Re: Briar Project

#163
post #6

I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…

FWIW, I think you can just get a Google Voice or other short-term burner number to sign up for Signal, and then never worry about it again. Signal's an order of magnitude more trustworthy than the other messaging players and have built out a good base of features at this point. (telegram specifically is a joke... proprietary closed-source encryption is a recipe for disaster.) I would strongly advise against picking a…

I had no luck getting people to use signal. Family thinks that I'm a freak because I try to make them understand that in socialist Denmark your communication is not secure from the government.

The app is easy to use, but people are not using it. They use sms and FB etc. to message friends.

Re: Briar Project

#164
post #64
post #62

What the fuck ever happened to communicating through plain old radios? Impractical for someone to track you, trivial to speak in codes.

Distance is an issue. And it's unlawful in the United States to encrypt ham radio traffic. No one's really monitoring CB much anymore though.

It’s unlawful to protest violently as well, I don’t see the point in obeying ham radio laws there.

Re: Briar Project

#165

Earlier quoted context omitted.

Did you look into Status? https://status.im/ https://github.com/status-im/status-react https://github.com/status-im/nim-status-client

I didn't, but since you linked to it, I took a peek. I couldn't find any linux, macos, or windows support within a couple minutes of visiting the site, so it fails my "cross-platform" and "easy enough" requirements. It seems to be married to Ethereum. That's mildly interesting. It raises questions about its relationship to cryptocurrency and blockchain tech, but until it meets my requirements, I'm not inclined to spe…

The desktop client (linux, macos, windows) is a work in progress; alpha builds are available. See the third link in my comment to which you replied. I could have been more clear on that point — I replied on my phone just before going to bed.

The wallet functionality is tied to Ethereum, but the chat functionality works separately.

Originally Status used the Whisper protocol, which used to ship with some Ethereum clients but never gained real traction. Status has switched to a protocol named Waku that's in development but progressing nicely.

If at some point you're interested and have questions, let us know! (I'm on the team developing the desktop client)

Re: Briar Project

#166

Earlier quoted context omitted.

It seems like this might be the eventual intent of the Scuttlebutt protocol, and so far that's also the furthest along in approaching such a solution.

I'm really intrigued by the Scuttlebutt protocol, but in practice it's super hard to get plugged into the community because, as a new user, nobody follows you. I haven't figured out how to just engage people in conversation -- I reply to their posts but nobody sees my replies. If there are other applications that can run over the protocol, I'm interested in learning about them.

Yeah, that behaviour's designed to counter spam and unwanted bots, but it does mean newbies need to be invited into a community. Meanwhile it's lonely talking into the void.

You could connect to a pub — an automatically-friendly bot account; see a list at https://github.com/ssbc/ssb-server/wiki/Pub-Servers — scuttle.space seems to be active right now.

If you're happy posting your SSB ID publicly, I'll follow you, and that may help. Or you can use the #new-people tag if you want to introduce/announce yourself :)

Re: Briar Project

#167
post #139

Earlier quoted context omitted.

Quick unrelated comment from the peanut gallery: Every time any crypto-currency related messaging app is published, I think it should be mandatory to immediately explain what the currency and/or blockchain brings to the table. Is it a paid app? Does it store ciphertexts indenfinitely to the blockchain? Or public keys?

While I understand where you're coming from, Status is an interesting project even if you completely disregard their (IMO shoehorned utility-) token. The main thing they have right now is an app acting as a wallet (ETH and Ethereum-based tokens) and IM app (Whisper protocol). It's standard practice that what you request is answered in a whitepaper, which is also the case for Status: https://status.im/whitepaper.pdf

Status now uses the Waku protocol, Whisper is pretty much dead.

Re: Briar Project

#168
post #138
post #74

Earlier this year, I finally took the time to revisit the state of instant messaging services. My requirements: - open source - cross-platform (linux, mac, windows, ios, android) - group chats - end-to-end encryption - well-understood crypto ciphers & protocols - mature enough for a reasonable expectation of security & privacy - easy enough for most computer users - some way to protect metadata (e.g. self-hosting) -…

"some way to protect metadata (e.g. self-hosting)" From whom are you trying to protect metadata? Briar distinguishes itself as a platform that doesn't leak it to anyone. Matrix always has at least one central point for metadata eavesdropping, and that's the device the entities interested in your communication will hack first. Or maybe the threat of the group is in the inside -- John, the creepy IT-guy of the peer net…

I think it's important to distinguish mass surveillance from targeted surveillance. They present very different threat models.

I need a general-purpose chat tool for use with friends, family, and business contacts. Protection from targeted surveillance by a state actor (or someone with equivalent resources) is neither a priority nor realistic today in light of my other requirements. I'm okay with using a separate tool if I ever need that kind of special-purpose protection.

Roughly stated, the goal is to regain the convenience of older tools like talk, ytalk, irc, ICQ, AIM, Yahoo Messenger, Facebook Messenger, and Google Talk, without being inaccessible to swaths of the computer-using population, and without exposing us all to mass surveillance any more than necessary. Matrix succeeds at this admirably, and continues to get better at it over time. (You might want to look at their in-progress P2P work.)

Briar fails unless you only talk to people using smartphones.

MoxieTalk fails because it exposes people to mass surveillance. In multiple ways. Over and over again. (Also, I've never seen a good linux client for it.)

I acknowledge that both those tools look very useful for certain purposes, and I have a good deal of respect for Moxie because of his contributions to the crypto/comms community, but neither tool does what I need.

Re: Briar Project

#169
post #74

Earlier this year, I finally took the time to revisit the state of instant messaging services. My requirements: - open source - cross-platform (linux, mac, windows, ios, android) - group chats - end-to-end encryption - well-understood crypto ciphers & protocols - mature enough for a reasonable expectation of security & privacy - easy enough for most computer users - some way to protect metadata (e.g. self-hosting) -…

Just installed it. How do direct messages work? Is it just a room with two people in it?

Yes. The reference clients recently started displaying those differently from group conversations, but the visual distinction has been pretty minor so far.

Re: Briar Project

#170
post #146

Earlier quoted context omitted.

You might want to look at Wire https://wire.com/

"some way to protect metadata (e.g. self-hosting)" is incompatible with Wire. Let's not just scream product names without understanding if it's for their threat model. If you're here to promote Wire then I perfectly understand why you'd recommend it anyway.

Yeah, Wire failed my requirements, but I probably should have mentioned it. (I simply forgot about it when I was posting.)

There's the issue you mentioned, and there's also the issue of them violating their published policy (either by the letter or in spirit) when they accepted new owners/investors.[1] Even if it met my requirements, I would be leery, and reluctant to suggest that others invest their time and build their communications network on such a foundation.

Of course, things can change over time. Maybe Wire will do things differently in the future, and become more appealing. That doesn't solve a problem for me today, though.

For the record, there's some discussion of Wire and other apps scattered about the privacytools.io issue tracker[2]. The signal:noise ratio there isn't great, but some folks here might find it interesting. As long as I'm posting links, their main site is worth a look, and the section about instant messengers[3] relates directly to this thread.

[1] https://nitter.net/Snowden/status/1194396764293550080

[2] https://github.com/privacytools/privacytools.io/issues

[3] https://www.privacytools.io/software/real-time-communication...

Post reply on HN