Live data from Hacker News

Briar Desktop for Linux

briarproject.org

41–50 of 87 posts

Re: Briar Desktop for Linux

#41
I don't feel comfortable trusting a new "secure" messaging platform or interested in doing the work to dig through the sources to see if it's legit or not combined with the fact that I don't even know if the source they provide generates the same binary they distribute to many.

Just use Matrix instead.

Re: Briar Desktop for Linux

#42

Never heard of Briar. Title made me think it was some new cool desktop environment for linux. It took me longer than I care to admit before I realized Briar is just a messaging app.

A new environment with just a handful of apps comes every so often. In that regard, what are other apps like Briar? The premise is: > Briar is a messaging app designed for activists, journalists, and anyone else who needs a safe, easy and robust way to communicate. Unlike traditional messaging apps, Briar doesn’t rely on a central server - messages are synchronized directly between the users' devices. If the internet…

There's some overlap with P2P Matrix (which isn't yet done but is in the works).

Re: Briar Desktop for Linux

#43
post #24
post #14

Do any of these "decentralized" and "end to end" encryption communication systems actually solve the fundamental problem which is that you have to trust the person you're communicating with to not give up the content of the messages they've sent and received. People's telegram and signal comms are always showing up in subpoenas because someone unlocks their phone for the feds. I guess what I'm thinking here is that t…

I love PGP, but let's be honest, it's not user friendly in the slightest. It's an esoteric bolt-on to email that requires both ends to want to use it and go through the trouble of setting it up, which basically means that it's really only useful to nerds and people with sufficient requirement for secrecy that they actually go through the trouble. Services like Signal are great because they're E2EE by default and they…

>Services like Signal are great because they're E2EE by default and they're user friendly.

Signal might be a bad example because it is not really that user friendly when it comes to the hard bit. That is: confirming that you are actually connected to who you think you are connected to and not some third party. In a usability study involving Signal[1], 21 out of 28 computer science students failed to establish and maintain a secure end to end encrypted connection.

We should not kid ourselves into thinking that the usability of end to end encrypted messaging has been solved. It is very much still an outstanding issue.

[1] https://www.ndss-symposium.org/wp-content/uploads/2018/03/09...

Re: Briar Desktop for Linux

#44
My experience a few years ago just giving Briar a try for fun was that both parties had to be online at the same time to relay messages (since there's no normal servers) and that it drained my phone battery quickly when I was online. Not practical.

I was thinking it would be nice to be able to run some sort of node under my own control that could buffer those messages. I feel like there was even an option to do that for phones, where someone could help relay messages between two friends, but I could be remembering wrong. At any rate, it would be cool if the desktop app could play this role.

Re: Briar Desktop for Linux

#45
post #14

Do any of these "decentralized" and "end to end" encryption communication systems actually solve the fundamental problem which is that you have to trust the person you're communicating with to not give up the content of the messages they've sent and received. People's telegram and signal comms are always showing up in subpoenas because someone unlocks their phone for the feds. I guess what I'm thinking here is that t…

The defense against that is 'disappearing messages' which is available in most popular E2E messaging apps nowadays, including Signal and WhatsApp.[1] PGP emails doesn't even have forward secrecy. Emails are not messaging, it needs video/voice calls, stickers/gifs etc etc to have any hope of being adopted by non-techy folks. The Signal blog has a number of articles on how they develop state-of-the-art privacy preservi…

>PGP emails doesn't even have forward secrecy.

Yeah, that is a bit of a mystery. There is no technical reason. I think that email users just want to keep their old emails around, which of course makes forward secrecy pointless. Perhaps PGP users would prefer to use the greater security available for the private key material in an offline medium like email to make it so they don't get compromised in the first place.

Re: Briar Desktop for Linux

#46

My experience a few years ago just giving Briar a try for fun was that both parties had to be online at the same time to relay messages (since there's no normal servers) and that it drained my phone battery quickly when I was online. Not practical. I was thinking it would be nice to be able to run some sort of node under my own control that could buffer those messages. I feel like there was even an option to do that…

it looks like briar is already working on that buffer node concept: https://code.briarproject.org/briar/briar-mailbox

Re: Briar Desktop for Linux

#47

I don't feel comfortable trusting a new "secure" messaging platform or interested in doing the work to dig through the sources to see if it's legit or not combined with the fact that I don't even know if the source they provide generates the same binary they distribute to many. Just use Matrix instead.

Briar is older than Matrix. It has been around since at least mid-2012, whereas Matrix is from 2014.

Disclosure: I was an intern for them in mid-2012.

Re: Briar Desktop for Linux

#48
When I tested peer-to-peer messaging a couple of years ago, Briar was the only messenger that was able to sync messages and data without needing a common router. Was very happy to see.

Re: Briar Desktop for Linux

#50

I don't feel comfortable trusting a new "secure" messaging platform or interested in doing the work to dig through the sources to see if it's legit or not combined with the fact that I don't even know if the source they provide generates the same binary they distribute to many. Just use Matrix instead.

Briar is p2p/offgridy/meshnety and Matrix is federated, always on internet connected.
Post reply on HN