Live data from Hacker News

Briar Desktop for Linux

briarproject.org

71–80 of 87 posts

Re: Briar Desktop for Linux

#72

My experience a few years ago just giving Briar a try for fun was that both parties had to be online at the same time to relay messages (since there's no normal servers) and that it drained my phone battery quickly when I was online. Not practical. I was thinking it would be nice to be able to run some sort of node under my own control that could buffer those messages. I feel like there was even an option to do that…

it looks like briar is already working on that buffer node concept: https://code.briarproject.org/briar/briar-mailbox

Thanks, I'll keep my eye on it!

Re: Briar Desktop for Linux

#73
post #42

Earlier quoted context omitted.

There's some overlap with P2P Matrix (which isn't yet done but is in the works).

Difference is P2P isnt matrix's main goal. Their approach to P2P is to just bundle an entire homeserver on your phone or desktop client. Briar was built for P2P from the ground up, so presumably they planned this better. This isn't a criticism of matrix. Matrix is great and I use it everyday but gotta give credit where its due.

A lightweight homeserver. If lightweight enough (which remains to be demonstrated in practice of course), I don't see a meaningful difference from a monolith design.

I see no reason to think P2P isn't a goal of Matrix either; the reason it's not P2P now is that federation was easier, but the long-term game certainly looks to be P2P with work on cryptographic, portable identities and Bluetooth mesh networking in the form of Pinecone. I've also seen arathorn confirm this on HN.

Re: Briar Desktop for Linux

#74
post #64

Earlier quoted context omitted.

is there already some compare available that shows differences with other messengers like Telegram or Signal?

It's been awhile since I used Briar, but unlike something like Signal, Briar is decentralized. So you can communicate with other Briar users in the absence of a central server. Briar at least used to be very strict about how you established contacts, so, for example, to add a contact you had to have them physically in your presence and exchange QR codes on your phone. You couldn't just add someone from your phone con…

> Briar at least used to be very strict about how you established contacts, so, for example, to add a contact you had to have them physically in your presence and exchange QR codes on your phone.

This has indeed changed, it is possible to exchange briar:// links over another channel and add contacts without physical presence.

> It also probably makes it more feasible to treat the desktop instance as a sort of "permanent on" server

I agree, and this might be one step towards solving the "using one briar key on two devices" problem by making the pc authoritative.

https://code.briarproject.org/briar/briar/-/wikis/FAQ#can-i-...

> although I have it on my phone, I haven't actually used it in some time

Me too. None of my friends/family would be interested in using Briar, but it's too cool for me to not keep it installed. I like reading the update notes and seeing it progress.

Re: Briar Desktop for Linux

#75
post #14

Do any of these "decentralized" and "end to end" encryption communication systems actually solve the fundamental problem which is that you have to trust the person you're communicating with to not give up the content of the messages they've sent and received. People's telegram and signal comms are always showing up in subpoenas because someone unlocks their phone for the feds. I guess what I'm thinking here is that t…

There is a lot of misunderstandings around messaging systems. End-to-end encryption is an extremely nice feature as it lets us make the assumption that messages cannot be read by a middle man even if 100% of the employees are corrupt and the messages pass right through FSB and NSAs networks twice. But, as you point out: for most people this falls flat in most cases once you are up against the big guys and they have d…

> Then there is federation, I guess that is what you mean by decentralized.

I can't speak for GP's use of scare quotes around "decentralized", but it's worth noting in this case that Briar is fully decentralized, not federated. It is peer-to-peer messaging.

Re: Briar Desktop for Linux

#76
post #20
post #14

Do any of these "decentralized" and "end to end" encryption communication systems actually solve the fundamental problem which is that you have to trust the person you're communicating with to not give up the content of the messages they've sent and received. People's telegram and signal comms are always showing up in subpoenas because someone unlocks their phone for the feds. I guess what I'm thinking here is that t…

The only reliable security you can implement here is not to send the message in the first place

Interesting I've been downvoted for that when others have posted the same comment since and not been downvoted. Further more I'd with no reply it's unclear how the person who reviewed that comment believes you could secure the message after someone has read it (clearly they think it's possible otherwise my comment wouldn't be "incorrect").

To expand on my previous post: what's to stop the recipient from taking a photo of the message using another device? Or transcribing it and republishing it manually? Or even just memorising it and telling someone else verbally?

Literally the only defence you have against the recipient abusing their trust is not to send the message to begin with. Everything else is just security theatre.

This is literally the same point others have made too. So why I was downvoted but others not I don't know.

Re: Briar Desktop for Linux

#77
post #57

I don't feel comfortable trusting a new "secure" messaging platform or interested in doing the work to dig through the sources to see if it's legit or not combined with the fact that I don't even know if the source they provide generates the same binary they distribute to many. Just use Matrix instead.

> Just use Matrix instead. No just don't. Matrix exposes metadata to every connected server.

no, Matrix exposes metadata to only the servers whose users are talking together.

Re: Briar Desktop for Linux

#78

Since I needed brief intro myself, Wikipedia says: "The initial target audience for Briar includes "activists, journalists and civil society" with plans to make the system "simple enough to help anyone keep their data safe." As the ability to function in the absence of internet infrastructure may also make the project valuable to disaster response and aid organisations, the developers are working with the Open Humani…

>"The initial target audience for Briar includes "activists, journalists and civil society"

Sounds exactly like a project an agency would help create/infiltrate to tap unto all of the above....

Re: Briar Desktop for Linux

#80
post #20
post #14

Do any of these "decentralized" and "end to end" encryption communication systems actually solve the fundamental problem which is that you have to trust the person you're communicating with to not give up the content of the messages they've sent and received. People's telegram and signal comms are always showing up in subpoenas because someone unlocks their phone for the feds. I guess what I'm thinking here is that t…

The only reliable security you can implement here is not to send the message in the first place

This. Or, in other words: OFFLINE COMMUNICATION.

In today's world, offline communication is safer, because to tap it you need manpower ( = more resources, more money ), and that is not efficient for those who want to tap you.

Post reply on HN