Earlier quoted context omitted.
I don't think it would be trivial (it's likely possible to some degree, but authentication and integrity checks might make it slightly more difficult), but the issue with this protocol is that you don't even need server control — any client with TextSecure installed can do this. Note: I don't mean to disparage TextSecure by saying this. By all means, TextSecure is a kickass app and you should use it. I'm just trying…
It seems pretty trivial to me. Can't you just send different messages to different people?
TextSecure's Private Group Messaging
61–70 of 109 posts
Re: TextSecure's Private Group Messaging
#62Earlier quoted context omitted.
I see you point but it should not weaken the security because encryption happens at the client, Google "only" gets metadata which at least authorities will get anyway. Besides, TextSecure is free software so it might possible to run your own server at least in the future.
Google gets the metadata? That's news to me. I thought the metadata was encrypted by the TextSecure server?
Re: TextSecure's Private Group Messaging
#63Earlier quoted context omitted.
Sorry, Thomas, but after you repeatedly replied to my private requests for conflict resolution with threats and abusive remarks, I refuse to interact with you entirely, publicly or privately. Those curious as to why I'm saying this should read Ptacek's other comments on this thread for a primer. Zed Shaw was right: http://zedshaw.com/essays/thomas_ptacek_should_apologize.htm...
Instead of writing your comments for Thomas, why not write them for the HN community? We're all very interested in hearing your thoughts. Thomas poses some good questions; why not consider answering them for us?
Re: TextSecure's Private Group Messaging
#64Earlier quoted context omitted.
Hence the continuous transcript consistency feature of the TextSecure protocol. Meanwhile: I'm curious about your answer to the question 'sdevlin posted downthread: https://news.ycombinator.com/item?id=7701510 Does your transcript consistency rely on the security of your server?
Sorry, Thomas, but after you repeatedly replied to my private requests for conflict resolution with threats and abusive remarks, I refuse to interact with you entirely, publicly or privately. Those curious as to why I'm saying this should read Ptacek's other comments on this thread for a primer. Zed Shaw was right: http://zedshaw.com/essays/thomas_ptacek_should_apologize.htm...
I agreed so much so that when I was invited to speak at CUSEC shortly thereafter, I was videotaped on stage opening my talk apologizing to him.
Zed didn't update his post on his site to account for that, although he was aware both of my plan to apologize (we spoke on the phone and I agreed the apology was warranted, though not without some debate), and of the fact that I apologized (I confirmed it for him afterwards). But Zed doesn't owe me an update to his page, and I didn't ask for one. You, on the other hand, do bear an obligation to know what you're talking about before you try to use this incident in a public discussion. You obviously haven't lived up to that obligation.
I owe you no apology. My opinion about you isn't concealed and you aren't misunderstanding me. However, you are misrepresenting my comments by referring to them as "abusive" and threatening. Unless you're threatened by criticism of your rhetoric and of the technical quality of your project.
Re: TextSecure's Private Group Messaging
#65Earlier quoted context omitted.
Sorry, Thomas, but after you repeatedly replied to my private requests for conflict resolution with threats and abusive remarks, I refuse to interact with you entirely, publicly or privately. Those curious as to why I'm saying this should read Ptacek's other comments on this thread for a primer. Zed Shaw was right: http://zedshaw.com/essays/thomas_ptacek_should_apologize.htm...
That's funny. I agree that Zed Shaw was right: I thought that the context of the barb I directed at him in a talk many years ago --- where I compared him with Daniel Bernstein, Theo de Raadt, and Jason Fried from 37signals --- put him in an appreciative and positive light. But he didn't think so --- I hyperbolically said "Zed Shaw will kill your company" (the same way Theo and Bernstein would), and on review, I agree…
You've ignored all my attempts to make discussion with you constructive. You are nothing but a great big bully and you should feel shame for your behaviour.
Every time I comment about anything on HN, and every time I am personally mentioned or my work is mentioned, you dutifully pop up to do your work. It's disgusting. You have a problem with me and anyone who cares to look into this can deduce the same.
I am not threatened by technical criticism, but you simply go so above and beyond reasonable discourse thanks to your irrational, mentally unfounded conviction that everything I ever do or write is necessarily either the result of incompetence or bad faith. Between me and you, it seems you never find the room for nuance and human respect!
That's my final say regarding you. Your technical knowledge is amazing and I've learned a lot from you. But you make HN a terrible place with your personality.
Re: TextSecure's Private Group Messaging
#66Earlier quoted context omitted.
That's funny. I agree that Zed Shaw was right: I thought that the context of the barb I directed at him in a talk many years ago --- where I compared him with Daniel Bernstein, Theo de Raadt, and Jason Fried from 37signals --- put him in an appreciative and positive light. But he didn't think so --- I hyperbolically said "Zed Shaw will kill your company" (the same way Theo and Bernstein would), and on review, I agree…
Since you've asked me not to share contents of private emails, I won't. But your insistence on assuming bad faith on my part and rudely rejecting any conflict resolution from my end is deplorable, and you should be ashamed of how baselessly aggressive you have been towards me. You consistently spin everything I say and respond to my attempts to be constructive by encouraging groupthink against what I'm trying to say…
* Requesting the crypto challenges and receiving some of them.
* Repeatedly asking me to talk to you privately, which, as you've acknowledged here in the least charitable way possible, I refuse to do. I respond to these requests simply and directly, without insult or explanation.
That's the extent of our correspondence.
As any reader of this thread can see, you and your work weren't "mentioned" on this thread. You're the manager of a project that competes with Whisper, and you chimed in on a thread about Whisper to ding them for something. I believed that ding was unfair and explained why. You then proceeded to --- if I may be permitted an uncharitable interpretation myself --- freak the hell out.
You should have just conceded the point (it turned out later in the thread that you were wrong to have brought it up). Instead, you relentlessly personalized it. Now you're unhappy with how that went for you. Maybe this can be a learning experience.
I was fine with the meta tangent we went off on earlier today, even though it didn't have that much to do with Whisper, because it did have something to do with forward secrecy, transcript consistency, and the relationship between protocols and their implementations. This, however has nothing to do with anything. The thread shows how this meta-tangent started: with me asking a technical question about your offering, and you giving a little speech about how bad a person I am.
We should probably wrap this up now.
Re: TextSecure's Private Group Messaging
#67I'm a big fan of TextSecure and recommended it to all my friends, both those in IT and 'normal' people. Usually, I managed to convince them that the open source nature of TextSecure and the crypto experts behind it (e.g. Moxie) make it more secure than Threema/... . However, the more sceptical ones among my friends always asked two questions, which I didn't have a good answer for: 1. What is TextSecure's business mod…
> 1. What is TextSecure's business model? Who pays for the server infrastructure? It's a good question. TextSecure is not a business, so we don't really have a business model in the traditional sense. Open Whisper Systems is a collective project made up of volunteers and a growing number of contributors, who are sometimes paid by donations ( https://whispersystems.org/blog/bithub/ ) and grants. Thus far, we've been a…
I'd pay even more good money for hosting to not be in Google's data centers.
Re: TextSecure's Private Group Messaging
#68Earlier quoted context omitted.
Since you've asked me not to share contents of private emails, I won't. But your insistence on assuming bad faith on my part and rudely rejecting any conflict resolution from my end is deplorable, and you should be ashamed of how baselessly aggressive you have been towards me. You consistently spin everything I say and respond to my attempts to be constructive by encouraging groupthink against what I'm trying to say…
The private emails you're referring to include: * Requesting the crypto challenges and receiving some of them. * Repeatedly asking me to talk to you privately, which, as you've acknowledged here in the least charitable way possible, I refuse to do. I respond to these requests simply and directly, without insult or explanation. That's the extent of our correspondence. As any reader of this thread can see, you and your…
My initial issue remains valid, and anyone who reads through the thread can see that you repeatedly attempted to change the focus to personalize this issue towards me. It's like I'm not allowed to offer any feedback, no matter how polite, constructive or valid, while you're around. Your doublethink is egregious.
Re: TextSecure's Private Group Messaging
#69Earlier quoted context omitted.
> 1. What is TextSecure's business model? Who pays for the server infrastructure? It's a good question. TextSecure is not a business, so we don't really have a business model in the traditional sense. Open Whisper Systems is a collective project made up of volunteers and a growing number of contributors, who are sometimes paid by donations ( https://whispersystems.org/blog/bithub/ ) and grants. Thus far, we've been a…
I'd pay good money for an iOS version. I'm limping along with Threema now (which, functionally, is really great!). I'd pay even more good money for hosting to not be in Google's data centers.
Re: TextSecure's Private Group Messaging
#70Earlier quoted context omitted.
Google gets the metadata? That's news to me. I thought the metadata was encrypted by the TextSecure server?
I don't know, but I would have guessed that Google needs to know when it should deliver a message and where it should go, no? That is metadata in my definition.