Live data from Hacker News

Wire – Modern Communications Network

wire.com

401–410 of 411 posts

Re: Wire – Modern Communications Network

#401
post #396
post #378

Earlier quoted context omitted.

From the homepage: > Send and receive extensible messages with optional end-to-end encryption Why would encryption ever be "optional"?

Because we don't want client implementers to be forced to have to jump through end-to-end crypto hoops if they don't want to. The simplest way to send a message in matrix is: curl -XPOST -d '{"msgtype":"m.text", "body":"hello world"}' " https://matrix.wherever.com/_matrix/client/api/v1/rooms/$roo... ...and we'd like to keep it that way. But you can always insist on only ever communicating with folks who are on E2E cr…

Is that the same way I can always insist on only ever receiving PGP-encrypted e-mail?

Re: Wire – Modern Communications Network

#402
post #379
post #378

Earlier quoted context omitted.

From the homepage: > Send and receive extensible messages with optional end-to-end encryption Why would encryption ever be "optional"?

Back in the day it was often optional due to the additional processing that it required.

That was indeed a thing in the days before AES-NI or simply having 1.4 billion transistors on a chip.

But in my day we've been spending years fighting this sort of short-sightedness: https://www.ietf.org/mail-archive/web/rtcweb/current/msg0274...

Re: Wire – Modern Communications Network

#403
post #401
post #396

Earlier quoted context omitted.

Because we don't want client implementers to be forced to have to jump through end-to-end crypto hoops if they don't want to. The simplest way to send a message in matrix is: curl -XPOST -d '{"msgtype":"m.text", "body":"hello world"}' " https://matrix.wherever.com/_matrix/client/api/v1/rooms/$roo... ...and we'd like to keep it that way. But you can always insist on only ever communicating with folks who are on E2E cr…

Is that the same way I can always insist on only ever receiving PGP-encrypted e-mail?

Not quite - as PGP is a pita to use, and not a formal part of the SMTP spec. So refusing to read non-PGP would be suicide. But if it was considered table stakes to implement the crypto option of the spec, and all the decent Matrix clients out there did so and sent end-to-end encrypted by default, then it'd naturally become the default. In other words, if you gracefully upgrade chats between capable clients to be end-to-end by default, everybody wins.

Re: Wire – Modern Communications Network

#404

Earlier quoted context omitted.

Based on past comments I'd expect the author to have the en_US layout (or something entirely different) and probably - now taking a guess here - even without umlauts. I'm German and use en_US here, so for ö I'd need to compose a character manually. Which is probably what was mocked (whether that is right or wrong I do not know - I certainly cannot judge the style of writing of someone in his native language, as a for…

I appreciate the great deal of thought you put into this. I feel like a mini-Internet celebrity of the minute. You are entirely correct about needing compose to type the symbol, but I use it so rarely, that I just copy-pasted. It's not an umlaut though, it's a different diacritic called diaeresis. It makes me feel like I'm speaking a more awesome language when I use it.

I'm glad you like the attention, but I have to admit that I didn't waste too much time on that post. Five minutes tops. :)

The 'not an umlaut' part doesn't seem to be relevant though, since we talk about the character composition. 'ö' is the same character both as o-umlaut and as o-diaeresis (I admit I checked if there's a different way to write the latter), so the argument is weird.

de_DE has a character 'ö' on the keyboard, if I use that as umlaut or not is a different problem.

Composing " and o (or whatever you use) produces what looks like o-umlaut to a German speaker - and my understanding was that you were 'attacked' (if you will) for going out of your way to write 'ö'. Whatever that character signifies here.

(I actually didn't know the name diaeresis, but the usage isn't uncommon here. I've driven my share of Citroën 2CVs in the past)

Re: Wire – Modern Communications Network

#405

Earlier quoted context omitted.

While you can argue that some piece of open source software can be more insecure than a proprietary alternative, auditing a piece of software requires access to the source code and that is mandatory. And with open source everybody can audit with no restrictions. Yes, OpenSSH is a piece of shit, but how do you think it was discovered, from 2 independent parties no less. Then there's another effect that I like - after…

OpenSSH or OpenSSL? I thought OpenSSH was pretty solid, forgetting the fact that configuring it isn't as straightforeward as one would hope.

Sorry, I meant OpenSSL. It was a typo.

Re: Wire – Modern Communications Network

#406
post #401

Earlier quoted context omitted.

Is that the same way I can always insist on only ever receiving PGP-encrypted e-mail?

Not quite - as PGP is a pita to use, and not a formal part of the SMTP spec. So refusing to read non-PGP would be suicide. But if it was considered table stakes to implement the crypto option of the spec, and all the decent Matrix clients out there did so and sent end-to-end encrypted by default, then it'd naturally become the default. In other words, if you gracefully upgrade chats between capable clients to be end-…

If you really believe that, then I feel sorry for your users. Privacy is a public health issue: https://www.theguardian.com/technology/2013/may/21/privacy-p...

In the absence of some forcing function, the trend is for it to get worse, not better.

Re: Wire – Modern Communications Network

#407
post #266

Earlier quoted context omitted.

Unfortunately, even if they DID specifically list out all the security measures that they used, someone would still complain because it isn't completely open source. The previous company I worked for not only had legitimate encryption for anything private we received from the user (e.g.: email passwords) so that nobody at the company could ever read them, but also had some (if I remember correctly) good documentation…

There are already FOSS replacements for Skype, such as Tox. The fact is that if every line of code can't be inspected then the software can't be considered secure, and we're forced to put blind faith in a faceless corporation, which is understandably not acceptable for many people. I don't really care if you think this is "practical" or not. That's simply the reality of the situation. Proprietary == insecure. If a co…

tox.im website is not working. Am I looking in the wrong place?

Re: Wire – Modern Communications Network

#408

Earlier quoted context omitted.

> "What we need is another messaging app" said nobody, ever. The usual negative HN top post. I have to disagree. We've moved from irc, to ICQ, to Microsoft Messenger, to ..., to Skype, to (what's hot now), so somehow all those people really DID want another messaging app and even adopted one. > It looks pretty, but this is yet another app in the long list of "Skype killers" or "Voice/video/text" messaging. Most of th…

> so somehow all those people really DID want another messaging app and even adopted one. Very disingenuous. In terms of ICQ, they were just early to market, had a competent client and... a deeply flawed method of identification. Messenger? Rolled out with Windows, just like certain other software that caused a bit of a stink in courtrooms at one point. Leverage. AOL did the same thing, pretty much. As for Skype... i…

I totally agree with you. I don't want to disdain Skype, which is a great tool for its intended audience (the noobs, the moms and paps, the grandmas, etc). Also, Skype technology was almost incredible when they first appeared, so .. lots of respect for their history and accomplishments.

But I also think there is a lot of room for "Skype Killers" in different niches. I think Skype UI is getting worse for the experienced/heavy user. What is your niche? Would love to hear more.

Re: Wire – Modern Communications Network

#409
post #117

Earlier quoted context omitted.

I've been in Brazil for the past five weeks. EVERYONE uses whatsapp, because SMS is expensive. And this all happened in the past couple of years or so, because that's when smartphones became widespread. I have never been asked my phone number. I've only been asked my "whatsapp". Make a good enough messaging app, and you can win an entire country. Or the world.

I'm from Brazil. You see small local businesses, with hand painted signs, where the phone number is followed by the whatsapp logo. Not even the name "whatsapp", just the logo. It's scary how they took over communications over here.

Yes. You are totally right. And the funny thing is that for many Brazilians who can't speak english WhatsApp became "ZapZap" (much easier for Portuguese speakers to say) or just "Zap".

Re: Wire – Modern Communications Network

#410

Am I such an outlier if I use Skype for business, not for leisure? I have clients on three continents and every single one used Skype to communicate about the project. Skype was generally running on every machine as a "watercooler chat"/IRC replacement. Just open groups, give them names and pin them to the sidebar. Done. So I really expected this to be more secure, more portable and LESS designer-driven. Who is even…

Hey, I don't think you are an outlier. I use Skype for business and the many SMB I work with all use Skype as well. The Skype target audience is the consumer not the SMB. Lync is great, as Jabber is great, but they are all for the Big Fortune 500, not the SMB. I am still looking... and will welcome new "Skype Killer" initiatives.

Despite of that, I don't think Wire is it. I downloaded the app and it is quite awful to use. We need a "Skype Killer" with better usability for business, not only a pretty screen and a good marketing landing page.

Post reply on HN