Live data from Hacker News

Toxic – A distributed, secure, command-line based instant messenging client

github.com

11–20 of 91 posts

Re: Toxic – A distributed, secure, command-line based instant messenging client

#11
post #9

The home page[0] seems to suggest that there are also audio and video capable clients... are they still in development, or is there something functional already? [0] - https://tox.im/

Toxic has 1 on 1 audio chats, and GUI clients such as uTox and qTox additionally have group audio, as well as 1 on 1 video. Both clients are usable, though I would personally recommend qTox.

Re: Toxic – A distributed, secure, command-line based instant messenging client

#12
DISCLAIMER: I am one of the many Tox ex-contributors, who used to work on it in the past. I don't want to be identified due to harassment other ex-contributors suffered in the past. The following message is my point of view on the project as a whole.

Proplex, a long-time member of the Tox-Foundation and in charge of both infrastructure and marketing, called out tox devs because the 2 people in charge (irungentoo and stqism) were dealing with money in a shady way and he got suspicious. This lead him to leaving the Tox Foundation Proof: https://gist.github.com/irungentoo/5af26f5edefcdb7eac72

After he went away and stopped to pay for the website and other servers (he hosted everything), Tox devs got angry and tracked his online activity by his browser UA, read his private email sent to his @tox.im address and considered breaking into his VPS account Proof: https://gist.github.com/urras/ba792274f5aaf662a082/5d91d2a78... and https://archive.today/KkSWp

Members of the Tox Foundation such as stqism try constantly to sneak in copyright changes in unrelated fixes: Proof: https://github.com/irungentoo/toxcore/pull/1219 and https://github.com/irungentoo/toxcore/pull/1224

irungentoo enforced censorship on his github repo to try to cover everything up Proof: https://github.com/irungentoo/toxcore/issues/1227

After it got out of hand and too many people called out the Tox Foundation, this happened: Proof: http://a.pomf.se/kqwgsg.png

irungentoo claims Tox is secure just because he uses a secure primitive, which is really arrogant and something only a pretentious deceiver would say. This is a crypto 101 mistake. Proof: https://github.com/irungentoo/toxcore/issues/121#issuecommen...

After the points exposed above, the conclusion is obvious, at least for me.

The Tox Foundation claims Tox is completely secure and nobody can break in, not even the NSA. Still, there's been no security audit and it is highly likely Tox isn't completely secure, given it's alpha software. But their website gives the idea people face no risk by using Tox right now. They are deceiving people to believe it is secure so they gain more users at the expense of putting users privacy at risk. Proof: https://tox.im itself. See all security claims even though it hasn't been audited. Saying it's "alpha" doesn't mean to anything to non-tech-savvy, they will think it's missing a feature or two, not that their privacy and security is possibly compromised.

I believe it's my moral obligation, and of everyone's else reading this, not to use Tox. You are contributing to a shady foundation composed of menchildren that don't care about other's privacy, deals with money in a shady way and dox people who go against them. Do not trust the Tox Foundation - this is my personal message.

Re: Toxic – A distributed, secure, command-line based instant messenging client

#13

Is Tox secure ? Compared to tinfoil chat

Tox still hasn't solved the serious metadata leakage issue.

They tried to cover it up by adding onion-routing for friend requests, but ACTUAL MESSAGES are still done directly.

Strong adversaries such as your ISP and agencies like the NSA, the GCHQ, etc. can still collect metadata about your conversations.

The "Tox Foundation" tries to cover this up and pretend that "tox was never meant to be anonymous", but the truth is harsh.

Now, this wouldn't be a problem if the Tox Foundation made this issue clear to its users. This is how P2P works, after all, direct connections, and that's fine.

But the problem is that Tox doesn't make that obvious for non-tech-savvy users.

When they read on the website that they are completely safe from the NSA and whatnot, they won't expect to be in any way exposed.

Still, unless these non-tech-savvy users "route all incoming and outgoing traffic through Tor" they won't be completely safe and should be worried about metadata leakage and adding people they don't actually know. But such a thing isn't made clear and Tox deceives users this way, only to get more people using it. It's unethical and outright wrong, in my personal opinion.

Re: Toxic – A distributed, secure, command-line based instant messenging client

#14

DISCLAIMER: I am one of the many Tox ex-contributors, who used to work on it in the past. I don't want to be identified due to harassment other ex-contributors suffered in the past. The following message is my point of view on the project as a whole. Proplex, a long-time member of the Tox-Foundation and in charge of both infrastructure and marketing, called out tox devs because the 2 people in charge (irungentoo and…

Oh for god's sake, will you trolls ever stop?

Re: Toxic – A distributed, secure, command-line based instant messenging client

#15

DISCLAIMER: I am one of the many Tox ex-contributors, who used to work on it in the past. I don't want to be identified due to harassment other ex-contributors suffered in the past. The following message is my point of view on the project as a whole. Proplex, a long-time member of the Tox-Foundation and in charge of both infrastructure and marketing, called out tox devs because the 2 people in charge (irungentoo and…

Open source developers with attitude problems? Surely this has never occurred before.

To be less sarcastic: Does it matter who the developers are and how they behave? If the source is open then it can be reviewed by anyone. If it works, there is no reason not to use it.

Re: Toxic – A distributed, secure, command-line based instant messenging client

#16

DISCLAIMER: I am one of the many Tox ex-contributors, who used to work on it in the past. I don't want to be identified due to harassment other ex-contributors suffered in the past. The following message is my point of view on the project as a whole. Proplex, a long-time member of the Tox-Foundation and in charge of both infrastructure and marketing, called out tox devs because the 2 people in charge (irungentoo and…

Sounds like an extremely one-sided version of an argument. Why should we care about the devs? If the source is open and the software is good, I can tolerate Linus-tier rants if need be.

Re: Toxic – A distributed, secure, command-line based instant messenging client

#17

DISCLAIMER: I am one of the many Tox ex-contributors, who used to work on it in the past. I don't want to be identified due to harassment other ex-contributors suffered in the past. The following message is my point of view on the project as a whole. Proplex, a long-time member of the Tox-Foundation and in charge of both infrastructure and marketing, called out tox devs because the 2 people in charge (irungentoo and…

Unfortunately, being affiliated with 4chan means we attract a lot of trolls pretending to be "ex-devs" or "concerned members of the community" who have nothing better to do with their time than to spread FUD (https://en.wikipedia.org/wiki/Fear,_uncertainty_and_doubt). We certainly aren't perfect, and have made our fair share of mistakes, but at the end of the day this is just personal drama that serves to distract from the software.

Re: Toxic – A distributed, secure, command-line based instant messenging client

#20
Make it worthwhile for someone to test how 'secure' this system is before touting that title.

An audit or a bounty with no limitations on rendering the system insecure. An example of how not to do this would be the Telegram contest sham.

Post reply on HN