Live data from Hacker News

Toxic – A distributed, secure, command-line based instant messenging client

github.com

41–50 of 91 posts

Re: Toxic – A distributed, secure, command-line based instant messenging client

#41

DISCLAIMER: I am one of the many Tox ex-contributors, who used to work on it in the past. I don't want to be identified due to harassment other ex-contributors suffered in the past. The following message is my point of view on the project as a whole. Proplex, a long-time member of the Tox-Foundation and in charge of both infrastructure and marketing, called out tox devs because the 2 people in charge (irungentoo and…

One of the "proof"s given here is that a pull request changed a 2013 copyright to a 2013-2015 copyright, as though that's sinister somehow. I stopped reading after that.

I think it's because of changing 'project' to 'Foundation': https://github.com/irungentoo/toxcore/pull/1219#commitcommen...

Re: Toxic – A distributed, secure, command-line based instant messenging client

#42
post #18

tox does not attempt to hide your ip. Every single friend you have added has your ip. This is by design.

That's partially true. However if you force TCP connections (in Toxic this is done with the -t flag) your IP is effectively hidden from your contacts because all your traffic gets relayed by TCP nodes in the network. The downside is that forced TCP connections are slower and less reliable. Though to be properly anonymous you would need to run it through Tor: https://wiki.tox.im/Tox_over_Tor_(ToT) The reason Tox doesn…

If broad adoption is truly your goal you have a branding problem. Normal people will not use a tool called 'toxic' which prints crazy ASCII letters in the command line. You might as well ask soccer moms to hold the line at occupy wall street.

Re: Toxic – A distributed, secure, command-line based instant messenging client

#43

My one experience with the Tox project was that I made a few (I thought) constructive suggestions. First, I suggested they use some form of static analysis or perhaps a 'safer' language to implement their core functionality - such as Rust or Go, instead of rather messy (at the time) C code. Furthermore, having spent a lot of time researching parsers and how parser differentials can affect the security of systems, I s…

There was a tox-core rewrite in Rust[1], but it's been abandoned. According to the author until Tox gets proper doc.

https://github.com/mahkoh/Xot

Re: Toxic – A distributed, secure, command-line based instant messenging client

#44

DISCLAIMER: I am one of the many Tox ex-contributors, who used to work on it in the past. I don't want to be identified due to harassment other ex-contributors suffered in the past. The following message is my point of view on the project as a whole. Proplex, a long-time member of the Tox-Foundation and in charge of both infrastructure and marketing, called out tox devs because the 2 people in charge (irungentoo and…

One of the "proof"s given here is that a pull request changed a 2013 copyright to a 2013-2015 copyright, as though that's sinister somehow. I stopped reading after that.

Read it again. https://github.com/stqism/ToxCore/commit/bed425598f26938bd54... He tried to get copyright away from people and assign it to the "Tox Foundation", all during a supposedly unrelated minor bug fix.

Re: Toxic – A distributed, secure, command-line based instant messenging client

#45

Earlier quoted context omitted.

The issue is that if you use Tox you support their foundation, the Tox Foundation™ which deals with money in a shady way and deceive their users just in order to grow. I, for moral and ethical principles, don't want to have anything to do with such a thing and believe it's necessary to let people know about the situation. If they couldn't even respect an ex-developer privacy[0] how can we expect them to run a foundat…

That's what you're saying, and how can I expect to trust a troll who copies and pastes stuff over and over again on 4chan?

A bunch of green accounts suddenly appearing and attacking back also are not very trustworthy.

Re: Toxic – A distributed, secure, command-line based instant messenging client

#46
post #42

Earlier quoted context omitted.

That's partially true. However if you force TCP connections (in Toxic this is done with the -t flag) your IP is effectively hidden from your contacts because all your traffic gets relayed by TCP nodes in the network. The downside is that forced TCP connections are slower and less reliable. Though to be properly anonymous you would need to run it through Tor: https://wiki.tox.im/Tox_over_Tor_(ToT) The reason Tox doesn…

If broad adoption is truly your goal you have a branding problem. Normal people will not use a tool called 'toxic' which prints crazy ASCII letters in the command line. You might as well ask soccer moms to hold the line at occupy wall street.

Are you aware that there are a myriad of clients available?

Re: Toxic – A distributed, secure, command-line based instant messenging client

#47
post #45

Earlier quoted context omitted.

That's what you're saying, and how can I expect to trust a troll who copies and pastes stuff over and over again on 4chan?

A bunch of green accounts suddenly appearing and attacking back also are not very trustworthy.

It's pretty pathetic indeed how neither side seems to know how to handle an actual argument like adults.

I guess that's not too surprising given the project's origins.

Re: Toxic – A distributed, secure, command-line based instant messenging client

#48
post #42

Earlier quoted context omitted.

That's partially true. However if you force TCP connections (in Toxic this is done with the -t flag) your IP is effectively hidden from your contacts because all your traffic gets relayed by TCP nodes in the network. The downside is that forced TCP connections are slower and less reliable. Though to be properly anonymous you would need to run it through Tor: https://wiki.tox.im/Tox_over_Tor_(ToT) The reason Tox doesn…

If broad adoption is truly your goal you have a branding problem. Normal people will not use a tool called 'toxic' which prints crazy ASCII letters in the command line. You might as well ask soccer moms to hold the line at occupy wall street.

Toxic is just one of many clients that are built ontop of Tox. Some clients fill a niche, others (like qTox) are meant for widespread adoption.

Re: Toxic – A distributed, secure, command-line based instant messenging client

#49

One of the links I posted above "mysteriously" disappeared. I have an archived version though. It's one of the key-points of the situation I exposed, so it's worth a read. https://archive.today/Y6LEw

HIGHLIGHTS

irungentoo: tox main developer, head of the Tox Foundation NikolaiToryzin (stqism): second in command, run the Tox Foundation's monetary operation The rest are other developers on the #tox-secret channel.

TRACKING PROPLEX, AN EX-MEMBER OF THE TOX FOUNDATION, ONLINE ACTIVITY THROUGH HIS UA:

irungentoo prolapses phone seems to have a unique user agent

NikolaiToryzin If you tell me it I can make tox.im return stuff to him only

irungentoo 'Mozilla/5.0 (Linux; Android 4.4.2; SM-N900V Build/KOT49H) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/40.0.2214.69 Mobile Safari/537.36' NikolaiToryzin That'll be fun

READING HIS PRIVATE EMAIL:

irungentoo basically proplex did an email request change on his digital ocean account which means an email containing his ip got sent to david@tox.im which ended up in the catch all email

urras irungentoo: Any interesting emails? irungentoo urras, if you want to forcefully gain access to his digital ocean account I can reset his pass

[...]

NikolaiToryzin But they want his personal info

urras How do you guys know

NikolaiToryzin Emails.

irungentoo comparing himself to the NSA:

irungentoo I feel like the NSA

irungentoo tracking people across ips even without cookies is so easy

irungentoo https://mail.tox.im/prolapse.txt [link now unavailable, but I archived it https://archive.today/KkSWp ]

irungentoo why would I want to go after terrorists?

irungentoo blackmailing people with power is much more lucrative

TRACKING AN EX-DEVELOPER AGAIN:

irungentoo 173.52.122.131 - - [13/Jan/2015:00:33:01 -0500] "GET /User:Proplex HTTP/1.1" 404 3656 "https://github.com/Tox/Tox-Website" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36"

irungentoo interesting

irungentoo I like how he checked if the wiki was up: 96.250.8.105 - - [20/Dec/2014:02:12:30 -0500] "GET / HTTP/1.1" 301 5 "https://tox.im/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/39.0.2171.95 Safari/537.36"

irungentoo you really don't need cookies to track people online.

Post reply on HN