Live data from Hacker News

BitTorrent Chat - Private instant messaging via secure, distributed technology

labs.bittorrent.com

111–112 of 112 posts

Re: BitTorrent Chat - Private instant messaging via secure, distributed technology

#111
post #86
post #33

Earlier quoted context omitted.

Still a far greater improvement to knowing the content of your conversations! If your design removes performance in exchange for removing metadata, and nobody uses it, it might as well not exist then.

This seems pointless when we have things like Off-the-Record messaging, which for all intents and purposes solves the content and trust problem, and even includes a legal defence against encryption cracking (cracking a message gives you everything you would've needed to forge the message in the first place, meaning it can't be mathematically proven to have come from you - something GPG and X509 do not). Distributed c…

You are right, OTR already provides all of this.

The only 'unique' thing that Bittorrent can provide although is execution, delivery & a tendency to open source their work. They have shown they can deliver by implementing usable bittorrent sync clients for the major 4 OSs (Windows, OSX, iOS, Android). That usability alone would increase the amount of the internet using encrypted communications significantly, putting a major hinderance on dragnet surveillance.

Hell we might find out that bittorrent chat uses libOTR once your in an actual conversation, since they did all the hard crypto stuff already. They'll just be adding a P2P discovery layer, since that is what they are actually specialized in. That is what I would do if I were them.

There are no usable open source OTR or PGP clients for all 4 OSs still. ChatSecure for iOS still crashes a lot. Adium/Pidgin is pretty much the only usable OTR client I know of, and they are desktop clients.

Re: BitTorrent Chat - Private instant messaging via secure, distributed technology

#112
post #72

Earlier quoted context omitted.

The dev team would love if you know someone with expertise and a bit of time to spare. We make no claims of perfection or even safety at this point. From the homepage: Bitmessage is in need of an independent audit to verify its security.

I believe that they need to link to the security review i linked , not hide it in forums. There was also someone who deanonimized bitmessage. They should link this too in a prominent place. If they solved any of those problems , they should link to solutions and a possible review.

There was also someone who deanonymized some bitmessage users' disposable identities: those who copy-pasted a link (that the client prevented them from clicking on) to a website they'd never visited before from a random user with whom they'd never communicated into a web browser that did not use any anonymizing method.

FTFY

Post reply on HN