Most are focused on the name, which is terrible, while only one other (so far) noticed the big problem: Electron, React, and Redux. A secure messenger needs to have strong endpoint security. Easiest way to do that is using safe, system languages with simple implementation, as few dependencies as possible, and isolation of app from rest of the system. That's one of safe C's, restricted C++, SafeD, Ada/SPARK, Component…
Felony – An open-source PGP keychain
121–130 of 241 posts
Re: Felony – An open-source PGP keychain
#122Earlier quoted context omitted.
> How does the app handle encryption? Has there been a security review? It's built on Electron, React and Redux. There is no security as it is a fundamentally insecure environment.
It's fashionable around here to criticize that tech stack, but do you have anything to back up that claim?
Re: Felony – An open-source PGP keychain
#123Earlier quoted context omitted.
> How does the app handle encryption? Has there been a security review? It's built on Electron, React and Redux. There is no security as it is a fundamentally insecure environment.
It's fashionable around here to criticize that tech stack, but do you have anything to back up that claim?
All in all an order of magnitude less security then a native app to put it mildly.
http://blog.scottlogic.com/2016/03/09/As-It-Stands-Electron-...
Re: Felony – An open-source PGP keychain
#124Earlier quoted context omitted.
Please change the name of the app. I'm Swedish, and to me the name sounds really repelling. Maybe someone could fork the application and rename it to something cool that I can use?
You seriously can't do this yourself? Clone the repo and change the name using find-and-replace and run install. No need to insult.
There seems to be a number of forks already (currently 12).
Re: Felony – An open-source PGP keychain
#125Earlier quoted context omitted.
This looks like an interesting project but has a poor name choice. If it's targeted at non technical users, it may actually prevent them from using it, out of fear that just using it is illegal.
It's not targeted at entirely non technical users. That's why it's on Hacker News ;)
Re: Felony – An open-source PGP keychain
#126Earlier quoted context omitted.
"It's just a word which makes it stand out as a product" So you think calling a product "nigger" is a good idea? It's just a word and it would certainly stand out. (Before responding directly to my comment, please consider that I'm criticizing your logic, and don't actually want anyone to create a product with a hateful name)
That is a needlessly crass example. I get your point, but that's not the best way you could have made it.
Re: Felony – An open-source PGP keychain
#127Earlier quoted context omitted.
Absolutely horrible choice of a name. There's so much BS regarding the use of encryption and it keeps coming up in criminal cases, that normal folks are going to avoid using a think that might somehow be linked with a felony.
Fork it, name it whatever you want. Problem solved, welcome to open source.
Re: Felony – An open-source PGP keychain
#128Interesting app, and it looks cool, but it rules out usage for me. Why the JS + Electron stack?
Re: Felony – An open-source PGP keychain
#129Re: Felony – An open-source PGP keychain
#130It's not obvious from the readme, how does key exchange work?
Once your key is generated you can click the 'copy' icon to the right of your name in the header. After that you can share the key on any platform you like, including Keybase.io :)
Please stop referring to non publicly open platforms as they were actually usable.
There is keys.gnupg.net, pool.sks-keyservers.net, pgp.mit.edu, etc. These are the well-known ones that had been around for a while.