Live data from Hacker News

Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

whispersystems.org

21–30 of 225 posts

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#21
post #18

Why didn't Google just develop this in house? It almost feels like they're admitting to having no credibility on privacy without an external partner.

Why bother if there is a ready solution, that's already got the trust of other market leaders?

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#22
post #18

Why didn't Google just develop this in house? It almost feels like they're admitting to having no credibility on privacy without an external partner.

That's nonsense. In-house proprietary encryption is not peer reviewed and untrustworthy by definition and if you're going to work in the open, especially for a new proprietary chat app, it makes better sense to build on an open platform that's already proven and is handled by people that really know their stuff. More secure and probably cheaper as well.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#23
post #2

This is fantastic news. The two largest messaging platforms on the Internet will both be using Signal protocol. I could ask for more: E2E could be the default for Allo, and it isn't. That's not great. But the E2E you get when you ask for it will apparently be best-in-class.

Skype is the last major messaging platform to not have end-to-end encryption in any way.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#24
post #6
post #2

This is fantastic news. The two largest messaging platforms on the Internet will both be using Signal protocol. I could ask for more: E2E could be the default for Allo, and it isn't. That's not great. But the E2E you get when you ask for it will apparently be best-in-class.

Uh, where are you defining Allo as one of the largest messaging platforms on the internet? It literally just launched. It might do well, but it could also easily be a flop (as many other social initiatives from Google have been). Either way it's a long ways from catching up to WeChat, Viber, or even Facebook Messenger.

It's going to end up on a lot of Android phones. If it's any good, it will catch on. Hangouts hasn't caught on that much because, imho, it has bad UI.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#25
post #11

Earlier quoted context omitted.

OWS apparently partners with NSA with metadata collection :>

Is this sarcasm of some kind? Is there some joke in here about Whisper Systems vs. Open Whisper Systems? This comment seems baseless and unfounded at best. Is there context I am missing?

Yes. Singal and RedPhone require google apps on android device or using browser that is spying on you all the time, eg. downloads binary blob that turns on microphones, even when feature is disabled. NSA needs only metadata to send drone strikes on a village and Singal provides only metadata to Google services.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#26
post #17
post #15

What I'm curious about, and think would be really neat, is if one could take advantage of the shared Signal Protocol to send messages cross-platform. Specifically, sending an encrypted message to a Whatsapp user from Allo. Or to a Signal user from Whatsapp. Or any combination/permutation really.

Moxie's on the record as being opposed to federated services. https://whispersystems.org/blog/the-ecosystem-is-moving/

I don't think I'd characterize his blog post that way. The last sentence captures what I got from reading it: "It may not be as beautiful as federation, but at this point it seems that it will have to do."

Also, as djb points out: https://twitter.com/hashbreaker/status/732912508089032706

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#27
post #18

Why didn't Google just develop this in house? It almost feels like they're admitting to having no credibility on privacy without an external partner.

The Signal protocol is for all intents asymptote the state of the art in the design of a secure messaging protocol. There doesn't seem to be any meaningful improvements to the design without changing the requirements.

New requirements might be

- Post Quantum forward secrecy

- Groups messaging with transcript verification

- Security weakness in x25519 or AES-CBC-HMAC or SHA256 primitives.

If you don't have any new requirements, crypto protocol developer time is a scarce resource. Why reinvent the state of the art?

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#28
To me it seems like Open Whisper Systems are accepting a lot of concessions in order to have Signal included into products. The trust I once had for moxie is quickly dissipating.

* Privacy is only provided in Allo in a secondary mode. Not by default.

* Federation of the Signal protocol has been rejected for non-technical reasons.

Also, on a personal note, the desktop client requiring chrome is pretty awful.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#29
post #18

Why didn't Google just develop this in house? It almost feels like they're admitting to having no credibility on privacy without an external partner.

The only reason I (somewhat) trust the encryption in Whatsapp is that it came from OpenWhisperSystems. For Allo, I imagine I'd feel the same.

Some of the value is in signalling to your users.

Re: Open Whisper Systems Partners with Google on End-To-end Encryption for Allo

#30
post #25

Earlier quoted context omitted.

Is this sarcasm of some kind? Is there some joke in here about Whisper Systems vs. Open Whisper Systems? This comment seems baseless and unfounded at best. Is there context I am missing?

Yes. Singal and RedPhone require google apps on android device or using browser that is spying on you all the time, eg. downloads binary blob that turns on microphones, even when feature is disabled. NSA needs only metadata to send drone strikes on a village and Singal provides only metadata to Google services.

"Apparently partners with NSA" is very different from "for plausibly-legitimate reasons, runs only a platform that has an increased attack surface".

That's like saying that Ubuntu partners with script kiddies because they're slow about fixing security bugs in LTSes. I understand the point you're trying to make, but no.

Post reply on HN