Live data from Hacker News

Kagi releases alpha version of Orion for Linux

help.kagi.com

231–240 of 325 posts

Re: Kagi releases alpha version of Orion for Linux

#231

Earlier quoted context omitted.

I hope freediver will shed some light on the open source plans, because that's a deal breaker for me too. I'm a long time paying customer and huge proponent (even evangelist) of Kagi, but a closed source browser is just too many steps backwards for me no matter who makes it. I get (though wouldn't necessarily agree with) keeping it closed while it's still in the works, but would like to know if the plan is to open so…

Wish granted!

Thank you! I'm obviously just one person, but I deeply appreciate your willingness to engage on HN, and your transparency and honesty about things (not just today, but also in the past). Makes me feel even better about being a paid Kagi subscriber.

Re: Kagi releases alpha version of Orion for Linux

#232
post #9

It seems weird to run a closed-source browser on an open-source operating system when so many open alternatives exist—I certainly wouldn’t do it, and I’m a Kagi customer. Does Kagi plan to open-source Orion on Linux?

Kagi founder here. Orion isn't open source yet primarily because we're a 5-person team that spent 6+ years building this and created significant IP doing so, and we're not in a position to defend our work against a well-funded company using it as a base (we care very much about the business model of the browser surviving). Restrictive licenses help in theory but enforcing them against a company with a larger legal bu…

When you do release it, do you know yet if you plan on releasing the full change history? Or would you start with a snapshot at the ~release date?

Re: Kagi releases alpha version of Orion for Linux

#233

Earlier quoted context omitted.

Kagi founder here. Orion isn't open source yet primarily because we're a 5-person team that spent 6+ years building this and created significant IP doing so, and we're not in a position to defend our work against a well-funded company using it as a base (we care very much about the business model of the browser surviving). Restrictive licenses help in theory but enforcing them against a company with a larger legal bu…

> managing an open source codebase of this size would add real strain to our small team Can you please elaborate what do you mean when you say this? This is something I do not understand. How licensing terms affect your codebase management beyond setting things up so the code is available to users? Publishing something under a FLOSS license doesn’t mean anything except that you grant end-users certain rights (the fou…

> you’re saying your legal department doesn’t have capacity to handle licensing concerns

My read is their legal department isn’t fleshed out enough to defend the work when e.g. a tech giant steals it.

Re: Kagi releases alpha version of Orion for Linux

#234

Earlier quoted context omitted.

They give you a key and only if you have a higher tier account. The act of doing that requires that there is a step in the process where they know you’re requesting a key and who you are. They could bind them in the backend if they wanted, before giving it to you. You’re still trusting them. Not to mention they could round them all up by IP or browser fingerprinting. There is still some level of trust. I happen to tr…

I am not an expert in the underlying cryptography, but the claim is indeed that the cryptographic approach makes it impossible for them to link the key to the queries in the backend.

Sure! But there is a stage where they generate those keys for you and give them to you. You need to be logged in to get that page. That is trust there.

Re: Kagi releases alpha version of Orion for Linux

#235

Earlier quoted context omitted.

Hmm good point. The issue is also the distinction between widevine L1, i.e hardware-backed DRM and L3 (the software backed one). Correct me if I'm wrong but to stream 4K, studios require a hardware root of trust and a verified media path. They need a guarantee that the video frames are decrypted inside a trusted execution environment and sent directly to the display without the OS kernel or user space being able to r…

> Am I right in this assumption? Yes. I tried using Chrome on Linux just to watch movies that I purchased on Youtube at HD/4K and watched as the stream was limited to 240P. IMHO regardless of what Google says in their ToS they have already broken the trust agreement by not providing what I paid for. Regardless of what the studios want, all this does is push me back towards piracy because once again the industry fails…

I'd imagine only SteamOS on the GabeCube could make this guarantee on Linux

Re: Kagi releases alpha version of Orion for Linux

#236

Earlier quoted context omitted.

I am not an expert in the underlying cryptography, but the claim is indeed that the cryptographic approach makes it impossible for them to link the key to the queries in the backend.

Sure! But there is a stage where they generate those keys for you and give them to you. You need to be logged in to get that page. That is trust there.

No, issuer-client unlinkability is a feature of the design. The token is finalized by the client using private inputs so Kagi never actually sees the redeemable token (until it's redeemed).

https://blog.kagi.com/kagi-privacy-pass#token-generation:~:t....

https://www.rfc-editor.org/rfc/rfc9576.html

Re: Kagi releases alpha version of Orion for Linux

#237

There is some strange irony in this. Apple initially used the khtml code-base to build Safari but it quickly became impossible to back-port the changes from the Safari branch of khtml back into Konqueror. Now, 20 years later, someone has made an open source version of Safari.

Who?

Re: Kagi releases alpha version of Orion for Linux

#238

Earlier quoted context omitted.

Sure! But there is a stage where they generate those keys for you and give them to you. You need to be logged in to get that page. That is trust there.

No, issuer-client unlinkability is a feature of the design. The token is finalized by the client using private inputs so Kagi never actually sees the redeemable token (until it's redeemed). https://blog.kagi.com/kagi-privacy-pass#token-generation:~:t... . https://www.rfc-editor.org/rfc/rfc9576.html

Using the example doc you’re citing from kagi.com - though not the RFC, I don’t have the time to dive into that one at the second, I see that a session token plus some other stuff is passed in and a token comes out.

Where does it show that on the Kagi backend they couldn’t, theoretically, save the session key before performing the token response?

Re: Kagi releases alpha version of Orion for Linux

#239

Earlier quoted context omitted.

No, issuer-client unlinkability is a feature of the design. The token is finalized by the client using private inputs so Kagi never actually sees the redeemable token (until it's redeemed). https://blog.kagi.com/kagi-privacy-pass#token-generation:~:t... . https://www.rfc-editor.org/rfc/rfc9576.html

Using the example doc you’re citing from kagi.com - though not the RFC, I don’t have the time to dive into that one at the second, I see that a session token plus some other stuff is passed in and a token comes out . Where does it show that on the Kagi backend they couldn’t, theoretically, save the session key before performing the token response ?

Sure, they probably do. Doesn't matter because neither the session key nor the token response can be linked to the tokens.

If you're not going to make an effort to understand how it works, don't make assertions about how it works. Ask your favorite LLM about the RFC if you have any further questions.

Re: Kagi releases alpha version of Orion for Linux

#240

Earlier quoted context omitted.

If you're using a "common browser" on Linux (Firefox/Chrome) Netflix should work, just at 720p for most of the content. If you're using a minor Chromium based fork the customized Chromium package provided by your distro it probably doesn't have Widevine by default. The same is true for running a vanilla Chromium build on Windows, the big difference is the quality of content you can get on Windows can be higher than 7…

> If you're using a "common browser" on Linux (Firefox/Chrome) Right. The user I was replying to was asking about a browser that isn't either of those.

[deleted]
Post reply on HN