Live data from Hacker News

Wire Server open sourced

medium.com

31–38 of 38 posts

Re: Wire Server open sourced

#31
post #30

Earlier quoted context omitted.

Nice appeal to authority you got there.

It is indeed , isn't it? I'm actually underselling it, using principally names that I think everyone on HN knows. But if you know anything about cryptography, the repudiation of that "backdoor" story is even more devastating. Look at the list at the bottom of this post: http://technosociology.org/?page_id=1687

I am more interested in actual arguments instead of just names. That being said, since you are so interested in names, here is a list by the FSF that includes whatsapp https://www.gnu.org/proprietary/proprietary-back-doors.en.ht... (I am sure that everyone here has heard of the FSF).

> This is the overwhelming consensus of the cryptography and security community

Yeah, having your client (automatically and without a warning to the user first) let a "trusted" 3rd party make it re-send and re-encrypt a message with another unverified public key is the "overwhelming consensus of the cryptography and security community".

This article did not try to debunk what the original article said at all. Instead its main argument seems to be "Sure, whatsapp resends a message encrypted with a different key when the server demands it without even informing the user but this is not bad (because of "usability concerns") and damn you for even daring to inform the users about it!". Its secondary argument seems to be "b-but users will switch away to less safe applications if you inform them about how much whatsapp sucks - even if you suggest signal afterwards!".

> Here’s a difficult attack that could allow a sophisticated, resourceful adversary willing to invest a good deal of effort, some components of which have never been demonstrated in practice, to read a few messages that had been sent but have not yet been read after events like the intended recipient changing phones or SIM cards

It's not a "difficult attack" if the trusted third party (or anyone who can compromise their servers or force them) can perform it at will.

In any case, even if this backdoor did not exist it would not make whatsapp any better as it still is a proprietary software that might perform shady things in the background (or might be updated at any time to do so).

For anyone else seeing this and wants to read more about the story see https://news.ycombinator.com/item?id=13389935 and https://news.ycombinator.com/item?id=13394900

Re: Wire Server open sourced

#32
post #30

Earlier quoted context omitted.

It is indeed , isn't it? I'm actually underselling it, using principally names that I think everyone on HN knows. But if you know anything about cryptography, the repudiation of that "backdoor" story is even more devastating. Look at the list at the bottom of this post: http://technosociology.org/?page_id=1687

I am more interested in actual arguments instead of just names. That being said, since you are so interested in names, here is a list by the FSF that includes whatsapp https://www.gnu.org/proprietary/proprietary-back-doors.en.ht... (I am sure that everyone here has heard of the FSF). > This is the overwhelming consensus of the cryptography and security community Yeah, having your client (automatically and without a w…

[deleted]

Re: Wire Server open sourced

#33
post #30

Earlier quoted context omitted.

It is indeed , isn't it? I'm actually underselling it, using principally names that I think everyone on HN knows. But if you know anything about cryptography, the repudiation of that "backdoor" story is even more devastating. Look at the list at the bottom of this post: http://technosociology.org/?page_id=1687

I am more interested in actual arguments instead of just names. That being said, since you are so interested in names, here is a list by the FSF that includes whatsapp https://www.gnu.org/proprietary/proprietary-back-doors.en.ht... (I am sure that everyone here has heard of the FSF). > This is the overwhelming consensus of the cryptography and security community Yeah, having your client (automatically and without a w…

I'm confident I understand the intent and implications of the open letter I've cited. People can decide for themselves how persuasive they think either of us are here.

Re: Wire Server open sourced

#35
post #29

I haven't used Wire [1] in a long time because it didn't have a way to backup and restore conversations when switching devices (Signal behaves the same way too). But I do look at the release notes whenever the client is updated. Recently I was happy to see that Wire allowed up to three accounts to be configured in the client! I also like the fact that Wire doesn't need a phone number (unlike Telegram, Signal, WhatsAp…

> But until any of these new age apps/platforms support federation and decentralized communication, there's not much use for the masses to look for servers run by specific people. Have you not heard of https://matrix.org ? 100% open source server + client(s), decentralized, federated, easy to stand up your own server, end-to-end encryption, bridges to tons of other networks (IRC, telegram, slack, mattermost, etc), fu…

Thanks for the mention and the description of the features and benefits of Matrix. It sounds like music to my ears! I did hear about Matrix probably a year or two ago, but didn't think much of it at that time. I tend to look these up once every several months or so to see what's available and what improvements have happened. I'll have to check this out again.

Re: Wire Server open sourced

#36

I haven't used Wire [1] in a long time because it didn't have a way to backup and restore conversations when switching devices (Signal behaves the same way too). But I do look at the release notes whenever the client is updated. Recently I was happy to see that Wire allowed up to three accounts to be configured in the client! I also like the fact that Wire doesn't need a phone number (unlike Telegram, Signal, WhatsAp…

>But until any of these new age apps/platforms support federation and decentralized communication, there's not much use for the masses to look for servers run by specific people. What's the use case for self hosting ? Since it's supposed to be e2e, does self-hosting buy you anything ?

It’s a requirement many organizations have - government institutions are a good example. Some might want to not leak any data to the outside world, run it only for internal use, etc.

Re: Wire Server open sourced

#37
post #17

Wire is really, really exciting. I don't know if I trust its crypto anywhere near as much as I trust Signal's, and I don't know if I trust its business model as much, but featurewise it seems a healthy competitor. Multi-device. Email-address-based. Federated [soon]. What's not to like?

Crypto - Wire’s Proteus is an independent implementation of Axolotl that was later renamed to Signal Protocol. There’s also an external audit available - info and links from Wire.com/privacy.

As to business model, Wire is VC funded by Iconical.com /Janus Friis (co-founder of Skype) and announced the first paid product in July - wire.com/teams.

Full disclosure: I work at Wire.

Post reply on HN