Live data from Hacker News

Wire – Modern Communications Network

wire.com

341–350 of 411 posts

Re: Wire – Modern Communications Network

#341
post #266

Earlier quoted context omitted.

There are already FOSS replacements for Skype, such as Tox. The fact is that if every line of code can't be inspected then the software can't be considered secure, and we're forced to put blind faith in a faceless corporation, which is understandably not acceptable for many people. I don't really care if you think this is "practical" or not. That's simply the reality of the situation. Proprietary == insecure. If a co…

I would argue that, theoretically, proprietary can be secure. A code base can be made secure by highly experienced engineers who are paid to make the code secure. You might never be able to see the code, but it could still be secure. The problem is that you can never actual verify how secure the proprietary solution is. So whether or not it is secure, you don't trust it. (there are even some interesting arguments to…

Yes, in theory it is possible. However even 100% secure proprietary software must be assumed to be insecure, because we're still running on blind faith, which is patently stupid for anyone who requires security.

Re: Wire – Modern Communications Network

#342
post #338

Earlier quoted context omitted.

I don't think it's as black and white as all that. This reads like the equivalent claim the NSA makes along the lines of, "if you have nothing to hide, why can't we record every facet of every communication and store it forever?" Business relationships run on trust. Claiming your software is secure when it is to the best of your knowledge is not dishonest.

You're making the baseless (and some might say naive) assumption that it is secure to the best of their knowledge. If they really wanted to build trust then they would prove it and leave no doubt in people's minds.

"Dear citizen, you're asking us to make the baseless assumption that you're innocent until proven guilty, if you really want to build trust you'll let us monitor you 24/7 and leave no doubt in our mind."

You're making an assumption of guilt. The fact that something isn't open source doesn't inherently make it insecure.

Re: Wire – Modern Communications Network

#344
post #110
post #23

Earlier quoted context omitted.

It's the other way around. Messaging apps need to demonstrate their own security by releasing the source code. So far only TextSecure does this.

One doesn't demonstrate security by releasing the source. One needs to have source released, audited and verified to match prebuilt binaries that are actually used by the unwashed gray masses. Without all three checked for each public build you have zero assurance that you are running a binary built from the released source and that the source doesn't have anything fishy in it. The only app that checks all three, som…

The Truecrypt audit still hasn't been finished yet, has it?

Re: Wire – Modern Communications Network

#345
post #338

Earlier quoted context omitted.

You're making the baseless (and some might say naive) assumption that it is secure to the best of their knowledge. If they really wanted to build trust then they would prove it and leave no doubt in people's minds.

"Dear citizen, you're asking us to make the baseless assumption that you're innocent until proven guilty, if you really want to build trust you'll let us monitor you 24/7 and leave no doubt in our mind." You're making an assumption of guilt. The fact that something isn't open source doesn't inherently make it insecure.

I'm not making any assumptions as to their motives; I have not accused them of any wrong doing. As far as I'm concerned, they might be working in good faith or they might not be. That's not good enough when it comes to security. You're incorrect with that last sentence as I and others have pointed out already.

Re: Wire – Modern Communications Network

#347
post #341

Earlier quoted context omitted.

I would argue that, theoretically, proprietary can be secure. A code base can be made secure by highly experienced engineers who are paid to make the code secure. You might never be able to see the code, but it could still be secure. The problem is that you can never actual verify how secure the proprietary solution is. So whether or not it is secure, you don't trust it. (there are even some interesting arguments to…

Yes, in theory it is possible. However even 100% secure proprietary software must be assumed to be insecure, because we're still running on blind faith, which is patently stupid for anyone who requires security.

You run OpenBSD, don't you? (To be fair, their approach since the 90s seems a lot more reasonable now)

Re: Wire – Modern Communications Network

#348

"What we need is another messaging app" said nobody, ever. It looks pretty, but this is yet another app in the long list of "Skype killers" or "Voice/video/text" messaging. It seems like it's the default goto for anyone that can't think of something more interesting these days.

I agree with you 100%. Right when I saw Wire I was like, "Oh great I have to download another messaging app and convince people to use it."

No thanks. I already use iMessage, Hangouts, Line, and Skype at work. There's too many messengers and they all do the same thing.

Wire is not a 10x improvement. Maybe like a 0.0015 improvement which won't even convince me to download it.

The call quality with Skype and other services is decent, making it slightly better with a cleaner UI won't do much.

Re: Wire – Modern Communications Network

#349

Earlier quoted context omitted.

Your Skype shows ads? I've never seen ads on Skype.

Not on Mac but it does on Windows.

That's not true at all. I have ads shoved in my face on my Mac continuously. It's bulky & ugly to use (UX-wise), so it's only used for business.

I make myself available on nth number of services because they people I want to talk to are spread across them; Skype is not one of them.

Re: Wire – Modern Communications Network

#350
post #347
post #341

Earlier quoted context omitted.

Yes, in theory it is possible. However even 100% secure proprietary software must be assumed to be insecure, because we're still running on blind faith, which is patently stupid for anyone who requires security.

You run OpenBSD, don't you? (To be fair, their approach since the 90s seems a lot more reasonable now)

No, my views are not based on my own needs or paranoia. As a security-oriented software developer I recognize that software that claims to be secure needs to deliver, because people like Snowden, Assange et al. may be relying on it some day.
Post reply on HN