Earlier quoted context omitted.
From the homepage: > Send and receive extensible messages with optional end-to-end encryption Why would encryption ever be "optional"?
Because we don't want client implementers to be forced to have to jump through end-to-end crypto hoops if they don't want to. The simplest way to send a message in matrix is: curl -XPOST -d '{"msgtype":"m.text", "body":"hello world"}' " https://matrix.wherever.com/_matrix/client/api/v1/rooms/$roo... ...and we'd like to keep it that way. But you can always insist on only ever communicating with folks who are on E2E cr…
Wire – Modern Communications Network
401–410 of 411 posts
Re: Wire – Modern Communications Network
#402Earlier quoted context omitted.
From the homepage: > Send and receive extensible messages with optional end-to-end encryption Why would encryption ever be "optional"?
Back in the day it was often optional due to the additional processing that it required.
But in my day we've been spending years fighting this sort of short-sightedness: https://www.ietf.org/mail-archive/web/rtcweb/current/msg0274...
Re: Wire – Modern Communications Network
#403Earlier quoted context omitted.
Because we don't want client implementers to be forced to have to jump through end-to-end crypto hoops if they don't want to. The simplest way to send a message in matrix is: curl -XPOST -d '{"msgtype":"m.text", "body":"hello world"}' " https://matrix.wherever.com/_matrix/client/api/v1/rooms/$roo... ...and we'd like to keep it that way. But you can always insist on only ever communicating with folks who are on E2E cr…
Is that the same way I can always insist on only ever receiving PGP-encrypted e-mail?
Re: Wire – Modern Communications Network
#404Earlier quoted context omitted.
Based on past comments I'd expect the author to have the en_US layout (or something entirely different) and probably - now taking a guess here - even without umlauts. I'm German and use en_US here, so for ö I'd need to compose a character manually. Which is probably what was mocked (whether that is right or wrong I do not know - I certainly cannot judge the style of writing of someone in his native language, as a for…
I appreciate the great deal of thought you put into this. I feel like a mini-Internet celebrity of the minute. You are entirely correct about needing compose to type the symbol, but I use it so rarely, that I just copy-pasted. It's not an umlaut though, it's a different diacritic called diaeresis. It makes me feel like I'm speaking a more awesome language when I use it.
The 'not an umlaut' part doesn't seem to be relevant though, since we talk about the character composition. 'ö' is the same character both as o-umlaut and as o-diaeresis (I admit I checked if there's a different way to write the latter), so the argument is weird.
de_DE has a character 'ö' on the keyboard, if I use that as umlaut or not is a different problem.
Composing " and o (or whatever you use) produces what looks like o-umlaut to a German speaker - and my understanding was that you were 'attacked' (if you will) for going out of your way to write 'ö'. Whatever that character signifies here.
(I actually didn't know the name diaeresis, but the usage isn't uncommon here. I've driven my share of Citroën 2CVs in the past)
Re: Wire – Modern Communications Network
#405Earlier quoted context omitted.
While you can argue that some piece of open source software can be more insecure than a proprietary alternative, auditing a piece of software requires access to the source code and that is mandatory. And with open source everybody can audit with no restrictions. Yes, OpenSSH is a piece of shit, but how do you think it was discovered, from 2 independent parties no less. Then there's another effect that I like - after…
OpenSSH or OpenSSL? I thought OpenSSH was pretty solid, forgetting the fact that configuring it isn't as straightforeward as one would hope.
Re: Wire – Modern Communications Network
#406Earlier quoted context omitted.
Is that the same way I can always insist on only ever receiving PGP-encrypted e-mail?
Not quite - as PGP is a pita to use, and not a formal part of the SMTP spec. So refusing to read non-PGP would be suicide. But if it was considered table stakes to implement the crypto option of the spec, and all the decent Matrix clients out there did so and sent end-to-end encrypted by default, then it'd naturally become the default. In other words, if you gracefully upgrade chats between capable clients to be end-…
In the absence of some forcing function, the trend is for it to get worse, not better.
Re: Wire – Modern Communications Network
#407Earlier quoted context omitted.
Unfortunately, even if they DID specifically list out all the security measures that they used, someone would still complain because it isn't completely open source. The previous company I worked for not only had legitimate encryption for anything private we received from the user (e.g.: email passwords) so that nobody at the company could ever read them, but also had some (if I remember correctly) good documentation…
There are already FOSS replacements for Skype, such as Tox. The fact is that if every line of code can't be inspected then the software can't be considered secure, and we're forced to put blind faith in a faceless corporation, which is understandably not acceptable for many people. I don't really care if you think this is "practical" or not. That's simply the reality of the situation. Proprietary == insecure. If a co…
Re: Wire – Modern Communications Network
#408Earlier quoted context omitted.
> "What we need is another messaging app" said nobody, ever. The usual negative HN top post. I have to disagree. We've moved from irc, to ICQ, to Microsoft Messenger, to ..., to Skype, to (what's hot now), so somehow all those people really DID want another messaging app and even adopted one. > It looks pretty, but this is yet another app in the long list of "Skype killers" or "Voice/video/text" messaging. Most of th…
> so somehow all those people really DID want another messaging app and even adopted one. Very disingenuous. In terms of ICQ, they were just early to market, had a competent client and... a deeply flawed method of identification. Messenger? Rolled out with Windows, just like certain other software that caused a bit of a stink in courtrooms at one point. Leverage. AOL did the same thing, pretty much. As for Skype... i…
But I also think there is a lot of room for "Skype Killers" in different niches. I think Skype UI is getting worse for the experienced/heavy user. What is your niche? Would love to hear more.
Re: Wire – Modern Communications Network
#409Earlier quoted context omitted.
I've been in Brazil for the past five weeks. EVERYONE uses whatsapp, because SMS is expensive. And this all happened in the past couple of years or so, because that's when smartphones became widespread. I have never been asked my phone number. I've only been asked my "whatsapp". Make a good enough messaging app, and you can win an entire country. Or the world.
I'm from Brazil. You see small local businesses, with hand painted signs, where the phone number is followed by the whatsapp logo. Not even the name "whatsapp", just the logo. It's scary how they took over communications over here.
Re: Wire – Modern Communications Network
#410Am I such an outlier if I use Skype for business, not for leisure? I have clients on three continents and every single one used Skype to communicate about the project. Skype was generally running on every machine as a "watercooler chat"/IRC replacement. Just open groups, give them names and pin them to the sidebar. Done. So I really expected this to be more secure, more portable and LESS designer-driven. Who is even…
Despite of that, I don't think Wire is it. I downloaded the app and it is quite awful to use. We need a "Skype Killer" with better usability for business, not only a pretty screen and a good marketing landing page.