Live data from Hacker News

Briar Project

briarproject.org

61–70 of 189 posts

Re: Briar Project

#61

Earlier quoted context omitted.

Spying on you is not Apple's business model.

Oh indeed it is. I spent years reading apple reports and my conclusion was that they want the data for themselves so they can sell it. Devices don't make much profit when you factor in how much is spent buying up almost all old devices that hit the market.

None of the big tech companies sell user data.

Re: Briar Project

#62
What the fuck ever happened to communicating through plain old radios? Impractical for someone to track you, trivial to speak in codes.

Re: Briar Project

#63
post #35

In an authoritarian regime with large masses of human and technological resources determined to have control over its population, nothing is really secure. Sending a message that can't be read by a third party? You're suspect. Have an illegal app installed on your registered "report to big brother" phone? Expect an unfriendly visit by big brother police. Don't have a "big brother" phone? There are various ways of sni…

If only Google and Apple would make a fully end to end encrypted chatting platform to take place of SMS that is fully federated and not controlled by a single entity, something the likes of Signal could support / join in on and other chat apps. When you turn crypto into something the masses use seamlessly it gets a little more complicated to figure out who the suspects are. Also default to not synching to the cloud,…

From what I an tell, this is the goal of matrix.org - though full federation and identity portability is not there yet.

Re: Briar Project

#64
post #62

What the fuck ever happened to communicating through plain old radios? Impractical for someone to track you, trivial to speak in codes.

Distance is an issue. And it's unlawful in the United States to encrypt ham radio traffic. No one's really monitoring CB much anymore though.

Re: Briar Project

#65

Earlier quoted context omitted.

It can't happen soon enough. I installed Signal a few years ago, and the first thing it did was notify a bunch of people I had in my contacts, that I was now using Signal... ...Including the unstable frenemy-guy who was only in my contacts so I'd recognize the number if he called and I'd know not to answer... ....who immediately PM'd me on Signal to push his latest delusion and make sure I didn't disagree. Great, jus…

I understand your frustration, but Signal didn't notify your contacts because you installed it. It notified the other person, because he had your phone number. Your local Signal installation regularly checks if any of your contacts (with the phone numbers you have of them) are registered at the Signal servers - and then lets you know it, such that you can text this contact securely.

doesn't make a difference. it shouldn't do that without user confirmation

Re: Briar Project

#66
post #6

I've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client,…

I'm surprised nobody mentioned Jami https://jami.net/

Re: Briar Project

#67

Earlier quoted context omitted.

Do you have any evidence of Apple selling user data?

It's right in Apple's privacy policy, see Disclosure to Third Parties section: https://www.apple.com/legal/privacy/en-ww/ They obviously sell user data in aggregate - not at a personal level, but which of the big tech companies sell personal data (maybe FB / Cambridge Analytica?) Also, Apple has Google as the default search engine which Google pays billions for. Is that selling your personal data?

You mean the disclosure to third parties section that explicitly says "Apple does not sell personal information"?

I can't see anything in that section that says that they sell information to third parties, personally identifiable or aggregate (I would consider the latter to be "personal" data as well fwiw). Is there a specific sentence you're thinking of?

It seems to be talking about the necessary sharing of data that happens when Apple contracts with third party services to run their own business. E.g. when they ship you a product they need to provide your address to the courier company. Or when they pay an advertising company to run ads for Apple products targeting certain markets/their own existing customers (not the same thing as selling personal data to an advertiser so that they can run ads for other products using said data - that would be selling personal data)

As far as I can tell you're either using a definition of "sell" that is different to mine, or you're claiming Apple is using weaselly language to make it sound like they don't when they do (which is not unheard of of course). But you haven't provided enough information for me to really know what you're talking about - which is it, and why?

Also no, making the default search engine google is not selling personal data.

Re: Briar Project

#68

Earlier quoted context omitted.

It can't happen soon enough. I installed Signal a few years ago, and the first thing it did was notify a bunch of people I had in my contacts, that I was now using Signal... ...Including the unstable frenemy-guy who was only in my contacts so I'd recognize the number if he called and I'd know not to answer... ....who immediately PM'd me on Signal to push his latest delusion and make sure I didn't disagree. Great, jus…

I understand your frustration, but Signal didn't notify your contacts because you installed it. It notified the other person, because he had your phone number. Your local Signal installation regularly checks if any of your contacts (with the phone numbers you have of them) are registered at the Signal servers - and then lets you know it, such that you can text this contact securely.

The technical details do not really matter.

Many people might have my phone number, possibly from a long ago. But the number itself is pretty safe -- there is no way to tell if this phone is in use or not.

Signal breaks that assumption -- it immediately tells every other user that this number is alive, valid, and can be contacted right now.

This is a terrible idea to do by default, especially if one cannot disable it.

Re: Briar Project

#69

Earlier quoted context omitted.

Because: a) Often the intended recipient isn't online when the message is sent, and it may happen that there is never a time when both sender and recipient are online simultaneously (e.g. sender's device only turns on to send the occasional message, receiver's device is usually off but turns on occasionally to check if there are messages) b) Often one or both devices can only connect to, but can't be connected to (be…

Is IPv6 likely to be a practical solution to the router/NAT issue? Are routers assigning globally-routable IPs to their clients, is that already a thing?

The NATs will be gone, but they'd be just replaced by firewalls with "default deny incoming" policies for most users. Some users might change this, but there would be enough people using defaults that one could not rely on p2p connectivity.

(The current networks are often not set up to handle malicious incoming internet traffic, and new protocol is not going to change this)

Re: Briar Project

#70
I don’t have an answer, but a slightly different perspective. Many different segments have a deep interest in using highly secure encrypted communications: politicians working on deals within/between governments (that should be auditable, but many try to avoid that), whistleblowers, organizers operating in adverse governments, dissidents, terrorists, pedophiles with a lot to lose (similar to Epstein’s network), healthcare professionals trying to talk to patients or other doctors in a hippa world, illegal transaction networks, attorneys with clients, VCs trying to debate the future of the world, companies trying to preserve trade secrets, you name it. It takes one of the egregious bad actors using the system to commit a crime worthy of public attention before the entire system is justifiably unpacked, banned, or considered a signal of bad intentions.

How can a system be made decentralized, but able to self-police against legitimately, publicly agreed upon bad behavior? If the system is able agree upon and exclude legitimately bad behavior automatically, the governments would not have a claim upon needing to police it and regular users would probably find it beneficial as well.

How could the self policing possibly happen?

Maybe you have a blockchain of anonymized encrypted messages that is read by open source scanning bots - if enough independent bots flag a message, then a group of anonymous judges can adjudicate to ban those user accounts?

Encryption is one challenge, but if you want true ubiquitous privacy, you need to deliver internal safety to prevent the need for external policing of activity. Social creatures of any species from dolphins to macaques have evolved some kind of internal behavior policing mechanism or trust is lost, and as such the system of value exchange grinds to a halt.

Post reply on HN