Live data from Hacker News

Delta Chat – Email Based PGP Encrypted Chat

delta.chat

61–70 of 106 posts

Re: Delta Chat – Email Based PGP Encrypted Chat

#61
post #59
post #49

Earlier quoted context omitted.

No, if anything we'd be using XMPP or Matrix. Email is the completely wrong protocol choice for instant messaging. It's just a completely different use case. You wouldn't send a letter to the fire department if your house is on fire either.

Only because we choose it to be. When you use XMPP or Matrix you know your message will be delivered instantly. When you use email you don't. But that's only because we haven't defined an extension that tells the client whether the server can deliver messages instantly. It's not really that inherent to the system. Surely you've had at least one real-time conversation by email because both of you happened to be online…

Yes, it's theoretically possible to adapt many protocols to many use cases, but that doesn't mean it's a good idea. Email and XMPP are just geared towards very different use cases.

In particular, Email has a lot of assumptions about acceptable delivery delays, bidirectional (non-)reachability etc. baked in that would be very hard to globally undo.

Re: Delta Chat – Email Based PGP Encrypted Chat

#62

Earlier quoted context omitted.

> WhatsApp is closed source, so whatever they claim to can't be proven E2E only requires a correctly-designed client, not a correctly-designed server. Since any binary can always be deobfuscated, deliberately putting in a backdoor in the client would be an extremely risky PR move, especially in an app as big as WhatsApp, and one surely receiving lots of attention from security researchers. Not to mention that OpenWhi…

>Let's face it, people over here just don't like Meta and love to spread FUD about them. It's called punching upwards. >Since any binary can always be deobfuscated, deliberately putting in a backdoor in the client would be an extremely risky PR move, especially in an app as big as WhatsApp, and one surely receiving lots of attention from security researchers Correct me if I'm wrong, but can't a proprietary delivery m…

Builds are signed by the software publisher, not the Play Store. So the store alone couldn't corrupt releases, it would need collaboration by the publisher. (Google does have a service for app developers where they keep and manage your signing keys for you, but it's not required)

Re: Delta Chat – Email Based PGP Encrypted Chat

#63
post #9

Earlier quoted context omitted.

> Signal and WhatsApp are likely a step ahead in terms of privacy WhatsApp is closed source, so whatever they claim to can't be proven. And remember that both WhatsApp and Signal are legally required not to disclose to you whether they are spying on you or not.

> WhatsApp is closed source, so whatever they claim to can't be proven E2E only requires a correctly-designed client, not a correctly-designed server. Since any binary can always be deobfuscated, deliberately putting in a backdoor in the client would be an extremely risky PR move, especially in an app as big as WhatsApp, and one surely receiving lots of attention from security researchers. Not to mention that OpenWhi…

> Let's face it, people over here just don't like Meta and love to spread FUD about them.

Yep, don't like it. They already have proven to not be trustworthy by various privacy scandals in the past

Re: Delta Chat – Email Based PGP Encrypted Chat

#64
post #51
post #45

Earlier quoted context omitted.

> Why did Person A (who already had an email address) send a SMS text to Person B (who also already had an email address) to chat?!? Arguably primarily because they want to chat with them and not email them. The two have vastly different UX beyond just contact discovery. Before WhatsApp there were ICQ (also number-based!), MSN, Skype... WhatsApp's main contribution over these was indeed using phone numbers and contac…

>but I don't think it makes sense at all to characterize it as a usability improvement on email. Chats in general (not WhatsApp specifically) have "better" usability than email for some people because: + chats skipp the extra keystrokes of email workflow such as "Compose new email" and then enter an extra "Subject:" line which makes normal people put useless things in there such as "a quick question..." and then put…

just give them your signal number and use signal desktop

i do the same as you as i dont carry a phone anymore (fucking with the police).

Re: Delta Chat – Email Based PGP Encrypted Chat

#65
post #6

On the positive side, the use of P2P and IMAP makes censorship difficult, which is a strong advantage in authoritarian regimes. However this comes with serious trade-offs. PGP lacks forward secrecy: if a key leaks, all past messages can be decrypted. Also IMAP offers no metadata privacy, anyone can see who you email and how often. Signal and WhatsApp are likely a step ahead in terms of privacy with their double ratch…

WhatsApp obviously cannot be trusted for message privacy for the simple reason that Meta paid gazillion bucks for it. I don't understand why people need more evidence beyond that.

the cant read your messages. thats the usp of using signal encryption

its the rest of the account and metadata that is at risk

Re: Delta Chat – Email Based PGP Encrypted Chat

#66
post #16

In a sensible world, we would be using this, instead of whatsapp. It is amazing that even really a vast majority of, even technical people, not once stopped and looked at whatsapp, and said "Wait, e-mail can do this, we just need a pretty UI".

I mean... WhatsApp is literally XMPP / Jabber... It's amazing that we didn't stop and said, wait, Jabber can do this, we just need a pretty UI... Hell, Jabber can still do this. I'm not convinced of the other modern alternatives that don't have half the functional capabilities that Jabber do. The only "downside" of Jabber is that it's XML based, but really if you think about it, that's a strength. Anyone here could p…

> it's XML based, but really if you think about it, that's a strength

Nope.

Another downside is the X. The protocol being extensible means that no two clients implement the same subset of extensions making it useless. I’ve been scolded in the past for using the "wrong" client, making my messages look weird for people using the "right" client. Just make a good protocol.

Re: Delta Chat – Email Based PGP Encrypted Chat

#67
The most important factor with email, is that your inbox is encrypted at rest at all times... and cannot be bruteforced.

The chances of your email messages being 'man in the middled' are almost non-existent. Its a micro-percent of live investigations that does this.

The police RELY ON finding messages in either your inbox or the recipients. It doesnt matter if they are encrypted or not in reality. Of course they'd like to read them and if they are this deep into you. Its likely they still will (probably from the recipients lesser password hygiene than yours).

Almost no evidence is every 'plucked' out of the air and read. It just doesnt work that way.

However, software like Delta is better than nothing esp for normies. Its just limited in use for people who really need ways to frustrate LE.

Source: Ive been under NCA and FBI investigation before. Protonmail with the two password method stopped them every time. Memorise the 2nd password and password manager the first.

Re: Delta Chat – Email Based PGP Encrypted Chat

#68
post #67

The most important factor with email, is that your inbox is encrypted at rest at all times... and cannot be bruteforced. The chances of your email messages being 'man in the middled' are almost non-existent. Its a micro-percent of live investigations that does this. The police RELY ON finding messages in either your inbox or the recipients. It doesnt matter if they are encrypted or not in reality. Of course they'd li…

> Ive been under NCA and FBI investigation before. Protonmail with the two password method stopped them every time. Memorise the 2nd password and password manager the first.

Unless you exclusively use proton-bridge and disabled auto-update, then proton controls all endpoints in which your passwords live.

So what is preventing the FBI from forcing Proton to serve a special UI just to you that will be used to exfiltrate your second password?

Re: Delta Chat – Email Based PGP Encrypted Chat

#69
post #68
post #67

The most important factor with email, is that your inbox is encrypted at rest at all times... and cannot be bruteforced. The chances of your email messages being 'man in the middled' are almost non-existent. Its a micro-percent of live investigations that does this. The police RELY ON finding messages in either your inbox or the recipients. It doesnt matter if they are encrypted or not in reality. Of course they'd li…

> Ive been under NCA and FBI investigation before. Protonmail with the two password method stopped them every time. Memorise the 2nd password and password manager the first. Unless you exclusively use proton-bridge and disabled auto-update, then proton controls all endpoints in which your passwords live. So what is preventing the FBI from forcing Proton to serve a special UI just to you that will be used to exfiltrat…

[deleted]

Re: Delta Chat – Email Based PGP Encrypted Chat

#70
post #68
post #67

The most important factor with email, is that your inbox is encrypted at rest at all times... and cannot be bruteforced. The chances of your email messages being 'man in the middled' are almost non-existent. Its a micro-percent of live investigations that does this. The police RELY ON finding messages in either your inbox or the recipients. It doesnt matter if they are encrypted or not in reality. Of course they'd li…

> Ive been under NCA and FBI investigation before. Protonmail with the two password method stopped them every time. Memorise the 2nd password and password manager the first. Unless you exclusively use proton-bridge and disabled auto-update, then proton controls all endpoints in which your passwords live. So what is preventing the FBI from forcing Proton to serve a special UI just to you that will be used to exfiltrat…

In the US you might be able to argue it amounts to "compelled speech", and is unconstitutional.

https://en.wikipedia.org/wiki/Apple%E2%80%93FBI_encryption_d...

Post reply on HN