Live data from Hacker News

Briar 1.4 – Offline sharing, message transfer via SD cards and USB sticks

briarproject.org

71–80 of 114 posts

Re: Briar 1.4 – Offline sharing, message transfer via SD cards and USB sticks

#72

Earlier quoted context omitted.

Safer how? On PC at least, SD card readers, both internal and external are attached via the USB protocol and are seen by the OS like mass storage devices, just like USB drives, including being bootable, so whatever malware you have for a specific PC target, the payload should basically work the same from SD cards as via USB drives.

Nyet. An SD card in a card slot can only be accessed as a mass storage device. A USB drive can act as a mass storage device as well as a keyboard and mouse and even contain an entire OS on it that could be remotely accessible via WiFi.

fwiw, it is most definitely possible to build an sd card that can exfiltrate its own data over wifi. in fact, that was the entire point of the Eye-Fi[0] product (though not with any nefarious intent).

though granted that's still a way smaller attack surface than what would be typically granted to a usb device.

[0]: https://en.wikipedia.org/wiki/Eye-Fi

Re: Briar 1.4 – Offline sharing, message transfer via SD cards and USB sticks

#73
post #25

Earlier quoted context omitted.

OMG yes, being able to share jpgs, mp3s and even java apps from one phone to another via Irda then Bluetooth felt mind blowing in the early to mid 00's, considering that most people didn't have internet on their phones (2G/3G data plans were eye-watering at the time, hell, even texts were expensive) but their phones had this short range wireless sort-of-WiFi-ish capability on their phones for sending and receiving fi…

Meanwhile, I couldn't change my 2006 phone's wallpaper without paying Verizon to enable the USB connection with a PC. I ended up taking a picture of the wallpaper using the phone, and then setting that image as the wallpaper. It was a 2-inch screen so it didn't look too bad.

Was there no way to flash it with a less restricted firmware? I remember running Alltel firmware on my Verizon Razr. And I was able to do similar things to the Rizr I got as my next phone.

Re: Briar 1.4 – Offline sharing, message transfer via SD cards and USB sticks

#74
post #53

Earlier quoted context omitted.

> Peer to Peer data transfer via computing devices is something I wish was be more mainstream. It's not, because the commercial cloud storage mafia has invested heavily in telling people that your data has to traverse their toll roads first. Been in software half my life never heard anyone saying anything like this. It's most of the time easier and more efficient to use cloud storage than to spin up and bootstrap a p…

I have seen many concerns of quantum computing and its ability to blow through most of our encryption standards with ease. So that trust in the cloud via encryption will likely soon fade

I haven't heard anything about symmetric encryption being easier to break with quantum computers.

Re: Briar 1.4 – Offline sharing, message transfer via SD cards and USB sticks

#75
post #45

Earlier quoted context omitted.

Sure, but take care as I said "easy, out of the box way" that any user can do, not the way that requires 5 years of sys-admin experience and 3 dev-ops certifications to pull off. I call it the (grand)parents test. If they can't figure it out on their own then it's not user friendly enough.

Yeah I get what you mean, I didn't actually mean implementing it yourself, but just going to snapdrop.net. That should doable for most people I assume.

Assuming they're already on the same wireless network.

Re: Briar 1.4 – Offline sharing, message transfer via SD cards and USB sticks

#76
post #6

I generally lean more toward “i like that iOS is locked down”, but this offline-app-sharing feature is one of the best arguments I’ve seen against that. That said, either I’d want peer-to-peer-shared apps to be signed by an entity I already highly trust, or that the sandbox containing the app was extremely solid (and preferably both of course).

Apple (or the military that controls them) can revoke the certs for any app at any time, rendering it unlaunchable.

Re: Briar 1.4 – Offline sharing, message transfer via SD cards and USB sticks

#78

How does it compares to Secure Scuttlebutt https://en.wikipedia.org/wiki/Secure_Scuttlebutt ?

That seems to be a protocol rather than an implementation.

From the project's download page, the only Android application is manyverse. How does that compare to Briar?

Re: Briar 1.4 – Offline sharing, message transfer via SD cards and USB sticks

#79

what do you think about this https://code.briarproject.org/briar/briar/-/wikis/FAQ#does-b... ?

It basically says what I would expect, but then I'm a tech-savvy privacy nerd who knows how this sort of tech works. Any particular reason you asked?

Re: Briar 1.4 – Offline sharing, message transfer via SD cards and USB sticks

#80

Earlier quoted context omitted.

> Bluetooth transfer There was a brief period while I was at school where people would share mp3 files with each other this way. This was before 2010.

In some areas of the world, this method seems to have persisted longer. Sahel Sounds released two compilations "Music from Saharan Cellphones" of tracks that they originally discovered on such bluetooth sharing networks: https://sahelsoundscompilations.bandcamp.com/album/music-fro... (Though I'm pretty sure that they then went back and established traditional contractual relationships with the artists before releasin…

Man I remember drifting around the internet and finding the blog post about purchasing song .MP3s in a market and transferring them over bluetooth. At the time that seemed like such a cool and unexpected alternate evolution of purchasing songs from itunes.
Post reply on HN