Live data from Hacker News

Darknet Messenger Briar Releases Beta, Passes Security Audit

briarproject.org

81–90 of 90 posts

Re: Darknet Messenger Briar Releases Beta, Passes Security Audit

#81

Why not develop tox instead, which is open source, end to end encrypted, on more platforms, and seemingly further along in general?

Briar is also e2e and open source. It also has a ton of mesh networking features that Tox doesn't have.

Can you say a bit ore about the mesh network features of Briar?

I've looked through a lot of the documentation and can't find anything other than references to bluetooth and wi-fi, which is opaque to me.

I'm kind of wondering about something like briar, but that can connect over a cjdns network if available... is that what it's doing?

Re: Darknet Messenger Briar Releases Beta, Passes Security Audit

#82

Why not develop tox instead, which is open source, end to end encrypted, on more platforms, and seemingly further along in general?

I have the impression Tox withered and died, which is really sad considering how usable (when compared to alternatives) it is.

FWIW, the git repository looks like it was worked on within the last couple of days.

Re: Darknet Messenger Briar Releases Beta, Passes Security Audit

#83
post #58
post #22

It's ironic that this update plays up how Briar "hides metadata" when the audit found that the application deanonymizes its users by exposing DNS lookups during RSS updates.

The article says: "All the issues found by the audit have been addressed in this beta release."

so the current version isn't audited?

if they changed the code and design after the audit, then much worse bugs might be hiding now, until that version is audited.

Re: Darknet Messenger Briar Releases Beta, Passes Security Audit

#86

When I see that one of the requirements for privacy-preserving software is to have been in the same physical location as the person I need to connect with, while running said software , I immediately stop reading and move on to other things. I've done this for roughly five years. Assuming I've never wanted to become a Debian developer, is there any important piece of privacy-preserving software I've missed out on? Is…

Short of web of trust, which has other issues, how else would you propose to bootstrap?

Using PKI, "winging it", etc.

Bitcoin - used PKI to download it. Now Bitcoin is reproducibly buildable, so you can read the forum to see if any zealots notice different hashes (which they certainly would unless you are personally being targeted in testing out the software). Make some small transactions to see if it works.

Bitmessage - downloaded it a few days after the initial release. Sent a message over Bitmessage to the Bitmessage author. Got one back from the author.

Tor - trust that the directory servers are doing their jobs.

Signal - haven't used it but if I did I'll piggy-back on phone numbers to message people I already know.

git - used PKI to initially grab the code, trust my own dev machine as I've made commits, occasionally posted commit hashes over various secure/insecure mediums for various reasons (may have done this in person wrt a bug, can't remember).

Notice that in all these cases, trying out the software (at least in the U.S.) does not at all imply that you trust it. You could practice installing Tor 20 different times, on 20 different untrustworthy Windows machines and simply use it to search for cat pictures. Then, the 21st time, you could take all kinds of precautions and build a special box just for running Tor, armed with all the first-hand knowledge about how it works and what its trade-offs are.

I can also completely fuck up something in git and get so frustrated I just clone it again from the repo I don't have to trust because I just check the hashes and go on working.

Requiring physical proximity and a formal key exchange before I can even use the software simply cannot work IMO. It a) requires special planning, coincidence, or proselytization to try out a working version of the app, b) it balloons the length of the engineering cycles and makes it hard to just start over, c) the reliance on in-person meeting implies a level of trust between you, your keys, and your smartphones that neither party should take for granted.

Also, it doesn't scale.

Re: Darknet Messenger Briar Releases Beta, Passes Security Audit

#88

Earlier quoted context omitted.

It is a term used by media and seen by general public when talking about many unethical or illegal things like child pornography and drug marketplaces, so perhaps not the best thing to associate with in your marketing material.

So should we stop saying "hackers" because it is also a term used by media and seen by the general public when talking about many unethical or illegal things?

It is a fair point, and I don't necessarily agree with the perception or misuse of either word.

But you have to admit there are connotations and that leads to bias when you start talking to laypeople who don't understand the other meanings or usages of 'darknet' or 'hacker'. There may be better ways to communicate that won't immediately stop the general public in their tracks when they hear a particular 'tainted' word.

Re: Darknet Messenger Briar Releases Beta, Passes Security Audit

#90
post #83
post #58

Earlier quoted context omitted.

The article says: "All the issues found by the audit have been addressed in this beta release."

so the current version isn't audited? if they changed the code and design after the audit, then much worse bugs might be hiding now, until that version is audited.

wtf :D
Post reply on HN