8 ms·
If the setup screen stays the way it is, this is probably never going to take off. The fact that it's officially coming from Tor devs is important and I'm sure
by dombili 11y ago
If the setup screen stays the way it is, this is probably never going to take off. The fact that it's officially coming from Tor devs is important and I'm sure people who already use Tor can use this app relatively easily, but if the point is to get more people to use secure and private messaging apps, asking people to enter their xmpp credentials isn't the way to go. Additionally, adding GTalk, Facebook Chat etc. into the mix is only going to confuse people because they'll assume they're secure just by using this app. But in order to have a secure and private conversation you need people on both ends of the conversation to use a client that supports OTR.
They mentioned Pond and Ricochet in that post and I'm a big fan of both but especially Ricochet. It has no setup, no configuration. Just share your address and talk. That's the way it should be. But it's only available on desktops. These days most people connect to the internet only by using their smartphones and if you only support desktop computers (even if you're x-platform) you're missing out on a lot of people already. The perfect solution would be Signal's encryption combined with Telegram's availability, but unfortunately we're not there yet.
I'll keep my eye on this project and I really do hope it takes off but as of right now, it's not that different from any other secure messaging app you can find on the internet that only tech savvy people can use.
- Perceptes 11y agoAs soon as Signal has native clients for OS X, Windows, and Linux, it's game over. I will use Signal exclusively for chatting everywhere.
- simoncion 11y agoWhat is the deal with the year+ it has taken to get this done? I'm sure that the WhatsApp thing took a large amount of effort, but that was over 6+ months ago, right? Is Twitter demanding too much of the Whisper Systems folks' time on other projects?
- khed 11y agoI am a huge fan of signal but it will never be the end game. Society needs communications that hide both content AND metadata. Signal only really hides content. The only programs I am aware of that do both all have significant limitations in other areas and none have gone through rigorous peer review. i2p-bote has mobile and desktop applications, can use possible post quantum secure encryption, it's asynchronous and real time, capable of multi party communication, and has optional delays between hops making it global passive adversary secure. Unfortunately it doesn't work well because many messages don't actually make it through. You can't send files greater than 500kb. Also it is not peer reviewed. Bitmessage has multiparty communication and is asynchronous but has a terrible user interface, is hard to setup, no mobile application, no attachments, no peer review. Ricochet works well and is easy to use but no attachments, it can't be asynchronous, no multiparty communication, and no peer review. Haven't played with pond. It looks promising. My wish list for the ultimate messenger: easy to use, secure by default, hides content and metadata, is multi party, can share arbitrarily large files, is both instantaneous and asynchronous, can be global passive adversary secure, is quantum computer secure, truly multi platform, and supports being signed in on multiple devices at once.
- newjersey 11y agoI'm sorry to derail the conversation with my lack of technical understanding but how do we protect metadata? If we have two devices (say Alice's phone and Bob's phone) that are sending messages to each other, how do we make sure nobody knows who is talking to whom? The answer seems non-trivial to me. Could we use Alice's and Bob's public keys to encrypt the message and then send them to the entire network, relying on the security of the encryption (and acknowledging that a third part can read all messages any way)? Is there a way to look at a public key and an encrypted message and say that yes, this message was encrypted with this key? It seems that we'd be paying through the nose in terms of throughput capacity (and processing capacity as everyone would have to take in everyone else's packets) if we wanted to maintain metadata privacy this way. I'm sure this is not what you had in mind. Can you please elaborate on how we can secure metadata?
- williamcotton 11y ago
- dombili 11y agoThat's my hope as well, but do they even plan on doing that? I know they're working on bringing TextSecure to Chrome as an extension, but that seems to be it. I also agree with khed. Signal needs to hide metadata.
- Perceptes 11y agoHmm, what I was thinking of as the in-progress desktop client is just a Chrome extension: https://github.com/WhisperSystems/TextSecure-Browser https://github.com/WhisperSystems/TextSecure-Browser. I hope there's more to come. :\
- simoncion 11y agoEh. That's not so bad. From my very limited experience, it seems that the extension would put you 90% of the way to a working Node.js program, which you could then slap behind any frontend you cared to create. A very brief perusal of the repo didn't turn up any protocol docs, but seem to have been rather thorough about that sort of thing in the past, so I would suspect that the changes to the TS and RedPhone protocol would be fully documented, so you could integrate it with libpurple or whatever.
- middleclick 11y ago> But in order to have a secure and private conversation you need people on both ends of the conversation to use a client that supports OTR. Tor Messenger doesn't allow you to talk with someone else, unless they have OTR. So it's encryption always, by default. I agree with the mobile part though. We need something that works on both the places. Check out http://conversations.im/omemo/ http://conversations.im/omemo/.
- deleted 11y ago[deleted]