4 ms·
Don't forget Ricochet†, it only does synchronous communication but it does solve the problem of leaking meta-data. All the other clients except Pond leak meta-d
by slasaus 11y ago
Don't forget Ricochet†, it only does synchronous communication but it does solve the problem of leaking meta-data. All the other clients except Pond leak meta-data.
† https://ricochet.im/ https://ricochet.im/
- tptacek 11y agoRicochet appears to rely on Tor's encryption, with an additional custom RSA handshake. That's two added levels of "nope" for me, but other people might feel differently.
- slasaus 11y agoI can see that but I think the self authenticating nature of Tor Onion Services and therefore bypassing bgp, dns and CA weaknesses is worth something†. Maybe in the future when prop224†† is implemented the encryption will be more solid. † https://media.ccc.de/v/32c3-7322-tor_onion_services_more_useful_than_you_think https://media.ccc.de/v/32c3-7322-tor_onion_services_more_use... †† https://gitweb.torproject.org/user/asn/torspec.git/tree/proposals/224-rend-spec-ng.txt?h=prop224-fixes https://gitweb.torproject.org/user/asn/torspec.git/tree/prop...
- tptacek 11y agoStipulate that Tor's encryption is modernized and drastically improved. I still don't think it's a good idea to build a messaging application directly on top of that, for some of the same reasons that it isn't a good idea to simply run a messaging application on top of TLS or Nacl. The service model and security requirements for a simple transport are different from those of a messenger. That's what's so exciting about the WhatsApp announcement. WhatsApp is by all accounts a pretty great messaging application, and it doesn't just have decent encryption now; it has best in class encryption specifically designed to protect a messaging application, designed by experts who thought about this problem for a long time.
- slasaus 11y ago(I've updated the parent about bypassing bgp/dns etc. before I saw your reply) The nice thing about using the onion address (transport layer) is that you have mandatory e2e authentication with only one id that solves multiple real world problems with bgp/dns/tls. How would you propose to go further from current state-of-the-art WhatsApp to stop leaking meta-data? I know Ricochet is open to use a stronger encryption layer on top of Tor †. † https://github.com/ricochet-im/ricochet/issues/72 https://github.com/ricochet-im/ricochet/issues/72