10 ms·
Not for people who don't want Google on their device. He only wants distribution via Google, and even went as far to demand that free/libre Play-alternative F-
by blablablaat 10y ago
Not for people who don't want Google on their device.
He only wants distribution via Google, and even went as far to demand that free/libre Play-alternative F-droid removed their build of TextSecure.
See: https://fdroid.eutopia.cz/ https://fdroid.eutopia.cz/
- AtticHacker 10y agoHuge deal breaker for me, regrettably.
- lisper 10y agoYou might want to try this then: https://github.com/Spark-Innovations/SC4 https://github.com/Spark-Innovations/SC4
- feklar 10y agoExperiment with a reversed play services framework http://forum.xda-developers.com/android/apps-games/app-microg-gmscore-floss-play-services-t3217616 http://forum.xda-developers.com/android/apps-games/app-micro...
- AtticHacker 10y agoI'm not familiar with this but it looks like an interesting project. My problem however is that I mainly do not like that GPL'd software isn't allowed to be redistributed. I might not be properly informed on this issue (and please correct me if I'm wrong) but from what I've read that seems to be the case.
- simoncion 10y ago> I might not be properly informed on this issue. You're not. Here's an okay starting point into the discussion: https://github.com/WhisperSystems/Signal-Android/issues/282 https://github.com/WhisperSystems/Signal-Android/issues/282 Another thing to remember is that (IIRC) -for approximately forever- Red Hat Enterprise Linux has been a Linux distro that's composed almost entirely of Open Source software, but prohibits folks who receive the binaries from redistributing them.
- Natanael_L 10y agoIt's the branding that allows Red Hat to effectively restrict distribution of binaries, due to trademarks. Since the source is still available, GPL is fulfilled.
- simoncion 10y ago+1 My memory of the mechanism was a little different but the trademark component is obviously a part. Something in the EULA like "If you distribute RHEL binaries without our consent, we'll cut off your access to security updates and patches ASAP.". Regardless, people seem to forget (or perhaps never bothered to learn in the first place?) that the GPL doesn't care to speak to binary distribution, just source code (and -sometimes- build instructions) distribution.
- jalami 10y agoYeah me too, I'm using Conversations[0] on Android and it's pretty awesome actually. Pretty actively developed with a smooth UI and no Play services or phone number requirement. Running a really light prosody[1] instance on my server to host my own XMPP connection, although since it's all E2E, I could have used a public one. [0] https://f-droid.org/repository/browse/?fdid=eu.siacs.conversations https://f-droid.org/repository/browse/?fdid=eu.siacs.convers... [1] https://prosody.im/ https://prosody.im/
- NoGravitas 10y agoI've run this, and I also found it easy to set up and use. However, my understanding is that you only get end-to-end encryption with OTR, and that OTR can only be used with both parties online at the same time. Am I mistaken about this?
- jalami 10y agoI think offline encryption works fine if your XMPP server implementes XEP-0198[0]. Prosody doesn't out of the box, but there's a community plugin available[1] for it. The plugins are really easy to install if you're running prosody already, if you're not then ask your XMPP name host. Stream management requires client and server to support this, which Conversations does so I'd assume your server is lacking. If you're in an OTR converation already, I think the server would just get encrypted garbage, hold it until the other party comes on the network and then pass it off and their client would decrypt it. I haven't read the protocol though TBH. [0] https://xmpp.org/extensions/xep-0198.html https://xmpp.org/extensions/xep-0198.html [1] https://modules.prosody.im/mod_smacks.html https://modules.prosody.im/mod_smacks.html
- NoGravitas 10y agoThanks. I'll have to try this.
- jalami 10y agoJust some more information if anyone else is curious. I have this setup and it works well enough when you have one device, but when you have multiple, I get garbage on one device and decrypted messages on the other. So if I keep my computer on, but switch to my phone I have to explicitly tell the sender to send messages to my phone instance instead of my computer instance, otherwise I get garbage. This is obviously because of e2e. It doesn't seem like there's an easy way to enable OTR multi-end e2e encryption/decryption sofar as I know. OMEMO[0] does this though, conversations supports it and Gajim has a plugin for it[1]. It's experimental and the plugin author warns to not use it for sensitive information FYI. Haven't tried it out as I'm using Pidgin atm, but plan to sometime soon. [0] https://conversations.im/omemo/ https://conversations.im/omemo/ [1] https://github.com/omemo/gajim-omemo https://github.com/omemo/gajim-omemo
- Joeboy 10y agoWhat are you going to use instead? Who are you going to talk to with it?
- AtticHacker 10y agoCurrently I'm using Telegram with secret chat to talk to my friends and family.
- dbalan 10y agoHere is moxie's reply in that matter https://news.ycombinator.com/item?id=10665520 https://news.ycombinator.com/item?id=10665520
- uola 10y agoI don't buy his arguments. It's one thing to say we have to be on Google Play Store or we have to use phone numbers despite the privacy implications because that is what people use. But ignoring much of the developing countries (see whatsapp), China or the people who are your strongest user base by saying "you can just" isn't pragmatic at all. Nor is it actually reasonable that we should expect to or rely on a few people to secure something that should be a fundamental and a fundamental right of communication. Not to rant to much, but it feels like going to parties (conferences) and talking about how much good you do and then being dismissive in the real world is how much of the security industry operates and that Signal has just become the latest excuse to why nothing has to be fixed. I'll give him credit for the whatsapp integration though. More people in the field should consider working with companies where they can have a lot of impact.
- neerdowell 10y ago> But ignoring much of the developing countries (see whatsapp), China Moxie says Signal works fine in China: https://github.com/LibreSignal/LibreSignal/issues/37#issuecomment-217673506 https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
- uola 10y agoSignal itself works, but since Google is blocked no phones are sold with Google Play Store and even if you hack it onto your phone (which will break when it wants to update play services) it will drain your battery trying to connect to blocked services. Unless you use vpn (which will drain battery by itself and also eventually be blocked), but notifications probably still won't work because of the phones original firmware. So yes it works if you hack it onto your phone and then remove play services and checks the application manually. Until it wants to update the app that is, which is often. Point. It doesn't really work because it only supports the Google Play Store, even as most Chinese phones can load apps directly (because of the fragmented ecosystem). So at least it doesn't work in the "prevent mass surveillance" way. I guess maybe it works from the Apple App Store? (which isn't blocked)
- simoncion 10y ago> He only wants distribution via Google... Untrue. He only wants distribution through channels that provide the same security assurances and deployment features that Google does through the Play Store. [0][1][2] He's also quite open to replacing use of GCM with WebSockets or some equivalent tech, but if you don't use GCM, the replacement is likely going to significantly reduce battery life of phones on cell networks. [3][4] > ...and even went as far to demand that free/libre Play-alternative F-droid removed their build of TextSecure. That's because -in part- the F-droid project managers had (and -AFAIK, but I haven't checked in quite some time- continues to have) very serious issues in regards to their APK signing key handling procedures. Signal is GPL'd. Anyone can take the code and do what they like with it, as long as it conforms with the license terms. However, it's very clear that Whisper Systems does not want people distributing Signal-branded builds on app distribution platforms that don't provide Whisper Systems the security guarantees and management tools that they need to get their jobs done. In short, you're free to distribute custom builds of the Signal-Android, Signal-Desktop, TextSecure-Server, and Signal-iOS projects. However, it'd be nice of you to: * Stand up an instance of the Signal server software on hardware you control, then point your builds of the Signal client software to your server. * Rename the software that you're redistributing, make up your own logo, and make it abundantly clear that -while your work is based entirely on Signal's code- you're neither operating with the explicit support of Open Whisper Systems nor are you likely to be providing the same security guarantees that they are. [0] https://github.com/WhisperSystems/Signal-Android/issues/127#issuecomment-13335689 https://github.com/WhisperSystems/Signal-Android/issues/127#... [1] https://github.com/WhisperSystems/Signal-Android/issues/281#issuecomment-21762482 https://github.com/WhisperSystems/Signal-Android/issues/281#... [2] https://github.com/WhisperSystems/Signal-Android/issues/127#issuecomment-13339504 https://github.com/WhisperSystems/Signal-Android/issues/127#... [3] https://github.com/WhisperSystems/Signal-Android/issues/1000#issuecomment-45943940 https://github.com/WhisperSystems/Signal-Android/issues/1000... [4] (see the reply to) https://github.com/WhisperSystems/Signal-Android/issues/127#issuecomment-36169360 https://github.com/WhisperSystems/Signal-Android/issues/127#...
- tombrossman 10y agoThese are some good points but when you say "He only wants distribution through channels that provide the same security assurances and deployment features that Google does through the Play Store." it must be noted that this isn't a guarantee of security. A quick search of 'Google Play malware' returns many results from 2016 and going back to when it was still called Android Market. This isn't hand-waving, there are many concrete and specific examples of security lapses in the Google Play store and this is a persistent problem. Plenty of bright people over there who care and are working on it I'm sure, but not solved yet. Bottom line is it's his decision to make, but the only certainty that using Google's store brings is that you must have a first-party relationship with Google to use his app. It's better than downloading APKs from some warez site but not a guarantee of security. Framing it this way misses the bigger picture.
- mikekchar 10y agoI think we're missing some information here. The supplied link says that the applications have been renamed due to legal threats. This seems completely reasonable to me. The names of the apps are trademarks and for a security product, who builds it is important to the integrity of the mark. I'm trying to remember how Android works, but I seem to recall that you need to sign the packages differently on Play and Fdroid. So you literally can't redistribute the same Play package with Fdroid (someone correct me if I'm wrong). This means rebuilding... and hence rebranding. It seems that MM was asked to provide a build for Fdroid. He decided not to. That's completely his right. He doesn't go into a lot of detail about why he has decided this, but it's completely up to him. So all I can tell is that there is an Fdroid version, which has a different name. You can't switch easily between the Play and Fdroid versions because of code suckage... which sucks, but isn't a GPL violation. Is this just a tempest in a teapot, or am I missing something?
- kuschku 10y ago> I'm trying to remember how Android works, but I seem to recall that you need to sign the packages differently on Play and Fdroid. So you literally can't redistribute the same Play package with Fdroid (someone correct me if I'm wrong). This means rebuilding... and hence rebranding. You can distribute the same build on F-Droid and Play, and also signed with your own key, if you use proper reproducible builds (And not the TextSecure variant of "let’s download this huge image and let it compile the app", because that opens you to evil compiler issues).
- neerdowell 10y ago> He decided not to. That's completely his right. He doesn't go into a lot of detail about why he has decided this, but it's completely up to him. He doesn't like how F-Droid uses centralized signing keys which are stored online: https://github.com/WhisperSystems/Signal-Android/issues/127#issuecomment-13339504 https://github.com/WhisperSystems/Signal-Android/issues/127#...
- mikekchar 10y agoThanks for that link. It is much more informative than the other one. I can see where he's coming from. Some of the things he wants as a developer are things that I don't personally want as a user (automated updates), but then I can build and install the thing myself, as he says.
- knevik 10y agoMoxie recently posted more of his thoughts on the subject: https://news.ycombinator.com/item?id=11672892 https://news.ycombinator.com/item?id=11672892
- sspiff 10y agoThis also blocks me from using TextSecure/Signal, because they require Google Play Services at run-time. I'm using a BlackBerry OS 10 device, which can run Android apps, and I even have Google Play running on it, but Google Play Services is stubbed for a large part on BB10, making some apps (such as Google Maps, Google Calendar, and Signal) impossible to use. Why a security/privacy oriented application such as signals wants to bind so strongly with Google's services, I don't understand.
- pureIDEOLOGY 10y agoThey want more users. Google actually makes special deals with carriers to optimize GCM, so it's best for battery life. It depends on your carrier, but the websockets fork LibreSignal can use up to 5x the battery life. On my phone using the fork bumps battery usage from 1-2% to 2-4% (Sprint), but is totally worth it to avoid Pentagon/Alphabet (I mean Google).
- pureIDEOLOGY 10y agoHe can only demand that they don't make builds using the same name or logo. That's his right. Who cares? Stop whining like we're supposed to care that you have to change the name of a piece of free software before you can distribute it.