8 ms·
Hi I'm Henry, the creator of Felony I’ve had a passion for politics, history, and programming since the age of 12 growing up in a suburb of Chicago. During my
by henryboldi 10y ago
Hi I'm Henry, the creator of Felony
I’ve had a passion for politics, history, and programming since the age of 12 growing up in a suburb of Chicago. During my freshman year, I developed an interest in software. A couple of apps and hackathons (programming competitions) later, I was working on my own startups when I made the leap to drop out of high school to become a software engineer at a venture-backed tech startup.
While working there I learned that PGP encryption was the tool used by Edward Snowden to securely send messages to journalists. The immense value of encryption as a core component of our free society became clear to me. Amongst fellow coders, I had no trouble using command-line encryption to communicate. But my friends who didn’t code couldn’t easily do the same since they don’t know how to use the command-line. Given how important encryption is, I decided to build a first-rate encryption tool that could be used by anyone on any website, regardless of background.
- brightball 10y agoReally love the name on a lot of levels. Do y'all get a laugh every time you do a git commit?
- henryboldi 10y ago.... maybe )))
- icebraining 10y agoHi! The app looks great. Can you speak a bit more about the interaction? How would two people who just downloaded Felony send an encrypted message to each other?
- henryboldi 10y agoHere's how it works... 1. Add public keys to your buddies list— A public key is like a username - Adding someone’s public key to your buddies list lets you send them messages. You can find other public keys on markets like keybase.io and darknet. 2. Encrypt a message— Select a recipient from your buddies list and compose a message. Only your chosen recipient(s) can read the message. Encrypted messages might contain sensitive information, such as an address, document, or anything intended to be read only by intended recipients. 3. Send the encrypted message anywhere— You can send the encrypted message on any website! For example, facebook messenger, twitter direct message, or youtube. Felony is security when and where you want it.
- deleted 10y ago[deleted]
- cyphar 10y ago1. Why did you choose PGP, when we have OTR and Axolotl -- which are specifically designed for informal communication where repudiation (recipient Y not being able to prove to others that X sent the original message) matters. 2. How are the public keys securely distributed? You say that "a public key is like a username", but without a central authority you hit a lot of issues (essentially the CAP tradeoff, but for user IDs). And with a central authority, you have no trustworthiness. Or are the users just meant to find public keys themselves (in which case you're back to the current state of affairs). 3. The name choice is stupid. Why on earth would anyone sane in this political climate call an encryption program "Felony"?
- brightball 10y agoAs for #3 I would think that it makes fun of the idea that encryption is somehow a crime. That's how I read it at least.
- cyphar 10y agoI get the joke, it's just not funny. And literally nobody outside of our community would get the joke.
- cdnsteve 10y agoThis looks like an interesting project but has a poor name choice. If it's targeted at non technical users, it may actually prevent them from using it, out of fear that just using it is illegal.
- mrmondo 10y agoYeah was thinking this too, as a techie I like it, but to the general user or business it screams IM DOING SOMETHING ILLEGAL! Question: what's the memory usage like A) at idle, B) after some using and left running for a day or two?
- henryboldi 10y agoIt's not targeted at entirely non technical users. That's why it's on Hacker News ;)
- menzoic 10y ago"Felony is the first PGP app that's easy for anyone to use" How about calling it "Freedom"
- henryboldi 10y agoWow, I like this a lot!
- saidajigumi 10y agoI agree that Freedom is a nice choice, but "Freedom" is already in use by a somewhat well-known website/social media blocker (as in "freedom from all those distractions"): https://freedom.to/ https://freedom.to/ Still, other suggestions are coming up in this thread that may be of use. I really like the idea of a name that, for a non-technical user, cab be a lead in to answering "why do I want this app? what does it do for me?"
- x1798DE 10y agoI would consider naming it something other than a common English phrase, honestly. I know it's the big trend these days, but it's making things incredibly hard to search for. Try searching for the messaging service "matrix" and the matrix client "vector". Insane amount of namespace collision there. Best to go with something like Freechain or something so at least people can search for it.
- yoklov 10y agoYou dropped out of high school your freshman year? i mean you seem smart enough to get by but uh, wow. (fwiw i say this as a college dropout who doesnt regret it at all)
- henryboldi 10y agoafter sophomore year. yay dropouts!
- menzoic 10y agodropouts ftw!
- henryboldi 10y agoyee!
- elliottcarlson 10y agoI dropped out after my sophomore year - I had recently moved to the States from Europe, and school was teaching things that I had learned already been taught a few years prior to that. I was completely bored and decided I was done with school. Getting my GED was really easy, and from there I have had a great career - while it may have hurt me in the beginning, I now have 20 years of relevant work experience behind me, it's generally not a concern to myself or any of my past employers - and if I were to interview somewhere that took issue with it, it's probably not somewhere I would want to work.
- superobserver 10y agoSchools are a way for parents to send their kids to a reliable daycare service. At a certain level, some don't really learn anything there. I did as much as I did (college) to pass among the clueless as normal but wish I had more opportunities to avoid it altogether. I recall even Snowden dropped out of high school.
- 746F7475 10y agoWhy are all dropouts who "made it" making such a big deal out of it.
- Mithaldu 10y agoWill this thing ever use less than 130MB of RAM? If so, how do you plan to do that?
- everfree 10y agoJust curious: Are you running on a Raspberry Pi or other machine with constrained resources? 130MB is less than 4% of the memory in most modern computers, and less than 10% of most mid-range phones.
- Mithaldu 10y agoJust to be nice i'll assume you ask earnestly and answer earnestly: I have 16 GB of RAM. However i also always have more than one app running at any given time. In fact, my system usually has 200+ things running. I also don't mind if things use a lot of memory if: They either use it to give me a lot of bang for my buck, or are not long-running processes. Felony ticks neither of these boxes. Also do keep in mind that the 130MB number is right after start without even logging in or using it at all. Due to memory usage by actual feature usage, and creep due to leaks, i can expect that number to easily double and more.
- JimmyAustin 10y agoI'm not sure that the doubling guess is going to be accurate. The majority of that 130MB is going to be in the overhead of keeping a seperate copy of Chromium in memory, not in the implementation of current features.
- LnxPrgr3 10y agoMy experience with Web browsers is they expand to fill all available memory and then some. This Firefox process has grown more than 50% since launch, and will stay mostly that big even if I close all but one new tab. Chrome does a better job of containing the damage to individual tabs, but I'm not how much that really helps with something like this. And of course, eventually I still end up killing Chrome periodically to get RAM back for real work, like running VMs without the host thrashing.
- SNvD7vEJ 10y agoPlease change the name of the app. I'm Swedish, and to me the name sounds really repelling. Maybe someone could fork the application and rename it to something cool that I can use?
- krisdol 10y agoYou seriously can't do this yourself? Clone the repo and change the name using find-and-replace and run install. No need to insult.
- unimpressive 10y agoThat won't mitigate the PR damage involved. A fork would need to actually just plain outcompete the original app.
- SNvD7vEJ 10y agoSorry, did not mean to insult. Just stating how I interpreted the name. There seems to be a number of forks already (currently 12).
- iso-8859-1 10y agoMany people will fork just to keep a backup.
- mathiasrw 10y agoWhat do you think the app should be named?
- SNvD7vEJ 10y agoHow about "PGPal"?
- deleted 10y ago[deleted]
- givinguflac 10y agoMight I suggest "FreedomKeyper" as an alternate name? Great project!
- conorpp 10y agoHave you heard of or used signal? https://whispersystems.org/ https://whispersystems.org/ Same idea -- strong crypto that's usable for anyone. It uses the OTR Ratchet protocol which uses perfect forward secrecy. The app also provides a way to verify keys through an OOB channel. I would recommend considering OTR Ratchet integration just like WhatsApp did recently. PGP is not a good design choice for a messaging app as you're always using asymmetric crypto operations which are computationally intense -- not terrible on modern computers but will be dreadful on mobile devices. Also can you provide some more documentation on how the app leverages PGP? Hopefully conversation is not using the same private keys to encrypt. That is vulnerable to data or side channel leakage. The modern approach is to generate and exchange an ephemeral key. Also please provide information on key storage. Rather than making vague security claims like "first-rate" and " Security++ to the greatest extreme" you should rather provide a threat model and explain why one can remain confidential and have authenticity against particular types of adversaries. No security tool is perfect and it's only a matter of time before an adversary breaks it. Developers are doing a disservice by claiming anything more. Before you can claim a first-rate security tool you will need to face a lot of scrutiny first.
- iancarroll 10y agoPGP is a great choice when you want to be able to send encrypted messages over any channel you want. It sounds like you do not understand how PGP works -- you exchange public keys over a trusted medium and then use public key cryptography to encrypt the AES key used to encrypt the rest of the message. The OpenPGP library it uses has been audited (twice). Most of the mistakes that could have be made are avoided this way. Edit: Yes, you lose PFS by using PGP, but it would not really be possible to negotiate PFS via, say, email.
- asimjalis 10y agoNice. How do you encrypt something? I see Add Key, Verify, Sign, Decrypt as options. I don’t see Encrypt.
- asimjalis 10y agoOk. I get it. You need to add someone else’s key before you can encrypt. It would be nice if I could encrypt messages to myself.
- datashovel 10y agoSo many comments about the name. All of a sudden I have a strange urge to see the next big open source project name themselves fjoi43isoitoei. Because names of technology projects only have as much importance as the reader attributes to them. If you can't see beyond that, and if your primary focus is what others might think of you because of what you named your project, I don't know what to say to you.
- 746F7475 10y agoDid you really have a passion for politics at age 12? This coupled with "I had no trouble using command-line encryption to communicate." makes this read like a farce. First you act like ultimate prodigy that peaked at tender age of 12 and then go boast with mad skills of running a cli command.
- DyslexicAtheist 10y agoIs it geared to mobile devices? The screenshot looks very much like one from a mobile. I wouldn't trust my phones underlying security architecture enough to store a PGP private key on the device. PS: I love the name. You did a good job with it creating a buzz. It made me laugh and curious enough to take a look. Maybe pointing out on your site that "privacy is a human right" and the name should remind us of that rather than succumbing to peer-pressure, in the hope of not offending the 0.01% of your non-tech savvy users.