10 ms·
TOX – A New Kind of Instant Messaging
- nvk 10y agoThe new version is out, seems to be getting much better. https://github.com/uTox/uTox/releases https://github.com/uTox/uTox/releases
- okket 10y agoFYI: https://en.wikipedia.org/wiki/Tox_(protocol) https://en.wikipedia.org/wiki/Tox_(protocol)
- zerognowl 10y agoIt seems robust, but I do worry about the client. Has the client been audited properly? I hope the track record's not like Pidgin's https://pidgin.im/news/security/ https://pidgin.im/news/security/
- iphy 10y agoqTox is currently undergoing major rewrites, so I'm not getting myself involved with that. Once the rewrites are done, I can see about reviewing it. Just like with toxcore, if I started reviewing it now, I'd come up with lots of trivial issues that need resolving before I can do a serious audit.
- ivcha 10y agoThat's too bad, pidgin is the only client I want to use, regardless of the protocol...
- zhovner 10y agoStill no contacts sync?
- klaupi 10y agoPut your profile in your Dropbox/Seafile/Whatever Sync Folder and use it with all your clients.
- ninesigns 10y agoI did this once and ended up with corrupted profile.
- nvk 10y agoIt's open source, they take pull requests and donations.
- commentzorro 10y agoWhat makes you think that parent has the knowledge, ability, and time to do this task? I see this "it's open source, make pull request" type of comment quite a lot but don't understand how you'd know if the person you're saying it to could do it. If not, it's kind of a dick move, isn't it?
- nvk 10y agoThe way the feature was requested, come across as a dick move and very self entitled. The least the parent could have done is added some niceties or some reasoning in more than 4 words when asking something for free.
- commentzorro 10y agoI know, people make the "I'd use it but for this feature" comment all the time. But I believe they do it without thinking rather than with the intent of being unkind. The "... pull request" is almost certainly knowingly mean spirited. (Even if true.) Edit: here's a possibly better response than the "do it yourself" response: XXX is a free and open source project. That means the developers put in the majority of their time on the issues that they want and enjoy coding the most, even if other good features are left out. If you're unable to help out with coding yourself, you could look through the open and closed issues and see of others have thought about your feature request too. If an open issue exists, a short "while I don't have the ability to code this, I'd like this feature too," added to the list would let the developers gauge interest and may sway someone into giving it a try. Thanks. Edit 2: It's a bit long. This sentiment but shorter.
- geocar 10y ago> What makes you think that parent has the knowledge, ability, and time to do this task? Okay, what about money? They also take donations. > I see this "it's open source, make pull request" type of comment quite a lot but don't understand how you'd know if the person you're saying it to could do it. If not, it's kind of a dick move, isn't it? No. Trying to make people feel bad for not wanting to work for free, is what I call a dick move.
- iphy 10y agoThis is a much wanted feature, and I have long term plans to solve this issue together with a lot of other issues using a distributed data store (file system, database, whatever you want to call it). See https://toktok.github.io/roadmap#distributed-file-system https://toktok.github.io/roadmap#distributed-file-system (milestone 9). More realistically, i.e. in the nearer future, milestone 4 (https://toktok.github.io/roadmap#optimisations-for-mobile https://toktok.github.io/roadmap#optimisations-for-mobile) covers a simple multi-device feature. GrayHatter has implemented a prototype and will deliver a design document for the full implementation likely by the end of Q4. It includes profile and contact sync as well as message history sync. If we follow the intended timeline, that feature would likely land somewhere in 2017Q1. uTox and qTox have preliminary support for the prototype. You and everybody else are invited to review the proposal when it comes out. Be sure to follow the issues on https://github.com/TokTok/c-toxcore/issues https://github.com/TokTok/c-toxcore/issues. You are also invited to join #toktok on Freenode to bounce ideas around. Offline messaging will be partially solved by message log sync, as mentioned in milestone 4. The idea is that if you have a desktop computer at home, you could sync the message from your phone to it, and the desktop computer will deliver the message to your friend when they come online. It could be that your desktop syncs with their desktop at some point, and later their desktop syncs with their phone which is the actual delivery. In any case, this solution requires at least one of your and their devices to be online at one point. So far, we have shied away from storing large amounts of data in the network itself. I think the described solutions are sufficient for a large group of users. Federated (email-like) server-based (still distributed, just not p2p) solutions could be used for the remainder.
- msh 10y agoStrange choice of screenshot.
- eps 10y agoWoah, indeed. http://i.imgur.com/3MdrSQi.png http://i.imgur.com/3MdrSQi.png
- Jaruzel 10y agoPlease forgive my ignorance, but it talks a lot about peer-to-peer conversations - how would that work if the peers are behind NATs or Proxies?
- dijit 10y agoProbably leveraging STUN servers https://en.wikipedia.org/wiki/STUN https://en.wikipedia.org/wiki/STUN
- iphy 10y agoThat works with UDP hole punching (https://en.wikipedia.org/wiki/UDP_hole_punching https://en.wikipedia.org/wiki/UDP_hole_punching), and there is a branch with uPNP (https://en.wikipedia.org/wiki/Universal_Plug_and_Play https://en.wikipedia.org/wiki/Universal_Plug_and_Play) support. We still need to review that code carefully before accepting it into master.
- tombert 10y agoI'm reasonably sure it does a UDP hole punch to do it.
- sgreen 10y agoWhat makes this better than Signal for texting?
- snowpanda 10y agoSignal still relies on Google Play Services, which is an issue for many people (see GitHub issue #127, #1000, #1106, #5450 etc....)
- Sir_Substance 10y agoI was mad disappointed by signal. Not only does it require google play services, it also asks for about two dozen privileges on your phone. Not a great look for a privacy oriented app.
- kuschku 10y agoMoxie doesn’t consider that kind of privacy important. Governments listening to you is irrelevant, and third party clients are something he actively tries to prohibit. His position is that it’s better if everyone gets a little safety, than if a few people get full safety.
- Freak_NL 10y ago> and third party clients are something he actively tries to prohibit. It's a solution that probably makes sense if you try to solve the problem from within the gilded cages of Google/Facebook/Apple, but it is a kind of exclusionary thinking that to me goes against the spirit of open standards and user freedom on the internet.
- Insanity 10y ago"that kind of privacy". So which 'kind' of privacy does it try to improve on? I've been thinking of switching to a different application for messaging and Signal came by a few times but I don't know a lot about it. Would you care to elaborate?
- gregn610 10y agofrom the FAQ: "How do I add someone to my contacts list? Look in the profile or settings panel of your client to get your Tox ID which should look something like: 56A1ADE4B65B86BCD51CC73E2CD4E542179F47959FE3E0E21B4B0ACDADE51855D34D34D37CB5" Yuk! I see this flaw so many products like this, just about anything p2p, blockchain addresses, commit ids, etc. I think there is zero chance of getting anyone who is not technology elite to adopt a product with UX that rotates around these untypeable/unpronounceable/immemorable identifiers. Why aren't Identicons(https://en.wikipedia.org/wiki/Identicon https://en.wikipedia.org/wiki/Identicon) or QR codes used more?
- Spydar007 10y agoToxMe[1] seems to attempt to solve this issue by creating a public databases of emails and Tox IDs, though this defeats the object of the service being anonymous. [1] https://toxme.io/ https://toxme.io/
- Freak_NL 10y agoIt's good that it is a choice you have though.
- pantalaimon 10y ago> Why aren't Identicons or QR codes used more? Nothing stops you from turning that hash into a QR code (afaik Antox does) - but then how do you copy & paste it?
- Dowwie 10y agoI tried an earlier version of a tox client. At that time, there were at least two competing clients that looked the same and did the same things. Is the tox civil war over yet?
- MerreM 10y agoLooks like no, there's uTox and Toxic - can't get Toxic to run.... so maybe?
- dysfunctor 10y agoBut you realize that's like saying "Well, I tried IRC but there are dozens of competing clients that all do the same thing." The Tox protocol is really the core tool. As long as the protocol is well-defined and maintained, I think developers should be free to make whichever clients that they want. I used tox ages ago, and I used the Blight client or whatever it was called, and I liked it pretty well. I think a bigger issue is convincing people to use it in small groups. My whole team is just fine using Mattermost/Hipchat/IRC and the majority of them don't see the need for something like this.
- Dowwie 10y agoIn this case, it's not like saying anything about IRC chat clients or Hipchat or whatever your team uses or develops. The clients really did look and behave the same. There was so much overlap between them. Not exaggerating this point.
- cakes 10y agoI had a similar experience and it seemed like they were both being developed by the same core group(s) dividing their time between both (again, my perception) which was confusing as they were very similar.
- teaearlgraycold 10y agoI think it'd be nice if the tox.chat domain would link to just one tox client implementation in the downloads section.
- eeZah7Ux 10y agoBe warned, Tox claims to protect users from "governments", which is a huge claim. Yet, it's written in C, it hasn't had a security audit, it does not publish a list of security risks and mitigations, and, regarding its roots in 4chan, see for yourself: https://github.com/irungentoo/toxcore/issues/1186 https://github.com/irungentoo/toxcore/issues/1186
- qwertyuiop924 10y agoList of security risks and Tox-ic (BDUM-KSSH) community are worrying, as is the lack of security audits. As for the fact that it's written in C, GPG, Tor, Psyc, and many other pieces of security software that you trust are written in C. It's dangerous, but writing secure apps isn't impossible.
- eeZah7Ux 10y ago> It's dangerous My point exactly. It's dangerous and if it's not paired with many good security practices, it's better not to advertise it as "protect you from XYZ".
- iphy 10y agoWe're in the process of writing a specification (https://github.com/TokTok/spec https://github.com/TokTok/spec) and new implementation in Haskell (https://github.com/TokTok/hs-toxcore https://github.com/TokTok/hs-toxcore). There is also a Rust implementation in the works (https://github.com/zetok/tox https://github.com/zetok/tox). As for security risks and mitigations, I'd like to do that when we have a web presence with space for it. Right now, the web presence is fairly poor (http://toktok.github.io/ http://toktok.github.io/). The specification contains some security risks and mitigations.
- EvgeniyZh 10y agoRust seems reasonable, but why Haskell? Also why not improve current core while writing new implementation?
- zaggynl 10y agoDoes it still use 1GB of network traffic per day when idle?
- akerro 10y agoThat's by design to keep connections with other peers.
- Gruselbauer 10y agoSome kind of throttle would be a good idea, in that case. A gigabyte a day is unacceptable for some of us.
- veeti 10y agoThat is a fundamentally broken design. There is literally no excuse for a simple messenger app to suck up a gigabyte daily. How do you expect people to adopt this when they have broadband and wireless plans with data caps?
- taneliv 10y agoI know nothing about TOX design, but it makes (to me, at least) some privacy sense to saturate the network with noise that is in message length, their interarrival time and recipient characteristics similar to the actual communication. No idea if TOX does that.
- bluedino 10y agoAside from the data usage - that will suck the battery life from your devices as well
- zaggynl 10y agoTo get back on this, this might be only the Windows client, just had latest qTox idling on Linux overnight and network data usage is 1.3MB.
- lucaspiller 10y agoRight now I'm not really bothered about end-to-end encryption. If a government wants to track me, they will find a way. I'm more concerned about Facebook/Google/Microsoft/Apple tracking me, reading my private conversations, and selling my data to the highest bidder. I'd like an open source, decentralised messaging platform, that has good mobile apps. Are suggestions?
- zerognowl 10y ago> If a government wants to track me, they will find a way Things like OTR: https://en.wikipedia.org/wiki/Off-the-Record_Messaging https://en.wikipedia.org/wiki/Off-the-Record_Messaging Actually stops these people though, and is even labelled in some of the Snowden Files as being "Catastrophic" to their efforts. But you are right, if they can't get chat on you they can just target you inside the Internet and send a malware payload disguised as an update to your browser.
- nmgsd 10y agoFor high value targets yes, they can't really be safe but for avoiding mass surveillance it's good.
- mrbiber 10y agoriot.im [1] (which is based on matrix.org) seems a good, decentralized, open messaging app. They have relatively nice mobile apps and they promise to soon release end-to-end encryption based on the OLM [2] ratchet which is similar to the Signal encryption. In contrast to Tox, Matrix relies on federated servers. Tox is pure P2P which, in my experience, never works very well on mobile devices. [1] https://riot.im/ https://riot.im/ [2] https://matrix.org/docs/spec/olm.html https://matrix.org/docs/spec/olm.html
- fizzbatter 10y ago> Tox is pure P2P which, in my experience, never works very well on mobile devices. That's (UX) my biggest concern, honestly. UX is just too important, and it's becoming an increasingly fast moving bar. Simple things like hitting up arrow to edit your message, to more complex things like stickers and gifs, these are (unfortunately) requirements for me in my peer circles. They sound silly, i know, but Telegram has (mostly) a great UX, and for such an important tool i can't currently give up features.. let alone convince my friends to likewise give up features. (Fwiw, i love Matrix in design)
- mrmondo 10y agoI've been a private beta tester for an iOS client for Tox called 'Antidote', and I can speak for its quality. I will not pretend to be an encryption or security specialist of any form however.
- huhtenberg 10y agoPreviously - https://news.ycombinator.com/item?id=6121225 https://news.ycombinator.com/item?id=6121225
- poi519 10y agoSeems like XMPP is still a viable option.
- mxuribe 10y agoSo, what happens if I download the client on one of laptops/PCs (for example my work computer) use it to communicate with peers...And then i wish to setup the client on another laptop/PC (for example my home computer) to contact my same peer/friends...How does the overall network (I guess DHT?) know that "its me!" (the same "me"), and not a different/new peer? With a centralized system there was the concept of identity...but I just don't get how this would work here. I'll admit I'm not a networking guru here, and I'm absolutely in favor of decentralized communications ...so my question above is not at all to knock on Tox; its me really wanting to know how the above scenario would play out...because I often need to bounce between a few different computers. Anyone know how this would work? Side note: I am currently using matrix protocol via a synapse/matrix.org home server (using the chat client from https://riot.im/ https://riot.im/), so for any computer that I use/jump to, I'm represented by my home server (up in the cloud)...so that makes sense to me. I just don't get how jumping computers would work on Tox. Anyone know?
- bisby 10y agoThis has been the #1 reason that I havent convinced people to use tox yet. I sometimes get up and walk away from a computer mid conversation, expecting to continue the conversation on my phone. It's the same reason I won't be using google allo. I need conversations to "sync" across mobile and PC. I'm not going to sit at a desk all day chatting on my phone, and I'm not going to miss messages just because I went mobile. I saw somewhere in a previous tox chat, that a possible solution would be a way to pin identities together (i say from desktop "this mobile is me" and from mobile "this desktop is me" and when they match, allow them to pair). And then send every message encrypted to both peers. If you have 5 devices linked, tox would behind the scenes send the message to 5 different destinations. They havent done anything like this yet as far as I know.
- languagewars 10y ago> If you have 5 devices linked, tox would behind the scenes send the message to 5 different destinations. I dislike existing systems that implement this kind of model since it is too easy for a ghost device to be getting copies of everything. My phone transitioning to different UX clients with notifications/verifications of transitions on its own UX is better.
- setra 10y agoIt may surprise some to know that this started as a project of 4chan's /g/ board
- hd4 10y agoIt may surprise less of us than you think ;)
- realworldview 10y agoA new kind of more of the same oh no not another bloody chat client wait i'm going to write a wordpress clone.
- ninesigns 10y agoCould someone please write a summary on what has changed in Tox project over last year?
- nikolay 10y agoNew? It's anything, but new!