17 ms·
Briar Project
- askxnakjsn 6y agoNow that I think about it, why aren't most messaging apps peer to peer? Shouldn't that be the standard? I mean it's literally the point of messages: sending from one person to another.
- inglor 6y agoFor multiple reasons but first of all because it would require both devices to be connected and online. The common alternative to overcome this is to pass the messages through the server and encrypt/decrypt them on the device (aka e2e encryption). I acknowledge that might not be secure enough for certain use cases.
- raspyberr 6y agoP2P requires both clients to be running at the same time in order to communicate. If you friend's phone is off and you send a message, they won't get it when they turn their phone on.
- myself248 6y agoSeems to me like there should be a DHT way to solve this. When you boot up, you take your place in the table and query your neighbors for messages. If someone's unreachable when a message is sent, you hand the message to their neighbors to hold it until they appear.
- untog 6y agoWhich requires you to trust your neighbours. To which you might say: aha! Just use end to end encryption! And sure, you can. But at that point, what benefits are you getting over using E2E with a centralised system? Very few. And you’re getting a bunch of drawbacks in terms of reliability too.
- myself248 6y agoI dunno, a centralized server means a centralized off-switch, that's a pretty huge drawback in terms of reliability.
- afiori 6y agowhich is why centralized/peer-to-peer is a false dichotomy the solution to many of the problems of both of them is (forkable) federated networks
- maqp 6y agoE2EE only protects content. Metadata is also very important and where as p2p apps like Briar, Ricochet, Cwtch and TFC hide it from all, centralized and decentralized apps have one or more weak points that allow eavesdropping on larger amounts of metadata.
- userbinator 6y agoDepending on whether you expect IM to work like physical mail or a phone call, this may be the expected behaviour. It seems the majority here seem to be expecting the former, although I think of IM as more like the latter: if the recipient is not available, then the message is simply dropped, much like I can't call someone who is not answering the phone.
- crazygringo 6y agoBecause: a) Often the intended recipient isn't online when the message is sent, and it may happen that there is never a time when both sender and recipient are online simultaneously (e.g. sender's device only turns on to send the occasional message, receiver's device is usually off but turns on occasionally to check if there are messages) b) Often one or both devices can only connect to, but can't be connected to (because behind a NAT, a mobile device, firewall, etc.) c) Communication is often desired between accounts rather than devices -- I may want to send/receive on my work computer, home computer, phone, and watch
- IgorPartola 6y agoIn before someone suggests storing encrypted messages in a public blockchain. This is a really good overview of the challenges with these messaging systems. Store and forward has been our MO since email and Usenet were invented because always on always connected devices that aren’t restricted by some network obstacle are not really feasible or even desirable most of the time. I do wonder what alternatives we have to something like a trusted online service to store and forward messages or a public blockchain. Some kind of crypto based system where nobody but the owner of a private key can even locate the message? A decentralized system where multiple copies of multiple fragments of your message are stored so nobody can piece together your (encrypted) message without controlling the majority of the nodes?
- raspyberr 6y agoDo you have an opinion on Skype like centralised coordinator that then sets up P2P connections?
- IgorPartola 6y agoThis really isn’t my field, I am more of a full stack developer who mostly works on web apps with a heavy interest in networking. So definitely not an authority on the subject. I think that’s basically the sort of system that most places employ. It’s nice because it’s easy to set up but you really need to trust Skype. Say they actually try to use end to end encryption. How does that work? Well, you could say “I am Alice and I want to establish a connection to Bob. Here is my public key he can use to send me messages and I’d like his public key so I can send him his.” That of course would need to happen in addition to establishing a network connection. So no if Skype is a good actor they will pass my public key to Bob, get his and send it to me as well as coordinate us establishing a direct connection. But what if Skype is a bad actor? Well they could take my public key and send Bob one of their own. Then they could also send me their own. Now they can listen in on my conversation. They can also in a similar fashion make it seem like I’m connected directly to Bob’s networked device but really just relay the connection through their servers. Neither Bob nor I would have any way of knowing that without having exchanged public keys prior and having verified them. So this system is basically insecure against Skype wanting to listen to my conversations or being compelled to do so by a state actor.
- kyshoc 6y ago> why aren't most messaging apps peer to peer [...] it's literally the point of messages: sending from one person to another. Messaging apps are more like postal services — "please deliver this message to $person" — you're describing driving across town to drop something in a mailbox directly. A peer-to-peer messaging system wouldn't have many benefits over an E2E-encrypted one (in a centralized E2E-encrypted service you already enjoy technical guarantees that the courier can't peek inside the metaphorical envelope), but would have several usability drawbacks that would drive away casual users, which the sibling comments mention. Driving away casual users has its own problems: you might drive them away to insecure services ("ah fuck it, this thing doesn't work, I'll just DM them on Twitter"), and the lack of casual users will make your remaining users stand out in traffic analysis (e.g. state agency says "hmm, askxnakjsn is using SuperEncryptoP2PMessenger, better go make sure they aren't a dissident").
- dunefox 6y agoI've been looking for secure messengers during the last few weeks. I use WhatsApp, Signal, and Telegram. Telegram isn't very secure, WhatsApp is owned by Facebook and even Signal - while very secure - requires a cell phone number... Briar seems great in this regard but isn't available on iPhone and has no support for images, calls, voice messages, etc. Apparently they're going to support images and a desktop client, though. In short, I just don't know what to use. Edit: Session looks great but is not fully released yet: https://getsession.org/ https://getsession.org/ This might be what I'm looking for in the future.
- dijit 6y agoHave you looked at 'threema'? I recently installed it and I'm actually pleasantly surprised. However, all of these bloody messengers mean that my contacts list is spread across a multitude of programs: we need the iOS/Android equivalent of pidgin.
- ssss11 6y agoPidgin is exactly what we need.. and each messenger needs to be a pluggable module. Then we dont need to hound friends and family to switch messenger apps they just use pidgin.
- raspyberr 6y agoBut why would something like Facebook open up their walled garden? Does it even count as a walled garden when you have 2 billion people on the platform?
- george120 6y agoFor multiple reasons but first of all because it would require both devices to be connected and online. The common alternative to overcome this is to pass the messages through the server and encrypt/decrypt them on the device (aka e2e encryption). I acknowledge that might not be secure enough for certain use cases. Visit here and check https://www.bloggerzune.com/2020/06/10-Most-Important-SEO-Strategies.html?m=1 https://www.bloggerzune.com/2020/06/10-Most-Important-SEO-St...
- placebo 6y agoIn an authoritarian regime with large masses of human and technological resources determined to have control over its population, nothing is really secure. Sending a message that can't be read by a third party? You're suspect. Have an illegal app installed on your registered "report to big brother" phone? Expect an unfriendly visit by big brother police. Don't have a "big brother" phone? There are various ways of sniffing you out. The bottom line is that while technology can help in the process, technology can't bring freedom from oppressing regimes. That is only achieved when a synchronised, large enough collection of people feel that they are willing to change things even at great personal risk. Authoritarian regimes know this, and thus put a lot of effort into using fear of consequences to suppress any hint of such development.
- giancarlostoro 6y agoIf only Google and Apple would make a fully end to end encrypted chatting platform to take place of SMS that is fully federated and not controlled by a single entity, something the likes of Signal could support / join in on and other chat apps. When you turn crypto into something the masses use seamlessly it gets a little more complicated to figure out who the suspects are. Also default to not synching to the cloud, and explain why syncing to the cloud could be compromised.
- andrepd 6y agoIf spying on you is their business model, why would they build an app to prevent you from being spied?
- LeoPanthera 6y agoSpying on you is not Apple's business model.
- shaniamama 6y agoOh indeed it is. I spent years reading apple reports and my conclusion was that they want the data for themselves so they can sell it. Devices don't make much profit when you factor in how much is spent buying up almost all old devices that hit the market.
- User23 6y agoCriminal conspiracy as a service. I don’t think I’d invest my money. Edit: to clarify their marketing is transparently targeting organizers of street violence. I have no problem with encryption and don’t think government forbidding it is a good idea.
- p1necone 6y agoYou're going to need to be more specific. People are downvoting you because it's not really clear what you're talking about, and I'm getting serious alt-right conspiracy vibes.
- User23 6y agoI can assure you that you cannot in fact read minds and any "vibes" you are experiencing are autogenerated. Also, please remember "Please don't comment about the voting on comments. It never does any good, and it makes boring reading"[1]. [1] https://news.ycombinator.com/newsguidelines.html https://news.ycombinator.com/newsguidelines.html
- ezluckyfree 6y agoOne of the core contradictions of liberal democracy is that all of the freedoms we hold up as advantages of it were obtained by people violently protesting it: labor rights, LGBT rights, environmental legislation, and obviously we are still fighting.. So, congratulations, I guess, on being privileged enough that your interests have always aligned with the interests of the state.
- maqp 6y agoNo it's being marketed to protesters, it's not helping violent people in any more ways than oxygen is. Let's ban oxygen from street thugs too? The cops are already doing great job on that. Also, privacy this app helps to protect is a fucking human right too. You're not welcome here, please leave.
- lawtalkinghuman 6y ago> their marketing is transparently targeting organizers of street violence. The cops already have radios.
- xwdv 6y agoWhat the fuck ever happened to communicating through plain old radios? Impractical for someone to track you, trivial to speak in codes.
- nichos 6y agoDistance is an issue. And it's unlawful in the United States to encrypt ham radio traffic. No one's really monitoring CB much anymore though.
- xwdv 6y agoIt’s unlawful to protest violently as well, I don’t see the point in obeying ham radio laws there.
- maqp 6y agoAnd the way to agree on the code over the radio anyone can eavesdrop is?
- dzink 6y agoI don’t have an answer, but a slightly different perspective. Many different segments have a deep interest in using highly secure encrypted communications: politicians working on deals within/between governments (that should be auditable, but many try to avoid that), whistleblowers, organizers operating in adverse governments, dissidents, terrorists, pedophiles with a lot to lose (similar to Epstein’s network), healthcare professionals trying to talk to patients or other doctors in a hippa world, illegal transaction networks, attorneys with clients, VCs trying to debate the future of the world, companies trying to preserve trade secrets, you name it. It takes one of the egregious bad actors using the system to commit a crime worthy of public attention before the entire system is justifiably unpacked, banned, or considered a signal of bad intentions. How can a system be made decentralized, but able to self-police against legitimately, publicly agreed upon bad behavior? If the system is able agree upon and exclude legitimately bad behavior automatically, the governments would not have a claim upon needing to police it and regular users would probably find it beneficial as well. How could the self policing possibly happen? Maybe you have a blockchain of anonymized encrypted messages that is read by open source scanning bots - if enough independent bots flag a message, then a group of anonymous judges can adjudicate to ban those user accounts? Encryption is one challenge, but if you want true ubiquitous privacy, you need to deliver internal safety to prevent the need for external policing of activity. Social creatures of any species from dolphins to macaques have evolved some kind of internal behavior policing mechanism or trust is lost, and as such the system of value exchange grinds to a halt.
- saagarjha 6y ago> It takes one of the egregious bad actors using the system to commit a crime worthy of public attention before the entire system is justifiably unpacked, banned, or considered a signal of bad intentions. Banning encryption because bad actors use it is not justifiable.
- zelphirkalt 6y agoThis is the same way of thinking many politicians subscribe to: "There has been one terrorist attack, which killed 20 people, quickly now, surveilance everyone and everything! Think of the dangers!" Throwing out the baby with the bathing water (does this proverb exist in English?) is not going to do society much good. Just because there some bad actors, one does not need to discard the whole idea of encryption. Also the dehumanized way of checking for bad content will not help. Bad actors can pre-encrypt or disguise content, whatever you do. Furthermore when the bots have the key to decryption, then the backdoor is built into the system. Bad actors and politicians will try to make use of that.
- foresto 6y agoEarlier this year, I finally took the time to revisit the state of instant messaging services. My requirements: - open source - cross-platform (linux, mac, windows, ios, android) - group chats - end-to-end encryption - well-understood crypto ciphers & protocols - mature enough for a reasonable expectation of security & privacy - easy enough for most computer users - some way to protect metadata (e.g. self-hosting) - signup without real-world ID - offline message delivery I ended up choosing the Matrix network. The reference client is called Element[1] (formerly Riot). There are things I dislike about the client, but they're pretty minor compared to the benefits of the underlying protocol, and lots of alternative clients are in development[2][3]. On top of meeting my requirements, all signs indicate that development is both active and moving in the right directions. Reading the team's weekly reports and issue tracker convinced me that they are making very sound decisions. [1]: https://element.io/ https://element.io/ [2]: https://matrix.org/clients-matrix/ https://matrix.org/clients-matrix/ [3]: https://matrix.org/clients/ https://matrix.org/clients/ Here's what I didn't like about the others: Briar: Lacked cross-platform support and (iirc) offline messaging. Tor brings baggage that not everyone is ready to accept. Cwtch: Not mature yet. Jami: Very fragile code base in my experience, which was also true when was called Ring, and when it was called SFLphone. Only about 25% of the builds I've tried over the years actually worked. I was unable to determine whether it had offline messaging. Keybase: Now owned by Zoom, which is a privacy nightmare. Ricochet: Same problems as Briar. RocketChat: Crypto is not mature yet. Session: Not mature yet. Small limit on number of group chat participants. Signal: Required phone number for signup. Required Google Play Services (aka spyware) for quite a long time. Weak cross-platform support. Some of that is finally changing, but Moxie will surely make more intolerable design decisions, and refuse to fix them for years, again. Telegram: Homebrew crypto. XMPP: Most clients are hard to use (or to teach others to use). Good servers are hard to find. Protocol standards are a mess. I couldn't find a real-world e2ee group chat implementation. Everything else: Failed to meet my requirements even before I looked closely, mostly due to closed code and/or problematic corporate interests. (For example, I will not use an app from Facebook or any of its subsidiaries.)
- michaelsbradley 6y agoDid you look into Status? https://status.im/ https://status.im/ https://github.com/status-im/status-react https://github.com/status-im/status-react https://github.com/status-im/nim-status-client https://github.com/status-im/nim-status-client
- ergwwrt 6y agoUse of wifi during blackout? Wifi does not work during wifi. Only over the air comms are secure. Any wired connaction is tapped
- maqp 6y ago>Any wired connaction is tapped Thats what encryption[1] is for. [1] https://en.wikipedia.org/wiki/Encryption https://en.wikipedia.org/wiki/Encryption
- lostgame 6y agoOh; wow. Not all heroes wear capes. Install now!
- gorgoiler 6y agoSupport for a TEMPEST mode of communication would be a killer feature. Perhaps vibrate mode on one phone being picked up by the accelerometer of another? In our hypothetical dystopian future The Regime will probably jam 2Ghz to 5Ghz in public spaces. TEMPEST mode would also force them to install vibrators into all coffee shop tables.
- ed25519FUUU 6y agoWhat’s TEMPEST? Something that communicates by vibrating a table? In my dystopian future theory, the government that has no issue jamming 2 and 5 ghz channels to keep people from talking would probably notice two people on on a table continually picking up And dropping their phones. Why wouldn’t they simply whisper to each other in that scenario?
- gorgoiler 6y agoTEMPEST is a generic term for extracting data that emanates from channels which were are not supposed to carry data. It’s usually an attack, used to spy on people. The classic example is pointing a high speed camera at an office window across the street and recording the brightness of the walls. Even if the office computer is hidden out of sight the attacker can reconstruct what’s on screen by analysing subtle changes in brightness reflected off the wall.
- riobard 6y ago> The classic example is pointing a high speed camera at an office window across the street and recording the brightness of the walls. Even if the office computer is hidden out of sight the attacker can reconstruct what’s on screen by analysing subtle changes in brightness reflected off the wall. Is this feasible now?
- Xophmeister 6y agoYep https://www.nassiben.com/lamphone https://www.nassiben.com/lamphone
- szundi 6y agoSince they are on their phones via factory rootkit, good luck.
- timeout_in_5 6y agoBriar Project (and other projects like Signal and Tor) are funded by Open Technology Fund. OTF is being killed by the current US government and this will affect all projects! https://en.wikipedia.org/wiki/Open_Technology_Fund https://en.wikipedia.org/wiki/Open_Technology_Fund https://saveinternetfreedom.tech/ https://saveinternetfreedom.tech/ https://saveinternetfreedom.tech/updates/ https://saveinternetfreedom.tech/updates/
- r41nbowdash 6y agomany of my friends are activists, and i'm hesitant to disclose to them which technologies they could use. 95% chance they're going to use it for getting drugs, or avoid monitoring to organize gatherings, which, without law enforcement protection always have potential to turn violent. i just don't want to take responsibility for these actions. then you have heavy stuff, people trafficking, bomb threats, suicide threats, organ trade, child abuse, and crypto seriously limits the options for a response. as long as we're talking about functioning democracies, it does more bad than good.
- ris 6y agoWhat I don't understand about Briar is how it can scale. Surely it can't know ahead of time which users are going to "travel to another part of town" and should therefore have messages pre-loaded onto their devices. Therefore to me this seems like it must use some kind of broadcast delivery model and so would be vulnerable to flooding attacks. Edit: seems there are some thoughts about this already https://code.briarproject.org/briar/briar/-/issues/511 https://code.briarproject.org/briar/briar/-/issues/511