18 ms·
Nothing on the Roadmap [1] about encryption. [1] https://revolt.chat/roadmap https://revolt.chat/roadmap
by drcursor 5y ago
Nothing on the Roadmap [1] about encryption.
[1] https://revolt.chat/roadmap https://revolt.chat/roadmap
- busterarm 5y agowritten in Rust! don't forget to `curl https://sh.rustup.rs https://sh.rustup.rs | sh`! Footnote: As the Rust community continues to bash everyone over the head about how safe it is while completely fucking up the 101 shit we've all been saying not to do for over 20 years, I'm going to continue to treat it how it smells.
- zamadatix 5y agoAt the risk of replying to an overtly aggressive post on language bashing nonetheless - can you explain why rustups implementation of `curl https://sh.rustup.rs https://sh.rustup.rs | sh` is worth mentioning? My understanding, from the 1,000 other times these flames start, is it's done properly and no more dangerous than any other way of running 3rd party binaries from a remote source. Regardless of any other thoughts on Rust folks I'll tip my hat to them for they definitely have made talking about security more common... one way or another apparently :).
- busterarm 5y agohttps://news.ycombinator.com/item?id=6650987 https://news.ycombinator.com/item?id=6650987 https://blog.dijit.sh//don-t-pipe-curl-to-bash https://blog.dijit.sh//don-t-pipe-curl-to-bash https://sysdig.com/blog/friends-dont-let-friends-curl-bash/ https://sysdig.com/blog/friends-dont-let-friends-curl-bash/ https://www.seancassidy.me/dont-pipe-to-your-shell.html https://www.seancassidy.me/dont-pipe-to-your-shell.html
- steveklabnik 5y agoMany of the things in this link are avoided by our script. For example, that last one is made impossible by putting the contents of what is to be executed in a function, and then invoking that function at the end. If the connection closes early, nothing will be executed. The last ones are the same as any other way of downloading software that's executable, and not specific to curl | bash.
- Macha 5y agoYou can of course install from your package manager [1][2][3][4]. If you're not going to install from your trusted source then I'm not sure curl https:// https://... | bash is really worse than downloading and double clicking a msi/dmg/deb/rpm. Especially if you're not going to verify that or verify it using keys downloaded from the same https host. [1] Homebrew - https://github.com/Homebrew/homebrew-core/blob/HEAD/Formula/rust.rb https://github.com/Homebrew/homebrew-core/blob/HEAD/Formula/... [2] Arch - https://archlinux.org/packages/extra/x86_64/rust/ https://archlinux.org/packages/extra/x86_64/rust/ [3] Ubuntu - https://packages.ubuntu.com/hirsute/rustc https://packages.ubuntu.com/hirsute/rustc [4] Fedora - https://fedora.pkgs.org/34/fedora-x86_64/rust-1.51.0-1.fc34.x86_64.rpm.html https://fedora.pkgs.org/34/fedora-x86_64/rust-1.51.0-1.fc34....
- superkuh 5y ago>You can of course install from your package manager Debian 11 was released a couple weeks ago and the rustc it ships with is already so out of date (7 months old, gasp!) software written for modern rust versions can't be compiled with it. And this isn't a Debian only problem.
- Macha 5y agoIs this a Rust only problem? Decided to pick the most well known Go project, kubernetes, and the Go version (1.15) included in Debian 11 is too old to build the first kubernetes project in my search results, kubernetes client as it requires go 1.16, released february. I've certainly had issues with e.g. the Python or Node version being too outdated on Ubuntu, RHEL, CentOS etc. And when that happens, it's a bigger problem, as it's a runtime dependency, not just a build time one. It's the risk you sign up for picking a fixed release distro. Consequently, if you're developing cutting edge software in those languages, you're probably running nvm, your favourite virtualenv wrapper (poetry, pipenv, pip-tools), or letting your IDE download a runtime for you. And yes, these tools are full of curl | bash or curl | python install instructions.
- hypothesis 5y agoIt appears that 1.16 is available in testing as different package. Chance is high that you will be able to install it without much hassle, since they shipped current stable like a week or so ago. [1] https://packages.debian.org/bookworm/golang-1.16-go https://packages.debian.org/bookworm/golang-1.16-go
- SkyMarshal 5y agoThey do sort of mention it at the bottom (grep e2ee), but don’t say anything concrete about it.
- Zomatree 5y agoThe plan is to make DMs end to end encrypted.
- stiltzkin 5y agoBe aware people will critique if only PM are only e2e, this is what people who uses Signal and WhatsApp downplay Telegram.
- schmorptron 5y agoI'm one of those people, but for a discord alternative, I think it's a pretty fair trade off. My WhatsApp groups are mostly under 100 people while discord servers get much, much bigger. The only thing I feel like would be viable would be one shared encryption key for large rooms that just gets shared between the members via a resource-intensive diffie-helman-like message once and then after that everyone just uses the same key.
- stiltzkin 5y ago> The only thing I feel like would be viable would be one shared encryption key for large rooms that just gets shared between the members via a resource-intensive diffie-helman-like message once and then after that everyone just uses the same key. I agree on that extent. I find Telegram on this grey area which people recommend it as an alternative to Signal or WhatsApp (these people ask for group e2e) and at the same time many communities use Telegram channels and groups as alternatives/complementary to Discord. An app as Telegram is not going to please the majority and maybe this could be the case for Revolt.
- beanjuice 5y agoIs there a group of people who use WhatsApp who care about e2e encryption and hold it as the standard? Surely its common knowledge that you cannot trust the parent company of WhatsApp, or its encryption since being broken.
- stiltzkin 5y ago
- cpach 5y agoLet’s say you have a channel with 500 participants. Is there even any sane way to encrypt that channel?
- zamadatix 5y ago500 isn't really asking for much, Signal does up to 1,000 in a group using standard direct messaging encryption (client side fanout). Whatsapp uses a shared hash ratchet and just spins up new keys when someone leaves, this allows it to do 10,000. Discord gets to 25,000 active users before they move to throwing resources at the problem for a hard max of 500,000 total users able to join (but not be active at once, that number is a little fluffy) so it doesn't seem e2ee is really slamming the breaks on scaling vs how far you could normally get. Signals approach https://signal.org/blog/private-groups/ https://signal.org/blog/private-groups/ Whatsapps approach https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857720642275_2152527586907531259_n.pdf/WA_Security_WhitePaper.pdf https://scontent.whatsapp.net/v/t39.8562-34/122249142_469857... Finally if you allow tying and verifying to real world identity and don't require forward secrecy then the encryption side of the problem is no more difficult than PGP.
- DenseComet 5y agoDiscord doesn't do E2E encryption, although those numbers for Signal and Whatsapp are pretty impressive.
- zamadatix 5y agoI probably wasn't as clear as I could have been on that. The Discord numbers were meant to provide a point of comparison on how little e2ee really impacts scaling active users vs a traditional system but I wasn't very explicit that's why it was being mentioned.