4 ms·
Since I needed brief intro myself, Wikipedia says: "The initial target audience for Briar includes "activists, journalists and civil society" with plans to mak
by dingdingdang 5y ago
Since I needed brief intro myself, Wikipedia says:
"The initial target audience for Briar includes "activists, journalists and civil society" with plans to make the system "simple enough to help anyone keep their data safe." As the ability to function in the absence of internet infrastructure may also make the project valuable to disaster response and aid organisations, the developers are working with the Open Humanitarian Initiative and Taarifa. Ultimately, the developers aim to create a system which is "as simple to use as WhatsApp, as secure as PGP, and that keeps working if somebody breaks the Internet.""
Would personally love a blog review or two of Briar but found little thus far.
- giphyman 5y agoTheir website has a press page with some reviews and presentations: https://briarproject.org/press/ https://briarproject.org/press/
- pulse7 5y agoWho can guarantee me that this isn't built by some national security agency with some tiny, hidden backdoors?
- grote 5y agoNo one can, but isn't that the case for all software? At least it is Free Software with reproducible builds, so you can audit the shit out of it.
- mburee 5y agoI totally agree, but no one ever pays the money to have it properly audited
- vorpalhex 5y agoIt's you. You can pay to have it audited right now. You can also audit it, if you have the skillset.
- sodality2 5y agoIt has been audited. https://code.briarproject.org/briar/briar/-/wikis/FAQ#has-briar-been-independently-audited https://code.briarproject.org/briar/briar/-/wikis/FAQ#has-br...
- coldtea 5y agoAnd who audits the auditors?
- sodality2 5y agohttps://code.briarproject.org/briar/briar/-/wikis/FAQ#has-briar-been-independently-audited https://code.briarproject.org/briar/briar/-/wikis/FAQ#has-br...
- Iolaum 5y agoThe person you can hire to audit the code ;)
- mobilemidget 5y agois there already some compare available that shows differences with other messengers like Telegram or Signal?
- derbOac 5y agoIt's been awhile since I used Briar, but unlike something like Signal, Briar is decentralized. So you can communicate with other Briar users in the absence of a central server. Briar at least used to be very strict about how you established contacts, so, for example, to add a contact you had to have them physically in your presence and exchange QR codes on your phone. You couldn't just add someone from your phone contacts, for example, or look up their phone number. The downside to these things is that Briar tends to use up battery on mobile devices, because it's constantly running to handle the decentralized communications. Also, having to have someone physically in your presence makes it difficult to add someone casually like some other apps. Some of these things might have changed, as they've been pretty consistent and active in developing the software, and it has evolved over time into offering more and more functionality. In general, Briar development tends to be very conservative about security, but also very encouraging of "robustness" development for lack of a better way of putting it (I think at one time they had an API so that it could be extended to general "off grid" communication protocols, or at least were discussing it). I'm a little surprised it hasn't gotten more attention over the years, because I think it has been audited and seems very very secure. It also pops up on places like HN from time to time. On the other hand, that conservativism about security makes it sort of impractical for someone who, say, just wants to chat with friends and family. I think the best comparison is probably with Matrix rather than Signal or Telegram, but Briar lacks the federated component at the moment. This desktop release is interesting to me because in some ways it represents a major expansion of the software. As I said, they've tended to be very conservative and it's interesting to see it added. It also probably makes it more feasible to treat the desktop instance as a sort of "permanent on" server with access to a power supply instead of running off a battery (to be honest, starting with a desktop service kinda makes more sense to me given the power requirements). Take this all with a grain of salt because, although I have it on my phone, I haven't actually used it in some time and haven't actively kept up with development in a couple of years.
- leonry 5y agoIf you understand German, then I recommend the review by Mike Kuketz (https://www.kuketz-blog.de/briar-anonymitaet-und-sicherheit-gehen-vor-messenger-teil8/ https://www.kuketz-blog.de/briar-anonymitaet-und-sicherheit-...). Maybe you get a decent translation with Deepl, though I stay wary. There is also a comparison to other messenger systems on https://www.freie-messenger.de/systemvergleich/ https://www.freie-messenger.de/systemvergleich/. They have a PDF in English available, but it doesn't really tell much.
- coldtea 5y ago>"The initial target audience for Briar includes "activists, journalists and civil society" Sounds exactly like a project an agency would help create/infiltrate to tap unto all of the above....
- rosndo 5y ago> as secure as PGP Well, that doesn’t sound promising at all. You can ask any cryptographer, they will tell you to not use PGP.
- 0xdeadb00f 5y agoPGP _supports_ up-to-date, secure cryptographic algorithms, but it's usability falls short. these new algorithms are rarely made the PGP implementation's default algorithms.
- rosndo 5y agoThose algorithms are unsuitable for messaging as implemented in gpg.
- scraptor 5y agoBecause the usability sucks (supposedly leading you to shoot yourself in the foot), not because of any problems with the crypto or the implementation.
- rosndo 5y agoThe crypto is also very questionable for any use case relevant to briar.