4 ms·
It is early stage, but there is now an alternative to Signal that doesn't use phone numbers at all: https://xx.network/messenger/ https://xx.network/messenger/
by rcarback 5y ago
It is early stage, but there is now an alternative to Signal that doesn't use phone numbers at all:
https://xx.network/messenger/ https://xx.network/messenger/
While you can add your number to be searchable by others, it doesn't let strangers with your number know you signed up automatically, either.
Full disclosure: I work on the infrastructure behind it.
- TacticalCoder 5y agoYup. For those who don't know that is David Chaum's quantum-resistant messenger and he's an OG cryptographer (and he's mentioned in Bitcoin's original whitepaper, funnily enough). > Full disclosure: I work on the infrastructure behind it. Oh cool... I ran a node for many months during the beta (from home, fiber optic at home). I'm busy atm so I'm not running anything anymore but I do really hope that a real secure messenger that doesn't leak metadata left and right, and which uses advanced cryptography, shall eventually prevail.
- pomian 5y agoCan you use this to send texts via SMS to regular phone numbers? How does this differ from Linphone?
- rcarback 5y agoNo it can't use SMS as a transport. It protects metadata using a mixnet and the E2E encryption for authenticated channels uses post quantum cryptography(SIDH) to establish symmetric keys. The infrastructure is run by 3rd party node runners and there's an open source API for other applications in addition to the messenger being open source.
- wolverine876 5y agoWe see many apps that promise to be secure. With due respect, why would someone trust this one?
- TacticalCoder 5y ago> With due respect, why would someone trust this one? It's the project of David Chaum: https://en.wikipedia.org/wiki/David_Chaum https://en.wikipedia.org/wiki/David_Chaum Which makes that messenger very interesting. It's also quantum-resistant from the get go. I think the beta just went live.
- godelski 5y agoHow is this handling usernames? I understand doing this is actually hard if you want them to replace the issues that are carried with phone numbers (i.e. being able to connect with an identity through cross referencing). And of course, birthday problems.
- rcarback 5y agoFirst come first serve right now. Identity is based on keys generated on device and the usernames are based on a network service which I expect we will decentralize (i.e., set up your own like e-mail).
- godelski 5y agoI also don't see usernames as really being that anonymous. Like even if I make a username there that's "notgodelski" if I share that username here on HN then I haven't done anything to keep myself anonymous. All it does is trades one PII for another (phone number for username). I'm also curious about scaling and collisions. Not only do you have a birthday problem with normal usernames, but what about special classes? Why do I not take all "nyt" and similar usernames to honeypot the actual NYT's contact?
- rcarback 5y agoAgreed that usernames aren't exactly anonymous, which is why the platform doesn't require one to use and you can share your QR Code directly instead. I think the mobile apps might force registration with user discovery (this is an active argument i've been having...) but it's not designed to be required. It's not fully baked, but my expectation is that it will work similarly to how the .eth, namecoin, and other systems work, where you'll be able to register a user discovery service on a blockchain which the clients will recognize and use for searching. In this model, NYT registers "nyt.xx" and "rcarback" pops up in the interface as "rcarback@nyt.xx". As it stands, we've rolled out a basic version with a single central user discovery point for now.
- 5y ago
- Aachen 5y agoIn years of browsing desktop-focused websites on my phone, this is the first website that lags at 2fps while I try to use it. High-end Samsung phone from ~2 years ago (second hand) so cpu power definitely isn't the issue. It also goes back up the page randomly if I scroll a certain way, maybe it tries to lock the view to a certain region rather than in between? No idea what's going on with that site but I can't check out your project. I'd be interested in a ~two-sentence description of what it's like and how it's different. E.g., is it using the Signal protocol without phone numbers? It so, how's it different from Wire? If not, what does it use, custom protocol? Does it have a description I can look up elsewhere?
- rcarback 5y agoIt protects metadata using a mixnet and the E2E encryption for authenticated channels uses post quantum cryptography(SIDH) to establish symmetric keys. The infrastructure is run by 3rd party node runners and there's an open source API for other applications in addition to the messenger being open source. I'm not having issues with the website, but I will raise it with the web developers to see if they know what's happening.
- missedthecue 5y agoNo problems for me on a Samsung Galaxy S10, using Chrome. Maybe it's your browser.
- lawtalkinghuman 5y agoBecame significantly less interested when I saw it had a cryptocurrency attached.
- rcarback 5y agoI respect this position, but it is notable that this project and its goals are different from all other blockchain projects. The private messaging is meant to be an intrinsic part of this blockchain for transactions and to provide a platform for applications that rely on the private messaging properties to provide services. As an example, one of the next applications I am working on with it is voting (a continuation of my PhD research). You can do things with this that you can't do anywhere else because you've got hundreds of untrusted, uninterested nodes, changing the threat model in a very important way. Unfortunately, I'm not aware of any other way to incentivize that without some form of payment system, which is why it is intrinsic to this chain. It is fundamental to safe and fair commerce to be able to not be tracked in the ways we care about folks not being tracked. I want to do things like read my news subscription without them being a data vampire that tracks how long my eyes hover over each paragraph of every story then sells that to some advertiser. I also don't want my credit card company selling my purchase history to some government that then uses that information to decide if I am allowed to enter their country 15 years from now. In other words, the project is not trying to be a slower, less private version of a credit card. We do not want to be just another privacy coin or utility for some pre-existing internet service and, unlike other mixnet projects, our goal is a much more ambitious resistance to global adversary threat model. We want to enable folks to do things over the internet with similar properties and experience as buying milk from the corner store with real money. We might not get there, but that's my vision for what we are trying to achieve.