10 ms·
Briar has been removed from Google Play
- vintermann 5y agoAssange endorsed Briar, and urged people in Ukraine to install it when he learned of the invasion. It's about the only thing he's commented on the situation in the outside world for the last two years.
- toomanybeersies 5y agoSo after a couple of years of silence, Julian Assange finally speaks out to spruik a messaging app? Colour me skeptical...
- vintermann 5y agoThe reason he's been silent is that he's been kept in isolation, is deeply ill and has only a fragmentary picture of what's going on in the outside world, based on the little they can discuss openly during visits (knowing everything is recorded to be used against him in any way possible). Your sneering says more about what color you are.
- boomboomsubban 5y ago>has only a fragmentary picture of what's going on in the outside world, based on the little they can discuss openly during visits And his fragmentary picture includes app recommendations? Skepticism seems like the right call, even though he has a very good reason for his years of silence.
- vintermann 5y agoThe app has been around in some form since 2014. In promoting it, Wikileaks are relating it to discussions in 2011 with Eric Schmidt, then Google chairman, first published in 2014. It's not so surprising that Assange would have had strong opinions on both the limits and opportunities of mesh networking, and knowledge about who were working on it who were competent and had sound ideas. Briar got an independent security audit in 2017.
- boomboomsubban 5y agoEverything you said in this post about Briar is a better reason to use the app than Assanges prison recommendation.
- vintermann 5y agoWell, I'm answering why he would recommend it. But if you couldn't evaluate the technical stuff yourself, you'd do well to trust Assange's (and also Snowden's) recommendation on such things above almost anyone else's.
- boomboomsubban 5y agoIt seems true https://mobile.twitter.com/wikileaks/status/1497314070738911236 https://mobile.twitter.com/wikileaks/status/1497314070738911... I also find it strange that he'd push something like this from prison and somewhat question how strong his recommendations are given he's been cut off from the digital world for several years. But I know nothing about the app.
- user-the-name 5y agoSo the guy who worked with Russian intelligence services recommends an app to people Russia are fighting against? I would maybe not take that recommendation that easily.
- deleted 5y ago[deleted]
- rvz 5y agoReason for removal: Because we didn’t provide Google’s review team with a username and password for testing the app. Apparently they didn’t realise they can choose any username and password they like. Well perhaps next time give the review team a way to login, since they don't know how to use the app?
- IanCal 5y agoThey have, just after your quote > We’ve provided Google with a username and password for testing
- robertlagrant 5y agoIf they don't know that signing up to apps is a thing, how can you be sure they'd know what to do with a username and password?
- nkozyra 5y agoI guess I'd have to operate on the only evidence I have to the contrary: there are thousands of apps with authentication in the Play Store that aren't banned. I think we all know the drill with walled gardens but if you want a fighting shot of getting in they at least give it their guidelines.
- inopinatus 5y agoThere's a multitude of reasons why review teams do not wish to create an account to test your app. Repeat testing is an obvious one, for clutter avoidance (and close relation, namespace pollution issues), email failures, payment barriers, variations between plans and account types, inadvertent secrets reuse, staff unauthorized to accept any additional T&Cs, simple efficiency, the list goes on.
- teddyh 5y ago> Briar is a messaging app designed for activists, journalists, and anyone else who needs a safe, easy and robust way to communicate. Unlike traditional messaging tools such as email, Twitter or Telegram, Briar doesn’t rely on a central server - messages are synchronized directly between the users' devices. If the internet’s down, Briar can sync via Bluetooth or Wi-Fi, keeping the information flowing in a crisis. If the internet’s up, Briar can sync via the Tor network, protecting users and their relationships from surveillance. Unfortunate timing by Google.
- Maxburn 5y agoOR was that the whole point?
- miohtama 5y agoFirechat was used in Hong Kong demostrations in 2014 and got janked out from the app stores by China https://edition.cnn.com/2014/10/16/tech/mobile/tomorrow-transformed-firechat/index.html https://edition.cnn.com/2014/10/16/tech/mobile/tomorrow-tran...
- mzi 5y agoIt seems to have been restored again.
- badRNG 5y agoWith this text as explanation: > Briar was briefly removed from Google Play because we didn’t provide Google’s review team with a username and password for testing the app. We provided Google with a username and password for testing and the app is now available again.
- dash2 5y agoIs it legit? I heard it had been heavily pushed by Russian media…
- deleted 5y ago[deleted]
- dgellow 5y agoAre you asking if the app is legit (i.e trustworthy and not a honey-pot) or are you asking if the information it has been removed is legit? I cannot answer the first one, but the second question seem to be legit: the store page returns a not found https://play.google.com/store/apps/details?id=org.briarproject.briar.android&hl=en_US&gl=US https://play.google.com/store/apps/details?id=org.briarproje...
- vertis 5y agoIt's open source[0] so possible to audit. So yes it's legit. [0]: https://github.com/briar/briar https://github.com/briar/briar (mirror)
- toomanybeersies 5y agoThere's been plenty of cases where an app/package/extension has publicly available source code which differs from what's actually distributed. However, I do see they have a section in their README regarding reproducible builds for verifying APKs against their source code.
- blendergeek 5y agoDo you have a source for this?
- czechdeveloper 5y agoIt's been pushed by WikiLeaks on Twitter to be used by Ukrainians. Due to some people believing that WikiLeaks has been hijacked by Russia, they do not trust the app. https://twitter.com/wikileaks/status/1497314070738911236 https://twitter.com/wikileaks/status/1497314070738911236
- throwaway984393 5y agoAt this point we should probably focus on releases of important software as APKs first, Google Play second. I'd hate it if Google took away my ability to release my product. Does Android allow installing public keys for specific apps so you don't have to allow all untrusted apps just to install one?
- vertis 5y agoAndroid lets you trust certain sources of APKs, where Firefox/Chrome/F-Droid are a source. Once enabled it will trust any APK that comes from that source (and obviously a browser can then download any).
- josephcsible 5y ago> Does Android allow installing public keys for specific apps so you don't have to allow all untrusted apps just to install one? This is kind of a silly question. The only point of the "Install unknown apps" setting is to make it less convenient to avoid the Play Store. You'll always be asked for confirmation before installing a new app (unless you've rooted your phone to bypass that), and installing an update with a different public key with the existing version uses will fail even if you do confirm the installation.
- radu_floricica 5y agoThis isn't about censorship, it's about outsourcing validations to people that work only with a very clear and simple set of rules. Saw the same thing trying to validate a shopify plugin, it was rejected for an equally stupid reason.
- konfuzio 5y agoFYI: Your logo is not displayed on mobile.
- willcipriano 5y agoI'm going to open a grocery store and hire an army of management staff, but I'll outsource trivial matters like deciding what products to sell to a third party sweatshop. If any of the products get someone sick I'll point to the terms of service, shrug my shoulders and say "algorithms".
- UncleMeat 5y agoThis one isn't black box algorithms behaving badly. You have to supply Play with a working test account for the review process. They didn't. There are definitely cases where an app is taken down for mystery reasons and Google basically cannot explain why but this isn't one of them.
- onion2k 5y agoYou have to supply Play with a working test account for the review process. They didn't. Briar has more than 500k installs according to its Google Play page. Why do Google need to remove the app entirely if they've previously accepted and published it? I can understand not allowing an update without the proper review process using a working account, but what's the reasoning behind removing the old version that Google allowed just because they can't review an update? That makes no sense.
- matwood 5y agoExactly. Unless the app is malicious, Apple tends to force changes during an update. Google appears to have turned on some algorithms in the last couple weeks, and is pulling apps down without warning. Then, this new review process appears to be really poorly run which makes it hard to get the app back in the store. Also, the developer console itself keeps getting redesigned making it hard to find where to put these new bits of information.
- rakoo 5y ago> You have to supply Play with a working test account for the review process. They didn't. Briar has no registration process. Pick any username and password and you're good to go. Google's process is probably not used to apps that aren't centralized with a single, third-party service delivering the golden with ticket
- dandanua 5y agoThere were many installs of this app in Ukraine in recent days, because people are expecting internet problems. Very suspicious decision from Google. And the reason is even more suspicious.
- Dave3of5 5y agoSeen this before with google. I accessed a "sensitive" scope so I needed verification and I'm almost 100% sure this was offshored to some sweatshop. You had to send them a video showing how your app used the scope which I did and in fact had to do multiple times to get the app verified. The whole process was stressful and poorly handled by google. The sent me an email saying there was a broken link on my homepage (a link to the blog at the bottom of the page which was also at the top). In the email they sent me all the links to google were broken. I asked why did it matter if my website had a single broken link and how this affected using scopes, no response. The don't speak to you and always send you back pre-canned messages, I got one saying my app was still in development, so communicating in this manner is really difficult. Btw in terms of security almost all the scopes are sensitive in their system so anything other than login you'll have to go through this process. I welcome extra security but the process was terrible.
- sschueller 5y agoMy app update was rejected because I accidentally had a duplication of a word in my description.
- DrBenCarson 5y ago“This app does not not steal user data.”
- gadrev 5y agoGold.
- slightwinder 5y agoSeems it's back again. Probably some Human at Google realized the situation and moved fast?
- AndrewDucker 5y ago"Update (February 28, 13:20 UTC): Briar is available on Google Play again."
- ddtaylor 5y agoWelcome to ~~Hacker News~~ Google Support.
- throw1234651234 5y agoI have several questions on this: 1. Is Briar or Firechat open source? 2. Are they actually effective past "within a crowd" range? I.e. has the Bluetooth "networking" ever worked? 3. Is there any way to "secure" traffic?
- dopa42365 5y agohttps://docs.google.com/spreadsheets/d/1-UlA4-tslROBDS9IqHalWVztqZo7uxlCeKPQ-8uoFOU/edit#gid=0 https://docs.google.com/spreadsheets/d/1-UlA4-tslROBDS9IqHal... No idea about 2. though. Going with "unlikely".
- hundchenkatze 5y agoBriar is https://code.briarproject.org/briar/briar https://code.briarproject.org/briar/briar
- m-p-3 5y ago1. https://code.briarproject.org/briar/briar/tree/master https://code.briarproject.org/briar/briar/tree/master (GPLv3) 2. https://briarproject.org/how-it-works/ https://briarproject.org/how-it-works/ any nodes can act as a mule to carry encrypted messages between "bubbles" through either Tor, WiFi or Bluetooth 3. The communications are encrypted all encrypted (at rest and in transit), only those who are added as contacts or part of a forum as a member will have the key(s) to decrypt the communication.
- throw1234651234 5y agoThank you, and thanks everyone who replied!
- kkfx 5y agoHonestly... I do consider such episodes as purely theatrical: who can be so .... (self-censor, since I have issue finding words that are not insults) to use smartphones for seriously dangerous activism, journalism etc? Who can trust the bloatload of crap, bugs, backdoors of such devices, even carrying them alone in such situations? Personally I try, and I'm not alone, to live without smartphones, and some propose to use them as "secure communication tools" for privacy-critical contents?!
- rocqua 5y agoBesides "only communicate face to face" how do you propose to do secure communication over a long distance without a smart-phone?
- kkfx 5y agoWith a desktop computer, running a FLOSS system? Or a classic phone with a simple voice scrambler? For written messages ciphered paper letters, with a classic and simply alphabetic cipher like the classic Vigenère?
- SamBam 5y agoYour contact is in a besieged city 100 miles away. They have WhatsApp or Signal and want to send you a message. Are you suggesting the journalist shouldn't have a smartphone that contact could contact you on?
- kkfx 5y agoIf my contact is besieged in an enemy land where if intercept might suffer bad outcomes I hope for him/her he DROP and hammer-smash his/shes phone time ago. If talking is possible BUT certain topics are taboo then a FLOSS desktop, possibly a VERY OLD one (classic bios, no frill), and some stenography trick, something simple, like abusing zip/gif file format to add extra encrypted information inside, might be used. DEFINITIVELY NOT via a proprietary service. A thing, that's NOT a personal attack nor something else but here is HN, so a place whose users typically are tech savvy humans: did you really imaging a smartphone as the best/the goto tool to communicate under a dictatorship/secret investigations etc? I'm curious because or you are secretly working for NSA and similar or... I can't imaging how you can be a (stereo)typical HN user. Supposing I'm a whistleblower communicate with a journalist, well the first mean I choose is passing something physically via trustable third parties, plural in the sense that one should contact another not much linked/unlinked to me who do the same, to make unlikely some small surveillance notice something strange. They just should know they do something "a bit secret" for me without knowing the rest. If he/she have a public GNUPG key I can use it to cipher what I pass but, unfortunately, that's unlikely for most journalist, they simply do not know tech enough. After the first contact I'll try to find a common ground to let him/her understand that I'm not joking and similarly that he/she is interested in doing that. I'll then teach how to use FLOSS tools on a third party computer, with a live USB key, running from ram. I'll keep changing at random the means of communication etc. If I live under a dictatorship and I'm involved in Resistant activities the last thing I want is hi tech gears around, at least they do my best to appear using and liking them, doing the opposite, trying to be double face. I'll do my best to organize coms via ephemeral/disposable tools, something low tech as possible and hard to massively track. If I'm a journalist, trapped behind enemy lines, I try to document as much as possible with some kind of deniable encryption, something like not so innocent and badly hidden while the real things are well deeply covered and try to keep a profile as low as possible, including NEVER communicate directly with the other side of the front. If you imaging going to war with a smartphone in your pocket I sincerely advise you to avoid that at all: you'll be a dead man in a far shorter period of time than normal...
- qiskit 5y agoRegardless of whether Briar was removed by accident or not, I wish the "app store" was separate from google/alphabet. Managed, controlled and run by and independent group. Or that we'd develop a more independent installation culture via apks like we used to do for desktops. 99% of smartphone users are entirely dependent on app stores which are controlled by two multinational companies. It's insane. I'd much rather prefer every nation maintained their own app stores rather than apple and google control it for the whole world. Would be nice if an open source alternative would gain popularity but I'm guessing it's even less likely on a smartphone than on the desktop.
- aspyct 5y agoThere are at least a few alternative app stores. The problem is: they're not installed by default. We should probably have some choice like we (used to?) have for browsers. One that I can happily recommend is F-Droid https://f-droid.org/ https://f-droid.org/ . In fact, I believe Briar is on it.
- minroot 5y agoCan it send files?
- steveharman 5y agoApple rejected one of our apps. I looked at the screenshots they sent, they weren't of our app. Pointed this out - app passed the review process.