16 ms·
Tox: secure messaging for everyone
- kin3tic 13y agoOoh a desktop app with a bunch of custom UI? Great, it will fit in with all the other useless shitty chat apps I've ever seen for Windows.
- Plexion 13y agoWebsite owner here: Currently getting a 50k pps DDoS. It'll be over shortly, I hope. EDIT: It's done.
- thaweatherman 13y ago?
- yogo 13y agoIt might be useful to mention more about how encryption is done on the website itself since that is the main selling point. As it stands I have to go through the source code.
- dmix 13y agoFound it on their wiki: https://github.com/irungentoo/ProjectTox-Core/wiki/Crypto https://github.com/irungentoo/ProjectTox-Core/wiki/Crypto
- rorrr2 13y agoEven if you do go through the code and don't find any bugs/backdoors, doesn't mean there are none. Both encryption and secure communications are pretty hard to implement right.
- yogo 13y agoRight. That is always the case. I was only referring to a high-level description about the kind of encryption being used and what made it secure.
- northwest 13y agoIf you're the author, you should add it to the list: https://en.wikipedia.org/wiki/Darknet_%28file_sharing%29 https://en.wikipedia.org/wiki/Darknet_%28file_sharing%29
- gsibble 13y agoAlso might want to get a better server. I'm not trusting a messaging service whose marketing site I can't even reach.....
- kostyakow 13y ago>I'm not trusting a messaging service whose marketing site I can't even reach You would rather trust a huge corporation instead of a community-developed project?
- riquito 13y agoI suppose he meant that he can't trust a product of someone who can't event run his website, since the software may be unstable. Security is not involved. For a new product the website should give to the visitors the feel that you are a professional (I'm trying to give a constructive critic here)
- lvh 13y agoIt is unfortunate that this thing's name collides with tox, the testing tool.
- northwest 13y agoWhy not rename one of the two to: detox (it'd even make sense)
- cpursley 13y agoThis is a good idea!
- X-Istence 13y agoHow about renaming this Tox to something else, since Python's testing tool has existed for quite a while.
- kmike84 13y agoThere is already a https://pypi.python.org/pypi/detox https://pypi.python.org/pypi/detox Python project that provides parallelized tox testing. It is nowhere near as popular as tox (python project) though.
- bizarref00l 13y agoThere are already one detox http://detox.sourceforge.net/ http://detox.sourceforge.net/ . It's a file name sanitizer.
- CompulsiveCo 13y agoThis has been a project on 4chan's /g/ board that began after Snowden's initial leak. Its good to see that this project has developed into something substantial.
- chuckd1356 13y agoHow's their service going to stop a Man-in-the-middle attack, client endpoint exploits? Or the HN effect crippling their marketing servers.
- DanBC 13y agoGithub maintained by someone with a troll username? Comments like this: > IMPORTANT: release two major sanctioned UIs, one for autists, one with inbuilt support for the previous list so that plebs can't get confused with setting it up and autists don't complain about it getting in their way. de geso > I would suggest a "Advanced options" where the autists can rejoice with all kinds of options (and it doesn't frighten the normalfags, since it's not shown by default). Also, 2 UIs would be chaos to maintain. Talk about not needing to be an expert to use it, but then a "learn more" button sending people to github? Not inspiring confidence so far. It's nice to see they're using an existing crypto library. I'd be surprised if they haven't made errors implementing it.
- diminoten 13y agoAccording to another comment, it's a product of 4chan, so the offensive verbiage is unsurprising.
- runn1ng 13y agoYes, it was made on 4chan's /g/ imageboard.
- deleted 13y ago[deleted]
- peterwwillis 13y agoGood to know different kinds of fags are still an important demographic there. (Normal, new, moral, etc)
- deleted 13y ago[deleted]
- kostyakow 13y ago>Github maintained by someone with a troll username? >Comments like this >> IMPORTANT: release two major sanctioned UIs, one for autists, one with inbuilt support for the previous list so that plebs can't get confused with setting it up and autists don't complain about it getting in their way. de geso > I would suggest a "Advanced options" where the autists can rejoice with all kinds of options (and it doesn't frighten the normalfags, since it's not shown by default). Also, 2 UIs would be chaos to maintain. The project originated from 4chan's /g/ (technology) board. It works differently from Reddit and HN, since there's no karma, and the comments are anonymous. This caused it to develop a unique culture. On one hand, it enables people to express their real opinions without being afraid of getting downvoted by hivemind. On the other hand, it attracts trolls and causes a lot of rudeness and offensive behaviour. I like the website, because you can see the true nature of people, and you don't feel the pressure to say what everyone else wants you to say. >Talk about not needing to be an expert to use it, but then a "learn more" button sending people to github? We were working on this for only about a month, and Tox is not even in the alpha stage yet. Once we get the GUI working properly, we will surely upload binaries to the website.
- irungentoo 13y agoSince you managed to kill the website: https://github.com/irungentoo/ProjectTox-Core https://github.com/irungentoo/ProjectTox-Core Tox is a completely decentralized secure messaging service which aims to replace skype. It it still in heavy development. So far we have IM working almost perfectly but no completed GUI yet except for a basic ncurses interface used to test the core. For the detailed info on how everything works see: https://github.com/irungentoo/ProjectTox-Core/wiki https://github.com/irungentoo/ProjectTox-Core/wiki
- foobarqux 13y agoWhy didn't you make use of existing projects like SecurePhone and OTR?
- igravious 13y agoHey, congrats on the hard work. I'm going to try it out. Is there a bird's-eye-view on how you have made it secure?
- PhearTheCeal 13y agohttps://github.com/irungentoo/ProjectTox-Core/wiki/Crypto https://github.com/irungentoo/ProjectTox-Core/wiki/Crypto
- runn1ng 13y ago/g/ has finally managed to make this somehow usable? Well, congratulations.
- shin_lao 13y agoUnconvinced. * Lossless UDP? Is there a reason not to do TCP? * There is no way to know if the public key is genuine, so the system is very sensitive to MITM. * The key exchange is inadequate. Why not do DH if it's just to have session keys? * The system is very easy to brute force as the acknowledgement is based on a known plain text. This is very bad. A quick glance at https://github.com/irungentoo/ProjectTox-Core/blob/master/core/net_crypto.c https://github.com/irungentoo/ProjectTox-Core/blob/master/co... I found a potential buffer overflow at line 143. If an attacker sends a large file, what happens? Making crypto software is not just a question of wrapping a crypo lib (in that case NaCl) with a GUI. There are some tricky security issues as how you use the crypto.
- irungentoo 13y ago>Lossless UDP? Is there a reason not to do TCP? Hole punching. >There is no way to know if the public key is genuine, so the system is very sensitive to MITM. If you want to add someone you need their public key (their id) which is 32bytes (It's small because we use ECC instead of RSA). Unless someone somehow replaces the key (your id) when you give it to your friend the system should be secure. >The key exchange is inadequate. Why not do DH if it's just to have session keys? The key exchange is designed that way because we want forward secrecy. >The system is very easy to brute force as the acknowledgement is based on a known plain text. This is very bad. Can you please elaborate on this. If you are speaking about the the second part of the crypto handshake I can assure you that the fact that the plaintext is known is not a problem. >I found a potential buffer overflow at line 143. If an attacker sends a large file, what happens? The function read_packet is hard coded to never return something bigger than MAX_DATA_SIZE.
- shin_lao 13y agoYour answer raises my eyebrows even more. I ask why you don't use DH and you answer "because we want forward secrecy". DH has been designed for perfect forward secrecy. Therefore I fear we might have some sort of misunderstanding here. You don't want to permit known plain text attack as "in depth defense" approach. If there is ever any weakness in your software, you want to make it very hard to exploit it. Known plaintext will make exploiting weaknesses in your PRNG very easy for example. As for your last comment... If someone ever changes the behavior of read_packet, you're dead. So I'm sorry, but you have potential buffer overflow. Think in 4 dimensions Marty! :)
- deleted 13y ago[deleted]
- unknownian 13y agoThankfully we have a graphic design board now to aid in this stuff, though it might have been a /g/sent who designed it. There are some undiscovered talents on 4chan.
- kostyakow 13y agoTox aims to be a secure replacement for Skype. There's several other similar projects, but they are usually hard to set up and use for an average user. Tox is FLOS software developed by community, and currently licensed under GPLv3. We are considering changing the license to something more permissive, so it would be possible to put it on the App & Win8 Stores. Currently, it is in really early stages of development. But we already have basic IM, and nCurses interface. We use NaCl library for encryption and will probably add FFmpeg for video. We are working on a cross-platform GUI using Qt5. Please note that the screen-shots on the main website are only mockups, and (in my opinion) should have been labeled as such. Since the website is down, here's some links: Subreddit: http://www.reddit.com/r/projecttox/ http://www.reddit.com/r/projecttox/ Core code: https://github.com/irungentoo/ProjectTox-Core https://github.com/irungentoo/ProjectTox-Core Qt GUI code: https://github.com/nurupo/ProjectTox-Qt-GUI https://github.com/nurupo/ProjectTox-Qt-GUI Website code: https://github.com/stal888/ProjectTox-Website https://github.com/stal888/ProjectTox-Website IRC Freenode chanel: #InsertProjectNameHere
- jnbiche 13y agoCongrats on the progress made so far. I'm eager to see how things shape up. Would love to see a community project analogous to this one develop in the e-mail space since too many users find PGP to be cumbersome, despite some very nice implementations. Bitmessage and I2P's bote are both very interesting, but the prior project needs more experienced security people working on it (and some serious refactoring), and the latter suffers from the perceived issues of the "darknet" (not an issue for me, but...).
- napoleond 13y agoWould love to see a community project analogous to this one develop in the e-mail space since too many users find PGP to be cumbersome, despite some very nice implementations. We're on it! https://parley.co https://parley.co will be entering pre-beta later this week. Maybe not technically a "community project" because it's being built by a company that is at least partly motivated by profit, but the whole thing is BSD-licensed so people can do whatever they want with it.
- anologwintermut 13y agoSo this appears to naively use DJB's NACL/crypto_box construction, which is a curious choice given the existence of OTR for messaging protocols which would handle things like session key negotiation and provide deniability. First, If I'm reading the source correctly, they are doing public key encryption for every message. Which, ok, DJB was a fan of at least for DNSCurve, but is generally regarded somewhat dimly for efficiency reasons. So I guess this puts them on one extreme of the Bell Curve or the other. I wonder which? [EDIT, removed point about nonce's in handshake] Funnily enough, at first glance it looks like they covered at least some of the obvious issues: they do at least attempt to authenticate the session key and the crypto_box's use of a Nonce prevents replay and re-ordering attacks. How do they handle video chat? Crypto_box won't work there naively sense packets will get lost and the nonce's won't be in sync.
- irungentoo 13y ago> Nonce's are "Numbers used ONCE", they 1) don't need to be secret and 2) ARE NOT encryption keys. We know. Putting the nonces in the handshake along with the session public key was simple. In the NaCl docs it is advised that if you can keep the nonces secret that you do so.
- anologwintermut 13y agoOut of curiosity, why not use OTR for messaging?
- znq 13y agoProbably because OTR only works when both parties are online at the same time. Edit: that said I haven't looked at their solution. Maybe it has the same issues. Or worse.
- anologwintermut 13y agoLooking at their crypto code, it appears they assume both parties are online. There is a two way hand shake for key negotiation. My guess was they wanted to handle things like video chat and file transfer that OTR doesn't handle. But at least for video chat, I don't think it NACL will work out of the box either
- cpursley 13y agoThis is great. A cross platform web app would be icing on the cake. Built on something open source like Lungojs.
- mtct 13y agoWell done /g/!
- fracchio 13y agoI do like your project, why not putting it on indiegogo or pledgie to help the development and large the audience?
- unknownian 13y agoMinor contributor here: we've been trying to recruit help from HN multiple times with no luck. /g/ recognizes that the dev talent on the web resides here, so if you have a mastery of any of the needed skills (C, GUI design) we'd love your help.
- fernly 13y agoAs a naive potential user I am willing to take the assurance of proper crypto and forward secrecy. What needs to be addressed also is the issue of metadata. It is the broad collection and easy analysis of metadata -- NOT content -- that makes NSA monitoring so sinister. By knowing all about who you connect with, when, for how long, and with what regularity, they can know a vast amount about you. What of the who/when/how-long/how-often metadata is evident when using Tox? As compared to normal skype or IM, that is?
- untitaker_ 13y agoIt's kinda impressive in how many languages the website got translated from the start.
- latitude 13y agoOh, I see you helped yourselves to my Secure Chat logo - http://dribbble.com/shots/479881-Secure-Chat http://dribbble.com/shots/479881-Secure-Chat http://logopond.com/gallery/detail/165288 http://logopond.com/gallery/detail/165288 https://www.google.ca/search?q=secure+chat+logo https://www.google.ca/search?q=secure+chat+logo - first page hit too Not cool at all, "cool guys around the world". -- (edit) Regardless of whether this was copied, over-inspired or independently conceived (but let's be realistic here), the generally accepted rule of the game is that the first to the finish line gets to keep the logo. I don't make my living with logo design, but I did kill a week of sketching, refining and re-balancing on this one and I do happen to like it a lot. For what it's worth, I wrote a P2P VPN system in the past (called Hamachi) and I am involved in p2p and crypto domains in general. So I expect you to extend some professional courtesy, change the logo and close this matter in an amicable matter.
- gohrt 13y agoBoth your logos might look nicer if the avatar moved up and to the left to make the chat bubble look more like a chat bubble.
- Craigpd 13y agoThen it would not look like a keyhole. :(
- sehrope 13y agoVery nice logo by the way. Took a second glance to see the speech bubble at the top but once you do it's beautiful.
- talles 13y agoMaybe it was just a coincidence..? Nice logo by the way.
- praisewhitey 13y agoOn your second link someone posted "it's funny...i came up with the exact same mark a few months back and presented it to a client. Almost uncanny how close it was to this." Perhaps the person who made the logo for this project had the same idea as this commenter.
- hnha 13y agowhy not exchange "proper" keys when both parties are first both online? messaging that does not let me send messages to offline peers is quite useless in many cases. I would much prefe
- rodolphoarruda 13y ago"...application that allows you to connect with friends and loved ones." ...who know what to do next after they click the 'download' button and are forwarded to a GitHub page. I'd like to give the app a try, but I look at that page and I don't know where to start.
- PhearTheCeal 13y agoThe app isn't even in alpha stage yet, it was started a month ago.
- osth 13y agoQuestions: 0. How important is simplicity (modularity) to the project? 1. Will Tox work for user "idontrungentoo"? Will it compile on Solaris, BSD, etc. 2. Will the GUI be optional? If not, why is it mandatory? 3. Can Tox work without DHT? What if two users just want to call each other without connecting to tens, hundreds or thousands of strangers? If there are problems with the DHT, are they SOL? It would be good to have competing teams all working on some similar system (a Skype alternative) and then have an open bake off, instead of just idle criticism in forums like this one. This way we could see which system actually works the best instead of just theorizing about design choices and taking random anecdotes from alleged users in forums on faith.
- syjer 13y agofrom the github repo: 0: it's a lib, and there are at least 2 client being developed (ncurse and qt) 1: it currently compile on linux/os x/window 2: see 0. 3: no, but you could potentially host a "private" boostrap node and have a separate network.
- astonex 13y agoIt's funny how many focus on what are rather trivial things, the logo and name, instead of looking at the actual things which matter: the code, the security, and the idea itself.
- runn1ng 13y agoOK, /g/entoomen, I will keep saying what I said in one of your threads. I feel it's strange that your IP is shared to the world together with your public key, so it is, in this sense, anti-anonymous. You cannot even use it with Tor, because it uses UDP.
- Zash 13y agoThis is why I believe in the federated client-server model. It is much easier to build a system with a few trusted parties that a system with zero trusted parties. Eg in XMPP, only your server sees your IP address until you initiate some out-of-band p2p thing such as file transfer. Federated client-server architectures such as email and XMPP are also pretty well understood by now, especially email has been around a long time. Trade-offs, trade-offs everywhere!
- BadassFractal 13y agoI'm glad that people familiar with security and cryptography in this thread are trying to poke holes in the product. As long as the development team uses these comments as productive criticism and fixes potential issues, everybody benefits in the end.
- dkhenry 13y agoI hate to be the bearer of bad news, but if your intent is to get around NSA snooping this doesn't do that. All you have really done is made sure that your communications are target for closer scrutiny. Remember I don't care _what_ you say I care _who_ your saying it to. Once I know who is talking to who and which person might be a good source of information there are much easier ways to get that information then trying to break encryption[1] 1. http://xkcd.com/538/ http://xkcd.com/538/
- pyre 13y agoYou lack imagination. :P If the NSA is collecting everything, then it's possible to go back in time once you become a person of interest. This doesn't necessarily help you if you are actively planning something that the government is interested in, but if you become a political opponent to the NSA, they could look into your past for skeletons to blackmail you with. Who you are talking to may not give them enough information to do anything without the content of the conversations.
- dkhenry 13y agoI don't think they need the content if They can identify the participants it works even better. """ I see in 2013 you had many long encrypted conversations with someone we now know to be a pedophile, what were you talking about exactly """
- pyre 13y agoOn the other hand, if you're having an affair with someone that you have a good excuse to talk to all of the time (family friend, co-worker, etc), the content matters. Also, that "OMG you were talking to a pedo!" threat doesn't mean much of the conversations were innocuous. To make that threat, they would need a good confidence that you couldn't (for whatever reason[1]) just turn over chat logs proving that nothing was amiss. [1] E.g. The chat reveals something you want to keep hidden, even if it doesn't relate to the fact that the person is a paedophile, or maybe the logs just don't exist, etc.
- donnfelker 13y agoBrought to you by the NSA.
- thaweatherman 13y agoAnother app that is the same as good existing solutions and is an outgrowth of spying revelations. Easy secure messaging, calling, etc apps already exist and are freely available. Once Whisper Systems apps are out for iOS at the end of the summer the bases will be covered.
- D9u 13y agoAll this crap about a fucking logo? What about the technical merits of Tox?
- mars 13y agowhy not hop on the xmpp train? xmpp just lacks a great client incl. some cross device synch capabilities, but besides that is secure, decentralized, open and a standard...
- nfkd 13y agoApparently, we can't use the name "Tox": http://tox.readthedocs.org/ http://tox.readthedocs.org/ Here are the most liked alternatives proposed on anther thread: tala whispr mila aspis orwell nota extasi eave fabula
- scdoshi 13y agotala: I'm guessing you know it means 'lock' in Hindi? http://translate.google.com/#en/hi/lock http://translate.google.com/#en/hi/lock
- e12e 13y agoAlso "[to] speak" in Swedish, and in certain Norwegian dialects, one of the official written forms of Norwegian[1], and in the old Norse language. [1] it's complicated.
- snowfox 13y agoWow how did you get it translated to so many different languages?
- mylorse 13y agoCan anyone convince me why I should contribute to this project when I can already use the following?: [[bitmessage.org][Bitmessage]] [[freenetproject.org][Freenet with a chat client]] [[gnunet.org][GNUnet with chat]] [[i2p2.de][I2P-Messenger]] [[retroshare.sf.net][RetroShare]] PS You could also apply a simple Icecast and/or MPD video stream under those proctols, even [[stomp.github.io][STOMP]].
- codebeaker 13y agoWhilst we're bashing them for IP theft, can anyone tell me why they're using the Github Octocat logo for their “Freedom” point? It doesn't appear to link to Github?
- xymostech 13y agoThey host their code on github. If you scroll about 100 pixels down, they say that. I'm not sure whether that's still okay (the not linking part) but they're not just randomly using github images.
- floor_ 13y agoThey're pushing the hell out of this on the /g/ technology board on 4chan. I wonder if large group chat rooms will be a new way of sharing files over secured/private connections.