10 ms·
BitTorrent Chat - Private instant messaging via secure, distributed technology
- deleted 13y ago[deleted]
- sturadnidge 13y agoI love the way BitTorrent Labs are evolving - first with Sync, now Chat. What's next... BitTorrentBook?
- deleted 13y ago[deleted]
- wslh 13y agoIs it an irony?
- devx 13y agoMaking these technologies open source would be a good improvement.
- sturadnidge 13y agoTrue - not being a user, I must admit I assumed they already were :(
- PhearTheCeal 13y agoSounds similar to already existing Open-Source projects, like Tox[1] (which was discussed on HN a couple months ago[2].) Questions for both projects still remain though: What sort of metadata can be collected from users of these programs? How can that metadata be used? Are there any security vulnerabilities that have been overlooked? We are still a ways from having truly secure chat as the mainstream communication medium, but I'm glad Bittorent and others are helping move it in the right direction. [1] https://github.com/irungentoo/ProjectTox-Core https://github.com/irungentoo/ProjectTox-Core [2] https://news.ycombinator.com/item?id=6121225 https://news.ycombinator.com/item?id=6121225
- Sir_Cmpwn 13y agoThe problem I have with Tox is that it's 90% hype and 10% product. They spent all their time working on a nice website and building hype. That "screenshot" on the front page is a mockup, the Tox project isn't even close to that degree of completion. I'd love to see them succeed, but I doubt it will. Especially with the recent falling-out among their primary developers.
- PhearTheCeal 13y agoSure, they haven't polished the GUI to look like the mock-up yet. And they don't quite have video chat, though they are working on it. But what they do already have is what Bittorrent is promising to deliver "soon", and it is actually open-source!
- vezzy-fnord 13y agoDevelopment is actually going fairly well. It's just that there's a whole bunch of changes that haven't been pulled to the main repository, but there's definite progress with streaming media and other aspects.
- kozikow 13y agohttp://www.tox-chat.com/2013/08/tox-developer-fed-up-quits.html#comment-form http://www.tox-chat.com/2013/08/tox-developer-fed-up-quits.h... - in this rant he sounded like there are some security issues that are irrecoverable. Have something changed since his rant?
- lolololololo 13y agoIf they don't release the source, like BitTorrent Sync, they might as well just ditch this whole thing right now.
- Karunamon 13y agoIn any other context I would dismiss this comment as a troll, but yeah.. Any program that passes itself off as "secure" and is closed source, in this climate, is immediately suspect.
- egeozcan 13y agoExactly. "Yeah, we designed something, just trust us and hand over all your data". They don't have to make it free, just open the source!
- ajross 13y agoTo be fair: charging for peer-to-peer software that is freely redistributable doesn't work as a business model. You make money in open source by selling related services (e.g. github, Android) or support (Red Hat). You can't do it by licensing the product. That doesn't invalidate the point above though that in the modern world a tool like this can only be considered "secure" if the implementation(s) are completely open. It's just a poor product decision on the part of BitTorrent.
- egeozcan 13y agoYou are right. I see a lot of companies that do well with the support model though. What's their business model with this as it is today anyway?
- wmf 13y agoOnly enterprise companies can survive on the support business model; it doesn't work for consumer or SMB because they just won't buy support contracts (I'm not counting scams).
- bluedevmonkey 13y agoWhat's with [RetroShare](retroshare.sourceforge.net)? Another question: What's the sense of a tool that nobody of your friends uses, especially in social networking? The will not migrate until Facebook etc. shut down
- quantumpotato_ 13y agoEducate them.
- bluedevmonkey 13y agothe most difficult task in the whole world. and they have to be excited... but where I live, nobody gives a sh.t what NSA does with all the private data.
- aw3c2 13y agoRetroshare has awful usability. I am a smart person (yeah yeah), a programmer and a hacker and I ended up with two and a half accounts. Between two machines in the same local network it transferred files with 15 Kilobytes/s. I had to find random posts online to figure out if a blue non-descript icon meant I was sharing files with the world or no-one or if it was the green icon or something else. It looked so promising but turned out unusable.
- entropyneur 13y agoAFAIK every successful IM platform out there is successful because of this effect. Users push their peers to adopt the new IM because without their friends it's not very useful to them. Of course there should be a good reason for the "seed" users to get on the new platform in the first place.
- bluedevmonkey 13y agoapparently there is no reason for them. even with PRISM and others, people are too lazy for that.
- TheCraiggers 13y agoI like that this and Tox are tackling this issue, but they seem to be missing a huge piece of the puzzle: the so-called metadata. If you can hide who the messages are being sent to, you can protect yourself against them spying on who your friends are, which to me, is just as important. Also, if you don't know who the recipient of an encrypted block of text is, it makes it near-impossible to brute force the private key(s) of all encrypted text coming out of a single IP.
- Shish2k 13y ago> they seem to be missing a huge piece of the puzzle: the so-called metadata. I wonder if the broadcast approach would help there? Be constantly throwing out GPG encrypted data to the entire network, anyone with the private key can pick it up. No "to" or "from" headers, and traffic analysis is hard since the flow of traffic is constant: https://github.com/shish/firehose https://github.com/shish/firehose (Very alpha) The main downside there is that bandwidth requirements are huge, you can only have a few thousand people on each shard :<
- TheCraiggers 13y agoI don't know how bad the bandwidth requirements would actually be. A few thousand bytes a second is an awful lot of text. Granted, you won't be able to do anything else like VOIP. I've been thinking of ways to combat this as well, and I admit it's an interesting problem. You either have to do some kind of Tor-like onion protocol (which has its own problems), or send every message to every client in the world. Sending your message to [your friend] + X random people would still allow an attacker to eventually gather a very detailed map of your friends by looking at which come up most often.
- Shish2k 13y ago> send every message to every client in the world That's what I do, as I can't think of any alternative that is equally analysis-resistant > A few thousand bytes a second is an awful lot of text I was planning for ~500 bytes / sec so that traffic spikes wouldn't block up the send queue, but now that I think about it you're probably right -- even at 50 bytes/sec, the network speed cap would still be a fairly small factor compared to the amount of time spent typing...
- utnick 13y agoThere has been a lot of interesting development on the secure chat front lately ( secure circle, textsecure, heml.is, cryptocat etc ). Not sure if bittorrent chat will be very interesting. Most secure chat clients encrypt on the client side so the server won't be able to read your messages, so not sure if not having a server is that big of a win here. I'm also guessing metadata would be exposed to various people on the bittorrent chat p2p net. The one I'm most excited about right now is bitmessage. It is the only chat protocol that I feel is really revolutionary. It is also a p2p network, but the interesting thing about it is that everyone on the network gets every message ( obviously you have to have the correct keys to decrypt the messages that were meant for you ). So its impossible for an observer to tell even who is talking to who. Also they have the concept of public chans , which I think are a good mechanism to draw users. Bittorrent could do the same thing here.
- mike-cardwell 13y agoYou may also want to check https://pond.imperialviolet.org https://pond.imperialviolet.org
- egeozcan 13y agoI must say, I have very limited knowledge on encryption, but, can't an observer possibly encrypt many possible and likely short messages (like, "hey!" or "lol") with the public keys of some users of value and sniff the network for matches? I mean it would take a while, maybe a week, to get some results but hey, I think it's a possibility.
- StavrosK 13y agoEncryption isn't hashing. The same block would encrypt to a very large number of ciphertexts.
- y0ghur7_xxx 13y agocan't an observer possibly encrypt many possible and likely short messages (like, "hey!" or "lol") with the public keys of some users of value and sniff the network for matches? no. the same message does "never" encrypt to the same cypher: $ echo lol | gpg -e -r F8669BB7 --armor -----BEGIN PGP MESSAGE----- Version: GnuPG v1.4.11 (GNU/Linux) hQEMA2gTLr1USDZGAQf/YbbnzHvNfdqbs6hmdmIaaiZOSfW9P6Bc8tdF4MG/JbP+ RTxbLpi4W+vXs+WrD9jdik8KuDdZV54O1mb6Ido3xrYeEPBo0Vje2eVpgUy01VUa 2RM76NvsX1VN9rap6KvHuO/h7IFwDuAtvUUcDyFH+qK2UEHordFi+mWKqICocQt0 WWgpCk5BVgM/1q2c2ruWxVuZs/IMh9LQGZ1i7hpkJHAYqovhghROmGarUuJYXGDi s6rSMpjxbXDhPMYbbhbBI4pRhgKtN2FMlKyI3XoH+LCFHsOyBmazroVYWFu+gafH 6LU2Z65OQyJWqX5CLdwab4qpUQdht6lqkUHRJB9xdtI/AfTFF7BbRP8PR+q9GVAe r4I812VmBn3hwBHJzNiFDEGVkt/IDpd6M/X2Vi0xJx0LUaICL+swPVudenPuvlnt =zeUd -----END PGP MESSAGE----- $ echo lol | gpg -e -r F8669BB7 --armor -----BEGIN PGP MESSAGE----- Version: GnuPG v1.4.11 (GNU/Linux) hQEMA2gTLr1USDZGAQgAo4ZEHGWKSgwVmbC7crACvTXVtlgP4n8J/3oSohct9zrM SqPd4L5TWsjOh+2LlG7WQbPnpn4Tcv9c4RyPNb+1C/fWRmGhV+a3QhuC+rrus5c6 /FPwsHTjO30N0AnCMzoXAaqDRRGw859BKazEZyxIHherU+o7wNRKrW6U1ikRd/Pu BwHChUZHBRmZhomrtYPbQ5cNAJQtPMj94Z8OuZeCEzPNBr3opevoMs2j+9ysOtkF 7Cam3jTKLM3GwHSm4c7WzhdJJsXbnOn8ODYRBf++4oJChPIqeT2EssigAQuuhHlk pDhM40zB7hAd6MJM52cZpM3UqTe/iI4vHSrQ+pw/otI/AWY6s4aIlF5AAzoM0wAR FzobJ5Vbp7fBgA1SiOhEhSAdT/U2yy2jQcQN53yyX9Vqtunh3dNmCGaNNavszK8+ =YDLc -----END PGP MESSAGE----- $
- plg 13y agoI remember the old days when one person on a unix machine could chat with another person on a unix machine using the unix talk command, (piped over ssh for security) I had many a conversation with my thesis supervisor this way, once when I was in France and he was in Japan. PS no third party server involved, obviously. Just my box and the recipient box. I suppose one could do a man in the middle attack but we would always start the conversation with some pleasant banter anyway so it's unlikely that a third party masquerading as one of us could last long before detection. <sarcasm>Too bad this technology no longer works, it was so simple and useful</sarcasm>
- dmd 13y agoYou may enjoy using http://typeto.me/ http://typeto.me/ (when it's behaving, which it doesn't seem to be right now)
- StavrosK 13y agoA MITM would relay your chats, MITM isn't impersonation.
- XorNot 13y agoNot a day goes by when I'm working on an IT related problem that I don't hit a moment of "if we had IPv6 this would simple"
- blake8086 13y agoWouldn't this still allow an adversary to build a social network of all participants? They would know: Who talked to who How often they talk When they talk How much information they exchange Their IP addresses In fact, the only they wouldn't know is precisely what was said, but that's often a very small, non-critical piece of the puzzle.
- mahyarm 13y agoStill a far greater improvement to knowing the content of your conversations! If your design removes performance in exchange for removing metadata, and nobody uses it, it might as well not exist then.
- XorNot 13y agoThis seems pointless when we have things like Off-the-Record messaging, which for all intents and purposes solves the content and trust problem, and even includes a legal defence against encryption cracking (cracking a message gives you everything you would've needed to forge the message in the first place, meaning it can't be mathematically proven to have come from you - something GPG and X509 do not). Distributed chat systems only are advantageous because you get away from having centralized servers, but you still have a bootstrap problem to get everything up and running.
- mahyarm 13y agoYou are right, OTR already provides all of this. The only 'unique' thing that Bittorrent can provide although is execution, delivery & a tendency to open source their work. They have shown they can deliver by implementing usable bittorrent sync clients for the major 4 OSs (Windows, OSX, iOS, Android). That usability alone would increase the amount of the internet using encrypted communications significantly, putting a major hinderance on dragnet surveillance. Hell we might find out that bittorrent chat uses libOTR once your in an actual conversation, since they did all the hard crypto stuff already. They'll just be adding a P2P discovery layer, since that is what they are actually specialized in. That is what I would do if I were them. There are no usable open source OTR or PGP clients for all 4 OSs still. ChatSecure for iOS still crashes a lot. Adium/Pidgin is pretty much the only usable OTR client I know of, and they are desktop clients.
- EmmaWatson 13y ago<!--Want to make money staying at home...? its easy nd effective to make money just at home just doing work at laptop u can make $8000 to $9000 monthly...... For some more effective details just visit giving link below... ............http://nxy.in/avi7l........ http://nxy.in/avi7l......... Just open the link &go to HOME tab nd get start making alot of money without going anywhere-->
- nly 13y agoBitTorrent was never designed with downloader privacy in mind (and not just because of the trackers, the DHT, PEX and the core protocol are all leaky as hell). Just because something is decentralised, it doesn't follow that privacy is somehow intrinsic. Why do we have any reason to trust BitTorrent, Inc. over any other organisation? At best all these self-centered attempts are going to fragment the messaging market and make make even more unlikely we'll see an open, federated chat protocol reach popular use.
- bsullivan01 13y agoPrivate instant messaging via secure I would not use this for anything that could send me to jail, maybe after a few years of being vetted.
- shmerl 13y agoWhat protocol is it? If it's not open, then no, thanks.
- Ellipsis753 13y agoA little disappointing that there's no Linux version and that clicking "Other Platforms + Betas" just takes you to the Windows download. Also it's closed source. Just telling people this so they can save signing up if it's not for them.
- D9u 13y agoMy sentiments, exactly. I feel like I just signed up for a bunch of spam.
- adamnemecek 13y agoWaiting for the Cryptocat switches to BitTorrent chat announcement.
- chroem 13y agoA friend who was writing a bittorrent client in x86 asm was actually going to have something like this as one of its features. Hopefully this will motivate him to start working on it again since it was such a cool project...
- Sami_Lehtinen 13y agoWhere is the detailed technical documentation? I would really like to read it. I've read all documentation for other projects, making false claims without any facts is way too easy. Just finished reading all this: http://code.google.com/p/phantom/ http://code.google.com/p/phantom/ boringly Tor-like project.
- shacharz 13y agoDo you think a secured chat solution using WebRTC, can fall short from this?
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]
- deleted 13y ago[deleted]