5 ms·
BitTorrent Chat: The Want For Privacy
- drdaeman 12y agoThere's no technical info in the article. This one (link from the article) seems to be more resourceful on details: http://engineering.bittorrent.com/2013/12/19/update-on-bittorrent-chat/ http://engineering.bittorrent.com/2013/12/19/update-on-bitto... The interesting part is their claim they somehow made DHT public key to IP discovery (mapping) "encrypted" and "secure". Sadly, I hadn't found any further details.
- Mandatum 12y agoIt would still require centralised servers for the mapping, in which case wouldn't it become immaterial?
- AnthonyMouse 12y agoUsing a public key to authenticate an IP address is trivial. You just sign the address (and a timestamp for how long it's valid) with the private key. Making it private is the interesting bit. Obviously you can't have privacy in the sense that someone who knows your public key can't use it to discover your IP address, because doing that is the DHT's purpose. So what they're probably talking about is that somebody observing the DHT can't use it to learn public keys, IP addresses or both. But it would be nontrivial to do that in a way that isn't useless (e.g. storing under public key fingerprint instead of public key: now you don't have my public key, and having fingerprint is totally different, right?)
- chewxy 12y agoFWIW, I wrote my own version of it not knowing about BitTorrent chat: https://github.com/chewxy/nanjingtaxi/ https://github.com/chewxy/nanjingtaxi/ It doesn't use the BitTorrent kademlia though. If anyone thinks that should be the case, feel free to send a pull request
- vxNsr 12y agoIs there Windows support in the works, or is this more of a weekend project? I would offer to help but I don't know go at all.
- chewxy 12y agoYup. Eventually. The first things I'm planning to add is some NAT and greater internet traversal stuff. Then using https://github.com/andlabs/ui https://github.com/andlabs/ui I might want to add a UI. Unfortunately my life schedule is kinda... complicated right now, so progress will be extremely slow
- zimbatm 12y agoIs this going to be open source ? Unless the code is verifiable by third parties and we have reproducible builds then trust is just transferred to Bittorrent Inc.
- deleted 12y ago[deleted]
- jamesgeck0 12y agoEven if it's not open source, that's not necessarily a bad thing. BitTorrent Sync seems to have set a bar and prompted development of open source equivalents[1]. If this gives open source secure messaging software a bit of competition, I'm happy that it exists. 1. Not that there wasn't open source sync software before, but a lot of it didn't have a gui, or was based on git, or something like that.
- x1798DE 12y agoIt's possible that BitTorrent's business model is going to change, but with the original BitTorrent, they kept the client closed source but the protocol was open, allowing for a wider variety of BitTorrent clients. It seems quite possible that they'll do the same thing for BitTorrent Chat (if not for BitTorrent sync as well), at which point an open-source client will likely be created that's compatible with the original. Either way, even if it were open source, it's new software, not stable software. Chances are almost any new software is going to be fairly leaky and buggy for some time. At the moment, I would personally trust BitTorrent chat somewhat more than Google, Microsoft, etc. to not deliberately put back-doors in their clients (not to mention it's not like those companies are claiming their stuff is end-to-end encrypted anyway, as far as I know), and I'd trust them to write higher-quality software with fewer severe exploits than many of the nascent open-source alternatives out there at the moment. That said, in a few years, I fully expect to be using something open-source for this sort of thing, whether it's Tox or TorChat or an alternative BT Chat client, and for the moment I don't plan on using any of the current "private chat" programs for anything important.
- nvk 12y agoIs it going to be fully Open Source or the same joke as Bitorrent Sync where no peer review is possible?
- navyrain 12y agoUntil there is open source and deterministic builds, this is just as functionally "secure" as Skype.
- vxNsr 12y agoWell here's the thing though, skype isn't p2p anymore, they've switched to a sever based model, is in that sense this is slightly more secure in that only those involved in the conversation have access to it.
- ossreality 12y agono they fucking haven't. god fucking damn. I get tired of combating this stupid telephone-style false story every single god damn day.
- shmerl 12y agoSkype was never purely P2P anyway.
- shmerl 12y agoYeah, just wanted to ask this. Is it going to be open? And protocol documented?
- doctorKrieger 12y agoif you want privacy you can simply encrypt your gtalk chat with gpg, another unecessary overhyped feature.
- indlebe 12y agoI think that given the relatively large existing userbase of the company and familiarity with end users it's notable. I think that end-users aren't quite ready to encrypt their gtalk chat, but could be willing to give something with an appealing UI a try (if it ends up having that).
- ffadaie 12y agoDisclosure: I am working on Bittorrent Chat. There are a few issues with using GPG over gtalk, gmail, mail, etc: 1- The metadata still exists. If you use gpg with any email server, the provider of that service knows that YOU contacted someone (and they know who that someone is). They also know "when" this happened. In fact, if metadata is not a concern, there are other much simpler solutions than using GPG. Technically speaking iMessage (or many other messaging apps) should give you the same result (well, if you trust Apple to be doing what they claim to be doing). With Bittorrent Chat, there is none of that. Bittorrent Inc. does not know who is talking to whom at what time. 2- It's difficult to use GPG (or OTR, etc) with your friends who are not technical or just don't want to spend that much time on sending a message. Honestly, I have rarely used it myself because it's just too difficult to get right both on the sending end and the receiving end. A messaging app that intends to be private is not doing a good job if everyone doesn't like it (or don't know how to use it). Privacy should be accessible otherwise people who need it the most, cannot use it. We are trying to create an app that is not only private but is in fact easier to use than other messaging apps. It has cool features (for technical users as well as non-techies) that everyone understands and can use. People should not have a "private messaging app" that they use for their "private" conversation and one that they use with their "normal conversations". Basically if you cannot say it on Twitter, it's private [to some extent]. Technical people should love it and use it with their non-technical friends and non-technical people should love it because it's just easier to use than other apps (and provides cool features that no other app is).
- doctorKrieger 12y agoif you want privacy you can simply encrypt your gtalk chat with gpg, another unecessary overhyped feature.
- unicornporn 12y agohttps://en.wikipedia.org/wiki/TorChat https://en.wikipedia.org/wiki/TorChat is open-source... Not a tough choice for me.
- synchronise 12y agoThat doesn't seem to have had much activity lately. Personally I use Torsion https://github.com/special/torsion/ https://github.com/special/torsion/
- ProfOak_ 12y agoI think there should be mention of Tox as an open source chat alternative. I'm really excited for it! http://tox.im/ http://tox.im/
- stasiek 12y agoWhy talk about it again? We're waiting like... 8 months since they've opened the Alpha Signup? =.=