6 ms·
Please authenticate with something that's not a phone number! I guess that's the simplest for most people (look at WhatsApp), but the reason why I use things li
by autodidakto 12y ago
Please authenticate with something that's not a phone number! I guess that's the simplest for most people (look at WhatsApp), but the reason why I use things like Signal is because I despise cell carriers. I'd like to use this on a (cheaper) non-cellular device (for myself and family members).
The Holy Grail of Secure Communications: Group Encrypted Text, Voice, and Video. Right now, Skype gives you the unholy grail, but you get all three (+group). I wish Open Whisper Systems luck.
- dublinben 12y agoTo my knowledge, Jitsi fulfills your Holy Grail of Secure Communications requirements. It certainly much more trustworthy than Skype.
- joeyspn 12y ago+1, and also uses zrtp
- jitl 12y agoNeeds to be quality on mobile too.
- dublinben 12y agoIt's all standard communication protocols. You can use any mobile client you want.
- zeeed 12y agonice. it requires a 3rd party FB, Google, AIM, ICQ, ippi, iptel or MSN account but it says they optionally use OTR. Not 100% secure IMHO but close. Why do they have to rely on a 3rd party for authentication? This still gives (at least, if you manually enable OTR encryption) the connection data to the service providers.
- sspiff 12y agoYou can get away with any old XMPP account, provided that your contacts are either on the same network or your network and theirs are federated. This used to be the case with GTalk, but sadly isn't anymore.
- imaginenore 12y agoYou missed the main holy grail requirement: open source. Nothing closed source can be trusted.
- bellerocky 12y agoComplete transparency from end to end would require more than just open source. You'd have to be able to build and run the software itself, which on an iPhone costs $99 a year to do and poses significant technical challenges. To go further you'd have to transparency at the hardware level as well. Your own device, built by you, with software you compiled yourself. Maybe then you'd achieve the level of security that you're aiming for, assuming you are competent enough to evaluate the software and hardware you are using.
- rdtsc 12y agoIt wouldn't be for iPhone. For Android it might work but you'd need a hardware platform you trust (one where you are sure no radio baseband processor is going to snoop at your memory any time it wants), use AOSP and then an open source app. Then also if there are any registration or routing services those would have to be open source as well.
- nobbyclark 12y agoHow do you know that the app published on the App Store is the same one you have the source code for? Can't I can just give you some source code then release something else entirely?
- lifeisstillgood 12y agoI could compile the source for iPhone (well someone could I have no idea. Probably some SDK). Then compare hashes.
- khc 12y agoActually you cannot. Rebuilding from the same source almost never yield identical binaries.
- ozmbie 12y agoWhy is it so hard to find cross-platform, encrypted group chat? Surely there's a market for it.
- dscrd 12y agoThese guys have been trying for as long as I think http://silcnet.org/ http://silcnet.org/ I would assume that the problems are more difficult compared to simple P2P.
- chatmasta 12y agoThe market exists, but it's in its infancy. The Snowden revelations blew a hole wide open in the privacy market, and that's why you're starting to see more and more privacy companies opening. I suspect it won't be long before one of them (whisper?) offers a cross platform, encrypted group chat like you speak of. But these things take a while to build.
- zeeed 12y agoif mobile/tablet-only is OK, try wickr (wickr.com). It works fairly well for me. They have a $100.000 bounty for someone who manages to break their code/get communication contents and they're sponsored by the EFF. The downsides are that it's closed-source and that there's no desktop client (yet).
- Nursie 12y agoThe announcement here says that Signal will support text messaging compatible with TextSecure later in the summer. I've been using TextSecure on android for some time, group chat is part of it.
- subbz 12y agoI agree with that but to bring encryption close to end-users you will have to use something that's simple and everybody has. Said that, I'm aware of the disadvantages - they should provide an alternative to the phone number too.