4 ms·
Our threat model is an attacker that wants to read and record the contents of conversations between everyone, they have the ability to modify/add/remove and log
by irungentoo 12y ago
Our threat model is an attacker that wants to read and record the contents of conversations between everyone, they have the ability to modify/add/remove and log any packets. We assume they do not have any access to the actual machines Tox is running on.
The main goal of Tox is to make it hard for a global threat to conduct mass surveillance on everyone at the same time without sacrificing performance.
If the majority of the people using Tox have "nothing to hide" and use it because it works better than skype, the minority that does need the crypto will be able to use it without being discriminated against.
- dredmorbius 12y agoThanks, that's a nice and concise statement. NB, a comment by Peter da Silva, who's been doing networking / communications / security stuff for quite a while: "Don't like the callback model in the API, they need a version of tox_wait() that takes a select() fd mask." https://plus.google.com/u/0/104092656004159577193/posts/MDYUCSjcjQd https://plus.google.com/u/0/104092656004159577193/posts/MDYU...