8 ms·
Show HN: Free, instant, secure, disposable chat rooms built in Go
- janoelze 11y agohn chat time! https://niltalk.com/r/bfT9W https://niltalk.com/r/bfT9W, hn-923732
- gnoupi 11y agoDisposing of the room does remove it and kick everyone out, indeed. And then the link is invalid. Neat. According for the privacy page, it's all living in RAM only, so in theory there is no logging (https://niltalk.com/pages/privacy https://niltalk.com/pages/privacy). Guess we can check the code and see for ourselves, of course.
- grey-area 11y agoThe dispose button is far too inviting where it is. I started to click it thinking it was the submit button till I read the text. Perhaps put it somewhere top right or someplace other than right beside the input box, also, it's kind of weird that there is no admin for the forum, so any participant can delete it I assume? Cool project though.
- knadh 11y agoYes, that's by design. These rooms are meant to be completely ephemeral and private amongst small groups of peers. It's critical to ensure that anyone who is connected is able to quickly dispose of the room for security / privacy reasons. Once a room is created, there is no "admin" or "host" per se, just a short lived private space.
- grey-area 11y agoIt's critical to ensure that anyone who is connected is able to quickly dispose of the room for security / privacy reasons. And if you're not a small number of trusted participants (e.g. anon participants, not all of whom you trust, or enough people that one might make a mistake or delete before everyone is ready), that's not going to work. See the example forums being created and deleted above. They could easily allow two passwords on setup though to avoid this - one for admins, one for posters. On the button placement, it really would be better elsewhere - it is not related to the text submission entry, so it belongs at top somewhere, along with the sound, which again is a forum-level setting.
- icebraining 11y agoGuess we can check the code and see for ourselves, of course. Alas, you can't really know if the code on Github is actually the same running on their servers.
- knadh 11y agoAuthor here. I concur, just like any other open source software running as a hosted service. It has to be trust based.
- akerl_ 11y agohttp://www.daemonology.net/blog/2012-01-19-playing-chicken-with-cat-jpg.html http://www.daemonology.net/blog/2012-01-19-playing-chicken-w... It doesn't need to be trust-based, and in fact shouldn't be trust-based, because even if I trust you, I also have to trust the people who could coerce or bypass you, or people who could maliciously access/modify your systems. This is why end-to-end encryption is really the only way to make promises as a server about not reading / storing logs.
- janoelze 11y agolooks like the room got deleted. hn chat time over!
- fmstephe 11y agoIs this open-source? If it is could you post a link to a public repo. Thanks :)
- gnoupi 11y agohttps://github.com/goniltalk/niltalk https://github.com/goniltalk/niltalk
- knadh 11y agoAuthor here. Yes of course - https://github.com/goniltalk/niltalk https://github.com/goniltalk/niltalk PS: The "source" link is in the footer of the website as well.
- fmstephe 11y agoMy apologies for being so unobservant :)
- pierrec 11y agoWait, you're the author but someone else submitted it as "Show HN"? That's... not how it's supposed to work, but hey, at least you're in the thread. Here's another room (pass is dontclickdispose): https://niltalk.com/r/8L5MD https://niltalk.com/r/8L5MD
- jobigoud 11y agoAnd it's gone. Last messages were about how the Dispose button is conspicuous and easy to press by mistake.
- harel 11y agoI'm curious to see if this takes off, how long before the powers-that-be start to say something.
- icebraining 11y agoIf the powers-that-be are annoyed, they'll just require the Niltalk operators to log the messages. It's not like they're encrypted end-to-end.
- SatyajitSarangi 11y agoYou can checkout the public repo here: https://github.com/goniltalk/niltalk https://github.com/goniltalk/niltalk
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- hurin 11y agoAnd this is secured how exactly?
- gnoupi 11y agoPassword-protected and no public listing, I assume. Nothing on secure data transfer, though.
- rurounijones 11y ago> All communication happens over SSL. Niltalk doesn't record or log IP addresses, messages, or peer handles anywhere.
- knadh 11y agoMessage transmission is over SSL with no logging anywhere.
- hurin 11y agoYes except it's all plain-text on the server?
- chinathrow 11y agoIn RAM only, it looks like. But yes.
- knadh 11y agoYes, there is no end to end encryption as of now, although there is no persistence or storage of any sorts on the server.
- jfindley 11y agoThe number of bcrypt rounds is extremely low, too[1]. While the Go bcrypt lib will actually accept a cost of 5, that seems an unreasonably low value to me. Coupled with absolutely no encryption of the messages in memory, I think "anonymous" would be a better term than "secure" for this. 1:https://github.com/goniltalk/niltalk/blob/master/api.go#L75 https://github.com/goniltalk/niltalk/blob/master/api.go#L75
- attilak 11y agoNice idea, sadly only as secure as https.
- eliaskg 11y agoAs all clients need a password to enter a room, the messages could be encrypted with that password. There are a lot of JS libraries that could do this, e.g. Triplesec
- icebraining 11y agohttp://matasano.com/articles/javascript-cryptography/ http://matasano.com/articles/javascript-cryptography/
- knadh 11y agoAuthor here. Right now, it's only as secure as https, but I'll look into JS encryption. It's just a fun project that came out of some Go experiments.
- lclarkmichalek 11y agoStill would only be as secure as https if the client is downloading your JS crypto lib every visit.
- untilHellbanned 11y agoThis is an awesome service. Thanks for making it available to everyone. Can I ask what the use case is for this? I talk to my friends using FB messenger or Google chat and my customers using a chat widget on our site, so I'm curious when I would use this.
- knadh 11y agoThanks! Use cases could be, quick private convo. at a workplace, taking a discussion on a public forum private (like HN or Reddit), talking to strangers (eg: Craigslist) without adding them to your FB or Google Talk, exchanging secrets with your friends without leaving logs on your Google talk etc. :)
- gnoupi 11y agoThe problem with taking a discussion from a public forum private, is that in the current state, everyone can choose to dispose of the room. As proven in this very thread, it doesn't really work. The idea that everyone can dispose of the room is interesting, but there probably should be an option so that only the creator (or the first to join) can dispose of the room, for such public place cases.
- knadh 11y agoIt's actually meant for small group of people to have private conversations and is not really ideal for take a huge public discussion private. The idea of marking a peer the creator or making the first peer an owner complicates the whole privacy and security aspect.
- gillianseed 11y agoPerhaps an option where a majority of users (if more than two) need to opt for deleting the room ?
- arfliw 11y agohttps://niltalk.com/r/h8XLk https://niltalk.com/r/h8XLk pw hnchat don't delete the room! lol edit: this doesn't work on a public forum. some asshole always deletes it.
- panamafrank 11y agofirst off... this is great! I wonder if you could make it so when you create a room, you can attach a message. So for instance i could generate a password then sign it with my partners public key then paste that in the message box so theoretically only they could get access to the channel. and and, create rooms that are meant for someone, so their public key is the index and their private key decrypts the message to get the password into the channel.
- knadh 11y agoThanks :) Public key encryption is definitely a good idea and could be an optional feature for an upcoming version.
- deleted 11y ago[deleted]
- DanBC 11y agoHave two buttons: "vote to keep open" and "vote to close". Colour them orange and blue. Release it to Reddit. Potential viral hit.
- addandsubtract 11y agoHave one button. Release to Reddit. Potential viral hit.
- zatkin 11y agoFor anyone who doesn't understand this reference, there is a massive social experiment going on at Reddit: https://www.reddit.com/r/thebutton https://www.reddit.com/r/thebutton
- hiddentao 11y agoGood work. Though I have to say I've seen so many of these web-based "secure, private, anonymous" chat services now, I've lost track. What we need is end-to-end encryption and with an open source client that just has to be downloaded and built/installed once (and in such a way that it's verifiably secure, think reproducible builds).
- knadh 11y agoAuthor here. This is meant to be something super simple and instantly accessible. Start and finish a conversation in mere seconds if need be with no traces. I am sure downloaded clients with end to end encryptions exist, but it's definitely outside the scope of something as simple as Niltalk.
- bhayden 11y ago>no traces Is a secure platform really worth anything if it's unverifiable as secure? We have no way of knowing there are no traces left.
- new299 11y agowhy does the client need to be built locally? Are you inherently suspicious of anything delivered over HTTPS? I'm genuinely interested in why people feel local clients are more secure than something running in a browser. It's something I came across when writing an ssh client in browser (www.minaterm.com). I guess it's the potential for a HTML page to updated overtime so it no longer reflects an audited version. However it seems that it's really a failing in our browsers that this is the case. Perhaps an external service that verifies the hash of a page would help? But this would need browser support of course. The only thing I could think of that could be implemented in current browsers was a small stub page which calculates and displays a hash of the HTML/Javascript to be launched. The stub would need to be small enough that a user could manually check that nothing malicious has been added here.
- icebraining 11y agoIf the code can't change, what's the point of having it be delivered through the browser each time? Aren't you better off saving the bandwidth by downloading it once?
- sgt 11y agoTo make it even more instant (in terms of UX), I would display the message immediately so you don't get the little delay. From where I'm at, it's about 250 milliseconds from the point I hit ENTER to when I see the text displayed.
- knadh 11y agoAuthor here. This is how it was meant to be but I somehow overlooked it. Thanks, will implement.
- jrussbowman 11y agoI've been killed kicking around the idea of doing something similar, in go, with the domain I own ChatFor.Us JavaScript encryption, as others have mentioned is the thing I see I was planning that's missing from yours. I'm planning on going a different direction with the domain, this functionality for private messaging for a platform set up for chat rooms as well. Right now though I'm investigating a node.js and rethinkdb infrastructure, but that's also because I will need to persist data somehow. Thanks for building this, at least validates that someone else has similar ideas.
- jrussbowman 11y agoNot sure how the word killed got in there. Typing on phone
- knadh 11y agoNice. From my crude and unscientific benchmarks, I've found that Go is able to handle a lot more concurrent WebSocket connections than Node.
- jrussbowman 11y agoI assumed it would. But I'm thinking socket.io would provide better client support and have been looking at meteor as a way to get something built fast. Going Roth a prototype first as I have a lot less time to do this stuff these days. I'm about equally proficient in both go and node which is to say I can stumble my way to a solution with both.
- Fastidious 11y agoHow one runs this? I installed go, and redis. The ran "go get github.com/goniltalk/niltalk", which installed. The previous command created three directories under my $GOPATH, one on which has a 'nilktalk' executable. For someone who has never dabbled with go, how do I run nilktalk after all of the above was done?
- icebraining 11y agoThe README has the full instructions. Edit the file config.json and then do "./run" on the terminal.
- Fastidious 11y agoThank you. More on the installation steps on an, now closed, issue[0]. [0] https://github.com/goniltalk/niltalk/issues/3 https://github.com/goniltalk/niltalk/issues/3
- 8rian 11y agoI only feel safe using end-to-end encrypted chatrooms. Currently, niltalk can read every message. At the very least, AES encrypting messages by the chatroom's password will reduce reliance on SSL. But it really should use public key crypto for a key exchange between users. This is what's done by other disposable chatrooms: https://crypto.cat/ https://crypto.cat/ https://ephemeral.pw/chat/ https://ephemeral.pw/chat/ (Also written in Go)
- hurin 11y agoThe problem with end-to-end encryption is not the encryption but the key-exchange (and especially so for multi-user setups). If you are trusting the server to create or associate identities with keys, the end-to-end encryption is easily subvertible.
- 8rian 11y agoNew keypairs would be generated on the client every time you join a chatroom. Another member of the chatroom sends you the shared_key encrypted by your public key. Server knows nothing, stores no keys. Keys exchanged between users. Javascript crypto is still a problem though: http://matasano.com/articles/javascript-cryptography/ http://matasano.com/articles/javascript-cryptography/ When you re-download the codebase on every use, there is no way to ensure integrity of the code. This is the reason cryptocat ships as a chrome extension, because it is downloaded once. Even with these issues, I'd take javascript crypto + open source over nothing (or just SSL).
- hurin 11y ago> New keypairs would be generated on the client every time you join a chatroom. Another member of the chatroom sends you the shared_key encrypted by your public key. Server knows nothing, stores no keys. Keys exchanged between users. The question is - how does the first public key exchange happen? It has be done outside of the site for it to be secure and your private key must exist locally on your device - which is contradictory to the premise of these websites.
- paulspringett 11y agoReally interesting to read through the source code and get an idea of how you're using Go to write APIs, thanks for sharing!
- knadh 11y agoDeciding on a pattern on writing http APIs in Go was a bit of chore. Ended up using the `pat` library for chaining middleware. Quite extensible and light weight. Also, using context to pass objects through the requests chain is a neat trick.
- pinjiz 11y agoThis site uses insecure 1024 bit Diffie-Hellman parameters for Diffie-Hellman key exchange! Please fix!
- pinjiz 11y agoWhy was this comment downvoted? The NSA has built custom hardware to crack 1024 bit DH in a few days[1], so the site owner really should regenerate the DH parameters and use 2048 bits. It would also be nice to disable 3DES ciphers and only allow ciphers with forward secrecy. [1] http://blog.erratasec.com/2013/09/tor-is-still-dhe-1024-nsa-crackable.html#.UipD1z9Bx8E http://blog.erratasec.com/2013/09/tor-is-still-dhe-1024-nsa-...
- kichuku 11y agoI have opened a room. https://niltalk.com/r/8CKyw https://niltalk.com/r/8CKyw I am not going to tell the password though. Let's see how long it lasts!
- BorisMelnik 11y agoHave you been measuring the server load of this at all since this thread has been open? Very curious as to what that looks like.