16 ms·
BitTorrent Bleep Now Publicly Available Across All Major Platforms
- Cantremeber 11y agoNo mention of it being open source and after what happened with Sync I don't understand who would use this.
- azdle 11y agoWait, what happened to sync?
- rpedroso 11y agoThere was some concern about the security of the product: http://2014.hackitoergosum.org/bittorrentsync-security-privacy-analysis-hackito-session-results/ http://2014.hackitoergosum.org/bittorrentsync-security-priva... These concerns were amplified by the difficulty of auditing a closed-source product. Their argument that hashes are one-time secrets and not permanent keys is difficult to validate without access to the source.
- lewisl9029 11y agoI personally switched to Syncthing (and the Syncthing-GTK GUI) and never looked back.
- unmagnet 11y agoIt would be nice to have a simple user-tag and official-tag customizable field for tagging related research and development patterns. Every time a closed source nightmare reoccurs, we can just let newbies find the related open source alternative.
- lewisl9029 11y agoYeah I'm not sure what their target market is either. Proprietary software is fine for a lot of things, but anything concerning security and privacy absolutely requires the additional transparency and scrutiny offered by open-source. I guess they are planning to market it to people who are worried about privacy but not tech-savvy enough to be able to understand these fundamental deficiencies of proprietary software, but that just seems really unsavory to me... But then again this is the same company that tried to sneak crypto-mining software as a value added offer to their installers so I can't really say I'm surprised.
- anonbanker 11y agoDo you like Bittorrent? Do you like Chatting with others? Then You'll Love Bittorrent Bleep! EDIT: I didn't say it was a good mindset. I just think Bittorrent is trying to leverage it's name into new markets, while alienating it's core users and promoters.
- FreeKill 11y agoI'm very intrigued by Bleep, I think that attempting to leverage the bitorrent protocol in a chat platform is a unique take, that I would like to see continue to evolve. However, I think it's important that they open the source up for this project and even potentially offer the ability for me to install and run my own server. I think until they take those steps, it will be difficult for them to gain any kind of large following.
- mike-cardwell 11y agoRun your own server? From my understanding there is no server involved. It is peer to peer and peers find each other by using DHT. It's closed source though, so you have to take their word on that.
- gcb0 11y agoit's bi bittorrent. you need a tracker. how do you think one client can find another? i hope you don't think it was a internet wide broadcast... :)
- mike-cardwell 11y agoMy understanding is that you don't need a tracker when using the DHT. I'm not sure what the bootstrap method is to find the initial peers to start accessing the DHT, but once you've found one peer, it's easy enough to find more. Feel free to correct me.
- gcb0 11y agoThats nonsense. The clueless torrent news sites like to boast that you dont need a tracker for dht, just a 'bootstrap node'. Whick is exactly a tracker. Its one simple node which address is hardcoded in the clients. So, it is a tracker, just not a full bittorrent tracker.
- GutenYe 11y agoHow does it manage the offline messages without a server?
- joshstrange 11y agoI don't trust anything released by BitTorrent. Sync was a huge let down and frankly I'm not going to waste my time on any more of their software after the ad/toolbar/bitcoin-mining infested installers they put out for uTorrent...
- solomatov 11y agoCompletely agree with you. If they want it to be focused on privacy, they should at least document their protocol.
- reymus 11y agoI dont understand. Could you explain why?
- solomatov 11y agoI don't trust a product which is closed source and closed protocol. It's ok to be closed source and closed protocol for a product which isn't focused on privacy, but for the product which is it's a showstopper. Also, bittorrent did bait and switch with btsync, and had supplied utorrent with spyware. I just don't trust the company.
- higherpurpose 11y agoCare to elaborate on why Sync is a huge let down?
- black_puppydog 11y agohttps://news.ycombinator.com/item?id=8626931 https://news.ycombinator.com/item?id=8626931
- Sir_Substance 11y agoThat's as dishonest as btsyncs statement, in it's own way. Because it's closed source, we don't /know/ how secure btsync is. However, we do know that microsoft, google and dropbox will just hand your shit over if the US government asks. Something is better than nothing. The only open source competitors in this space are owncloud, who /still/ won't let me upload to both a work and person cloud at the same time, and syncthing, which I have high hopes for but which currently has a workflow so bad I think I'd rather just use a thumb drive. I've stuck with btsync 1.3.94, the version with the beautiful workflow, just before it went off the rails. It solves my need to avoid google/facebook etc. /Maybe/ it doesn't protect me from the US government, but that's still better than dropbox. I think bleep's gonna struggle, because it requires me to get /other/ people to buy into my disquiet, which turns out to be really hard if my experiments with XMPP over skype tell me anything. You know what I might actually pay for? A gateway to facebook/gtalk/skype. I'd be willing to pay $5 per month for a bleep-to-everything gateway, either from bittorrent or someone else. Half of bleeps value is simply in my not needing another account (e: I could say the same about btsync).
- lenova 11y agoI would love to hear Moxie's thoughts on Bleep and whether he thinks this is secure or not...
- JshWright 11y agoUnless they have published their source code (or at least a protocol spec), then I don't think there's much in the way of 'thoughts' to be had.
- dmix 11y agoTwo benefits over TextSecure that I can see: - Doesn't require your mobile phone number to use it - Not dependant on google services on Android Downsides: - Cant beat Textsecures crypto - Not opensource The last two points make this a no-go for me.
- higherpurpose 11y agoAnother benefit is that it's P2P, which doesn't do much in terms of privacy (although Bleep's website claims that it does somehow...) but it can help with censorship - think Turkey, Iran bans of apps and services. I think even Brazil wanted to ban Whatsapp at some point. I wouldn't consider it a top 5 priority right now, but I do hope OWS takes into consideration making Signal P2P as well in the future (perhaps with some new technologies that may appear or mature by then). My own priorities for what I want to see in Signal/Textsecure next: 1) integrated Android app 2) desktop client (ideally web/browser-based, but if that's not too secure, I could live with a native app, too, maybe one that works only through Windows 10's store for the sandbox security and digital signing benefit, as well as for the new auth features) 3) video-chat support
- dmix 11y agoRe #2: TextSecure has a web/chrome extension version in development: https://github.com/WhisperSystems/TextSecure-Browser https://github.com/WhisperSystems/TextSecure-Browser
- userisuser 11y agoWhy not use Kik? Its a more popular closed source messenger.
- mike-cardwell 11y agoKik is not end to end encrypted. Kik the company can access any message you send or receive.
- cbd1984 11y agoAnd how do you know the same isn't true here?
- mike-cardwell 11y agoWe don't know what the truth is. We know what we're being told though. And Kik is telling us that their messages aren't encrypted end to end, whilst bittorrent are telling us their messages are.
- sandebert 11y agoApparently "all platforms" means Mac, Win, IOS and Android. Not to be snarky, but that's not even close to "all", even if we exclude esoteric ones with extremely few users.
- derefr 11y agoNow available across all major app stores.
- higherpurpose 11y agoWhat's with the super weird installation process on Windows? Also very little information about how everything works on its website (the technical stuff, especially for security).
- sarciszewski 11y agoSecurity through obscurity, exhibit A. Just kidding, we know there are too many exhibits for even Unicode to enumerate.
- deleted 11y ago[deleted]
- black_puppydog 11y agoI am particularly annoyed by the name "Whisper" for the "25 seconds only" messages: It got me to read on because I thought they interfacing with WhisperSystem's protocol for TextSecure. Because, open protocols, federation and all that. Would have been nice, right? Well, thumbs down for that. Also, if you don't trust the other to not want to log your conversation, don't send sensitive stuff. But then again people do seem to like snapchat and thelike, so I shouldn't judge too much there maybe.
- robmcm 11y agoI guess it's a slight reassurance, for example if I want to send a password to someone I trust, I could do it with whisper knowing if someone picks up their phone in a weeks time it will be gone.
- baran1 11y agoWhat about Telegram?
- vonuebelgarten 11y agoDue to the general architecture, I think it's better compare Bleep with Tox.
- MichaelGG 11y agoTelegram should be avoided. They do weird things with their security and ignored criticism on it. The key verification requires checking an image, so you can't do it over the phone. Plus closed source, so you're very likely entirely depending on trusting Telegram. Their response to using AES IGM? It's along the lines of "yeah this strange mode no one uses has issues but not in the way we use it so whatever. We've got math PhDs, so trust us." I'm no expert, but I get a really bad feeling about them, since it's the totally wrong attitude to take.
- leni536 11y ago>closed source I can't comment on the other arguments, but the client of Telegram is certainly FOSS [1]. Their service being open source is irrelevant, since you couldn't verify it anyway. [1] https://f-droid.org/wiki/page/org.telegram.messenger https://f-droid.org/wiki/page/org.telegram.messenger
- pnt12 11y agoThat screenshot protection thing is kind of dumb. As they show in their website, you take 2 screenshots and there you go, name and message. You can say you make it harder to take screenshots but you cant promise a secure way to prevent people from saving the data you send them. That's unfeasible, its promotion of false security.
- cmdrfred 11y agoWhat are the limits on implementing the bittorrent protocol? A open source sync alternative seems doable (even if I had to resort to port knocking or something), maybe build it on top of owncloud and get the best of both worlds?
- spullara 11y agoThere is no way to make a service that guarantees that messages are erased with current mobile technology that doesn't allow you to make another client that saves the message. Snapchat and the FTC had a conversation about this. https://www.ftc.gov/news-events/press-releases/2014/05/snapchat-settles-ftc-charges-promises-disappearing-messages-were https://www.ftc.gov/news-events/press-releases/2014/05/snapc...
- sarciszewski 11y agoWarning: This is going to sound mean. Feel free to skip it if mean words upset you. They claim to support "all major platforms" then completely skimp out on Linux and BSD. Bleep isn't open source. They claim to provide privacy, and their testimonials read: Software Engineering at it's finest. If you haven't read the blog post on this app then you need too. Once you see how it works your gonna want it. Most secure messaging I've seen yet. That's great, now show me the source code so I can decide whether or not it's the most secure messaging _I've_ seen yet. Publish the git repository. Make it run on GNU/Linux and *BSD. Or get the fuck out and stop making claims you cannot back up. DDDD i t h TTTTT h i sss D D ttttt ccc h T h s D D i t c hhh T hhh i sss D D i t c h h T h h i s DDDD i tt ccc h h T h h i sss BBBB U U L L SSSS H H I TTTTT ! B B U U L L S H H I T ! BBBB U U L L SSSS HHHH I T ! B B U U L L S H H I T BBBB UUU LLLL LLLL SSSS H H I T !
- GutenYe 11y agoOpen source is the way to go.
- dotBen 11y agoSome things are highly valuable but just don't make sense to monetize. Bit Torrent is a great example of that. BitTorrent Inc is evidently scrambling to find a way to monetize the core technology having raised money and promised investors it would do that. They just laid off a %age of their staff, which indicates to me the end of the road might be nearing and Bleep maybe one of the last attempts they have to pull something off. I love Bram, but IMHO Bit Torrent should return to being a true open source technology developed by the community.
- Thlom 11y agoThey could potentially have sold BitTorent technology/software to companies that needs to move lots of data across multiple nodes. Instead most of them use libtorrent.
- zbyte64 11y agoI don't think that makes sense. It is kind of like selling TCP/IP before the internet age ; network standards should be just that - an open standard that is open to all players.
- leni536 11y agoSo far I know these decentralized (supposedly) secure messaging software/protocols: 1. Bleep 2- Tox 3. Ring (formerly SFLphone, DHT based authentication)
- zbyte64 11y agoAdd OTRTalk to the list: https://github.com/mnaamani/otrtalk https://github.com/mnaamani/otrtalk
- tui 11y agoI tried it for 5 mins,the encryption is freaky slow. Telegram is still my favorite private chat app
- lxgr 11y ago"Private"?
- danieldk 11y agoOne thing that is missing from the marketing copy: even if you accept a closed-source messenger and forget the whole uTorrent saga, what's the monetization model here? What costs can we expect in the future and where? (The cynic in me thinks: Bleep 2 offers many new features, buy Bleep 2 Pro if you communicate with more than 10 contacts.)