11 ms·
uTox – Free, Secure Instant Messaging
- bluesmoon 11y agoBack in 2001, the ayttm project supported free, secure instant messaging by using gpg to encrypt all messages and by allowing you to split a conversation across multiple networks (Yahoo, MSN, AOL, XMPP).
- nickpsecurity 11y agoAppreciate the tip. The Snowden leaks appear to support that GPG is so robust that even NSA analysts use it. So, a project using IM over it is playing it extra smart (albeit clunky). Turns out it's still active: http://ayttm.sourceforge.net/features.php http://ayttm.sourceforge.net/features.php
- thomasfl 11y agoWould be cool ta have FOSS iOS apps made with this.
- orange_county 11y agoThere is one in progress and should hopefully be done by the end of the summer https://github.com/dvor/antidote https://github.com/dvor/antidote
- cbsmith 11y agoWe basically have this stuff with Signal: https://whispersystems.org/ https://whispersystems.org/
- yellowapple 11y agoPart of the issue is that both uTox and toxcore are GPLv3'd, which forbids "TiVoization" (and therefore makes it legally difficult to release on, say, the App Store). A more permissive license would make that more plausible.
- belorn 11y agoWhile TiVoization would be a problem in the App Store, but its actually all the other details regarding the App Store which really prohibits using them for distribution. First off, the App Store agreement explicitly prohibit users to further distribute any software which is distributed through the store. This makes any "copyleft" licenses a no-deal in there since distribution is a defining attribute of those licenses. Second, as a matter of policy, Apple forbids developers to put any GPL software in the store. If you would dare to break the App Store agreement and the apple policy for developer, then at that point GPLv3 TiVoization clause would indeed make it further legally difficult. I would however be more concerned about being chased by apple's lawyers, so as a general advice I would be careful and make sure that any licensed software you upload is compatible with both the agreement and policy. It doesn't matter if it is permissive, copyleft, or closed source.
- nvk 11y agoSeems really cool, anyone audited this project yet?
- counterculture 11y agoyou know its good cause it offers "ROCKSOLID encryption"
- adwf 11y agoI've been using this for the last 6 months or so. Seems pretty good as a client. Stable on the comms side, although short of an audit, I'm just having faith in the security side of things. What it really needs is some way of having a roaming profile though. Currently you have to have multiple accounts, one for each device. So my friends list has a lot of duplicates depending on whether they're on their work computer, at home, on their phone, etc... I'm not actually that fussed about the encryption side of things. I'm far more happy with the lack of reliance on centralised servers. You don't need an account somewhere to get it up and running, you just send a message to a friend and compare secrets to authenticate.
- lockyc 11y agoWhy don't you copy the profile between computers?
- adwf 11y agoIt's not my computer that's the problem. He has three and has separate profiles for each. Also, asking people to export profiles and import multiple times is a bit too technical and far too much effort to ask all my friends to do. It needs to have some easy way of merging profiles cross-device. Maybe if a friend authenticates two profiles as the same person it will merge them if you agree to it. Or something along those lines anyway.
- Sir_Substance 11y agoI'm a big fan of accountless systems, but utox does need to solve the roaming profile issue. It simply cannot be used in the real world until they nut that one.
- lewisl9029 11y agoDefinitely a crucial feature, but a difficult one for any truly distributed application. I'm actually prototyping a similar distributed messaging app using remotestorage.io to try to tackle this issue of profile roaming and persistence. In theory it should allow profiles to live in the cloud (in any backend supported by remotestorage, such as Dropbox, Google Drive, and ofc remotestorage servers) and be sync'd automatically across devices to enable features like roaming profiles and simultaneous logins in a distributed manner. In practice, however, there is still a number of complications such as the need to secure the data being stored from storage providers (remotestorage itself doesn't offer encryption natively), and coordinating communications between accounts with multiple devices (network endpoints) to minimize network inefficiencies. I'm mostly done with the former and steadily making progress toward the latter, so I feel this could be something to consider for the Tox team as well. https://remotestorage.io/ https://remotestorage.io/
- tetrep 11y agoI wonder if we'll ever get to the point where projects start advertising what methods they use to weed out memory management bugs (i.e. static analysis, fuzzing, etc) because an adversary that can execute arbitrary code on my machine is far more intimidating than one that can eavesdrop (imo).
- bobdole1971 11y agoSpeaking of that, I wonder why uTox & Tox weren't made in memory safe languages in the first place. There could be many possible reasons, so I won't bother speculating.
- irungentoo 11y agoJust build it with asan and you will get all the safety, memory usage and slowness of a memory safe language.
- bobdole1971 11y agoYou'd need UBsan as well, and even that doesn't catch everything. Regarding memory usage/slowness: why not OCaml, D, or Rust?
- chc 11y agoRust only recently hit 1.0, so it's pretty obvious why somebody would not have built their software using that.
- bobdole1971 11y agoYes, my mistake.
- Jfreegman 11y agoAlso, current benchmarks show Rust to be about ~3x slower than C, making it more comparable to Go or Java.
- jzelinskie 11y agoIsn't this a project that was developed by users of the /g/ board on 4chan? I've only ever seen it berated on that board (everything is berated on that board) and don't really know how solid the actual software is.
- subjectsigma 11y agoAs far as I know, the project really only gained any traction once it distanced itself from /g/'s bikeshedding. I think in light of this the uTox team has made an effort to distance themselves from 4chan entirely. It's been a while since I read anything about them but last I heard, the crypto was fairly solid and the only problems were one of reliability and user experience; that being said, I'm no expert and we won't know until it gets popular enough to deserve an audit from someone important.
- vezzy-fnord 11y agouTox is one client of several. For a full list, see: https://wiki.tox.im/Client https://wiki.tox.im/Client
- chrismartin 11y agoWhy would I use this instead of XMPP and OTR?
- adwf 11y agoThe main thing for me is the lack of a central account server. Even with XMPP, you still need to have an account and login somewhere to authenticate. With this, you have to authenticate each friend manually, but only the once. After that, there is no account but the profile stored on your hard drive.
- nickpsecurity 11y agoThat's certainly a selling point. The problem: newer and hand-rolled stuff always has serious problems. Many continue to have serious problems over time. I'd be interested in seeing software that solved those problems while leveraging proven protocols, clients, etc. Might just be a plugin to several popular IM clients.
- lawl 11y agoIf you're worried about how good the encryption is, you can actually use Tox with Pidgin and then layer OTR on top of it. That way you get decentralized messaging and don't need to trust their crypto. https://wiki.tox.im/Tox_Pidgin_Protocol_Plugin https://wiki.tox.im/Tox_Pidgin_Protocol_Plugin
- astonex 11y agoI would use Tox and any of its clients with caution. At one point in time, your friends would be able to execute arbitrary shell commands on your PC if you were running utox and accepted a file download. Even with large security concerns like this, the lead developer believes Tox and uTox is secure because he reads the code he wrote himself (none the less git history is filled with bug fixes he clearly missed in his reading). This isn't exactly reassuring, especially coming from someone who doesn't have provable past experience in security software. Edit: I just got banned from their IRC for stating this opinion here.
- stal 11y agoStill sour you got rejected for Summer of Code?
- RottenHuman 11y agoAnd your opinion is based on what? What you just said is true for any software. Any reason why you pick out tox in particular?
- rgovostes 11y agoThe comment you replied to seems to be a fairly specific and verifiable criticism of uTox, which, like all security software, deserves to have its claims approached with skepticism.
- tux3 11y ago>I would use Tox and any of its clients with caution. It's hard to argue with that given that Tox is still in alpha, and this is generally a good idea for any software you use if you have reasons to believe that an adversary is trying to exploit your computer.
- Jfreegman 11y agouTox was not originally written by the main toxcore dev. However he and a few other brave volunteers have made a big effort to clean up uTox's code over the past few months. That's why this thread was created now and not 6 months ago.
- blucoat 11y agoSomething to keep in mind: Of all Tox clients, uTox is written in C, using its own UI framework that directly interfaces with X11 and WinAPI. This makes the code itself a mess. The reasoning behind this is that it's somewhat of a meme on /g/ that anything but pure C code is "bloat". I tried contributing a bit last year, did some work on copy/pasting inline images, and found a remote code execution vuln. Then I got fed up with how terribly confusing the codebase was for something so simple. I'm not a professional programmer or anything, just a student, but it seems like it's the same for everyone else in the project.
- kolev 11y agoGee, yet another identity nomenclature - <username>@utox.org! When will this trend end?! Aren't you tired of the ever-growing lists of identities you need to share with people?
- fastball 11y ago"Future of Instant Messaging" Not with that UI.
- dbbolton 11y agoWhy aren't the name/Tox ID requirements listed on the site? I tried registering a few times and got an "invalid" error each time.
- listic 11y agoWow, Skype must have really cemented its place in public conscience as an instant messaging service. I would think a new service should support video chat before comparing itself to Skype, but no. (I am actually seeking an open-source alternative to Skype that supports video conferencing: I know of audio clients/services, but not about video)
- Veratyr 11y agoI like the idea of Tox but there are a couple issues that make it unusable for most users (at least me and a few I've talked to about it): - No push notifications of any kind, meaning mobile devices have to keep a connection open (kill their batteries) or poll for updates (and get the message later). - No multiple device support, so I can't use my phone _and_ my desktop. I have to pick. It'll be great when it's been polished up and completed a bit more but it's not there yet.
- JackH2 11y agoi prefer software that do not need runtimes and can run without dependencies on major distros.
- JackH2 11y agoqTox please consider making static builds
- hobarrera 11y agoSo how does this improve on existing IM, say: XMPP?