Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

To me it seems like Open Whisper Systems are accepting a lot of concessions in order to have Signal included into products. The trust I once had for moxie is quickly dissipating.

* Privacy is only provided in Allo in a secondary mode. Not by default.

* Federation of the Signal protocol has been rejected for non-technical reasons.

Also, on a personal note, the desktop client requiring chrome is pretty awful.



WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages, no real ability for the servers to do anything smart, no real search functionality, desktop client that requires the phone to be on, etc.

An incognito mode allows the default mode to have more functionality, and matches their approach with Chrome. It's not a bad tradeoff.


I don't get why encryption and incognito (not leaving a trace on the device) go together. I should be able to have one without the other.


They wouldn't be able to insert a chat bot to all of your conversations if they were all end to end encrypted. I agree it's a good trade-off


But why not allow E2E without incognito? Have both as separate options.


What use-case does E2E without incognito address?

* Sharing naked pics on a monitored work network? No - there is at least some chance that your company owns your device, so therefore you want it to disappear from that

* Sharing politically outlawed content? No - you can be compelled to give up your device.

Wanting it "just because" is fine, but simplifying the UI is a pretty valid counter argument too.


Protecting against dragnet surveillance. Which is what the encrypted-by-default in Whatsapp achieved over night.


Combined with full disk encryption it ensures nobody can get it.

Or maybe you want to use an open WiFi hotspot without letting anyone get your data. (Https solves this, though.)

Or maybe you don't want Google to have your messages for targeting purposes.


Full disk encryption and end-to-end are not really ensuring no one can get it. I feel like I beat this point into the ground in these discussions, but all encryption is weak against rubber hose cryptography. If someone can compel you to give up your device and key, then all end-to-end does for you is make it less likely you will be caught by someone monitoring traffic.

Which brings us to point two: if that's your primary concern, then using Google may not be your best bet. If you are using Google messaging apps, it's likely because you value the additional convenience Google provides and privacy is a secondary concern.


Probably because proliferation of options is bad for UX for most user types and bad for uptake, and "incognito" is what they've named the package of privacy-related options, including E2E.


It seems to me that it's simpler to understand. If you really want to keep something a secret, it's probably not a good idea to keep a copy on your (or their) phone.

Providing separate options would make it easier to make mistakes.


Pretty much no other E2E app feels the same way, and certainly doesn't enforce that.


You have this in qTox and uTox


Did you watch what Allo does? In its normal mode it couldn't possibly function with end-to-end encryption. They also have encryption to and from the server in the middle when you aren't in that mode.


Incognito is a useful feature. E2E encryption is a useful feature.

There's no reason to only allow those two features to be used together. You could have them both turned off by default, and have three modes, one which turns on E2E and one which turns on incognito.

Also, the incognito decision should be made by each side independently. Just because I want to delete my traces doesn't mean my partner does.


> There's no reason to only allow those two features to be used together.

UX simplicity is, in fact, a reason.


Then have the default incognito be as described, with an option in settings to separate the two features.


I don't think you've thought this through.

If one side enabled this "use E2E encryption for everything" feature, then the other side would presumably no longer have access to any of the smart assistant features. And it would not be obvious why.

Additionally, it would be hard to explain why you'd ever want to enable such a feature which means nobody would do it. I suspect you want default E2E encryption for political reasons. Such things don't work unless it's on by default.


>If one side enabled this "use E2E encryption for everything" feature

That's not what I'm suggesting. I want E2E to be separate from the "delete chats when I'm finished" feature.

Wanting an E2E chat that stays on my device when I'm done should be fine.

I'm fine with having E2E require a separate mode, but that shouldn't be bundled with the incognito feature of not remembering history.


I see. In that case, yes it'd make sense to have such a feature, probably implemented as an archive button in the incognito window (with a warning that archiving such a chat makes it non-private).


Are you assuming that all storage ends up on Google's servers (because that's what hangouts does, maybe)?

Why can't it store E2E chats locally and never upload to google, or even encrypt with a passphrase like Chrome sync does?


Congrats, you have dug it down to the core. Google just doesn't need chats that it can't mine for useful data.


Then why build E2E at all?


To stay competitive (or perceived so).


So you're suggesting Google crippled the feature so it doesn't get used? This seems unlikely.


For Google privacy is a problem, since they want as much data they can get. So they've put in "incognito" so it sounds modern enough what competitors have with E2E, but they'll try and make it inconvenient and not default as much as they can.

Of course they won't be open about this, because they're making the world a better place <insertcuteemojihere>


Wanting an E2E chat that stays on my device when I'm done should be fine.

Only if all other participants in that chat are fine with it. So you'd end up with an implementation that only allows saving to disk if all parties allow saving. That's a lot more complexity than simply a separate checkbox.

I still agree with you, there is value in allowing the features to be controlled separately.


Why? I could always screenshot it, there's never a guarantee when you send information that it won't be retained by others with access. Letting me keep it without screenshotting is just a local convenience feature.


Sure, you could screenshot it. You can make a screencast too. But that would be your choice and your effort, not the tool's. There is a difference between a conversation partner that spends effort to violate the (possibly implicit) rules for that conversation, and a conversational tool that encourages subversion without effort.

In other words, it would be bad for Whisper to allow saving confidential conversations for two reasons:

- the user chooses to not save the conversation, but can't be sure if other partners save it regardless

- the user chooses to save the conversation, but can't be sure if the tool will really do so because of other partners' choices

Either of the options above will lead to more end-user questions (and necessary UI to prevent those) than simply combining E2E and persistence in one option.


I think this is a terminology issue - from what's been said elsewhere the only two differences in incognito mode is that it is E2E and doesn't show messages on your lockscreen.

It's not ephemeral messaging like Snapchat or something, although they are discussing it as a future feature.


I followed the arstechnica liveblog. http://live.arstechnica.com/google-io-2016-keynote/#post-885...

>Incognito also offers message expiration. When you close incognito mode, your message is gone forever.

I assumed that was accurate. Did they misrepresent it somehow?


Possibly - the two sites I've seen with "hands-ons" do not mention this anywhere.


http://www.wsj.com/articles/google-takes-on-apple-facebook-w... (https://archive.is/ELitC for paywall)

>All chats will be encrypted, but a special incognito mode will have an end-to-end encryption, and expiring chats that are permanently deleted once you leave them.


I don't mind the two being used together. I've been using OTR in Gtalk/Hangouts for a long time, too (yes, I know Google actually keeps those messages anyway).

However, I would like an option to make the Incognito mode the default (always-on), just like Firefox can make Private Mode the default.

If Google wants people to believe it cares about their privacy (which is probably the reason they're even doing this in the first place), then it should not just offer the feature to them in an obscure way, but it should make it easy for them to use it if that's what they want.


> If Google wants people to believe it cares about their privacy

They don't, it's just more easibly marketable this way since it's a checkmark on someones Powerpoint slide.

> but it should make it easy for them to use it if that's what they want.

Google doesn't cater to users, since they aren't customers (services are free), but advertisers are.


I think it could if the AI was done locally, but don't expect Google to do that anytime soon, even if it becomes technically feasible and cheap to do. Didn't Apple already employ some client-side AI for photos and gave the reason that this is for privacy? I don't recall what the feature was exactly though.

As a sign of good faith, Google could also stop data-mining Hangouts now, since they have Allo for that, and make Hangouts end-to-end encrypted by default.


> WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages

Small clarification: WhatsApp actually does seem to have a backup feature, at least on my Android phone. I was prompted by the application to enable it just this morning.


Message backup is there on iOS too.


Didn't WhatsApp Web require the phone to be on, before they got encryption?


It still does


> WhatsApp makes a lot of sacrifices to have encryption by default, like no backup of messages

Huh? I have backup of messages.

> no real search functionality

I can search on my phone.

> desktop client that requires the phone to be on, etc.

I want this: the messages should live on my phone.


Having exactly same feelings towards moxie. He wrote a lot about Telegram and how they are not using encryption by default and security is optional, now he is accepting Allo, which is not going to use encryption by default, otherwise it cannot answer to questions like this[1]

[1] - https://lh3.googleusercontent.com/1ai7j4RhAwXDz33dFcS5xcxk1I...


I lament the fact that we're moving more and more to closed chat protocols. Shortly, nothing will work with Pidgin/Adium any more, and it's a shame because it's by far the best way to chat.


Moving to closed protocols isn't the whole problem. Everyone used to use AIM, ICQ, MSN Messenger, Yahoo! Messenger, which were all* closed protocols. And yet, the developers of gAIM (now Pidgin) and Trillian both developed clients that interoperated with all of these services and others.

Sure, we had five years when everyone was on XMPP. But given that rich history of protocol investigation, what's surprising to me is that progress on support for closed protocols is so much slower now than it was ten, fifteen years ago. Support for Skype, Facebook, Slack, Whatsapp, Signal, Telegram -- is poor or limited, and some of these are even open protocols. (Plus, there's still SMS to support, both natively on phones and via services like Pushbullet on the desktop.)

Is there simply no call for unified messaging anymore? Do people enjoy having to use four different messaging apps now? Are the protocols so much harder to figure out? Or are there simply not enough volunteers?

* AOL had two protocols: TOC was mostly open, but the closed OSCAR protocol offered many more features.


Most people use whatever is dominant. People who have contacts on more than one 'app' simply install those apps and mope about it a bit (but accept it nontheless). In the Netherlands (and a lot of other countries), the dominant player is Whatsapp, although some countries have their own dominant player, such as Kakao Talk in South Korea.

Of course there is call for unified messaging; it just isn't in the interest of the companies behind the currently dominant messing apps to facilitate it. To monetize their product, they need you to use their software, on (or through) an operating system approved by them, following their rules (e.g., Whatsapp's requirement of a relatively high-value personal identifier in the form a phone number). Using anything else to access their protocol causes a devaluation of their product — whatever their eventual business model will be after the make-sure-everyone-uses-us phase will be (advertising, user tracking/marketing profiles, freemium model), users will need to interact with them on their terms, with their software.


That was always the case, though. The problem with making a WhatsApp Pidgin adapter, for example, is that WhatsApp only allows a single client. I'm not sure why nobody has tried to make one that talks to the phone, like WhatsApp Web does (although that also only allows a single browser).

Generally, we've taken a big step backwards where chat is concerned.


I think federation has largely moved to the device. I do most of my messaging on my phone, where which app I'm using isn't invisible, but it's also not really a hassle to switch (mostly it involves dragging down my notification shade and tapping on the message I received). Not perfect, but also not really requiring the cognitive overhead that switching between desktop clients seemed to have. My phone federates my contacts, email, calendars, etc without much input from me and I believe chat will go that direction as well.


Your phone federates your contacts, email, calendars, etc because those are all open protocols.


Matrix uses the same encryption protocol but is also federated, which is nice.


Matrix uses an encryption protocol of their own devising that employs the double ratchet, which is one component of Signal Protocol. But it's not Signal Protocol, it's their own thing.


Yup, just to reinforce from the Matrix side: Olm is an independent E2E protocol which happens to implement the double ratchet (formerly known as the axolotl ratchet), but it's not Signal Protocol and it's increasingly divergent from Signal, and it's completely independent of Open Whisper Systems. For instance, we're defining different behaviour for group chat ratchets, called Megolm, following our own design at http://matrix.org/speculator/spec/drafts%2Fe2e/client_server....

That said, we've tried to architect it such that we could implement compatibility with Signal if Moxie and OWS were ever open to it. But it looks like we'll need to first prove that Matrix can support a rapidly evolving yet federated ecosystem without compromising UX or privacy :)


And interesting enough, Matrix faces a different problem than Signal: It doesn't have many good clients at all (at least, last I had checked a few months back). I will agree it would be very nice if Matrix was the dominant messaging protocol that everyone needed to speak with their friends. However, that's not feasible until somebody makes an easy-to-use, beautiful Android and iOS client that doesn't require the user to install multiple bridges or wrangle several accounts to chat with their friends.


Vector is now out on both Android[1] and iOS[2], and the web version of Vector has improved significantly.

It doesn't have end to end encryption support yet, but they're working on it.

1: https://play.google.com/store/apps/details?id=im.vector.alph... 2: https://itunes.apple.com/us/app/vector.im/id1083446067


Yup, it's very true that until recently native Matrix clients have been geared up for developers. Hopefully the arrival of FOSS yet polished apps like Vector (https://vector.im) changes that - and meanwhile one can always benefit from Matrix via bridges from existing polished apps (e.g. Slack!)


Vector and recently Tensor are pretty awesome.


I have no experience with iOS anything, but at least the Matrix Console Android client is pretty good for what I use it for. It even supports multiple simultaneous accounts which I really appreciate. I believe the iOS version of it is very similar.


Making someone else's crypto not suck is not the same as endorsing their product.


> the desktop client requiring chrome is pretty awful

That's rubbish. They are a small company with not enough person-time to develop native versions for all OS. Would you prefer only to have a windows version available? Developing with Chrome/NW.js/Electron allows you to have an app that runs on 3 OS's from the start. I think it's pretty awesome.

Plus you only need chrome installed, it doesn't have to run if I understand correctly. Who doesn't have Chrome installed? Or why would you not install it?


I've used NW and electron based applications and don't have chrome installed. Why is Chrome needed at all for those to work?


To add to what rtkwe said, I assume the Signal client is a Chrome plugin because as far as I know you can't use GCM push messages with Chromium/NW/Electron, but only in Android and Google Chrome.


Signal Desktop does not use GCM. You can use the extension with Chromium or any Chromium-based browser.


Really? Wow, how did I miss that... Thanks for correcting me!


it's a chrome app, you can launch it independently of chrome. At this point I don't know why they didn't go the Electron route.


Electron uses chromium as the renderer.


> on a personal note, the desktop client requiring chrome is pretty awful.

Why? I haven't had any issues with it.

I even have a shortcut on linux for dmenu, typing "signal" opens the chrome extension URL, opening the app in a new popup window (not a full browser, just the app in a chromeless window). So it functions just like a normal app to me. This is the `signal` bash script:

    #!/usr/bin/dash

    /opt/google/chrome-unstable/google-chrome-unstable --user-data-dir=/home/dmix/.config/google-chrome-unstable --profile-directory=Default --app-id=bikioccmkafdpakkkcpdbppfkghcmihk


I don't use chrome for a number of reasons, the main one being I can't imagine using a browser which doesn't support the blocking of ads, and on Android there are no plugins at all, and given that I use firefox on multiple desktops, all syncing passwords, tabs etc, I'm not about to make an exception for this or that chrome-only feature. I have no idea why chrome doesn't support plugins on Android; they said they'd do it years ago.


>the main one being I can't imagine using a browser which doesn't support the blocking of ads

This hasn't been true for... ~6 years? And even then, it could block them, it just couldn't block their network download until... like 6 years ago or longer.

>I have no idea why chrome doesn't support plugins on Android; they said they'd do it years ago.

Chrome is removing all support for all plugins [see the deprecation policy they're about to introduce for Flash], but I suspect you're talking about extensions. I suspect they're coming very, very soon. They've been changing the desktop extension UI slightly and slowly and I suspect it's about enabling extensions on other form factors.

Not to mention this discussion is about using an app written for Chrome, not about somehow being forced to use Chrome for day-to-day browsing. I could (and do) use Chrome apps at times without actually using Chrome. I flip flop between Chrome and Firefox for months sometimes.


Why would you have to use Chrome? You just need Chrome as a platform to launch your chrome app...

I don't get it


Why would I want to use a browser to do non broswery things? It's bad enough that we have to use browsers in the first place. Wouldn't we be better starting from scratch and developing a secure, standards-friendly way of deploying text, images and video rather than taking something which was designed to display just text and try and make it useful?


Any ideas?


I don't really have any ideas. Software distribution should be a solved problem by now but even if we limit ourselves to GNU/Linux on x86-64 computers, we can't agree on a distribution mechanism. We are all over the place from the blessed apt and yum to oh just curl this url and pipe it to sh (I am a n00b so I may have said it incorrectly). There is no good way to make sure everyone gets updated. It is a mess.

I am typing this on Mozilla Firefox but I can see the draws of Chrome as a platform. I personally love the distraction that working on the plumbing on different platform involves but I would rather the people who work on secure communications -- that journalists, politicians, and policy makers, and social influencers in general can trust with their lives -- not be distracted by the fun plumbing.

The way I see it, we have to abstract it at some level. If systems folks can't agree on a standard, then applications will standardize on apps that live on top of them.


Because some of us don't want to use Chrome? How is vendor lock-in at the browser level any better than at the OS or device level?


The script above basically acts like a wrapper script, launching in a small square chromeless window. So you don't even need to use Chrome, just launch that at startup so it runs in the background.

Small software companies have to make platform decisions. They chose the most popular browser (and notably most secure browser), allowing the app to work on all OSes.


I don't think you completely get how some of us feel about chrome.

Chrome is a good, modern browser but this constant pushing by google (telling me to download a "better browser" when I'm visiting their site in Firefox) as well as every lazy web developer annoys me (seriously, at least consider if you should test basic functionality in all major browsers even if you aren't directly paid for it) .


Wish I could remove the "lazy" part, my apologies webdevs!

Still: wish less companies would be fine with shipping web apps that break in one or more of modern browsers.


On what basis can "notably most secure browser" be asserted?

I think both aspects of this statement are definitely not clear - certainly not notably (reference?), and comparisons based on some searching seem to go one of numerous ways.

I would be happy to see a security expert's view on this though.

See also this link on Chrome devs essentially telling users that upgrading their kernel from 3.16 (not even > 7 months old at the time): https://news.ycombinator.com/item?id=9164251. Thankfully better sense prevailed and it was resolved fast. So even in terms of OS support it is not unambiguously better than others.


To me it is personally annoying because so many people and esp developers seems to want Chrome to become the new IE: a subpar (yeah, until google give you nested vertical tabs ;-) browser that web developers have fallen in love with to the point where they forget anything else.

Anything that reinforces this automatically qualifies as bad (and I'm only partially joking here ;-)


This is exactly it! People are now making chrome apps instead of web apps.

How many times have you been to a webapp and it said "Your browser is not supported, for best results please use Google Chrome."


I use Firefox and hate Chrome. I don't see how this affected by how much you use Chrome




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: