adam_b,

SimpleX exists

Briar : he copied my whole flow, word for word, bar for bar

😄

01189998819991197253,
@01189998819991197253@infosec.pub avatar

…so, Briar, but new?

whale,
@whale@lemm.ee avatar

deleted_by_author

  • Loading...
  • 01189998819991197253,
    @01189998819991197253@infosec.pub avatar

    I’ve never used their forums. Only used it as 1:1 messaging. Worked great.

    onlinepersona,

    No link to a repo? I’m not going to watch a video to know what a project does or how it does it. No thanks.

    vim_b,
    onlinepersona,

    Thanks.

    So it has a new ID for each tunnel/channel/whatever. As usual, that comes with the downside of discoverability: how do you find all your contacts when installing the app? You always need an out of band transfer of the user ID - be it email, username, or a transient one like this.

    I’m not sure how much better that is than existing chat apps that don’t have discoverability.

    BearOfaTime,

    OOB is arguably better for privacy.

    onlinepersona,

    How?

    If the OOB is not encrypted --> hello MITM attack or impersonation (unless of course you’re physically in the same place, which is quite limiting)

    If it’s encrypted, why not just keep using encrypted channel? I have to find an encrypted channel to initiate an encrypted chat?

    I’m not seeing the benefit

    BearOfaTime,

    I can give someone my ID in person. I control how it’s delivered.

    whale,
    @whale@lemm.ee avatar

    deleted_by_author

  • Loading...
  • onlinepersona,

    Signal has backup 🤔

    whale,
    @whale@lemm.ee avatar

    deleted_by_author

  • Loading...
  • BearOfaTime,

    If I recall correctly, SimpleX came out of the development of a file-transfer protocol, similar to torrenting.

    It’s been probably a year since I read up on what they were doing, and I’ve been running it on a couple devices.

    I keep it around as a backup chat tool. Sadly I can’t get people away from SMS, but I also use Signal and Telegram. Each has its pros and cons.

    adam_b,

    I think the spammers won’t be a problem for this service, only if you’re in a public group, but then I must ask, why didn’t you use incognito mode ? Let the spammers spam the temporary profile…

    Telegram had to remove commenting as a channel, ( well they gave it to premium users ) ( which makes you question their “we care about your safety” claim )…

    But I never saw anything like this, if Incognito mode is on, every account link you share creates a fake account

    Also I think public rooms are limited to 50 or 100, I’m not sure

    Gargari,

    Is it a simple chat app or something like Telegram with channels and groups support?

    moreeni,

    It doesn’t have channels, only groups. It’s more like Signal with no phone number req but with worse UX as a trade off

    blkpws, (edited )

    But briarproject.org can be used on Gaza right now, works without internet.

    EDIT: And has forums posts for important notices around you, which is super useful on war/censorship times.

    BearOfaTime,

    I think they serve different (though related or overlapping) purposes.

    Briar started (IIRC) as a Bluetooth-only comm tool, and they’ve done a great job expanding what it can do (think it does Tor now?). Briar is not battery friendly, and the devs will tell you so. I don’t consider it a daily driver, but rather for specific circumstances. I keep it around just-in-case.

    SimpleX is more of a daily driver since it’s a more conventional IP networking app, though it’s a little battery hungry too.

    blkpws,

    Yeah, you are right, I just think SimpleX is not for me as I already use many Matrix chat even for work stuff and collaborations (group chats), and I’m not sure if I can do the same or chat daily with my team as I do on Matrix. And I just hope and have faith that they will fix those metadata issues:

    github.com/matrix-org/matrix-spec/issues/660
    github.com/matrix-org/matrix-spec/issues/549

    But can take long, for now I am not worried at all.

    BearOfaTime,

    Yea, it’s a different tool. And it’s still early days.

    I don’t use SimpleX as a daily driver, yet. But it has a lot potential. Just glad to see another tool out there, and the devs seem really earnest (I worked with them a year ago while testing the app).

    blkpws,

    I should give it a try, but not sure if I will be able to talk with anyone… I don’t really have friends that care about privacy… 😢

    BearOfaTime,

    Lol, welcome to the club!

    God how I despise SMS, and I can’t get anyone off it, even if other options are easier to use than SMS, much more robust, faster, more flexible, etc.

    There are a couple messaging apps that are self-hostable (like I believe SimpleX is). Litewire is one. At some point I plan on hosting one myself, and preconfigure accounts for friends/family to make it even easier for them. Maybe that will get them on board.

    blkpws,

    Yeah, and I first need to get friends… such a hard work… physical world isn’t for me…

    BearOfaTime,

    Lol, there is that problem. One thing at a time…

    EngineerGaming,
    @EngineerGaming@feddit.nl avatar

    My main concern wit Briar is that it would be of not much use without a smartphone (I meant the internet-less features in particular). I would not trust sensitive things to a smartphone. I wonder if soemthing like that could be doable with an Android VM or Waydroid with a laptop’s bluetooth…

    BearOfaTime,

    Maybe. Check out Android Subsystem for Windows. It’s essentially an Android VM though you don’t have a launcher/home screen. You just see the apps in your task bar like any windows app. I run it on an older laptop, it’s a touch slow but works well enough.

    github.com/MustardChef/WSABuilds

    EngineerGaming, (edited )
    @EngineerGaming@feddit.nl avatar

    Windows is as much of a spyware as an average smartphone though, so not much of a point.

    Edit: I should try it in Waydroid then.

    BearOfaTime,

    Lol, true. I just assume most people are using it.

    I’m working on getting away from it, been stuck on fining a OneNote replacement.

    authed,

    Signal only ask for a phone number to verify your identity… its far from private

    jelloeater85,
    @jelloeater85@lemmy.world avatar

    It’s more or less truly anonymous chat. Like you meet someone on the street and need to chat with them, but don’t want to give them any personally identifiable info. It’s really cool in concert, but good luck getting anyone to use it. Signal is good enough if you’re paranoid. TBH Telegram secret chats are just as good for sensitive stuff and way easier to get folks to use.

    einfach_orangensaft,

    i like the whole concept but it seamed to good to be true and not some type of backdoored honeypot, ill guess ill check it out when enough people reviewed the sourcecode

    noodlejetski,

    back when I was using reddit, whenever it would be posted in /r/privacy or /r/privacyguides it would get like 30 or 40 upvotes in a matter of minutes. for a service that came seemingly out of nowhere, it really felt suspicious to me.

    moreeni,

    I think that’s because it’s the content for privacy subs. Now that it had been audited and privacyguides recommends it I put my trust into SimpleX

    whale,
    @whale@lemm.ee avatar

    deleted_by_author

  • Loading...
  • BearOfaTime,

    I thought you could run your own relay?

    It’s been probably a year since I chatted with the devs (did some testing with a few devices I have sitting around). Biggest issue I had was it required a current version of Android, as I thought it would great to be able to run it on older devices.

    Cheradenine,

    Well, since it was audited quite awhile ago you could probably check it out now.

    simplex.chat/blog/20221108-simplex-chat-v4.2-security-audit-new-website.html

    fmstrat,

    Oof, bad timing for that name selection. Especially with payment processing.

    The invitation method is interesting, but will likely be its limiting factor vs its draw. Regular Jane/Joe wants to share their username, just not their number or email. Not being able to share verbally is tough.

    BearOfaTime,

    Simplex has been out for a year or so.

    It’s tough getting people used to systems that respect privacy, since Out-of-band ID sharing is part of that.

    possiblylinux127,

    I’ve found it easier to get contacts though the QR code

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • uselessserver093
  • Food
  • aaaaaaacccccccce
  • [email protected]
  • test
  • CafeMeta
  • testmag
  • MUD
  • RhythmGameZone
  • RSS
  • dabs
  • Socialism
  • KbinCafe
  • TheResearchGuardian
  • oklahoma
  • feritale
  • SuperSentai
  • KamenRider
  • All magazines