Tor Messenger Beta: Chat Over Tor, Easily
blog.torproject.org
blog.torproject.org
They mentioned Pond and Ricochet in that post and I'm a big fan of both but especially Ricochet. It has no setup, no configuration. Just share your address and talk. That's the way it should be. But it's only available on desktops. These days most people connect to the internet only by using their smartphones and if you only support desktop computers (even if you're x-platform) you're missing out on a lot of people already. The perfect solution would be Signal's encryption combined with Telegram's availability, but unfortunately we're not there yet.
I'll keep my eye on this project and I really do hope it takes off but as of right now, it's not that different from any other secure messaging app you can find on the internet that only tech savvy people can use.
The only programs I am aware of that do both all have significant limitations in other areas and none have gone through rigorous peer review.
i2p-bote has mobile and desktop applications, can use possible post quantum secure encryption, it's asynchronous and real time, capable of multi party communication, and has optional delays between hops making it global passive adversary secure. Unfortunately it doesn't work well because many messages don't actually make it through. You can't send files greater than 500kb. Also it is not peer reviewed.
Bitmessage has multiparty communication and is asynchronous but has a terrible user interface, is hard to setup, no mobile application, no attachments, no peer review.
Ricochet works well and is easy to use but no attachments, it can't be asynchronous, no multiparty communication, and no peer review.
Haven't played with pond. It looks promising.
My wish list for the ultimate messenger: easy to use, secure by default, hides content and metadata, is multi party, can share arbitrarily large files, is both instantaneous and asynchronous, can be global passive adversary secure, is quantum computer secure, truly multi platform, and supports being signed in on multiple devices at once.
If we have two devices (say Alice's phone and Bob's phone) that are sending messages to each other, how do we make sure nobody knows who is talking to whom? The answer seems non-trivial to me.
Could we use Alice's and Bob's public keys to encrypt the message and then send them to the entire network, relying on the security of the encryption (and acknowledging that a third part can read all messages any way)? Is there a way to look at a public key and an encrypted message and say that yes, this message was encrypted with this key? It seems that we'd be paying through the nose in terms of throughput capacity (and processing capacity as everyone would have to take in everyone else's packets) if we wanted to maintain metadata privacy this way. I'm sure this is not what you had in mind. Can you please elaborate on how we can secure metadata?
I2p-bote routes the messages through multiple intermediaries with layered encryption so that no intermediary knows both the ultimate sender or ultimate recipient.
Pond works by running servers over tor (a mixnet). When you send a message it doesn't go to the server you have service through it goes directly to the recipients server.
Ricochet sets up your own server on tor that you are hosting.
There is also Pir-Tor. It attempts anonymity by using the secure multiparty communication combined with PIR to attain provable anonymity.
By using traffic obfuscating systems like TOR or Mixmaster.
I also agree with khed. Signal needs to hide metadata.
A very brief perusal of the repo didn't turn up any protocol docs, but seem to have been rather thorough about that sort of thing in the past, so I would suspect that the changes to the TS and RedPhone protocol would be fully documented, so you could integrate it with libpurple or whatever.
Tor Messenger doesn't allow you to talk with someone else, unless they have OTR. So it's encryption always, by default.
I agree with the mobile part though. We need something that works on both the places. Check out http://conversations.im/omemo/.
Note that InstandBird last had a release in December 2013 and their blog was abandoned in July 2014, so their future is a bit up in the air even though commits still happen on the Mercurial repository at Mozilla. Pidgin has released multiple security updates since the December 2013 release of InstantBird 1.5. I'm unsure if the Tor folks have incorporated these changes offhand. They use the clunky gitweb client for web browsing of their repository and I don't have time to clone a git repo at the moment.
It's also worth noting that Pidgin's libpurple uses XMPP for Facebook and Google chats, neither of which will work well any longer due to both of them deprecating XMPP.
If you'd like to use secure chat and are unconcerned with the meta-data, there are quite a few better options at present. If you'd like to use secure chat over Tor, you can use any of those options over the Tor network manually. This does have a lot of promise for making it easier for a regular end user, though, so testing and feedback are encouraged.
*Update - According to a comment reference below, they now build without libpurple using their own custom Javascript libraries.
Tor Messenger does not seem to be using libpurple, at least judging by the comments here: https://lwn.net/Articles/662471/#Comments. And I tried it with Google Talk and it works. Wikipedia says that Google Talk as a client was deprecated but you can still use it with third-party clients like Pidgin, Tor Messenger, etc.
You can still mostly connect into Google via XMPP, it's just a bit clunky. And it doesn't work as a true XMPP service as you can't connect to anyone but Google with it. I'm using it in Pidgin right now.
Otherwise if you want end-to-end over Tor communication, Ricochet works quite well :).
In general, the fact that each time you launch the client (or generate a new path through the Tor network) you get a new IP, these sorts of security measures put in place by the chat networks could be a difficult issue to work around.
As someone who trains people on using XMPP and OTR, Google Talk used to be a great XMPP service and now makes it very difficult for most users to understand why they are having problems with the service.
1) https://developers.facebook.com/docs/chat 2) https://xmpp.org/2015/03/no-its-not-the-end-of-xmpp-for-goog...
I guess Tor will provide more anonymity, which is a nice plus.