Rumble: Twitter over sneakernet
disruptedsystems.org
disruptedsystems.org
Here's an example photo share app: http://blog.couchbase.com/photodrop
Unfortunately, it can't use WiFi effectively, because Android doesn't allow symmetrical WiFi. You can only connect to an access point; handsets can't connect to each other. If two handsets are connected to the same access point, there can be communication.
It does not, apparently, have encryption.
http://www.thinktube.com/index.php/tech-en/android/wifi-ibss
Or Tor, right? It seems like it's effectively a local onion router, albeit with significantly fewer possible sources.
The problem with this, to me, is that if an adversary is targeting a certain user, they know that the actual source is in close physical proximity to whomever they actually track. That said, if they hooked this into a WiFi mesh network, things could get really interesting...
Step two... here's how you can hamstring the protocol, so you can use it in real life.
Hey - are we losing any of the benefits of the ideal protocol when we hamstring it?
SHHHHHHH!
I could suppose a system where identities are pinned to a key that is stored from the first time the user is identified (because a "packet" is seen from them).
But how does that stop a determined attacker from broadcasting out his fake Alice identity, so that the real Alice can no longer spread their messages?
Edit: Actual site http://app.getrumblr.com/
https://github.com/Marlinski/Rumble/blob/master/app/src/main...
Hm, looks like group-chat uses shared secret, AES CBC without any form of authentication? So I guess it's not just using null cipher. I'm not sure if I'd go as far as to call it "actually secure", though?
https://github.com/Marlinski/Rumble/blob/262a8b0a618c9f90457...