Wire – modern, private messaging from Skype co-founder
wire.com
wire.com
ChatSecure has a nice writeup about this: https://chatsecure.org/blog/fixing-the-xmpp-push-problem/
But it seems that only some crypto libraries are opensourced, no frontend and things like that.
I'm a bit worried about using something that is free and has no ads while maintaining central servers though..
It's too bad though - as you say - it is very nice for collaboration and teams (It's geared exclusively towards gamers).
Interesting to note that "American" is implicitly synonymous with "insecure".
- As a non-American, I see America as one of the least safe places to store my information. The Snowden leaks showed that the US government has zero respect for the privacy of non-Citizens.
- As someone who's lived both inside and outside America, I've noticed that privacy laws in the US are weak relative to other countries (much of Europe, Australia) that I've been in. Europeans have things like Right to be Forgotten. Americans have companies that have refused to remove my personal information after I terminated my account with them.
It doesn't affect:
- "contents or substance of a communication"
- "information that states an address to which a communication was sent on the internet, from a telecommunications device, using an internet access service provided by the service provider and was obtained by the service provider only as a result of providing the service"
When they first introduced that bill it was rather scary looking but by the time it passed it's not too bad.
"information that states an address to which a communication was sent on the internet"
I have yet to find someone, even among the "privacy aware" people to chat on Facebook using Pidgin's OTR plugin.
That's because the "privacy aware" folks don't use Facebook. And if they did (likely a damn good reason) they would. Makes it all the less likely for you to have met them
They seem like a complete copy of Signal to me: they're a centralized service with open source clients that promises end-to-end encrypted communication. I see no difference between them. It's like re-inventing the wheel. Honestly, I don't see a single reason why I should use this.
I'm kind of skeptical if this is the solution, but it checks a lot of boxes I want.
But, I feel like that the tools that promise to solve the same problem should at least have one drastic difference between them.
Kind of like social networks. Even though they all tackle the same problem (trying to keep us connected) each of them does it in its own distinct way.
I don't see any such feature here. They're tackling the very same problem in a very similar way. A bit too similar for me in fact. And since their target is a niche audience, I only see us having even more difficulties if Signal gets more and more alternatives.
That's not how evolution works.
Signal is great for those who confine their instant-message-like communication to their phones, since desktops being treated as second class citizens isn't an issue for them. I am not one of those individuals. I want to be able to read and reply to messages on whichever device I'm using at the moment without having to think about my phone's presence at all.
1. Their desktop support isn't provided by a native app but rather ducktaped onto Chrome, which in turn forces me to have that pole of junk installed.
2. There's no iPad app, granted you can run the iPhone app in compatibility mode but that's just feels wrong in 2016.
3. Their support for multiple devices using one account can at best considered an afterthought attached to their mobile apps with gum. When I checked last it only worked with their Android and their Chrome clients so no love for iOS users.
Wire provides all of this, wrapped in beautifully designed apps (if currently a touch unstable)
For good security, I have email/PGP which has few of my friends, but lots of usage for secure communication.
For secure chat I have Signal which some of my friends use, but not many.
For most of my chat I have WhatsApp which is relatively secure, and has a relatively good UI. Almost all my friends and family have this.
For the rest of my chat I have Facebook Messenger which isn't secure in the slightest, but it also has almost all of my friends and family on it. It has a very good UI, and lots of features that I make good use of.
Wire on the other hand has almost none of my friends, isn't open, so can't be any more secure than WhatsApp, and has a pretty but ultimately annoying UI, and very few features.
I'm not using Wire yet - so I'm just quoting their marketing material - but they directly address your comments: "Wire uses open-source cryptography to encrypt all content. We made the source code for data handling available to the public under the GPL License. This means that anybody can review the source code." "Only Wire offers fully encrypted calls, video and group chats available on all your devices, on any modern platform. Unlike niche security apps we do not sacrifice usability for security — Wire is simple and straightforward to use."
Thanks for pointing it out!
Their privacy page (in the comparison table) claims they are open source. I didn't see any links to their code however.
edit: Sorry, reading on mobile (after just waking up) and didn't see the link. Thanks @ukblewis
It's 2016, and technical people are still asking why people should use $SINGLE_APP instead of $COLLECTION_OF_OTHER_APPS_WITH_POOR_UI.
You'd think people would learn by now.
By it you mean Wire.com? interesting. Do you allow Wire.com access to your address book on your mobile device? See https://news.ycombinator.com/item?id=11288169
It's better than iMessage, for example. With iMessage, the protocol is described, and we can confirm that it is a "secure" protocol, for some definition of secure, but we have no idea if that's what they actually use. With Wire, we can go a step further, the protocol is described in code, so we can verify that the code is correct, however we still cannot verify that this is indeed the code being used.
A step further, which as far as I can tell doesn't exist, would be to provide a bare-bones client (maybe a command line interface) that can be reproducibly built, so that people can interact with other Wire users, using code they built themselves, this would show that the protocol that the open source code describes is being used, however there's still the possibility of the closed-source Wire app subverting it in some way, perhaps with decreased entropy in random numbers, for example.
I apologise for not reading closely enough to see the GitHub link, but I also don't think this gets Wire anywhere near the level of Signal for example, which I have compiled and run myself in the past (and contributed to).
On second thought this kind of thing is already done around the torrent sub-culture with regards to seed boxes..
So innovation, much technology ...
Plus, for any such application to have trust these days, it should be open source both for clients and servers. Enough of this walled garden closed instant messaging.
It runs in the browser so technically it runs on Linux.
> Download the latest version of Google Chrome, Mozilla Firefox, Opera or MS Edge to use Wire for Web.