ICQ New
icq.com
icq.com
"(2010) AOL has sold ICQ to Digital Sky Technologies (DST), Russia's largest Internet company, for US$187.5 million. DST's offer was apparently more attractive than those of Russia's ProfMedia and China's Tencent. ICQ, originally released in 1996 and bought by AOL in 1998 for US$407 million, was one of the world's first major instant messaging systems. Although largely forgotten in English-speaking countries, it remains widely popular in Central Europe, Russia, and Israel. Moscow News has additional coverage of the deal."
(https://tech.slashdot.org/story/10/05/01/1516234/russian-com...)
Same here... I haven't even thought about it since the turn of the century!
I only used it a couple times. A colleague asked me to install it so we could work together on a project. If I recall right I started getting messages from people I didn't know so I deleted it shortly after installing it.
There was a great acquired episode on Tencent. https://www.acquired.fm/episodes/season-3-episode-10-tencent
They have like 200k users now, lol
Cooler for some. Infuriating for others.
Do you remember that feature that you could use to "call someone's attention"? It would make a lot of noise and the window would shake like crazy in your face.
Found it. The "nudge" feature.
Back in the day nicknames were still pretty unique.
There were no programming classes back then at my school and I found someone, half way across the world, who patiently taught me programming everyday.
Adium.im
It used to be popular in Russia to the point of being synonymous to instant messaging, but it's since been largely forgotten. My current circles use VK and Telegram. WhatsApp is also somewhat popular apparently but not so much around me. If ICQ ever pops up in conversations these days, it's always something nostalgic (also, back then no one used the atrocious official client).
LOL
Though it looks like exact copy of Telegram minus the core and most important feature. :D
* https://telegram.org/faq#q-how-secure-is-telegram
* https://telegra.ph/Why-Isnt-Telegram-End-to-End-Encrypted-by...
* https://telegra.ph/Why-you-should-stop-reading-Gizmodo-right...
This debate has taken place over and over again on HN, there's nothing new here.
Surely, that doesn't mean that expert were wrong, but at least mentioning that in Telegram vs WhatsApp debate doesn't look like a strong point.
And like heinrich5991 said, there's no need for backdoor or vulnerability when the data leaks by design to the server.
And no secret chats aren't an option. E2EE needs to be cross-platform and enabled by default. Signal can do it, Wire can do it. Telegram can't, because the developers are completely incompetent.
For a good UX impl, check out Keybase. It's encrypted chat feels just as good as Telegram's unencrypted chat.
"GPG isn't that hard! You see, you just..."
I still remember my 7 digit invisible vanity number.
Its just propaganda move to ban Telegram to make it look independent
(not the E2E ones)
Also, people don't really want to use secret chats because they aren't cross platform. Sure, some people only own phones, but those that switch to laptop/desktop computer don't want to whip out phone hundreds of times a day, but opt-in for the insecure cloud chats that are accessible with simple alt+tab.
So yeah. Sure, secret chats can be mostly secure, the problem is the E2EE isn't practical to any reasonable extent and again, using it leaks metadata.
People can't threat model because they don't really know what the governments consider interesting and a threat to their exercise of power.
So always use E2EE.
I'm one of those people that refuses to accept that "privacy is dead"; but there's also a lot of casual/low-stakes communication that I treat like a personal conversation in an IRL public setting, operating on the assumption that a stranger can/will overhear it.
>I'm one of those people that refuses to accept that "privacy is dead
I never claimed it was. I was making the point that you should protect everything so you don't leak metadata about when you're having private conversation. That's exactly what happens when you e.g. enable secret chats in Telegram. You're telling the company "I'm now talking to Bob, and I'm intentionally making the decision to not share that data with YOU". That's really, really valuable metadata to governments.
ICQ New: has entered the chat
Good opportunity for Apple to step in and open up the message/facetime platform imo.
- status and visibility could be controlled for each contact at a granular level
- locally-stored, fully searchable chat history that gave results in a sensible manner and which you could migrate to new computers
- notification intrusiveness (ding, flash, etc) could be adjusted with one or two clicks
- dense UI (less whitespace meant more information packed into a smaller window that took up less of my screen)
- hitting X actually exited the program
Yesterday's thread about DECUS and HP's OpenVMS hobbyist program opened a can of nostalgia worms so I remembered that my first laptop was a late-Digital era 11"-screen laptop with a pretty low-res screen (800x600, I think?).
I used ICQ on it and its interface was about as awkward as Skype's is today -- except today I'm running Skype on a laptop with about twice the screen estate. It's a little silly that all that research work in the industry -- and all that money I've paid -- went into screens that I now use just to display more whitespace.
I know it's supposed to help with touch screens but a) my laptop -- like most laptops currently in use -- doesn't have one and b) this isn't 1997 anymore, UI toolkits today make it trivial to adjust element sizes and paddings so that they're appropriate to whatever pointing device is currently in use.
That being said, the window in that screenshot is about 200 x 320 px. It would have taken about a third of the horizontal space of the screen, and about 2/3rds of the vertical space of a 640x480 screen. It was certainly usable -- way, way more usable than Skype on a full HD monitor today -- but lots of stuff was claustrophobic in 640x480.
(Then again, most modern apps are practically unusable if you resize their window to 640x480...)
Yes to Slack! Ask whoever manages your organization to enable XMPP or IRC gateway connection, then add the appropriate type of account to Trillian. You won't have access to rich cards or shared files from within Trillian, but you will be able to read and send messages to channels and individuals.
How is that good UX for a chat app?
E2E encryption is _practically required_ if you want to build an app that doesn’t get bad press from security professionals. Just look at Zoom.
Want a fast server-side archive search? Forget it, you're using e2ee.
Want to add a new device and load all your chat history? Forget it, you're using e2ee.
Now, by downloading and decrypting it on another device, you are adding a THIRD end where is is accessible. To achieve that, you have basically two options: one is to pass over decryption keys to a new device (potentially breaking E2EE security model for another guy who does not expect you to use 2 devices without his explicit authorization), and another approach is to do an own encrypted archive to store data and sync between your devices. You basically encrypt data and store it on a server, decrypting it with your password or certificate or something that you share between devices. It's not E2EE at all, actually, cause you'll be breaking the security model for some convenience, because the idea of e2ee is to communicate only with devices, each and every one of which were authorized by you. If you don't follow this rule, you make a travesty out of E2EE, basically stating that all you really need is a nice and cozy feeling of being secure, not true security.
You have to face it: true E2EE is not achievable without significant sacrifices of user experience.
You're not thinking straight. End-to-end encryption does not refer to two devices, it refers to two parties. If you have two devices that can receive the message, that's still only accessible to you.
>one is to pass over decryption keys to a new device (potentially breaking E2EE security model
That's just stupid, you can scan e.g. public key of the other device and then have your device send packets to that
>and another approach is to do an own encrypted archive to store data and sync between your devices.
Which is perfectly valid provided the user has to create sufficiently secure password.
> It's not E2EE at all
The reasoning how you came to claim this is beyond moronic.
>actually, cause you'll be breaking the security model for some convenience
You aren't breaking anything. Claiming things without reason is moronic.
>because the idea of e2ee is to communicate only with devices
No the idea is only you and your peer have access to the data. You can't be serious.
>each and every one of which were authorized by you
Yeah that is kind of what happens with proper E2EE, only you have access to your data on devices you've authorized by e.g. scanning the QR code of the trusted instance.
> basically stating that all you really need is a nice and cozy feeling of being secure, not true security.
Geez, maybe start by learning how cryptographic protocols work before making such claims.
>You have to face it: true E2EE is not achievable without significant sacrifices of user experience.
Majority of them are with smart cryptographic design. The claims you made were more hand waving than I've ever seen before. Incredible.
Scott Chapman:
> The actual origin of the Uh Oh sound: My ex wife and I used to talk in Squeaky Voice a lot and were quite good at it. I used both WS_FTP and ICQ back in the day and I made the original recording of this sound and sent it to one or both of those companies. I think I sent it to WS_FTP first where it was used to indicate an error in connecting to a remote host. I don't recall if I sent it to ICQ or if they got it from WS_FTP. Someone below said it came from Gremlins. That is not the case. Happy Trails!
DJHEADPHONENINJA replies:
> Why would you just record your voice and send out to companies? Sounds pretty weird man. I'll go with Gremlins because I just watched the movie and heard this sound effect so I had to google the true origin of the ICQ sound.
Scott returns:
> Go with gremlins if you like but the sound is not the same. Back in those days it was not about remuneration.
To this day, this 'uh-oh!' sound makes me tingle all over.
Nowadays, you have to jump through hoops to get even a few of the messaging services in one program, it's clunky and barely works, and you'd be breaking terms of service of half of them. Also, it would break anyway in a week or two, because the service owner changed something in the proprietary protocol.
Fortunately, with Matrix and a few other pioneers, it's getting better again, but in the meantime, there is an entire generation used to having their communication hamstrung by american corporations.
I guess what I’m saying is, things sucked just as much then as they do now. Maybe more! Sigh.
IRC was of course always open, but that's kind of orthogonal to this discussion as it never really had any traction with the general public the way AIM, ICQ, Yahoo! Messenger, etc. did.
Also, users weren't yet conditioned to expect proprietary chat apps and nothing else back then. Recently, I installed a small family Matrix server, for chatting and sharing photos. I had one heck of a time explaining that the client app (Riot) is named differently from the protocol (Matrix). And I'm glad I did not have to explain why the server software has yet another name (Synapse).
(In the end, I went with comparison to e-mail, which has different clients like Outlook or Thunderbird. That seems to have lit some overhead lightbulbs. :) )
Now not only do I have a million chat apps again, but they're almost all a godawful resource hungry non-native UX disaster. :(
On the other hand, if Yandex or VK had an E2E chat (maybe they do), I would not trust it at all.
Certainly I can't see a way of logging in with my icq number from back then
I get a "you cannot recover the password", maybe my account was too unused for too long
I always liked ICQ, but there was always a tad bit of friction remembering huge strings of numbers as practical IDs, and the naming schemes came way later.
11984431 or whatever doesn't roll off the tongue very well.
But Mail.ru deleted old accounts. So...
They even tell you that you can't restore in anymore.
So I know my first library card number was 1000102772901. I had to replace the card a few times, getting new numbers, but I only ever remembered the first one.
On the topic of New ICQ, it looks like all those other multi-user messengers. I wish everyone would switch to Jabber were there are clients for people who don’t have group messaging as their primary use case.
If not, not interested. We have plenty of proprietary instant messages already.
I wonder how much of this is intentional, or if it's just a case of convergent evolution? The adversarial relationship between ICQ (with connections to Russian oligarchs) and Telegram (with connections to Russian dissidents) makes this feel unlikely to be coincidence.
I have to scroll right to see the other ~60%+ of its content, and there’s no way to zoom out to fit it all in, even at a smaller scale.
"Why test the website on phones? Who uses messaging apps on their phone anyway?"
tl;dr - they don't encrypt anything, are owned by a russian company, and take no responsibility for the leaking of your data.
Year - 2004. Place - Moscow Russia. Before Facebook(or Russian VK).
High school. Everyone I know using mIRC chats in my city supported by local ISP and using ICQ.
I had Nokia 6280 phone with S40 OS and using ICQ on it with J2ME app 'JIMM' that looked like this[0][1]
At that time in 2004 it was like magic, it was so cheap to chat with status messages and Emojis, not paying for SMS.
And desktop clients of that era like QIP or Miranda IM[1] were so minimalistic and extensible.
And yeah I remember purchasing good looking ICQ number 94444911 on some shady auction, fun time
[0] https://upload.wikimedia.org/wikipedia/ru/b/b5/Jimm_screen.p... [1] https://cs7.pikabu.ru/post_img/2014/08/04/12/1407181990_1167... [1] https://www.miranda-ng.org/en/
I don't want to make a new one tied to my phone number.
Unneeded permissions are practically a cliche by now and the permissions that apps get are routinely abused. Give an app notifications and they will spam you while the app interface isn't running.
Some software doesn't even need to be native or connected. Word processors, calculator apps, many lower definition games and even image manipulation could be done with one fat webpage.html file.
I'd personally suggest setting up a virtual machine with some sort of "checkpointing" feature, where you can rewind the machine to an earlier state if you don't like what an app did to it.
Way to ruin the nostalgia with such a poor reboot. it's a shame so many of the old internet 1.0 brands are rotting away.
> Convert audio messages to text, use smart replies, stay online even with bad internet connection
That doesn't cut it, IMO. In fact it is repulsing me (offline apps are great) but I don't want to convert audio messages to text unless that happens locally. Fuck smart replies, no thanks.
I don't understand why no other popular chat app has ever brought that feature back. It really gave the chats a sense of humanity and conversational connectedness. You could even rewind and play back the conversations!
We've found a lot of nostalgic mentions here, and we want to say that we have the same feelings. But it's similar to looking through the school photo album. It's nice to remember but now you are another person who live in the next decade.
Sooo...welcome to ICQ New with group-calls up to 30 people, smart replies and conversion of voice messages into text!
We'll be appreciate for any feedback, feature requests and opinions. Share it with us here or right in ICQ: side menu — report an error.
See you!
Last time I logged into my account a couple of years back, it still showed the last profiled update I filled in the 2000s.
Heck ... not sure I even have it anymore.
Interesting read about the old one: https://medium.com/@Dimitryophoto/icq-20-years-is-no-limit-8...
I still remember my UIN, but I don't think 'new ICQ' uses those? I tried logging in on the web site, but I am unable to recover my password using my UIN.
With the random chance of any app with the right timing/reach and features to gain some traction (see whatsapp) etc, guess they figure why not put ourselves out there again hehe
Basically, it's company in the pocket of russian government, and you should use any of it's product if you completely disregard your privacy.
> Always use apps that are E2EE by default (e.g. Signal)
You are contradicting yourself here. You are required to trust Signal the company to respect your privacy, to trust that it's actually doing end-to-end encryption, doing it properly and doesn't issue an update breaking it because of some secret US government order. Because Signal controls software distribution, it's pretty much just a binary blob that some guy from Signal can update any time.
A proper end-to-end encryption at minimum requires an open source implementations and distribution to avoid trusting the company to respect your privacy, since this is the primary reason for end-to-end encryption to exist. Otherwise incentives are misaligned and it will be broken by the same company it is supposed to protect from as soon as they need your messages for something.
You can read the source, you can compile it yourself, and you can use it.
You can also do a reproducible build and check that it matches the hash of the APK served by the play store.
"Open source distribution?" What is that? If you can't trust the vendor, no F-Droid is going to help there. If you need to verify the source, you need to do it yourself.
>some secret US government order
Explain how that would work on legal level when compelled speech violates the constitution.
Your reasoning isn't exactly solid.
I can read some source code they provide, not necessarily what everyone has installed at any given moment. Even if I could review it and compile it and run it the other ends of end-to-end won't, so I still have to trust Signal the company to not violate the other ends.
Open source distribution means packages in various open source repositories, not controlled by software vendors.
> If you can't trust the vendor, no F-Droid is going to help there.
F-Droid model is exactly what's going to help with not having to trust the vendor. It's sort of an infrastructure to reduce trust in software vendors. Independent parties maintaining forks and packages are more likely to notice if vendor does something stupid, more likely to have people and tools to verify claims and implementations, provide a way for independent implementations.
> Explain how that would work on legal level when compelled speech violates the constitution.
It doesn't matter, they can come up with plenty of bullshit excuses claiming child porn or whatever. The important thing is you have to trust Signal the company, the US government, the legal system, etc.
That applies to any distribution mechanism.
>I still have to trust Signal the company to not violate the other ends.
99% of people are going to download the app from Play store, even if F-Droid was available. You're screwed.
>It's sort of an infrastructure to reduce trust in software vendors.
Oh dear god. No. It's just more steps into distribution chain the user needs to trust.
>Independent parties maintaining forks and packages are more likely to notice if vendor does something stupid,
The same people might look at Signal's main repository for the same concern, and notice the same things. Furthermore, Signal is the entity innovating on secure messaging protocols, so I wouldn't say the chances are they're doing stupid things.
>more likely to have people and tools to verify claims and implementations
No. Nobody's looking at some John Smith's Signal fork. Besides, using such fork is an incredibly dangerous weak point, from the maintainer's improper singing key storage and signing process, to just having to trust random maintainers. Absolutely no.
>It doesn't matter, they can come up with plenty of bullshit excuses claiming child porn or whatever.
So I take it you're not just clueless, you're also not following the news https://signal.org/blog/earn-it/
>The important thing is you have to trust Signal the company
The literal point of the ubiquitous E2EE, FOSS codebase with reproducible builds is to eliminate the need to trust them. The FUD you're spreading is incredibly damaging.
I don't know what's so confusing about it. You like Signal and trust them, that's fine, but I don't trust them or anything coming from the US, I really would like to eliminate such trust. Claiming that I don't have to trust them is unproductive and a lie.
That doesn't make any sense whatsoever. Vendor supplies the E2EE, users and experts review it, and then if it changes, review changes. Third parties can trivially make edits to their forks and that's the easiest backdoor possible. How can you not see that.
>Please don't make arguments that "Signal does this or that you can trust them", you do not eliminate the need to trust them this way at all.
I already explained there are technical measures in place that allow you to verify the build you're using yourself. You're clearly not a subject matter expert here so I suggest you move on.
> If you do have to trust them not to spy on you, it's not a proper "end-to-end" encryption, simple as that
You're arguing from the wrong premise. You don't have to trust them.
>it's effectively the same thing as a regular TLS encryption to the servers, where you have to trust them not to spy on you on the servers.
if Signal was doing an active MITM attack against their own encryption, that would be eavesdropping which is a felony in the US.
>And in either case that trust will be eventually violated, because there is no incentive not to, but plenty of pressure and incentives to violate it.
And somehow random repository maintainers are immune to pressure and incentives. I get it, you're trolling.
>I don't know what's so confusing about it.
If you really stretch those brain cells of yours you might understand it one day.
>You like Signal and trust them, that's fine, but I don't trust them or anything coming from the US, I really would like to eliminate such trust.
Again, you don't have to trust Signal.
>Claiming that I don't have to trust them is unproductive and a lie.
So you ignore the concept of reproducible builds and just establish an opinion with average-joe level reasoning.
I won't waste my time further.
There are no technical measures for Signal in place that allow anyone to verify the build all ends of said end-to-end encryption are running nor any technical measures to ensure the software they are running won't be updated with compromised end-to-end encryption by the vendor in the future. The measures I talk about address both points by removing trust from the vendor and distributing it across many independent entities.
> if Signal was doing an active MITM attack against their own encryption, that would be eavesdropping which is a felony in the US.
It's not just legal anywhere in the world, it's what a lot of software already does.
Anyway, if end-to-end encryption requires the exact same level of trust as TLS, there is no point in it. It's only useful in truly open source messengers, not Signal, Whatsapp or other binary blob centralizedly controlled messengers.
There is no technical measure in existence that allows that for any application. This is called a nirvana fallacy.
> nor any technical measures to ensure the software they are running won't be updated with compromised end-to-end encryption by the vendor in the future.
That applies to all software that requires automatic software updates, i.e. networked TCBs. You want something that doesn't require updating, you use stronger model like TFC.
>The measures I talk about address both points by removing trust from the vendor and distributing it across many independent entities.
And users are going to compare diffs of multiple vendors for every update to see nothing malicious was added? Give me a break.
>It's not just legal anywhere in the world, it's what a lot of software already does.
Extraordinary claims require extraordinary proofs.
>Anyway, if end-to-end encryption requires the exact same level of trust as TLS, there is no point in it.
And this is the general whataboutism propaganda I run into all the time. "There is no perfect E2EE model, therefore using it doesn't matter".
Forward secrecy and risk of legal trouble are two perfectly valid reasons to use just opportunistic E2EE, even if you don't authenticate the keys.
May the rest of the community credit your "ideas" with the silence they deserve.
"hostile takeover" = bought with money
"hostile takeover n. An acquisition of a firm despite resistance by the target firm's management and board of directors"
it's an appropriate label considering the founder was openly against it and had to leave the country
[1]: https://qz.com/960948/what-happens-when-you-try-to-send-poli...
[2]: https://www.theverge.com/2020/3/3/21163844/wechat-yy-censori...
edited to remove an erroneous claim
Not to say it's something they wouldn't do, but that was by far the most interesting part of your comment.
My friends from the mainland (but who live in HK) were sending me plenty of photos of the protests and none of them seemed to be blocked.
Looks like they've resurrected the brand to make a new chat app.
It was wildly popular at the time alongside Yahoo and AIM (AOL Instant Messenger).
It's one of the earliest fairly widely used instant messaging apps.
I think tomorrow I'll bring back myspace.
Still a centralized messaging service though. I'm sticking with Signal I think.
It would be awesome to be able to use your old icq number and hear the "uh oh" notification sound - nostalgia is about the whole experience not just brands.
Please take a moment to review this privacy policy before signing up; for example, it does not indicate any intention to comply with EU, GDPR, CCPA, etc. privacy laws or guarantees in any respect whatsoever.
App is extremely aggressive asking for location and contact access.
Net!
1. Signal: Open source with E2EE group chats. Best choice, let's use that.
2. WhatsApp, Proprietary with E2EE group chats. E2EE implementation might have a backdoor with some probability. Let's avoid it if we can.
3. Telegram: Open source client with no E2EE group chats. The implementation leaks all group chats to server and anyone who hacks the server, and there's nothing we can do. It's backdoored by design. Let's avoid it at all costs.
On the height of their popularity, they started naming their products appending either "devil" and "demon" to their products.
Of course, most people who are conservatives back then like parents, aunts, 99% of the their users, basically other than "you" the power users didn't like the new naming.
So they move-on to Yahoo Messenger and never looked back.
Moral: Don't name your popular product like how Mirabilis ICQ does it back in the late 90s.
But I could see not avoiding games, but very much wanting to avoid communications software.
https://twitter.com/TimSweeneyEpic/status/118194495168648806...