Briar has been removed from Google Play
briarproject.org
briarproject.org
Unfortunate timing by Google.
> Briar was briefly removed from Google Play because we didn’t provide Google’s review team with a username and password for testing the app. We provided Google with a username and password for testing and the app is now available again.
What kind of username/password?
It's not like you sign up for Briar like when you create an account on HN.
https://edition.cnn.com/2014/10/16/tech/mobile/tomorrow-tran...
The sent me an email saying there was a broken link on my homepage (a link to the blog at the bottom of the page which was also at the top). In the email they sent me all the links to google were broken. I asked why did it matter if my website had a single broken link and how this affected using scopes, no response.
The don't speak to you and always send you back pre-canned messages, I got one saying my app was still in development, so communicating in this manner is really difficult.
Btw in terms of security almost all the scopes are sensitive in their system so anything other than login you'll have to go through this process.
I welcome extra security but the process was terrible.
Briar has more than 500k installs according to its Google Play page. Why do Google need to remove the app entirely if they've previously accepted and published it? I can understand not allowing an update without the proper review process using a working account, but what's the reasoning behind removing the old version that Google allowed just because they can't review an update? That makes no sense.
Also, the developer console itself keeps getting redesigned making it hard to find where to put these new bits of information.
Briar has no registration process. Pick any username and password and you're good to go.
Google's process is probably not used to apps that aren't centralized with a single, third-party service delivering the golden with ticket
One that I can happily recommend is F-Droid https://f-droid.org/ . In fact, I believe Briar is on it.
Colour me skeptical...
https://mobile.twitter.com/wikileaks/status/1497314070738911...
I also find it strange that he'd push something like this from prison and somewhat question how strong his recommendations are given he's been cut off from the digital world for several years. But I know nothing about the app.
Your sneering says more about what color you are.
And his fragmentary picture includes app recommendations? Skepticism seems like the right call, even though he has a very good reason for his years of silence.
It's not so surprising that Assange would have had strong opinions on both the limits and opportunities of mesh networking, and knowledge about who were working on it who were competent and had sound ideas. Briar got an independent security audit in 2017.
I would maybe not take that recommendation that easily.
Does Android allow installing public keys for specific apps so you don't have to allow all untrusted apps just to install one?
This is kind of a silly question. The only point of the "Install unknown apps" setting is to make it less convenient to avoid the Play Store. You'll always be asked for confirmation before installing a new app (unless you've rooted your phone to bypass that), and installing an update with a different public key with the existing version uses will fail even if you do confirm the installation.
Who can trust the bloatload of crap, bugs, backdoors of such devices, even carrying them alone in such situations?
Personally I try, and I'm not alone, to live without smartphones, and some propose to use them as "secure communication tools" for privacy-critical contents?!
A thing, that's NOT a personal attack nor something else but here is HN, so a place whose users typically are tech savvy humans: did you really imaging a smartphone as the best/the goto tool to communicate under a dictatorship/secret investigations etc? I'm curious because or you are secretly working for NSA and similar or... I can't imaging how you can be a (stereo)typical HN user.
Supposing I'm a whistleblower communicate with a journalist, well the first mean I choose is passing something physically via trustable third parties, plural in the sense that one should contact another not much linked/unlinked to me who do the same, to make unlikely some small surveillance notice something strange. They just should know they do something "a bit secret" for me without knowing the rest. If he/she have a public GNUPG key I can use it to cipher what I pass but, unfortunately, that's unlikely for most journalist, they simply do not know tech enough. After the first contact I'll try to find a common ground to let him/her understand that I'm not joking and similarly that he/she is interested in doing that. I'll then teach how to use FLOSS tools on a third party computer, with a live USB key, running from ram. I'll keep changing at random the means of communication etc.
If I live under a dictatorship and I'm involved in Resistant activities the last thing I want is hi tech gears around, at least they do my best to appear using and liking them, doing the opposite, trying to be double face. I'll do my best to organize coms via ephemeral/disposable tools, something low tech as possible and hard to massively track.
If I'm a journalist, trapped behind enemy lines, I try to document as much as possible with some kind of deniable encryption, something like not so innocent and badly hidden while the real things are well deeply covered and try to keep a profile as low as possible, including NEVER communicate directly with the other side of the front.
If you imaging going to war with a smartphone in your pocket I sincerely advise you to avoid that at all: you'll be a dead man in a far shorter period of time than normal...
Pointed this out - app passed the review process.
1. Is Briar or Firechat open source?
2. Are they actually effective past "within a crowd" range? I.e. has the Bluetooth "networking" ever worked?
3. Is there any way to "secure" traffic?
2. https://briarproject.org/how-it-works/ any nodes can act as a mule to carry encrypted messages between "bubbles" through either Tor, WiFi or Bluetooth
3. The communications are encrypted all encrypted (at rest and in transit), only those who are added as contacts or part of a forum as a member will have the key(s) to decrypt the communication.
No idea about 2. though. Going with "unlikely".
I cannot answer the first one, but the second question seem to be legit: the store page returns a not found https://play.google.com/store/apps/details?id=org.briarproje...
[0]: https://github.com/briar/briar (mirror)
However, I do see they have a section in their README regarding reproducible builds for verifying APKs against their source code.
So much so, in fact, that I've actually seen the contra-conspiracy asserted: Russia made Assange/Wikileaks push this app precisely to drive Ukranians users away from it and into the arms of something else to which they presumably have more visibility.
And the app is open-source, you can even compile it yourself.
Because we didn’t provide Google’s review team with a username and password for testing the app. Apparently they didn’t realise they can choose any username and password they like.
Well perhaps next time give the review team a way to login, since they don't know how to use the app?> We’ve provided Google with a username and password for testing
Briar doesn't work like services like HN where you sign up with a username and password.
You can literally type in anything, since there's no server that validate that info.
Signups typically involve agreeing to some terms, and you absolutely don't want company employees working their official job duties agreeing to random T&C's.
I think we all know the drill with walled gardens but if you want a fighting shot of getting in they at least give it their guidelines.