Edit: looks like it exists, and is called Briar.
Edit: looks like it exists, and is called Briar.
You can also send encrypted messages over any other medium. You don't need the messenger app to encrypt your messages for you.
One of the common arguments that PGP is bad is that it's "inevitable" that someone will send a message in cleartext, defeating the whole purpose of encrypting your messages. I don't understand this. The fact that this is possible to do is obviously an artifact of the idea that the user should be unable to tell whether the messages they send and receive are encrypted or not. Do the encryption and decryption yourself, and this is not a mistake it's possible to make. Don't confuse the encryption, which is something you do, with the delivery, which is something the channel does. The point of encryption is that the channel can't be trusted!
This is a rare case where it's centralized in practice and yet the option to do your own thing hasn't been removed from the relevant software.
Why? It can easily be the case that that traffic is observable by outside parties. You'd still need to encrypt your communication.
Connecting to the DNS server "securely" doesn't really get you anything except some DOS resistance.
$ dig +short @<trusted_server> TXT <encrypted_content>.
<encrypted_content_back>https://chatiwi.com/ seems to be the only real e2e encrypted chat without installling an app (can check the network and source code as it’s just JavaScript)
https://briarproject.org/ and https://tox.chat/ requires to install an app and doesn’t work on iOS.
Briar seems discontinued
“Latest News
AUGUST 31, 2023
Briar Desktop 0.6.0-beta released - blogs“
What's nearly impossible is to make it easy and popular among "normal users". Onboarding would be pretty involved. Adding your friends to the contact list would require jumping through a number of hoops. Having several sessions open (phone and laptop, typically) would not be trivially easy, and synchronizing between them would not be very easy, or automatic. Also, forget about push notifications.
It might be far easier to run an instance of Matrix, or whatever Jabber server, etc, on a private host, with full disk encryption, and only accessible via Wireaguard. It's not hard to set up fully automatically from an app; see how Amnezia Proxy does that.
It, of course, will have a special node (the server), but it's definitely not a public service, and it cannot be encountered by accident. It of course would be limited only to people you would invite. Should be enough for family, friends, a small project community, and other such limited circles. It would not require much tech savvy to set up.
But a grand social media kind of network, like FB or Twitter, can't be run this way, because the UX friction would inevitably be too high for a lay person to care.
I suppose only public services, advertised for new users, are the target of the "chat control" directive. You can't join pseudonymously. But joining my VPN-based chat server would require being my acquaintance; should I ask an ID from a person I met at a pub? If so, should I ask their ID before I engage in a small talk with them in the pub?
Do all of your acquaintances even use VPNs? Because 97,56% of mine don’t. So it's not about you and your friends.
But lets assume for a moment that it's about you and your friends... If this law goes through, what’s to stop them from pushing through a series of follow-up laws forcing every VPN provider include backdoors? Who’s going to stop them? Why stop them? By then, the public will have already given in. No one will care if you or your friends are sentenced to 25 years for using a “non-compliant” (read: secure) VPN. Do you have _something to hide_?
In five years, any provider without a backdoor could easily be branded as “insecure.” We’re already living in a world where words often mean the exact opposite of what they should. Why would this be any different? And from my PoV, why take the risk? Children need safe ways to communicate as much as adults.
If you live in one of the authoritarian countries and it pretends to be a democracy to a sufficient extent that voting can actually change things, try doing that. If not, your options are pretty much "apply for the passport" or "sharpen your weapons".
The cliché about how you should not approach political problems with technical solutions is recited all the time in these threads, but nobody ever presents evidence for this claim. It seems like a meme that is disproportionately useful for those who are confident in their abilities to win any political contest.
You can also go to jail for any of the above, should your particular government authority decide to throw the book at you.
Technical capability is necessary, but rarely sufficient.
It's instructive to read the I2P threat model, https://geti2p.net/en/docs/how/threat-model, as it details a number of potential attacks within reach of a large corporate or state-level adversary
We've tried the political solutions for so long, but this thing just keeps coming back. We have to put our lives and day jobs on hold to push back against this, while the authoritarian camp's agenda is carried by people for whom advancing it is their day job. Therefore it costs them nothing to try over and over again, and they only need to succeed once.
I mean, we enjoy workers rights only after decades of violent protests and many deaths, and yet they are still constantly threatened, because its is a nature of power and politics.
But pro-privacy people consider writing a petition a peak of political struggle, and when it fails it is over for them.
There is no "Eureaucracy", Council decides, countries may or may not implement.
https://commission.europa.eu/law/application-eu-law/implemen...
I think that people are no mentioning enough that there is a specific country:
DENMARK
which is leading this effort. Not saying that there aren't plenty of EU bureaucrats who support Chat Control but this is not primarily some "top-down" EU thing. Its a specific subset of countries trying to impose their dystopian ideas on the entire EU.
If the EU parliament and court of justice are the main institutions that can stop this if countries like Germany etc. just rollover.
This is what people say when they're afraid that technological solutions would actually work.
Technologies have a network effect. If the rest of the world is using a technology which is resistant to censorship or surveillance, any given country will have a harder time banning it, and those technologies defend against governments that violate privacy rights in secret even when the law prohibits them from doing it.
Build privacy into every internet standard and protocol. Make it seven layers deep with no single point of compromise. Make attempts to break it an exercise in futility because it's built so thick into so many things that stripping even a piece of it back out would break the whole world and still not compromise the security of the system.
In my opinion, federated is the sweet spot: you do have to trust the server with your account management, but that server can easily be yours, or one you ethically align with, and through it, you will be able to talk with anyone on the network.
P2P sounds great on the surface but in a mobile-first messenging world, that comes with practical tradeoffs in bandwidth and battery consumption, unless you offload discovery and push to trusted servers, at which point you are back to federation with more steps.
Don't you think that it makes them obvious high-value targets? I mean, that's not even like this profusely pragmatic take has no precedent in the real world: the Snowden revelations showed that all major tech companies were in bed with the NSA to spy extrajudicially on everyone. It's a leap of optimism to think they would "fight legally for its own interest in protecting its customers".
Then, compare that to the low-scale/low-value/hobbyist/residential service providers. How high do you think the chances are for a malicious state-actor to "corrupt" many service operators without it widely being known and publicly dealt with? There's also a deniability dimension to this: XMPP uses OMEMO as a zero-knowledge encryption scheme: whatever the users are doing is none of the operator's business, and the choice of encryption scheme and implementation is purely a client-side affair, so now you are no longer dealing with "reluctant" operators, but potentially millions of end-users using strong encryption. And that is assuming the server is operating in the open, but nothing prevents service operators from offering it over tor (with very little impact on the end-user-side), further raising the bar for the malicious state actor.
TLDR: That sounds like it is some kind or grift.
In all seriousness, google the Sidetree Protocol. Daniel Bruchner promoted it at Microsoft. And now we can even do zk-rollups too.
Where was I? Oh yes, some kind of grift!
If I know Marisa's public key and Marisa knows Omar's public key, she can sign a message to me saying, "Omar's public key hash is c2ecc3b9b9eb94dcafe228f8d23b1e798597d526358177c95effa6bc0ded3a35". I can then use that key hash to authenticate messages from "Marisa's Omar". If she gives Omar mine too, he and I can set up a private channel without further involving Marisa.
Hopefully we aren't just talking to Marisa's MitM proxy. If other mutuals also know him as "Omar" then I can ask them for his key too, and if I get the same response, I can have more confidence that Marisa isn't playing that trick on us.
Never total confidence, though. You need some way to bootstrap a non-MitMed connection; no evidence can ever prove conclusively that you aren't a Boltzmann brain floating in the post-heat-death void, or Descartes being tricked by his evil demon that controls all his perceptions, or Neo in the Matrix.
But meeting up with one of your friends in person once to exchange either public keys or a shared secret, even before you start using the system, can go a long way to ensuring that you are all actually enjoying privacy.