Show HN: P2P microblogging over Bluetooth to avoid government censorship
github.com
github.com
This could be particularly problematic if you're targeting an internet blackout situation, because people will likely use the tools they have until they can't anymore, at which point it will be too late to download yours.
So you might think about positioning it differently, or coming up with an application for it that people will enjoy outside of a crisis situation, so that it will be one of those tools that people already have.
I know it's probably an unpopular opinion, but I don't believe that we should be distributing APKs outside of the Play channels. It takes us back to the PC distribution model, with all of the associated security and usability problems.
It doesn't allow you to easily get at apks you've downloaded from the Play store, if that's what you mean, but I think that's just an anti-piracy measure. An apk you've downloaded from somewhere else is, as far as I can tell, just another file. I can't imagine why (or how!) it'd stop you from exchanging them, particularly if you have some sort of custom Bluetooth client.
Does it really try to stop you?
Not allowing apks via bluetooth seems like a usability issue too.
This could become very popular in parts of India. I could see people using this share photos/songs with their friends.
P.S. I agree with what I think is the principle behind this -- I have for some time, with respect to freedom on the Internet and its like. That being that the only true security and reliability will come from owning and controlling the physical layer.
I also like that, unlike with autonomous wifi access points, the signal might be able to hide -- and move about -- within a larger sea of Bluetooth connectivity and at lower powers and therefore exploitable ranges. If I'm thinking about this at all correctly (I'm unsure).
EDIT: If you are not already familiar with it, take a look at the PGP web of trust idea to get a better feel for the "proven authorship" use case. Some linux distros use PGP keys to prove authorship of software. http://en.wikipedia.org/wiki/Web_of_trust.
...and the authorities, or any other attacker, wanted to disrupt the system -- they could just put all sorts of devices in the area distributing an incredibly high volume of spammy messages. As you circulated and downloaded messages from other nearby devices over bluetooth -- the legit messages from good actors would be overwhelmed by the spam messages, taking up all your storage space and making it hard to notice the legit messages.
I was thinking about this, but then read this thread, and it occurs to me there may be some solution involving crypto, whitelisting certain signatures as 'known good actors', or even a web of trust thing. But yeah, that also could compromize the desired anonymity.
And it's also probably true not to bother designing for a hypothetical problem/attack, the actual problem/attack will be subtly different. Still, I see a lot of these systems that are _really neat_ tricks, but seem to me like they would break down if they actually became popular, they work only as neat tricks.
But yeah, I also really like the idea of private person-to-person (or person-to-known-group) encrypted messages -- they could even be distributed over participating third parties devices right? Author walks by person X, who's device picks it up but can't actually read it, and later hands it off to person Y, one of the intended recipients, who can read it. I'm not sure if that would end up actually being useful or not, but it would be NEAT.
Either way it'd be great to support it for those power reasons you mention and for how much faster it would be to sync.
I've been hoping there's a company coming out with a phone/tablet with two 802.11 interfaces, so I can stay on Wifi and at the same time join an ad-hoc network :-)
EDIT: typo
Still a cool little project the OP has there though and I'm sure they learned quite a bit while doing it.
Do I think its really cool?: Hell yes.
Is there any possibility of eventually adding settings to do things like make the "delete all messages" button a one-press affair, instead of having to go through a confirmation? Those crucial couple of seconds could be the difference between securely deleting your info and giving it all up to Totalitarian Regime X.
[1] http://chirp.io
What's the point of that? Especially as this discussion has it's roots in an offline, censorship free communication system.
You'd be better off using SSTV — http://en.wikipedia.org/wiki/Slow-scan_television
If only mobile phones had good, configurable radio transmitters...
(EDIT: rephrased as question)
Is it truly impossible to make wifi behave in a peer-to-peer/mesh network fashion?
-authorities won't care msgs are anonymous and will assume you wrote them or know who did if your phone is seized, you will get rubber hosed anyways
-just having the app on your phone means guilty of dissent if arrested the erase function pretty useless. should camoflauge the app
-wandering around with bluetooth enabled while your adversary is a despotic regime with money to buy corporate intelligence contractor provided sophisticated malware and spyware is dangerous. hey here's my phone wide open for you to exploit even better, create spyware that jumps from phone to phone as we pass msgs you can create a virtual listening network to spy on the entire revolution
-intel can be changed by agents or censored before being passed on
to pass the app between devices could use nfc or wifi but that would also be dangerous to leave on all the time should agents get close enough to you and exploit your nfc to copy contacts or inject spyware, or wifi.
that said this is better than nothing which is the alternative