Avatar: A browser OS with built-in privacy and anonymity
sneakpeek.avatar.ai
sneakpeek.avatar.ai
So if you know your crypto and you are intimately familiar with Alice and Bob, please lend us a hand and take a look at the protocols. Our discussion forum has a special section for security and protocols where you can post your comments.
Thank you!
Never mind your protocols, I'm pretty sure nothing can go wrong here!
Its meaning is only slightly different from "platform", which basically means "any API to which you can program applications."
Also, by your definition, Android and Slackware Linux are the same "Operating System" because they share the same kernel and drivers.
Which is exactly my point. This term is in common use and means different thing to different people.
Well, no, they don't. Android still uses a slightly modified Linux kernel, and there is zero overlap in the drivers. Also they have fundamentally different approaches to task & memory management at the kernel level.
Pedantics aside it's clear that Avatar is not an OS, not even with the most generous and broad definition. At least not with what little they've said so far. Because what they have so far in their diagrams and minimal technical info is yet another JavaScript framework paired with yet another set of web services around user authentication.
The Android Mainlining project continues to trudge onward, it's not complete. There's a decent chunk of stuff sitting in staging as well that hasn't been accepted by mainline, but still more that hasn't even gotten to staging. There's also a few things where mainline rejected Google's version and provided an alternative, but Android was never changed to use the new thing (Alarms/Timers fall into this case)
Does Avatar serve pages over plain HTTP(S) like Freenet, or is there some other magic here?
I wrote more about how Avatar compares to X here: https://discussions.avatar.ai/topic/13/comparison-to-tor-fre...
EDIT (from here to end): to clarify - my question is to assess security of the 'runtime' - if it's downloaded from the server what is there to stop malicious party from compromising the server and sending modified verification code?
Would it be downloaded through the bridge then (and only then) verification with block chain could be done on received updates (providing first d/l wasn't compromised). User browser would then access files exposed by the bridge.
At least this is how I imagine it but the OP overview is light on details.
Anyway... TFA states this:
"We are aware of theoretical weaknesses in secp256k1"
What are the theoretical weaknesses in EC secp256k1?
You will have better results by going out and educating people about how technology works than inventing a internet-obscurity-security sort of thing.
On top of it, if the NSA can detect who encrypts its traffic the most, who use what OS, what browser, if that person has used PGP, etc, it just needs to monitor this person a little bit more.
I don't want to sound cynical, but I wish I could see programmers work on solving real problems, like economical ones: you'll be surprised how miscommunication and lack of information spreading can worsen situations.
Many people seems to criticize facebook, why am I not seeing anyone reinventing the social network ? I'm not talking a website like diaspora or google+, but anything which is designed for making the economy work better. Like a craiglist for masses, but more efficient and relevant.
How the fsck is that in any way an OS?
>"We believe it's not your job to keep track of what social networks your contacts use. With Avatar you simply just write a message and the system takes care of delivering the message to your friend. You can use your Avatar to communicate "cross-border" with other social networks like Facebook or Twitter."
I saw someone mention this yesterday on HN for another service, but I'll say it here. This seems like a huge WTF, as people separate services for a reason. If I want to talk to someone on facebook, I might not via email, or via a different email address to the default. See: Google recently outing a trans person who used different services for different identities.
Do the authors have a plan to address data loss? Do they have a plan for caching/replicating data to alleviate hot spots? Will their replication strategies on read/write objects include a well-defined consistency model?
According to someone (a developer?) further down this thread, they realize that incentives will be needed for things like this. It sounds sort of like the same problem that the bitcloud people are trying to solve, but to my knowledge nobody has any solid solutions.
Why pay more for a blind CDN when 99.9% of your customers use infrastructure that only require you to use unsecured ones? That shouldn't be a rhetorical question--this is an important issue that needs to be addressed if we want to make the Internet a better, freer, and more secure place to communicate. We'll see if these guys come forward with something that sounds like it can work, I guess.
However, it seems that this requires a lot of people using it to be useful (network effect)? Is there a plan for getting this used by people?
I can't help thinking they're looking at this the wrong way round.
Any action videos or demo available?