Friends: a p2p, decentralized, secure messaging platform
moose-team.github.io
moose-team.github.io
* Non-repudiable. Everything you send is signed with the public key on your GitHub account.
* Uses SHA1. (via the ghsign NPM module)
* Uses mDNS and BlueTooth LE and a gossip topology algorithm, so I'm not sure what would prevent a random third party from eavesdropping.
I would hesitate to market this as "secure".
Messages are not end-to-end encrypted, and this is not an anonymous system. See below for more details. We use the term 'secure' here to mean that we do not use plaintext transports.
Although to my admittedly meagre security knowledge, I would've assumed that "no plaintext transports" would mean it was encrypted end-to-end.
package main
import "fmt"
func main(){
fmt.Println("Hello World")
// Contributions welcome!
}(Seriously, what's that supposed to mean? Should that increase my confidence in how "secure" this is?)
It seems to me that they're encrypted with your private key and paired with "username". The client then attempts to decrypt using the public key associated with that username on github.
In this system, the receiver and any MITMs (okay, so everyone) know it came from "the real grrowl according to github" — authenticated but not confidential at all.
First, you're describing RSA signatures. "Encrypt X with your private key" means "X^D mod N" which is how RSA signatures work. In the context of RSA-based cryptosystems, it's clearer to just say "signed".
Second, the ghsign library uses the `RSA-SHA1` signer, which runs the message through SHA1 before signing it. The reason it does this is because "textbook" RSA (i.e. RSA on arbitrary messages) is vulnerable to chosen-plaintext attacks.
But, why does something saying it is p2p always seem to have some centralized dependency? In this case, it's GitHub auth.
It seems that the initial authentication of you are who you say you are could be done via transferring a key to someone- by email, flash drive, whatever- and then after that, as long as you could connect to them, you could talk to them- with no other dependency except the network itself, which may involves a lot of significant dependencies, or may not, e.g. a cross-wired cable.
> There is no middle man, no proxy, no 3rd party, no UPnP/STUN/ICE required, no spoofing, and no DNS tricks.
The FAQ is great too :)
Ok, so does this really work?
Yes. Try it!
I'm confused. This can't work.
You should be, and it does work.
But it can't. My NAT blocks incoming packets and so will the other.
I know."This user claims to be Jimmy Jimson (image of fingerprint). Trusted by 19 people you directly trust, and by 250 people they trust. [add] [ignore]".
Is this feasible? I'd rather attackers social engineer people rather than subvert the technical, non-human aspects.
And like Facebook, if you see two of the same person on your Trusted list, you know one of the accounts is probably not under their control.
I know this might sound snarky, but this is the combination a lot of my peers and I use.
I'm wary of the "yet another proprietary new messenger", all of which are only compatible with themselves. I can not understand why none of them implement protocols all the messengers can agree upon like for example tent.io, remoteStorage or ZeroNet.
Distributed messaging is hard and a lot of people are giving it a try, leaving us with lots of different half baked walled gardens. Yes, I'm looking at you, threema, telegram and your friends...
I'll probably make a Show HN post once we open source it.
So if I understand it right, if you make a P2P app in js using websockets, it still requires a server to spread IPs between hosts. So it's "decentralized", but you could still track users since the server has everybody's address.
So when you chat, it's P2P, but when you start it up, it's still centralized.
Unlike kamdelia, bitcoin, bittorrent, bitmessage, you could still shut this down if it uses js. Not very interesting.
* https://en.wikipedia.org/wiki/RetroShare
* http://freecode.com/projects/alliancep2pIs it http://nwjs.io/ ?
I could be wrong but now that the latter has been integrated into Microsoft's tools, I think there's an open gap for what Skype used to provide: a friendly P2P chat tool.
It has a ways to go in the way of frontends and mobile support, but it works. The biggest feature it's missing is proper synchronization of your profile between devices (which is a development priority). That and it has a small network of users, so you won't be talking to your mom over Tox.
[1]: https://tox.im/