TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Briar: Peer-to-Peer Encrypted Messaging

424 点作者 matthewmorgan超过 2 年前

26 条评论

californiadreem超过 2 年前
My wife and I use Briar for household communication because of subsidiarity rather than any direct privacy concerns. Out of all the messenger projects that we&#x27;ve tried, Briar actually <i>works</i> for local communication. It&#x27;s <i>actually</i> instant messaging without any client hiccups or latency (looking at you, Signal). We&#x27;ve tried a ton of other options, but we keep ending up back at Briar.<p>There <i>are</i> points of UX friction in the name of good opsec that are inconvenient but totally understandable given the project goals. The big ones being that you have to manually login after any reboots and notifications are intentionally sparse, so good luck using a smartwatch for reading or replying. Otherwise, the forums and blogs are great for managing household projects, IM is a dream, and as a bonus, anyone willing to install and use it probably has a large enough values overlap that we can use it as a social pre-filter for close friends.<p>The only other option that has come even remotely close to being as functional as Briar is DeltaChat. The only issue that stops us from using DeltaChat (or email in general) is that we both have email hosting in Europe while we live in the US, so neither of us, being frugal in principal, wants to send information to Europe and back in order to tell the person 100 ft away to come help bring in the groceries.
评论 #33691780 未加载
评论 #33687965 未加载
评论 #33716010 未加载
评论 #33690724 未加载
评论 #33691896 未加载
评论 #33691174 未加载
评论 #33688569 未加载
kevinfiol超过 2 年前
Just wanna say this app saved my family and I when we went on a cruise. Normally, we would had had to pay to use the chat service via the ship&#x27;s paid-only Wi-Fi (since we get no phone reception on the seas). Without needing to pay for the Wi-Fi, we were all able to use Briar to communicate whilst connected to the network, which made coordinating and finding each other on the ship way easier. It was great and worked really well. So thanks, Briar!
评论 #33687548 未加载
评论 #33689139 未加载
评论 #33686992 未加载
评论 #33686961 未加载
评论 #33691553 未加载
评论 #33687007 未加载
dang超过 2 年前
Related:<p><i>Briar Project – Secure messaging, everywhere</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=33412171" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=33412171</a> - Oct 2022 (7 comments)<p><i>Briar has been removed from Google Play</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30498924" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30498924</a> - Feb 2022 (85 comments)<p><i>Briar Desktop for Linux</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30023169" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=30023169</a> - Jan 2022 (84 comments)<p><i>Briar 1.4 – Offline sharing, message transfer via SD cards and USB sticks</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29227754" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=29227754</a> - Nov 2021 (110 comments)<p><i>Secure Messaging, Anywhere</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=27649123" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=27649123</a> - June 2021 (63 comments)<p><i>Briar Project</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=24031885" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=24031885</a> - Aug 2020 (185 comments)<p><i>Briar and Bramble: A Vision for Decentralized Infrastructure</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=18027949" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=18027949</a> - Sept 2018 (11 comments)<p><i>Briar Project</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17888920" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=17888920</a> - Aug 2018 (10 comments)<p><i>Briar: Peer-to-peer encrypted messaging and forums</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=16948438" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=16948438</a> - April 2018 (1 comment)<p><i>Darknet Messenger Briar Releases Beta, Passes Security Audit</i> - <a href="https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14825019" rel="nofollow">https:&#x2F;&#x2F;news.ycombinator.com&#x2F;item?id=14825019</a> - July 2017 (85 comments)
neilv超过 2 年前
Briar&#x27;s &quot;F-Droid&quot; installation option wants you to add a new package distribution repo to the F-Droid app.<p>Rather than the usual way, which is to have F-Droid verify the source build of each version, and distribute through the official F-Droid repo.<p>(And normally that &quot;Get it on F-Droid&quot; button links to F-Droid&#x27;s page for the app, rather than to another page of the project.)
评论 #33689710 未加载
评论 #33692414 未加载
jacooper超过 2 年前
I am waiting for Matrix&#x27;s P2P support, once its out, its going to crush everything else.<p>Supposedly its should come out with the improved mobile apps too, which are sorely needed.
评论 #33690852 未加载
评论 #33687500 未加载
评论 #33687200 未加载
lsh123超过 2 年前
Building a completely p2p (no servers) e2ee messaging app is not hard except one big problem: contacts discovery. I looked through briar website and it seems the solution is to constantly ping all contacts and hope that everyone is online plus at least one of IPs stays the same between pings. Did I miss something more interesting?
评论 #33686491 未加载
评论 #33692108 未加载
评论 #33686394 未加载
Ptchd超过 2 年前
Briar is nice, too bad they don&#x27;t have a Linux app (only an Android app)... Also, it chews through battery in no time.
评论 #33686497 未加载
评论 #33689371 未加载
评论 #33689489 未加载
lrvick超过 2 年前
The biggest privacy problem of Briar is it requires iOS or Android to use.<p>If you cannot control your endpoint, you cannot control your keys or your privacy.<p>Briar will become useful to me when it can run on open platforms like a Pinephone, Librem 5, Precursor, etc.
评论 #33691903 未加载
maqp超过 2 年前
Briar is one of the most important secure messaging projects currently. Not only does it remove the need to trust the vendor about content (like with all E2EE messaging apps), you also get to keep the metadata about communication to yourself as data transits from one Tor Onion Service to another.<p>The downside is of course, you need to keep the endpoint powered on when you want to be reachable so it will increase the battery drain on your phone.<p>Note: There&#x27;s also a desktop client if that&#x27;s easier to keep online <a href="https:&#x2F;&#x2F;briarproject.org&#x2F;download-briar-desktop&#x2F;" rel="nofollow">https:&#x2F;&#x2F;briarproject.org&#x2F;download-briar-desktop&#x2F;</a><p>One extremely important thing Briar is doing, is it&#x27;s using the P2P as means to host alternative social interaction formats, like forums and blogs. Similar to Signal&#x2F;WhatsApp stories (which is somewhat similar to microblogs&#x2F;FB wall), it&#x27;s a way to indirectly share information. You could pretty much emulate any social media platform on top of E2EE protocol with ~zero infrastructure cost and without having to worry about data mining. I&#x27;d argue what Briar&#x27;s innovating on here is one of the most important aspects in what&#x27;s left for secure messaging.<p>Finally a small caveat: Briar will share your Bluetooth MAC address with all peers so it can automatically use that when you&#x27;re in close proximity with your peer. Thus sharing your Briar ID publicly is not a good idea for two reasons:<p>1) major global adversaries may have access to the leaking Bluetooth MAC (e.g. if Google aggregates it) which can deanonymize your account. This also allows slightly technical person to confirm identity of briar account if they suspect it&#x27;s you (a bit wonky threat model but still).<p>2) it ties everything you do across your accounts on same device together, so there&#x27;s strong linkability even if you rotate the identity key by reinstalling the app.<p>Briar is pretty clear about this in it&#x27;s FAQ, but it&#x27;s still not very well known although it definitely should be.<p>---<p>That being said, if you want similar Onion Service based communication with no such linkability, there&#x27;s <a href="https:&#x2F;&#x2F;cwtch.im&#x2F;" rel="nofollow">https:&#x2F;&#x2F;cwtch.im&#x2F;</a> which is a fantastic project.<p>There&#x27;s also <a href="https:&#x2F;&#x2F;www.ricochetrefresh.net&#x2F;" rel="nofollow">https:&#x2F;&#x2F;www.ricochetrefresh.net&#x2F;</a><p>Both are spiritual successors to John Brooks&#x27; `Ricochet` application which pioneered the whole Onion Service based instant messaging in 2014.<p>You can also chat and share files (among other things) with <a href="https:&#x2F;&#x2F;onionshare.org&#x2F;" rel="nofollow">https:&#x2F;&#x2F;onionshare.org&#x2F;</a><p>(And finally, you can get remote exfiltration security for keys&#x2F;plaintexts with TFC <a href="https:&#x2F;&#x2F;github.com&#x2F;maqp&#x2F;tfc" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;maqp&#x2F;tfc</a> (my personal work), at the cost of losing some features like message forwarding etc that the architecture prevents you from doing.)
评论 #33700496 未加载
dijit超过 2 年前
Note: on iOS&#x27;s App Store searching for Briar shows Signal for me.<p><a href="https:&#x2F;&#x2F;i.imgur.com&#x2F;5YiR1Xk.jpg" rel="nofollow">https:&#x2F;&#x2F;i.imgur.com&#x2F;5YiR1Xk.jpg</a>
评论 #33691620 未加载
评论 #33697180 未加载
nullc超过 2 年前
Since the protocol appears to use adhoc synchronization, the authors might be interested in <a href="https:&#x2F;&#x2F;github.com&#x2F;sipa&#x2F;minisketch&#x2F;" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;sipa&#x2F;minisketch&#x2F;</a> which is a library that implements a data structure (pinsketch) that allows two parties to synchronize their sets of m b-bit elements which differ by c entries using only b*c bits. A naive protocol would use m*b bits instead, which is potentially much larger.<p>I&#x27;d guess that under normal usage the message densities probably don&#x27;t justify such efficient means-- we developed this library for use in bitcoin targeting rates on the order of a dozen new messages per second and where every participant has many peers with potentially differing sets--, but it&#x27;s still probably worth being aware of. The pinsketch is always equal or more efficient than a naive approach, but may not be worth the complexity.<p>The somewhat better known IBLT data structure has constant overheads that make it less efficient than even naive synchronization until the set differences are fairly large (particular when the element hashes are small); so some applications that evaluated and eschewed IBLT might find pinsketch applicable.
ofrzeta超过 2 年前
Related: Are there any standards, APIs, best practices for p2p peer discovery?<p>I found this <a href="https:&#x2F;&#x2F;github.com&#x2F;status-im&#x2F;bigbrother-specs&#x2F;blob&#x2F;master&#x2F;data_sync&#x2F;p2p-data-sync-comparison.md" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;status-im&#x2F;bigbrother-specs&#x2F;blob&#x2F;master&#x2F;da...</a> (mentions Gossip and Kademlia) but it is several years old and doesn&#x27;t contain much info on peer discovery.
评论 #33690551 未加载
评论 #33689981 未加载
oska超过 2 年前
Keet (still in Alpha) is also doing P2P encrypted messaging (and video calls).<p><a href="https:&#x2F;&#x2F;keet.io&#x2F;" rel="nofollow">https:&#x2F;&#x2F;keet.io&#x2F;</a>
ementally超过 2 年前
Well... P2P isn&#x27;t the best when it comes to messaging <a href="https:&#x2F;&#x2F;github.com&#x2F;simplex-chat&#x2F;simplex-chat&#x2F;blob&#x2F;stable&#x2F;docs&#x2F;SIMPLEX.md#comparison-with-p2p-messaging-protocols" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;simplex-chat&#x2F;simplex-chat&#x2F;blob&#x2F;stable&#x2F;doc...</a>
评论 #33690325 未加载
评论 #33698833 未加载
bawolff超过 2 年前
&gt; The adversary has a limited ability to monitor short-range communication channels (Bluetooth, WiFi, etc).<p>That seems like a pretty big assumption. From what i understand there already exists deployment of wifi hot spots to track people (both for advertising purposes and for spying purposes) to the extent that phone providers started radomizing MAC addresses.
评论 #33686861 未加载
upofadown超过 2 年前
You can verify identities in person by scanning a QR code. That&#x27;s completely solid. Otherwise you can send someone a link. It should be made clearer in the documentation that that link might end up with someone other than who you expect and the potential downside of that.
puntofisso超过 2 年前
What I find interesting is that such p2p comms applications return with a certain recurrence. I think one of the first was Nokia Sensor (2005?), and there was one that was famous during the Arab Spring&#x2F;Hong Kong protests.
exabrial超过 2 年前
Most of the world uses Android, so I can understand the reason why it&#x27;s an Android project. I just wish there was an iOS port too!
LibertyBeta超过 2 年前
I want to like Brair, but I have yet to find any one who does use it. Which is a shame, really.
braingenious超过 2 年前
This is super cool! I’m assuming that there is nothing on iOS that’s comparable, which is a bummer.
LoganDark超过 2 年前
Another mobile-only messaging app. If I wanted to use my phone, I&#x27;d just use SMS or RCS!
评论 #33693330 未加载
lgxz超过 2 年前
Are there similar iOS Apps?
评论 #33691516 未加载
matthewmorgan超过 2 年前
Useful in warzones I&#x27;d imagine
anonymousDan超过 2 年前
How does it handle spam?
评论 #33692201 未加载
DoItToMe81超过 2 年前
Why this, and not something with a proven record of stability like Tox?
评论 #33698735 未加载
评论 #33690467 未加载
willnonya超过 2 年前
Briar, for when security and deliverability of your messages aren&#x27;t really the point...
评论 #33687006 未加载