Re: [Endymail] Another view of the problem and what the IETF could do

Tim Bray <tim@kooky.org> Tue, 02 September 2014 22:54 UTC

Return-Path: <tim@kooky.org>
X-Original-To: endymail@ietfa.amsl.com
Delivered-To: endymail@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 18EDB1A88CD for <endymail@ietfa.amsl.com>; Tue, 2 Sep 2014 15:54:28 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -0.001
X-Spam-Level:
X-Spam-Status: No, score=-0.001 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, SPF_FAIL=0.001, SPF_HELO_PASS=-0.001] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id DC7g1IHYFFtq for <endymail@ietfa.amsl.com>; Tue, 2 Sep 2014 15:54:26 -0700 (PDT)
Received: from herm.doylem.co.uk (herm.doylem.co.uk [IPv6:2001:41c8:51:5b0:feff:ff:fe00:17d2]) (using TLSv1.2 with cipher DHE-RSA-AES128-SHA (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 77A591A88C9 for <endymail@ietf.org>; Tue, 2 Sep 2014 15:54:26 -0700 (PDT)
Received: from timdeb.doylem.co.uk ([2001:8b0:17a:0:20e:cff:fe77:4b8e]) by herm.doylem.co.uk with esmtpsa (Exim 4.80 #2 (Debian)) id 1XOwxy-0006od-Cj for <endymail@ietf.org>; Tue, 02 Sep 2014 23:54:22 +0100
Message-ID: <54064A9D.4050405@kooky.org>
Date: Tue, 02 Sep 2014 23:54:21 +0100
From: Tim Bray <tim@kooky.org>
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:24.0) Gecko/20100101 Icedove/24.7.0
MIME-Version: 1.0
To: endymail@ietf.org
References: <CAHBU6iuxfqs9RszSaJLaTV_obKBCJ9Pzii+t9XANN3q+bJm-3Q@mail.gmail.com> <878um3prio.fsf@vigenere.g10code.de> <cddbc815-a98a-48e5-8dea-c3d8a68ca4d9@gulbrandsen.priv.no> <87y4u2laqh.fsf@vigenere.g10code.de> <20140902114217.lp_a_yD8%sdaoden@yandex.com> <20140902160206.GA7900@vegoda.org> <5405EEB8.1060107@cs.tcd.ie>
In-Reply-To: <5405EEB8.1060107@cs.tcd.ie>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
X-SA-Do-Not-Run: Yes
X-SA-Exim-Connect-IP: 2001:8b0:17a:0:20e:cff:fe77:4b8e
X-SA-Exim-Mail-From: tim@kooky.org
X-SA-Exim-Scanned: No (on herm.doylem.co.uk); SAEximRunCond expanded to false
Archived-At: http://mailarchive.ietf.org/arch/msg/endymail/4KjHQuoaKAMlXBA8XAJBQEXd_sE
Subject: Re: [Endymail] Another view of the problem and what the IETF could do
X-BeenThere: endymail@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: <endymail.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/endymail>, <mailto:endymail-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/endymail/>
List-Post: <mailto:endymail@ietf.org>
List-Help: <mailto:endymail-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/endymail>, <mailto:endymail-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 02 Sep 2014 22:54:28 -0000

Just to add another 2p in the pile.


Does anybody have a view on https://telegram.org/

It is a whatsapp clone which claims to have reasonably strong encyption, 
with optional end to end encryption.  They make some fairly bold claims 
about security on their website.  The client side is open source.

It is one of the best to use IM on your phone apps I've used.

I'm told there are some scathing writeups about the encryption.  I'm not 
enough of a crypto person to be able to reason about these.

Telegram do store (non secure) chats on their server side, and they sync 
between devices very well.  Downside for crypto/intercept.  Good for 
usability.

The server side isn't open source, and is run by the service operator. 
You can't install your own, and no server to server comms.


But, it is a very very usable service.  It does what it says on the tin. 
  It is how a service aimed at a mass user base has to be.

I'm not suggesting telegram is an answer.  Just something to look at for 
inspiration.

Tim



-- 
Tim Bray
tim@kooky.org | +44 7966 479015 | http://www.kooky.org
Huddersfield, UK