Hacker News

Top stories

Live mirror
30 storiesupdated just nowView source snapshot
  1. Parley: Federated, decentralised chat that speaks plain IRC (mills.io)
    93comments
  2. What Heraldry and Mon Can Teach Us About Building Visual-Identity Generators (benovermyer.com)
    —discuss
  3. Coding Is Not Solved (alexewerlof.com)
    160comments
  4. Jensen Huang says AI distillation is 'competition.' (cnbc.com)
    25comments
  5. 37,500 border drawings: a map of the world as people remember it (habibicode.org)
    28comments
  6. Show HN: Hntui – A TUI for Hacker News (github.com/ahmd-sh)
    36comments
  7. MongoDB CEO resigns "effective immediately" to join Meta, stock drops 20% (reuters.com)
    20comments
  8. Show HN: PaperMono, e-ink fridge magnet shopping list with mobile web page (github.com/seamusc)
    16comments
  9. Footguns with Postgres "at time zone 'UTC'" (bookofrevenue.com)
    55comments
  10. Owed a billion dollars in Nvidia stock (colo.to)
    395comments
  11. Ember-1 (fireworks.ai)
    235comments
  12. When did Google get so weird? (sancho.bearblog.dev)
    849comments
  13. Nissan's third generation e-POWER powertrain (nissan-global.com)
    261comments
  14. Thinking fast and slow in AI: The role of metacognition (2021) (arxiv.org)
    57comments
  15. Self-Hosting on the Dark Web (alvarezrosa.com)
    101comments
  16. Show HN: Free alternative to graphics design giants (scissor.studio)
    8comments
  17. Malleable software: Restoring user agency in a world of locked-down apps (2025) (inkandswitch.com)
    66comments
  18. Alan Kay's answer to “Did the ENIAC have a BIOS”? (quora.com)
    56comments
  19. Functional Mechanical Sympathy [video] (youtube.com)
    11comments
  20. Guitar amp and effects pedal built on the Waveshare ESP32-S3-Touch-AMOLED-2.06 (github.com/dashersw)
    67comments
  21. Made by Mechanical Means (felixrieseberg.com)
    22comments
  22. Lunar Terminator Paradox (secretsauce.net)
    63comments
  23. Three Days in August: What a DDoS Attack Exposed in Our Network (nine.ch)
    16comments
  24. The state of SIMD in Rust in 2026 (shnatsel.github.io)
    46comments
  25. Don't couple your Go code to GitHub (iain.rocks)
    154comments
  26. In an $80 motel room, a discovery to shed light on the origins of life (nytimes.com)
    105comments
  27. Deterministic Concurrency [video] (youtube.com)
    5comments
  28. Replacing the old battery on rechargeable bike lights (jvns.ca)
    112comments
  29. Reading’s Bayeux Tapestry (diamondgeezer.blogspot.com)
    27comments
  30. Show HN: Lofi Cities – Pixel-art city nights with browser-generated lofi (loficities.com)
    118comments

Friends: a p2p, decentralized, secure messaging platform

103 pointsby 11y agomoose-team.github.io
45 comments
11y agoHN ↗

* No confidentiality. All communications are sent plaintext. They plan to "add support in the future when solid approaches emerge".

* Non-repudiable. Everything you send is signed with the public key on your GitHub account.

* Uses SHA1. (via the ghsign NPM module)

* Uses mDNS and BlueTooth LE and a gossip topology algorithm, so I'm not sure what would prevent a random third party from eavesdropping.

I would hesitate to market this as "secure".

11y agoHN ↗

Then why the hell are you advertising it as "secure"? There's utterly nothing secure about it.

11y agoHN ↗

From the home page:

Messages are not end-to-end encrypted, and this is not an anonymous system. See below for more details. We use the term 'secure' here to mean that we do not use plaintext transports.

Although to my admittedly meagre security knowledge, I would've assumed that "no plaintext transports" would mean it was encrypted end-to-end.

11y agoHN ↗

  package main
  import "fmt"

  func main(){
    fmt.Println("Hello World")
    // Contributions welcome!
  }
11y agoHN ↗

I really really really don't recommend outsourcing your security architecture to interested passers-by if that's going to be a core feature of your project.

11y agoHN ↗

But, real crypto.

(Seriously, what's that supposed to mean? Should that increase my confidence in how "secure" this is?)

11y agoHN ↗

Apparently so. It uses DTLS, but I'm not sure where the certificates for that would come from or how their authenticity is verified. If it's all self-signed, then your best solution is TOFU (trust on first use). Otherwise your confidentiality and integrity are completely dependent on your network position.

11y agoHN ↗

When you send messages, they're signed with your SSH key

It seems to me that they're encrypted with your private key and paired with "username". The client then attempts to decrypt using the public key associated with that username on github.

In this system, the receiver and any MITMs (okay, so everyone) know it came from "the real grrowl according to github" — authenticated but not confidential at all.

11y agoHN ↗

Two things:

First, you're describing RSA signatures. "Encrypt X with your private key" means "X^D mod N" which is how RSA signatures work. In the context of RSA-based cryptosystems, it's clearer to just say "signed".

Second, the ghsign library uses the `RSA-SHA1` signer, which runs the message through SHA1 before signing it. The reason it does this is because "textbook" RSA (i.e. RSA on arbitrary messages) is vulnerable to chosen-plaintext attacks.

11y agoHN ↗

This sounds a lot like the spirit of Skype in its early days.

I could be wrong but now that the latter has been integrated into Microsoft's tools, I think there's an open gap for what Skype used to provide: a friendly P2P chat tool.

11y agoHN ↗

Tox[1] is aiming to fill that gap. It works, and although it hasn't been properly audited (that I know), most people agree that it's reasonably secure and anonymous. It's also completely p2p with no federation of any kind.

It has a ways to go in the way of frontends and mobile support, but it works. The biggest feature it's missing is proper synchronization of your profile between devices (which is a development priority). That and it has a small network of users, so you won't be talking to your mom over Tox.

[1]: https://tox.im/

11y agoHN ↗

4chan trolls aren't actively trying to destroy it.

11y agoHN ↗

I suppose this isn't oriented around file sharing, but it reminds me of

  * https://en.wikipedia.org/wiki/RetroShare
  * http://freecode.com/projects/alliancep2p
11y agoHN ↗

The number one thing I'm looking for in an open-source Skype alternative is persistent group chats with history (so when you sign in, you're still in the same group chats you were, and the history of messages that were sent in that chat while you were gone are sent to you). I'm baffled that this seemingly necessary thing is such a rare feature, and I'd be all over this project if it gets this.

11y agoHN ↗

We thought the exact same thing, so we're creating Matrix [1]! It supports all sorts of things, but especially public/private group chats with multiple device support. We're basically a team of people who use IRC all day, so we really do feel your pain :)

[1] http://matrix.org

11y agoHN ↗

TextSecure has encrypted group chats. If there's any downsides there, I'd be curious to hear what they are.

11y agoHN ↗

irssi in tmux on a cheap VPS.

I know this might sound snarky, but this is the combination a lot of my peers and I use.

I'm wary of the "yet another proprietary new messenger", all of which are only compatible with themselves. I can not understand why none of them implement protocols all the messengers can agree upon like for example tent.io, remoteStorage or ZeroNet.

Distributed messaging is hard and a lot of people are giving it a try, leaving us with lots of different half baked walled gardens. Yes, I'm looking at you, threema, telegram and your friends...

11y agoHN ↗

I have approximately zero chance of getting all of my friends and family to set up their own VPSs and tmux and irssi so I can chat with them.

11y agoHN ↗

My senior project is this. We plan to open source it in a bit after the semester ends. You can try it out here: https://projectdefero.com/

I'll probably make a Show HN post once we open source it.

11y agoHN ↗

I love how you've simplified the problem space by delegating keys and key sharing to ssh and github. Nice way to get to MVP quickly!

11y agoHN ↗

Poor nullsoft. Milkdrop is still the best music visualiser available, NSIS is still(!!!) being updated (last release October 2014), and they just did Great Work until AOL came along. So sad.

11y agoHN ↗

Among other, non-technical things it simply didn't scale well because of its re-broadcast nature.

11y agoHN ↗

Neat service!

But, why does something saying it is p2p always seem to have some centralized dependency? In this case, it's GitHub auth.

It seems that the initial authentication of you are who you say you are could be done via transferring a key to someone- by email, flash drive, whatever- and then after that, as long as you could connect to them, you could talk to them- with no other dependency except the network itself, which may involves a lot of significant dependencies, or may not, e.g. a cross-wired cable.

11y agoHN ↗

Because key distribution is a pain. That said, it would be neat if you could choose centralized keystore. That would mean that you would get one account per online service, but the communications could be multiplexed.

11y agoHN ↗

Key distribution and NAT traversal. The latter is literally impossible without some kind of external third party to facilitate.

11y agoHN ↗

Simply put, this is a proxy server that works behind a NAT, even when the client is behind a different NAT, without any 3rd party or network changes.

There is no middle man, no proxy, no 3rd party, no UPnP/STUN/ICE required, no spoofing, and no DNS tricks.

http://samy.pl/pwnat/

The FAQ is great too :)

    Ok, so does this really work?
	Yes. Try it!

    I'm confused. This can't work.
	You should be, and it does work.

    But it can't. My NAT blocks incoming packets and so will the other.
	I know.
11y agoHN ↗

It's clever, but not exactly relevant to the GP's comment. pwnat requires the initiator to know the IP of the target host, so some form of external seeding is still required.

11y agoHN ↗

Knowing who you want to contact is usually a requirement to be able to contact them.

11y agoHN ↗

Something like PGP without automatic trust of new connections may work, as if cross with Facebook's friend system.

"This user claims to be Jimmy Jimson (image of fingerprint). Trusted by 19 people you directly trust, and by 250 people they trust. [add] [ignore]".

Is this feasible? I'd rather attackers social engineer people rather than subvert the technical, non-human aspects.

And like Facebook, if you see two of the same person on your Trusted list, you know one of the accounts is probably not under their control.

11y agoHN ↗

More secure, while in this case is not a high bar, is just an assumption without the source code.

11y agoHN ↗

Don't websockets require a server to work ? You can't just directly connect to an host (obviously to prevent malicious scripts, I guess) using js.

So if I understand it right, if you make a P2P app in js using websockets, it still requires a server to spread IPs between hosts. So it's "decentralized", but you could still track users since the server has everybody's address.

So when you chat, it's P2P, but when you start it up, it's still centralized.

Unlike kamdelia, bitcoin, bittorrent, bitmessage, you could still shut this down if it uses js. Not very interesting.

11y agoHN ↗

Exactly what I thought. WebRTC has this limitation and it's not actually possible to implement a DHT on top of it. Not sure why the developers decided to use WebRTC. I mean, it's a good transport layer for real-time communication (where bandwidth is a limited resourced), but not for decentralization.