back
96 comments
Aside from the typical encryption worries here are some features I would love to see being offered on a alternative messenger app

-ability to give out your alias or username to people to reach you on whatsapp instead of a phone number, something you can change later after banning the contact.

-transcribe voice messages to enable search among them.

-ability to hide the fact that i have listened to their voice message.

-ability to hide the fact that i am on whatsapp network and receive 'add to contact' requests from people where i can accept or reject without them knowing i actually rejected.

-hide the 'online' in conversation window when im reading the message.

-save my chat history in the cloud so that i dont lose everything when i move from iOS to Android or vise versa.

-ability to save incoming and outgoing media attachments to the cloud for access later

-full desktop support for video and voice calls

-ability to record the calls, and have their transcribed texts easily searchable.

-ability to ignore certain kind of messages from certain people such as 'allow text messages only, no calls, no pictures, no videos.' etc.

- user accessible backups. WhatsApp backs up to your Google Drive account but you can't access it directly. Only WhatsApp may do that (f_ck you Google for contributing to WhatsApp's lock-in). Local backups are encrypted so you can't read them. Exports are incomplete (for example, on one chat it would give me the last month or so when I could scroll back more than a year). WhatsApp discards old messages at its discretion without letting you configure otherwise. I lost a ton of very important texts from the last months of my now-deceased mother. I f_cking had to scrape what was left from WhatsApp Web.

- open protocol and open source clients and servers, with network working independent of any particular provider to be able to ditch any misbehaving one.

- no expiration on software versions. Why are we being forced to update versions to view old messages?

Damn is software becoming user hostile.

>save my chat history in the cloud so that i dont lose everything when i move from iOS to Android or vise versa.

Implementing this could make key management either less secure, or more difficult for users. If the user still had access to both devices, it wouldn’t be too bad. But if you want the users to be able to ‘recover’ their message history on any device, then you’d need to use something like the mnemonic seed phrase, which isn’t an improvement in UX, or security.

The audio transcribing sounds difficult too, as you’d have to do it all client side if you wanted to preserve the security model.

Is there any issue with the Automatic Key Backup feature in Riot?

>Once enabled, your device will maintain a secure copy of its keys on your server. To ensure those keys can only ever be accessed by you, they are encrypted on your device, with a key that you either store yourself or secure with a passphrase and upload to your server. It is important to understand that to protect your privacy your keys will never touch the servers unencrypted. https://medium.com/@RiotChat/the-big-1-0-68fa7c6050be

> -full desktop support for video and voice calls

Any desktop support would be nice. WhatsApp web is not a real solution.

It kind of is, at least it is 80% there. What is your problem eith it? Having to handshake almost everytime?
I think most if not all of that is possible with matrix.org.
Matrix should have improved XMPP rather than added yet more fragmentation.
> -transcribe voice messages to enable search among them.

> -[..] video [..] calls

> -ability to record the calls, and have their transcribed texts easily searchable.

> -ability to ignore certain kind of messages from certain people such as 'allow text messages only, no calls, no pictures, no videos.' etc.

Apart from these I believe Telegram offers already the other features (voice desktop calls are a bit unreliable often)

>-save my chat history in the cloud so that i dont lose everything when i move from iOS to Android or vise versa.

the key is that the data has to be encrypted. currently i think whatsapp uploads your chat history as plaintext. this basically allows the corps. to get your data.

> -save my chat history in the cloud so that i dont lose everything when i move from iOS to Android or vise versa.

Is there something in the existing WhatsApp cloud backup feature that prevents you from bringing those backups between iPhone and Android?

I did a lot of research and apparently its impossible because if different database formats the messages are saved on two platforms. At least that's what I understood on some random forum.
- ability to add custom emoticons to your library, and ability to share them
Isn't that called Signal? Maybe just put the funding into extending that?
I tried signal, much more inferior to WhatsApp in terms of functionality and usability
I use signal on the reg, and the short comings are both superficial and unrelated to the security. In my opinion.

What are your specific concerns? I could list things like: lack of bold and italic , poor voice message UI, lack of video conferencing , lack of group names, ...

Note that WhatsApp was wildly popular for over half a decade before it got most of those features.

In other words: I don’t get the point of talking about these cosmetic blemishes. * Signal today feels like WhatsApp at its inception. I.e. a messaging app with the potential to be used by everyone and their dog.

Or is there some fundamental problem you’re encountering that I’m blind / oblivious to?

* edit: let me clarify: “... talking about these cosmetic blemishes as if they’re fundamental blockers to adoption.

A few points that I hope dont come off snarky

1) It's open source, so if you can code and have time, you can help.

2) Some small friction adders seem like a small price to pay to not have a facebook product installed on my phone and suck all my metadata down.

A 500 billion dollar corporation will always be able to beat nonprofits on usability. The question you should ask yourself is whether the marginal difference in usability makes up for all the negative consequences of being a Facebook user.
There are real tradeoffs between functionality and usability that any "more secure" chat service would have to deal with.
Yes, because there is an inverse relationship to usability and security. Signal won't add a feature until they can call it entirely vetted and secure.
How is Signal inferior to WhatsApp "in terms of functionality and usability"?
Put effort into improving usability of Signal then? I don't understand.
WhatsApp is Signal under the hood. And as I recall, Moxie helped them set it up.
That's exactly my thoughts.

Interestingly, WhatsApp uses the same e2e encryption protocol under the hood... or at least it used to I know Facebook is trying to merge it with messenger which certainly means removing the e2e encryption.

Good news is this means Signal could probably be on parity with WhatsApp with a little government grant money love.

This makes it sound like DARPA wants to take some commercially developed tech and adapt it to the military, but just for the record that grossly misstates the relationship and the general history of Silicon Valley.

Ever wonder how Siri got her name? From SRI International, a research org largely funded by the DoD.[1] DARPA is the origin of much of the tech, including secure Internet tech. Just one recent example: Tor[2]. It's developed at taxpayer expense and either given away to private industry or "transferred" for a pittance.

[1] https://en.wikipedia.org/wiki/SRI_International#Employees_an...

[2] https://www.onion-router.net/Sponsors.html

I don't think there's an official origin for Siri's name. Someone said it was named after a child. I suspect (without evidence) it was named after the female robot in the pilot episode of the Logan's Run who ran Mountain City, a paradise city.
From : https://www.sri.com/engage/ventures/siri

https://www.sri.com/work/timeline-innovation/timeline.php?ti...

"Siri, the first virtual personal assistant, arose from decades of SRI research in artificial intelligence (AI). The technology was developed through the SRI-led Cognitive Assistant that Learns and Organizes (CALO) project within DARPA's Personalized Assistant that Learns (PAL) program, the largest-known AI project in U.S. History, and joint work with EPFL, the Swiss institute of technology.

SRI spun off Siri, Inc. in 2007 to bring the technology to consumers, raising $24 million in two rounds of financing.

In April 2010, Apple acquired Siri, and in October 2011, Siri was unveiled as an integrated feature of the Apple iPhone 4S."

I'm not verifying that - I just found it via google search "sri Siri"

I like the link to Logan's Run :-), it could be also true.

It's mildly entertaining that we have calls for a more secure and trust-able version of an encrypted chat service, but other agencies in the executive branch are calling for loopholes and vulnerabilities for the same encrypted channels.
Do we really need yet another chat app? I think there are far too many of them. Can't we go back to XMPP again and make everything compatible like it was ten years ago?
From the description, it seems like it's less about the chat app itself and more about developing and designing a new secure protocol and infrastructure that will influence future products by commercial or other entities. They want people to take the tech they develop and make their own stuff more secure, which sounds awesome.
Amen.

If anyone wants to be on XMPP with minimal fuss, try https://quicksy.im/ . This is an XMPP client, with registration based on your phone number.

Seems like Keybase's key model would work well here: https://keybase.io/blog/keybase-new-key-model
> Exist completely within a network

I bet this requirements implies working seemlessly between online and offline networks. In which case this project is not just building another XMPP/WhatApps/Signal/etc. They are building another Cabal (https://cabal-club.github.io/) :-)

The title makes it sound like they want to use whatsapp, not that they want encrypted chat.
Agreed, i think the title is a bit misleading.
What's wrong with the current encryption? I'm told that Signal's encryption technique if very superior and probably the best in the industry.
Just wait till Telegram open sources their code?
Original solicitation is from June 2018, not clear that this story is anything but a reheating of that announcement, found here: https://www.fbo.gov/index?s=opportunity&mode=form&id=c244cde...

(As an aside, it is always a bit unsettling when a federal function is represented by something that looks like a link farm. I mean, I know you elected Trump and all, but "FedBizOpps" probably predates him by a decade)

Besides signal, there is also

1. Threema. Swiss based but not Open Source AFAI

2. Frozen Chat. Android client based on Jabber XMMP/OTR

Frozen Chat seems to be removed from the Play Store, and I can't find many references to it online. Never heard of it before.
Anybody using Wire? I've recently been looking for a skype replacement myself and seems like wire is a pretty good fit.
I always wonder why few people here acknowledge Telegram, is it little know or is it not considered secure enough?
There's also Conversations, an Android XMPP client that supports OTR/OMEMO.
Don't they have one already!
Trust us, this totally isn't another Dual_EC_DRBG
Darpa had absolutely nothing to do with Dual_EC_DRBG.
DARPA's not doing this for shits and giggles; they want to use it (or later iterations of it) for military communication. They also want to open source it.
They should invest in the BEAM virtual machine. IIRC, Whatapps is built on Erlang and its VM.

There are many benefits in helping an existing project with active developers. If dealing with the politics of managing existing project is annoying, just fork it and make their own branch. The original owner can deal with the merging if they want the contribution.