back

by colesantiago·4y ago·view on hn ↗
It seems encrypted messengers are turning into cryptocurrency ponzi scam projects.

Keybase -> Stellar

Session -> Oxen/Loki

Whatsapp -> Diem/Novi

Signal -> Mobilecoin [0]

There really is no defence of introducing this at all and it's sad that this is becoming a trend, looks like one has to look at Threema, Wire and possibly Element as our only hope.

[0] https://www.wired.com/story/signal-mobilecoin-payments-messa...

8 comments
I generally agree, but in the specific case of Session, the crypto scam is a feature. The crypto scam provides for the thousand or so independent nodes that makes a ProtonMail-style law enforcement order useless.

Any centralized service like Threema is vulnerable to a court order to log, at the very least, connection metadata.

It's a LOT more expensive for LE to launch a Sybil attack on Loki than to get some bootlicking judge to compel logging and/or silent client update.

But yeah, I totally agree that the crypto scam is long-term unsustainable and Session needs to find a way for the users of Session to have to pay for Loki network access to keep it running.

To the point above, the biggest weakness of Session, by far, is that its official packages are released and signed in Australia. There is no doubt in my mind that .AU will eventually come down hard and compel signing of compromised binary releases. They HAVE to distribute official release building and signing to multiple developers around the world, and soon.

I sort of understand people feeling like Signal/Mobilecoin is a get-rich-quick scam (though I really don't think it is), but I don't understand why, beyond the ickiness if that were the case, it actually matters.

Does it somehow reduce the effectiveness of Signal Messenger?

The argument against Signal here seems to rest on the weakest foundation. As I understand it, it's something like:

- This could be a get-rich cryptocurrency scheme. We don't have any evidence for it, but you can assume the worst.

- The project embarking on this scheme shows they don't have users' best interests at heart.

- If they don't have users' best interests at heart, how can I trust any of their other decisions?

This is not an argument I'd want to hang my hat on.

if Signal can do Mobilecoin without any access to our Contact address book, then I expect a mass adoption by the general populace.
Where is the scam part? I don't need to use their crypto, its just built in, and its not dishonest in any way. There is no monopoly, and suggesting they should run encryption and servers all day with no compensation and free isn't sustainable, in fact that makes me even more suspicious that it is a govenment run system.

I prefer that I can at least see it being sustainable, and if its a P2P protocol it could be free, but if they paid the developers well I would feel even better for various reasons.

You could flip that argument too and say that the thousands of dollars one must pay to run an Oxen node is a threshold that intelligence agencies and governments can easily afford. While the idealists who just want to support the onion routing with bandwidth for a few bucks a month are shut out.

That's why tor is so massive, because anyone can support it. But that's also what makes tor vulnerable to sybil attacks. It's a catch 22.

Either way, my warnings bells go off when someone asks for thousands of dollars for crypto coins that have no real advantage like Monero.

Another question that comes up with Oxen is what happens if it's adopted. Because afaik each onion routing node is also calculating the blockchain. So the more transactions happen, the heavier these calculations get, right? So each onion routing node will require a lot of resources eventually, if this ever takes off.

Your statement on the intelligence agencies is incorrect. You need oxen to run the nodes not dollars, and obtaining oxen has an exponential cost due to market forces.

If you want to run 1 node you can obtain the oxen pretty easily. If you want to obtain enough oxen to control 50% of the network you will need to buy more oxen than is in existence.

That's a really good point that I had overlooked. Thanks.
Also the oxen blockchains state growth is pretty mild. Its currently 20gb after 4 years. Even moneros blockchain is pretty mild which gets heavy use (sub 100gb i believe).

State growth is an issue all blockchains face, but there are ways of addressing it. If oxens blockchain gets to 200gb in 40 years though i dont think that is an unreasonable expectation to put on the people running nodes.

It's been slow because the coin hasn't been adopted by anyone yet. I'd imagine that if it was actually adopted by some real market, giving it real value, it would grow a lot faster.

So it is an issue to combine those two features, onion routing and blockchain. Because onion routing only requires bandwidth donation.

Conversations too. It works well, ticks all the boxes except voip, and is available on f-droid.
But Session being linked to a cryptocurrency project is a non starter and inexcusable.
Why?
Take a look a Signal, which the whole of Signal is to be a private WhatsApp alternative not a trojan horse to introduce a cryptocurrency pump and dump scam. [0]

So for Session, I am unfortunately also sceptical on them as well, I would say they are arguably worse since their project is embedded within cryptocurrencies and it won't be long until they force their Loki/Oxen coin in their apps.

[0] https://www.stephendiehl.com/blog/signal.html

That didn't answer my question. How does Signal supporting Mobilecoin or Session supporting--whatever this is--impact your usage of Signal/Session?
> That didn't answer my question.

I did, you just didn't like the answer.

It didnt really. It was just cryptocurrency = bad
I might not have understood it, which is different. Can you make it a little more explicit for those of us who are slow?
But Conversations has voip... I use it all the time.
Indeed it does! Just not for group calls.
Matrix (Element and friends) is the future.
It's sad Tox never succeeded in getting widely used, as it solved a lot of problems (almost, multi-device was in a beta branch last time I used it).

Fully distributed (while current solutions are centralized or, at best, federated), no single entity to be attacked, no dependency on phone numbers, being blessed by a server, or strange coins.

Session does all those things.

The political view on cryptocurrency that causes you to label it as a bad thing means you blanket category something that adds a lot of features to session.

I think tors uptake in general was limited because the FBI was able to still to track people, and here the cryptocurrency element fights against exactly that.

In sessions case the cryptocurrency is a protective measure thats stops eve from spinning up loads of nodes on their backend and snooping the message packets.
Don't forget XMPP, and Jami as the hope.
In particular, XMPP to a TOR hidden service to entirely replace something like Session:

* https://gist.github.com/dllud/a46d4a555e31dfeff6ad41dcf20729...

XMPP is better than anything else I have seen for this sort of thing in that it is federated and gives you a choice of servers. There is no single point of failure.

Here is what that looks like using Conversations on Android:

* https://creep.im/xmpp_tor/

Checkout Snikket if you haven't yet: https://snikket.org/ - Not affiliated, just a fan of Matt's efforts here.
I told a person I know to use XMPP to which they said

"Which XMPP app should I use"

To which I dismissed XMPP its own as a viable alternative to anything, there might be hope for Jami as long as it is not linked to anything cryptocurrency and the security is sound.

Your objection is that there are multiple clients for an open protocol?
To which my non technical friends don't know which to choose and didn't bother at all and went back to using WhatsApp.

If that is the consequence for multiple fragmented clients then no thanks.

Just recommend the client you are using?
Yes, and everyone went back to using WhatsApp as I said, including me.

Nobody bothers with Signal and all these other fringe privacy apps or alternatives.

That is my point.

No, nobody in YOUR circle bothers with it. Approaching 50% of mine does.

Don't project that laziness onto the entire populace, enabling others to feel comfortable that it's "too hard" to use Signal....that's awful.

I've had a lot of success getting people to move over to Signal personally. I have 400ish contacts on WhatsApp, and at least 150 on Signal, from like 5 or 6 before the T&C update from WhatsApp.
Then:

'What platform?"

Then:

Tell them.

No, the answer was WhatsApp which they unfortunately went back to.

The point is, there are far too many XMPP clients for which it is very unlikely that their friends are on and have interoperability features.