trash
27
@Yujiri
link
fedilink
33
edit-2
5M

Some red flags about this messenger:

They are dishonest about the merits of existing secure messengers.

From the homepage:

Download Olvid, the most secure messenger in the world.

There is no “most secure messenger in the world”; that judgement is much too nuanced and situation-dependent for such a claim.

Most of the supposedly free messaging services are financed through the exploitation of the exchanged data.

This is false of at least several alternatives, including Signal and Matrix.

From the “technology” link on top bar:

Our security model is utterly game-changing. Olvid is the first and only messaging system whose security no longer relies on any trusted third party, either operators or their servers.

Objectively false. Even if you consider end-to-end encrypted and federated platforms like Matrix to “rely on a trusted third party”, there are P2P messengers which truly have no servers and which solve the problem of mapping username to public key, such as Tox.

Olvid servers get hacked? Not an issue! No one will ever be able to read your messages, including the servers relaying them. It is forever impossible. Nor can any users identities ever be revealed. Olvid is the only system that also encrypts metadata, thus guaranteeing the anonymity of interlocutors. Finally, Olvid guarantees the authentication of users, contrary to all messaging servers that replace trusted third parties…

Actually, all existing secure messengers have cryptographic authentication, and I’m pretty sure some of them also encrypt as much metadata as possible, such as Signal.

It seems like they’re dishonest about the merits of their own messenger.

Inability of the operator to know “who is talking to whom”. No third party could ever identify the participants, not even the server. No trace of any metadata.

This is huge. I’m developing a federated messenger and had given up on hiding the recipient ID when sending a message because I couldn’t find a way to do it. If there’s a practical way to do it, I want to hear about it. So I opened their protocol specification.

In the section “Upload message and get UID”, I see that the request actually contains a list of both the device UIDs and the identity of all recipients. They call it “encoded”, but it sounds like that just means JSON.


In summary, I would stay away from this messenger in favor of another option like Matrix or SIgnal.

I think Molly may be trying to do something similar https://ccs.getmonero.org/proposals/vd-molly-payments-stage1.html and molly.im

@Yujiri
link
fedilink
15M

Similar to what? According to their client’s github readme, it’s just an alternate client for the signal server (which IIRC is illegal and previous alt-clients such as LibreSignal have been shut down because Moxie threatened legal action, so I’m not sure how Molly’s getting away with that).

Your right, they could be shut down at any time so that’s a risk for now. That’s why they are working on their own messenger that improves on signal using their own decentralized servers. Signal hasn’t taken down others in operation currently either

@BridgeBum
link
fedilink
25M

Marketing speak bends the truth? Say it ain’t so!

@AgreeableLandscape
mod
admin
link
fedilink
12
edit-2
5M

Just browsing around the Swift files in the iOS app, I found these:

final class PersistedDiscussionOneToOneLockedToPersistedDiscussionOneToOneLockedMigrationPolicyV24ToV25: NSEntityMigrationPolicy {

private func processContactGroupHasUpdatedPendingMembersAndGroupMembersNotification(obvContactGroup: ObvContactGroup) {

try UtilsForAppMigrationV24ToV25.createDefaultPersistedDiscussionSharedConfiguration(forDiscussion: dInstance, destinationContext: manager.destinationContext)

And they say Java has verbose names.

@Copio
link
fedilink
25M

Sometimes, for my own internal solo projects, I give my variations and functions wacky names because I was bored, I wonder if that’s the same for whoever named those.

@Echedenyan
admin
link
fedilink
105M

NonFree server.

sj_zero
banned
link
fedilink
25M

To me, self-hosted and federated (so you can self-host and others can self-host and it seamlessly works across instances) is the way of the future. There might be criticisms of xmpp or matrix, but to me the moment you’re no longer looking at a single point of failure like with big tech services (or aspiring big tech services like this) you’re much more secure because your data isn’t in one centralized spot with everyone else’s data to get picked up in one big hack.

Hope someone forks it and makes all premium features free, lol.

@ree
link
fedilink
25M

such a dick move.

There is little incentive to publish open source code in a commercial setting comments like that validates it.

¯\_(ツ)_/¯

Well, I’m poor and I’m already expecting that stuff for free, my poor friends are also not going to pay for that and therefore they will not switch to a private messenger therefore, so give me free real state or gtfo. I know people want to live from that and it must be great, but I live under capitalism and I don’t have many choices.

@Reaton
creator
link
fedilink
4
edit-2
3M

deleted by creator

@Yujiri
link
fedilink
45M

Unfortunately it might not be since it seems their server is still closed source.

@Reaton
creator
link
fedilink
2
edit-2
3M

deleted by creator

repost of that xkcd article which goes: “there are 14 standards”; “that’s too many! we need one that meets all use cases!”; “there are 15 standards”

Here you go!

How Standards Proliferate (See: A/C chargers, character encodings, instant messaging, etc.) Situation:  There are 14 competing standards. Cueball: 14?! Ridiculous! We need to develop one universal standard that covers everyone's use cases. Ponytail: Yeah! Soon: Situation: There are 15 competing standards.

@danileonis
link
fedilink
15M

I don’t think matrix protocol will be surpassed by this.

But competition is good for business, and innovation. Maybe Matrix is ‘forced’ to implement some features because of this.

@ninchuka
link
fedilink
15M

what features does olvid have that matrix doesnt have yet?

Halce
link
fedilink
15M

Most notably voice calls probably.

Jama
link
fedilink
25M

Matrix/element should have that too, afaik

@a_Ha
link
fedilink
05M

“Olvid’s not Covid” 🤪

...gnu

Gnu’s not Unix

@HamsterDeveloper
link
fedilink
21
edit-2
3M

deleted by creator

@Reaton
creator
link
fedilink
1
edit-2
3M

deleted by creator

@esi
link
fedilink
9
edit-2
3M

deleted by creator

@airikr
link
fedilink
-45M

Apperantly, they run E2EE which means no servers are being used for storage of what people send to each other. They tell their visitors this on olvid.io (below “Olvid cares for you”).

E2EE doesn’t mean servers are not used for storage, it only means servers can’t see message contents.

Note that this doesn’t mean that Olvid uses no servers (it does). It means that you do not have to trust them: your privacy is ensured by cryptographic protocols running on the client-side (i.e., on your device), and these protocols assume that the servers were compromised from day one. Even then, your privacy is ensured blush.

(From the GitHub repo of the Android app.)

@peppermint
link
fedilink
2
edit-2
4M

deleted by creator

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

Rules

  • Posts must be relevant to the open source ideology
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

Community icon from opensource.org, but we are not affiliated with them.

  • 0 users online
  • 31 users / day
  • 58 users / week
  • 111 users / month
  • 506 users / 6 months
  • 5.22K subscribers
  • 1.82K Posts
  • 6.41K Comments
  • Modlog