Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

The IRC admins can read all your messages, be it to a channel or to another user.

Even without registering my nick, I would expect a modern protocol to keep my pm communication private by default.

 help



How will you verify who you're talking to?

You verify identity over the now-encrypted channel, just like SSL should have done 30 years ago but refused to for doctrinal reasons. And in the (frequent) cases where you don't actually care about the other party's identity you just don't verify it at all.

Are we talking about with OTR? You're meant to verify fingerprints out of band as usual. Without, I guess you check if they've authenticated to nickserv if there are services. Or do your own checks or heuristics.

Imagine joining IRC channel and all messages are as meanningfull as reading base64 strings aloud aka all are somehow encrypted messages.

Now you can cryptographically check to who you are talking.

No other party can read your plain text.

You can pick any cryptographic property you like future proofing or deniability, etc.

Becouse IRC is just very nice transport.

And clients can be very easily scrypted to encrypt and display just human readable text.

You can even relay messages to wherever you want, HR lady, video player, anywhere.

Try that with Matrix or Discord ;)


That is indeed how Matrix works already. And Discord is also doable with https://gitlab.com/An0/SimpleDiscordCrypt

O, didn't know that. I think I had in mind triviality of adding client-side encryption to IRC messages.

However server side... :) Looked probably twice to hosting Matrix server and Java part was fat no no. And Discord one-click "servers" ? :)

Edit:

Ok, can't find any Java in Matrix servers context... Must be I messed it with Signal server.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: