I agree with you. I don't think Cryptocat or how the implementation is handled is perfect by any means, but people have been complaining about that for a long time, and we still don't have good alternatives. What I'm saying is that if somebody makes something that is technically sound and is as attractive for regular users, in Syria and elsewhere, then this whole debate becomes relatively moot.
If Nadim is as unwilling to cooperate as you're implying (which I don't think is totally true, but I will grant you that the underlying constructions for the group chat component were switched out recklessly and ignorantly), then surely complaining about it in blog posts will be very ineffective.
I don't think he's unwilling to cooperate, and I don't mean to pick on the guy, because he's basically become a whipping boy. I think the reason he reacts so adversely to the criticism is the obvious use of him by bloggers and "crypto pundits" to bolster themselves. It's not constructive, and I don't wish to encourage that.
That said, security issues are still security issues, and my tl;dr as someone no one on this site cares about is for Nadim to just stick with a set of crypto primitives and protocol design that work, fix the problems that arise and stay there until he's more confident in what he's doing.
Comments
I think you responded to my comment that I somehow managed to delete, but re-posted here: https://news.ycombinator.com/item?id=6990738
I agree with you. I don't think Cryptocat or how the implementation is handled is perfect by any means, but people have been complaining about that for a long time, and we still don't have good alternatives. What I'm saying is that if somebody makes something that is technically sound and is as attractive for regular users, in Syria and elsewhere, then this whole debate becomes relatively moot.
If Nadim is as unwilling to cooperate as you're implying (which I don't think is totally true, but I will grant you that the underlying constructions for the group chat component were switched out recklessly and ignorantly), then surely complaining about it in blog posts will be very ineffective.
I don't think he's unwilling to cooperate, and I don't mean to pick on the guy, because he's basically become a whipping boy. I think the reason he reacts so adversely to the criticism is the obvious use of him by bloggers and "crypto pundits" to bolster themselves. It's not constructive, and I don't wish to encourage that.
That said, security issues are still security issues, and my tl;dr as someone no one on this site cares about is for Nadim to just stick with a set of crypto primitives and protocol design that work, fix the problems that arise and stay there until he's more confident in what he's doing.