Skip to content

Comment on Cryptocat Considered Harmful: The Root Causeparent

Comments

Ironically, OTR is what Cryptocat uses. But for the sake of argument, let's compare it to the OTR plugin for Pidgin, another IM: It's just not as usable. I'm sorry. Look at the very website you linked!

But... it's possible to make it just as easy to use! Or even better: To make a minimal client that accomplishes the same as Pidgin without presenting as large of an attack surface.

Glenn Greenwald nearly missed out on the biggest national security story of the past decade because he couldn't figure out how to get PGP to work. Yes, we can expect people to put a little more effort into protecting themselves if they genuinely believe they're at risk, but we can't expect to do things they can't do. Not everyone is a techie.

OTR is only used in one-on-one communications in CC; group chat mechanisms are custom, and may now converge towards the mpOTR draft but that's still a pretty big risk.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.