Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

While we're speculating about trust and such, the video mentions that it's a browser extension which connects to a trusted peer and uses the peer as a proxy. This leads me to believe that,

1. Since it's a normal browser extension, the source will be readable and verifiable.

2. It probably uses WebRTC.

It seems Google merely plays an incubator role here for the authors. Either way, I don't see much trust issues that other comments are complaining about.

Looking forward to trying this out when it's released.



> the source will be readable and verifiable.

that's all well and good, but if it's executed by an unverifiable binary build of Chrome (i.e. the one distributed by Google), it's not worth much. For what you know, Chrome might just detect the extension is installed and silently eavesdrop on all its calls.

If this extension will work as-is on third-party Chromium builds compiled from public sources, then yeah, it can be trusted on those builds.


You say that like it probably won't. They state in the FAQ that it will work on FF and Chrome; there's no reason to think it won't work on Chromium as well.


No, I say that from a paranoia perspective. Any security measure is only as strong as its weakest link.


http://uproxy.org/

Can I look at the source code?

The source code will be released by the University of Washington under the Apache 2 license after the trusted tester phase is completed. If you would like to get involved sooner go to http://uproxy.org/#join


And your "friend" on the other end would also need to be running it on Chromium from trusted source.


Don't proxy it through friends who don't use software audited and compiled by you/people-you-trust then.


Sure, I'm not saying it isn't surmountable. I'm just stating that this is another constraint.


We actually don't know with 100% certainty that Chrome runs the code that we see.

Considering Google is forced to comply with NSA's shit (and other agencies in their respective countries), I wouldn't trust my life to this extension.


Then compile it yourself. If you don't trust your hardware then what else can you use?

Can you actually trust people who built your house? What if NSA has built a device hidden in everyone's house right now?


if you don't trust the university compile it then ! what can they do more than releasing the source code ?! This is pure bad faith.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: