Hi, curious about the "not perfect" part (I work at Wire) - what stuff would be prio for you to improve?
HN user
Siimteller
Marketing @ Wire.com
wire.com/download for the free/personal use downloadables
We have the beginnings of an API - Wire.com/developer
Crypto - Wire’s Proteus is an independent implementation of Axolotl that was later renamed to Signal Protocol. There’s also an external audit available - info and links from Wire.com/privacy.
As to business model, Wire is VC funded by Iconical.com /Janus Friis (co-founder of Skype) and announced the first paid product in July - wire.com/teams.
Full disclosure: I work at Wire.
It’s a requirement many organizations have - government institutions are a good example. Some might want to not leak any data to the outside world, run it only for internal use, etc.
If security is of importance then try wire.com (I'm part of the team so biased).
One of the details we haven't quite settled on yet. Safe to assume that once all of the server code is open then at first you'd need to roll your own apps pointing to the right server.
Since a lot of the interest for self hosting comes from companies then a nicely packaged version is somewhere in the future.
Care to name one?
If you're into rust then their crypto is all in Rust https://github.com/wireapp/proteus
The post states that the app level review is coming. As a comparison afaik Signal only has protocol review available, no implementation review.
Edit: typo
https://medium.com/wire-news/open-sourcing-wire-server-code-... if you're looking for the announcement
For an independent and serious comparison check https://www.securemessagingapps.com that focuses mostly on the security/privacy aspects of various messengers.
It's open source indeed [1] and was recently audited for the quality of the crypto protocol implementation [2]. Not sure what questions you specifically have but I'm happy to answer as I'm part of the team.
[1] https://github.com/wireapp [2]https://medium.com/wire-news/wires-independent-security-revi...
Their iOS repo was finally updated couple of weeks ago after last update from August, 2016.
2 days ago - Wire's independent security review https://medium.com/wire-news/wires-independent-security-revi...
They reviewed protocol implementation and the post on Kudelski site says that they'll tackle the complete solution in the next phase.
I'm no expert but these reviews are no trivial matter, takes time and effort.
Direct link to the report itself https://www.x41-dsec.de/reports/Kudelski-X41-Wire-Report-pha...
Check the report again - they've now added Wire replies.
Open sourcing the client was always the plan after moving everything to E2EE. Just took a number of months to get the code into a shape that we wanted.
Monetization - we've invested 0 dev time into this so far. So a bit early to claim "they also failed".
Hi mate, fair criticism. After working on making everything E2EE we had to play catch up in terms of features for a while. Turns out people want security and privacy AND useful and fun features.
We're now focused on clearing up some of the technical debt and the issue you describe is being worked on.
Another thing we're rewriting is the calling part to speed up connection time, improve robustness, reduce meta data footprint. This is now in internal testing.
Wire sent in comments which have now been published in the same analysis.
1. They lied about having end-to-end encryption in their app
That was before I joined but that got fixed in 24 hours. Not sure how the incorrect claim made it live in the first place.
2. They lied about being open source for years.
Wire open sourced it's crypto protocol in March 2016. It never claimed to be open source before that. It further open sourced it client apps in July 2016 and will open source server some time in 2017.
3. They lied about being based in switzerland.
Citation needed. Wire is registered and headquartered in Switzerland with an office in Zug.
3. They rolled their own crypto, and experts disapprove of the choices they made.
Link?
Rolling out paid stuff next year. As someone said - VC funded so have had the luxury to focus on building a great app, see if people find value in it. This has been true, lots of interest form B2B world from groups, teams, organizations where privacy and security important.
Fair enough critique on Android bugs, we're fixing them at a steady pace. But if you know any good Scala developers in Berlin / interested in moving to Berlin then we're hiring https://wire.com/jobs
Servers are closed source, will open source in 2017.
I've found https://www.securemessagingapps.com to be an interesting source of comparison. The author seems to actively update it based on crowd-submissions.
There's also http://öä.eu/bac.html (based on http://öä.eu/bac.pdf thesis) but I've emailed with the author and he said that he's not keeping it up to date.
That was indeed the case in December, 2014 (before I joined the team). Legal docs were quickly fixed. Tech was fixed in March 2016 when everything (text, assets, calls) were moved to E2EE and open sourced.
Have you looked into Wire as an alternative? Also HQd in Switzerland, E2EE with multi-device and desktop support + open source.
Happy to walk you through it (I'm siim@wire.com).
Video calls in general are CPU/battery heavy operations, I've done pretty long ones with Wire (my employer) and yes, the phone gets warm but no issues with performance (iPhone 6).