Remove Ricochet as it is already discontinued in 2016. #476
No reviewers
Labels
No Label
🔍🤖 Search Engines
approved
dependencies
duplicate
feedback wanted
high priority
I2P
iOS
low priority
OS
Self-contained networks
Social media
stale
streaming
todo
Tor
WIP
wontfix
XMPP
[m]
₿ cryptocurrency
ℹ️ help wanted
↔️ file sharing
⚙️ web extensions
✨ enhancement
❌ software removal
💬 discussion
🤖 Android
🐛 bug
💢 conflicting
📝 correction
🆘 critical
📧 email
🔒 file encryption
📁 file storage
🦊 Firefox
💻 hardware
🌐 hosting
🏠 housekeeping
🔐 password managers
🧰 productivity tools
🔎 research required
🌐 Social News Aggregators
🆕 software suggestion
👥 team chat
🔒 VPN
🌐 website issue
🚫 Windows
👁️ browsers
🖊️ digital notebooks
🗄️ DNS
🗨️ instant messaging (im)
🇦🇶 translations
No Milestone
No Assignees
1 Participants
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: privacyguides/privacytools.io#476
Loading…
Reference in New Issue
No description provided.
Delete Branch "patch-1"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Description
The Tor Project said Ricochet is a "Discontinued software" thus it shall be removed.
Software listed here has become depreciated and development has ceased. They are therefore considered unsafe and it is highly recommended to avoid using them. This section is here purely for historical value.
Ricochet IM is an open-source, decentralised instant messenger project that officially ended development in November 2016. Ricochet starts a Tor onion service on the users local system and facilitates communication with other Ricochet users whom are also running their own Ricochet-created Tor onion service, providing End-to-End encryption by never allowing the connection to leave the Tor network.
HTML Preview
Replace [GITHUB_USERNAME] with your GitHub username and [BRANCH] with the branch name.
http://htmlpreview.github.io/?https://github.com/ohmynameisrico/privacytools.io/blob/patch-1/index.html
https://github.com/ricochet-im/ricochet/issues/579
https://github.com/privacytoolsIO/privacytools.io/issues/474
With the availability of tens of services like this, I guess removing one that doesn't have proper maintenance is a must. @Shifterovich?
what is going to take its place?
I'd suggest moving up one of the "Worth Mentioning", such as ChatSecure.
Also, if Richochet is to be removed, the first article of the "Related Information" subsection has to be removed as well.
Agree, remove. @kewde @beardog108 Which one to replace it with?
Need a separate PR for that, can't change code in this one.
Its not actually [fully] discontinued. I don't think it should be removed unless someone can show these supposed "10 known vulnerabilities", the Tor wiki page doesn't even mark it as discontinued anymore.
Edit: The 10 vulns were probably referring to it shipping with an outdated Tor binary. You can easily have ricochet use your system binary or replace the one it uses. I suggest we update the site to show a warning for this.
Ricochet is relatively simple, and if it had known unpatched vulnerabilities, the authors would make it clear that its not safe to use.
In addition Ricochet (the protocol anyway) is being extended to support group messaging via the Cwtch project, so development around it is not completely stopped.
Quote From dev on June 4 2018:
IMO Ricochet is just as safe/unsafe as the day of its last release, unless someone can link the vulnerabilities that are claimed to be known. Is it the safest messenger available? No, but it is pretty good, and remember, it did pass the security audit in 2016, which was for the then (and still latest) release.
I wouldn't be upset about moving it to "worth mentioning", since it is clearly not well supported. Tox is alright, but has its own sets of problems and is not as private as Ricochet, although since it is supported, it would be better for the featured spot.
Tl;dr
I suggest moving it to worth mention like suggested, and move Tox to the recommended.
Hopefully one day Ricochet is better supported, as it is simple yet secure (in concept) and anonymous, which is rare.
As mentioned here https://github.com/privacytoolsIO/privacytools.io/issues/474#issuecomment-438347467 I don't think this should be removed.
I also don't think that "Tox" should be argued as a "replacement" they aren't really the same thing and fundamentally work quite differently.
See:
https://github.com/ricochet-im/ricochet/pull/580#issuecomment-394176462
https://github.com/ricochet-im/ricochet/issues/579#issuecomment-392788611
Without any strong evidence of major security flaws, why should it be deleted?
If you want security with decent ease of use, you use Ricochet. Very few apps come close to it.
Edit: One decent alternative: http://retroshare.net/
This should be closed along with the duplicate https://github.com/privacytoolsIO/privacytools.io/issues/474
They're not duplicates, one is a PR and the other is an issue. But yeah, unless there are legit concerns there's no reason to remove it.