Keep it clean
If you believe that a wish duplicates another one or is not meant for the category, use Options button above to report a duplicate or spam.
Add your wish
If there is an item you wish to have on GOG.com and it’s not yet on the wishlist, please add your wish
End-to-End encryption on chat
+1
End to end encryption is a MUST for private communication over the internet.
@Johnny.
Since you are part of the GOG team, I hope, you do know that SSL has nothing to do with end-to-end-encryption of chat messages. Therefore I find your comment down there rather questionable, to say the least.
Chat logs should be optional. You want to keep an archive of your chat? You should be able to have one. You don't need an archive? You should have the option to delete it automatically.
Also, being able to choose if the archive is kept locally or on the could would be a boon.
Yeah that would be nice. It would be a first but it's not going to help unless they open source the client because otherwise there's no evidence to prove they don't possess the encryption keys. And it would have to encrypt the metadata to not just the content.
Thanks for the information, Johny. Probably some people will be happy enough with this. Reading the comments I can see we're pretty divided on this matter, as not everybody believes to have real OTR chats is necessary on an application like Galaxy, while others even implies that it should be migrated to XMPP and opened to other servers.
So probably a portion of the people who backed my proposal is happy enough to know about the SSL encryption.
Thanks for the info again :)
It's already encrypted with SSL. :)
Xmpp Texting already can provide this with OTR or even better with:
OMEMO
I feel like there's way too many people who think encryption is some kind of magic. End-to-end encryption with the way GOG is right now would be a joke
For one, any and every chat client would have to be open-source so we can at least verify that encryption is actually happening in a secure way. Not to mention the even bigger problem of how GOG is supposed to generate and distribute encryption keys
Just encrypt your chat with pgp there done :/
I like chat encryption too but... Really? Honestly I couldn't care less about someone spying my gog chat :| The only point in favor for me it's that it's so easy to implement they should do it... I mean it's really important for me, I wish all my emails sms and other personal message were encrypted end to end but gaming chat, lol, I couldn't care less.
You'd have to change the chat system a good deal to make this real.
Currently chat persists on the server and can be viewed from a variety of browsers. To get end-to-end encryption, you'll need the javascript in the browser to unpack the data. That's pretty reasonable, but for usability purporses, you'll need to somehow tie it to the login process. This means significant site rework (currently the passwords are sent in clear to gog, not pre-hashed).
I'ts a worthy goal, but I'm not going go hold my breath on this one.
The encription is very important to our privacy
I agree with Mromson. There's no point in promising encryption when there's no way to check it.
Let's hope GOG hear us.
@ELGONZO
It's important that the encryption is open sourced because there ARE people with cryptographic knowledge to identify possible weaknesses and backdoors. Whether they'll discover them or not is up in arms, however it's an important step. Just being told that everything is encrypted isn't good enough.
And it as well will allow using third party chat clients with GOG servers. No reason *not* to use XMPP really.
May be add a wish for chat to use XMPP. Then adding OTR would be trivial.
"In my opinion the only possible way to do this is to make the Galaxy client open source. Only then someone can be sure that their are no backdoors in the encryption."... How many of the people looking at Galaxy client code would in your opinion have the necessary education in cryptograpy to understand cryptographic algorithms and to identify possible weaknesses/backdoors? If in your opinion there are more than none, then you are way more optimistic than i am... ;)
This is possibly the MOST IMPORTANT feature that the GOG Galaxy client should have.
Look, the work is already done, just drop in an OTR library en.wikipedia.org/wiki/Off-the-Record_Messaging
What a wonderful idea. Definitely hope it pans out, it would give something unique and necessary in this day and age to GOG galaxy.
In my opinion the only possible way to do this is to make the Galaxy client open source. Only then someone can be sure that their are no backdoors in the encryption.
The 2013 NSA revelations showed E-t-E encryption is needed to protect innocents. We who use GOG to play games and talk to our friends have nothing to hide but should have the right to have our private chats be private, to keep any prying eyes out; be it government, corporations, ISPs or hackers.
Encryption is essential to many who use a computer today whether its pgp or a zero-knowledge vpn - Others have mentioned cloud storage below so could we have the option to a) Store chat-logs in the cloud or b) store locally and define a folder to put them in.
Well, I think that cloud stored logs are not a good idea, unless they can only be viewed if your fingerprints match. Anyway, I believe offline chat logs are a lot better, since you can backup them securely if you want to. I remember that MSN Messengers offline logs era was a hell more convenient than today's Skype, Whatsapp, whatever.
You got a point anyway, DracoMagister, and, as I said, I believe this deserves a proper discussion. Thanks for your contribution.
I think storing chat logs locally to your PC makes more sense, because you're not going to format your PC that often, and if you are then you can just make a backup yourself. But I generally don't like automatic chatlogs.
There's no reason to have non encrypted chat, but there is to have cloud stored conversations. Probably people most concerned about security and privacy don't want that and prefer always end-to-end encryption but many people want for sure cloud stored conversations.
I think default end-to-end encryption is the best one. There is no reason to have a non-encrypted chat.
I'd like if they do like Telegram, where you can use normal chat and private chat, which use end-to-end encryption and even has the option of selfdestruct messages.
I'd be in favor of making chatlogs optional, rather than totally nonexistent. Personally, I'm in favor of encrypting them, but I want to still *have* them, because I like being able to track down exactly where my ideas come from, and missing bits of chat history make that harder.
29 comments about this wish