We're acutely aware of this conversation, and know that we must prioritize the safety of our user base. All of the issues reported on the article are already being fixed, and we should have updates published in the next few weeks.
Hi! You can skip the SMS verification step, which is how thousands of people have used it after earthquakes and hurricanes :) we also have an SDK so that developer can create their own app and make it work however they want.
Considering what others have described here to skip verification, you have used a dark pattern to force users to resort to SMS verification, endangering all those thousands of users you/your company claimed have downloaded the app in Hong Kong. This dark pattern would also inhibit or reduce usage during natural disasters unless you place a “Skip Verification” button that’s as prominent as the one for SMS verification. You could explain to the user the benefits or disadvantages of both on the same screen.
Having seen FireChat, another closed source mesh network app that allows people to sign up without giving a phone number, there’s no reason for me to recommend your app or even for me to try it.
Apparently you need to fail verification a few times before it'll present the option. I kept giving it bogus phone numbers and eventually a "skip" button appeared.
It's likely because of those dark patterns that they can use it in the first place given how walled garden app stores treat apps that do allow for actual anonymous or distributed messaging systems.
I wouldn't either, but it would seem that HKers don't have many options at this time. Hope more are identified and that there aren't malicious intentions with this current one.
How is that a dark pattern? It's better if you do verify, so you can see your contacts and others can know it's you. If that fails, then we offer to use the app without verification.
Are you aware that by doing SMS verification (optional or not) you're making your servers a very juicy target for hackers working for Chinese intelligence? They could probably assume that anyone in Hong Kong with the app is a protester
Hi Jorge, fyi I just browsed for Bridgefy on google and clicked on the first link that showed up and some random page turned up. It looked like it was hacked or something.
That happened to me as well. Can anyone explain to me how that works? Is there entire site hacked, but only triggered when coming from Google? Or does it work some other way?
That first link from Google is highly NSFW. A fully nude woman appears on the screen from some scammy local dating ad network. Has their DNS been hijacked?
Pardon my ignorance but lets say that someone runs a typical cell phone jammer in the area, would that block the Bluetooth signal from working or are RF wavelengths not able to be jammed?
They'd have to specifically jam BT or all the public 2.4 Ghz band which includes WiFi and other protocols. Given that a BT jammer can be bought online for less than 100$, it's trivial to block this app over several tens of meters.
Since we use Bluetooth Low Energy and the algorithm works to make broadcasting/forwarding efficient, we've found that running messages for 24 hours consumes around 7-10% battery total on an average device. These numbers may differ depending on the OS, device, usage, etc. but in a nutshell: we don't consider battery consumption to be a problem.
Several companies have tried to create blockchain-based products using offline mesh networks, but there's the problem of there not being a ledger, and thus transactions not being able to be confirmed. Do you think blockchain-centric companies could integrate technologies like, say, Bridgefy to enable their mobile products to work without Internet and thus become more decentralized?
We're acutely aware of this conversation, and know that we must prioritize the safety of our user base. All of the issues reported on the article are already being fixed, and we should have updates published in the next few weeks.
Here's our blog post: https://bridgefy.me/bridgefys-commitment-to-privacy-and-secu...
As always, we're available to keep the conversation going; please refer to the email address included in the blog post.
Thanks!