One of the links I posted above "mysteriously" disappeared.
I have an archived version though.
It's one of the key-points of the situation I exposed, so it's worth a read.
The issue is that if you use Tox you support their foundation, the Tox Foundation™ which deals with money in a shady way and deceive their users just in order to grow.
I, for moral and ethical principles, don't want to have anything to do with such a thing and believe it's necessary to let people know about the situation.
If they couldn't even respect an ex-developer privacy[0] how can we expect them to run a foundation and create a supposedly secure instant messaging?
Tox still hasn't solved the serious metadata leakage issue.
They tried to cover it up by adding onion-routing for friend requests, but ACTUAL MESSAGES are still done directly.
Strong adversaries such as your ISP and agencies like the NSA, the GCHQ, etc. can still collect metadata about your conversations.
The "Tox Foundation" tries to cover this up and pretend that "tox was never meant to be anonymous", but the truth is harsh.
Now, this wouldn't be a problem if the Tox Foundation made this issue clear to its users. This is how P2P works, after all, direct connections, and that's fine.
But the problem is that Tox doesn't make that obvious for non-tech-savvy users.
When they read on the website that they are completely safe from the NSA and whatnot, they won't expect to be in any way exposed.
Still, unless these non-tech-savvy users "route all incoming and outgoing traffic through Tor" they won't be completely safe and should be worried about metadata leakage and adding people they don't actually know.
But such a thing isn't made clear and Tox deceives users this way, only to get more people using it. It's unethical and outright wrong, in my personal opinion.
DISCLAIMER: I am one of the many Tox ex-contributors, who used to work on it in the past. I don't want to be identified due to harassment other ex-contributors suffered in the past. The following message is my point of view on the project as a whole.
Proplex, a long-time member of the Tox-Foundation and in charge of both infrastructure and marketing, called out tox devs because the 2 people in charge (irungentoo and stqism) were dealing with money in a shady way and he got suspicious. This lead him to leaving the Tox Foundation
Proof: https://gist.github.com/irungentoo/5af26f5edefcdb7eac72
After he went away and stopped to pay for the website and other servers (he hosted everything), Tox devs got angry and tracked his online activity by his browser UA, read his private email sent to his @tox.im address and considered breaking into his VPS account
Proof: https://gist.github.com/urras/ba792274f5aaf662a082/5d91d2a78... and https://archive.today/KkSWp
After the points exposed above, the conclusion is obvious, at least for me.
The Tox Foundation claims Tox is completely secure and nobody can break in, not even the NSA. Still, there's been no security audit and it is highly likely Tox isn't completely secure, given it's alpha software. But their website gives the idea people face no risk by using Tox right now. They are deceiving people to believe it is secure so they gain more users at the expense of putting users privacy at risk.
Proof: https://tox.im itself. See all security claims even though it hasn't been audited. Saying it's "alpha" doesn't mean to anything to non-tech-savvy, they will think it's missing a feature or two, not that their privacy and security is possibly compromised.
I believe it's my moral obligation, and of everyone's else reading this, not to use Tox.
You are contributing to a shady foundation composed of menchildren that don't care about other's privacy, deals with money in a shady way and dox people who go against them. Do not trust the Tox Foundation - this is my personal message.
Hopefully I archive most for good measure.
https://archive.today/Y6LEw
https://archive.today/MajJV
https://archive.today/KkSWp
https://archive.today/CWBUp
http://a.pomf.se/kqwgsg.png