Viewing profile — at612
at612
HN member- Joined
- Sun, Dec 04, 2016, 9:09 PM UTC
- HN karma
- 18
- Public activity
- 32 items
- HN profile
- View on Hacker News ↗
About at612
No profile information was provided.
Recent public activity
-
comment
Comment #13151806
> if you're a stock holder, certain places (like interactive brokers) Any specific examples?
-
comment
Comment #13138644
> From a developer perspective however, encouraging or even tolerating unofficial installation channels for secure communication software is bad. What is your threat model?
-
comment
Comment #13138636
> I really don't see why someone should be on my shitlist for lying to godaddy dot com or whatever giant registrar unless you consider fudging identifying details about something t…
-
comment
Comment #13138422
> Is OTR really a practical option? You message seems unclear about it. It depends on your threat model, like other alternatives. I have never initiated an OTR session myself, but …
-
comment
Comment #13138319
> It's free. You misunderstand. He is running a company, what do you think their exit strategy is? You may want to look at his previous company and "red phone", I think was his pro…
-
comment
Comment #13136724
Now gents, a number of you in the comments have wondered about what other alternatives are out there. You may have seen that I specifically advise against Signal, and other users h…
-
comment
Comment #13136525
>> Can I run a client from the Git repo and still use all of their infrastructure? > Yes. You can. The thing is, lucideer, the "restrictions" on the use of the source code are engi…
-
comment
Comment #13136366
> I am really interested why Signal. Why not Telegram? And I would be really interested to know why people are downvoting a perfectly reasonable question.
-
comment
Comment #13136352
> The suggestion that the motivation for this article is profit for the NYT or Moxie is quite destructive. No, that's literally how it works. Media need to sell copy (clicks these …
-
comment
Comment #13136320
Are you aware that the guy behind this signal app sold his previous "secure messaging" thing to Twitter?
-
comment
Comment #13136307
> what's a reasonable heuristic for conducting private business? You need to do a threat analysis. I did not immediately find any good introductory resources via a quick Google sea…
-
comment
Comment #13136206
> Re: Google Play Services. Here's is the way I understand this to work, so please do correct me if I'm wrong. > Signal uses Google Play Services to notify me that I have an incomi…
-
comment
Comment #13136052
> I'd even argue it's free software Terminology. What you call free software I call open source. As you go on to mention, you can see the source but not use it in any meaningful wa…
-
comment
Comment #13135907
> I'm probably just inviting myself to get trolled by replying to this I'm sorry that you get that impression, but I do appreciate your input. > Cryptographer Matthew Green on Sign…
-
comment
Comment #13135600
> Don't want to invest my time into something that will eventually sell out And what do you think the gentleman behind Signal is out there for? His modus operandi: * Start a compan…
-
comment
Comment #13135563
Just wondering, but why not just use XMPP? You can choose any server that you like or trust, or run your own (on your own or third party infrastructure, up to you), and use OTR for…
-
comment
Comment #13135445
> Neither Telegram nor WhatsApp are viable alternatives to anyone interested in privacy. Are you suggesting that the application under discussion here is a viable alternative? If s…
-
comment
Comment #13135382
Download Signal? No, thank you. The fact that the guy behind it is hyping it via the New York Times, a generalist publication, instead of validating the thing through professional …
-
comment
Comment #13135169
> It's 2016 and our best crypto messenger options are worse than what we had 10 years ago when Skype was peer to peer, or Jabber with federation. Actually, Jabber with OTR is prett…
-
comment
Comment #13130602
For me, the takeaway from that article is this: > Different people will have different testing strategies based on this philosophy, but that seems reasonable to me given the immatu…
-
comment
Comment #13119282
> So distribute keys on smart cards that don't allow you to export the key That's what I covered in the second paragraph. :-) The thing is, both those implementations were a disast…
-
comment
Comment #13119057
> How do you distribute the one time pad in the first place? If you do it insecurely, it's a waste of time. If you can do it "securely", why not just use that secure channel to sen…
-
comment
Comment #13118989
> all the experts here Which experts? And what are those fundamental flaws?
-
comment
Comment #13118986
> IMO we should aim for a Crypto like Signal presents it; You mean by leaking the plaintext in the device logs? By having to trust a single party which is known for being economica…
-
comment
Comment #13118930
> Just get the national government to distribute RSA USB keys to every citizen. I lived in a country that did exactly that. And it was a disaster. The keys were trivially easy to s…