Live data from Hacker News

Viewing profile — elvisloops

elvisloops

HN member
Joined
Wed, May 22, 2013, 7:53 PM UTC
HN karma
20
Public activity
22 items

About elvisloops

carnivore

Recent public activity

  1. comment
    Comment #45455644

    Historically as long as everything remained "in the app," it was secure. It's an easy assumption to make and communicate to others. Now it's more complicated: there are things that…

  2. comment
    Comment #45455616

    The history of Signal has been to provide the security properties we're talking about without users having to think about it or understand. To suddenly remove forward secrecy is a …

  3. comment
    Comment #45455566

    Yes, if Signal has effectively removed ratcheting and forward secrecy from the logical "encryption protocol" by encrypting all messages (even disappearing messages) with a single s…

  4. comment
    Comment #45453926

    It's not optional because you don't know whether the people you are communicating with have it enabled. One person in a group chat with the feature enabled undoes the forward secre…

  5. comment
    Comment #45453831

    If the app takes your disappearing message, encrypts it with a static key that never changes and is never deleted, and uploads it to the cloud, then the message is never truly "dis…

  6. comment
    Comment #45453785

    There's a difference between what Signal does in the app and a manual action a user performs outside of the app. It is not realistic to expect that people will see a feature Signal…

  7. comment
    Comment #45452821

    Yes, but you don't need a complicated ratcheting protocol if you've eliminated forward secrecy in other ways. This post is about "post compromise security," but there is already no…

  8. comment
    Comment #45452800

    I think this used to be true. Now one problem is that a Signal message goes through this whole forward secrecy protocol, but the receiving device has some probability of uploading …

  9. comment
    Comment #45452744

    Strange that they are posting about the "signal ratchet" when they just removed it by launching cloud backups that use a static key? Since those cloud backups include disappearing …

  10. comment
    Comment #45175493

    Giving people a 64-character key also feels uncharacteristically crude for Signal. It's not realistic to hand people 64 characters and tell them to “store this securely.” Most peop…

  11. comment
    Comment #45175446

    It's not opt in: signal protocol for a group chat is eliminated if one person in the group chat turns this on, whether or not you do. Communicating with someone who acts adversaria…

  12. comment
    Comment #45175421

    Yes, it undoes all of the security features of Signal's encryption protocol.

  13. comment
    Comment #45175409

    That's not how forward secrecy works. Ciphertext isn't "deleted" unless the key used to encrypt it is also deleted. That's the point of Signal's cutting edge protocol. This undoes …

  14. comment
    Comment #45171974

    The implementation feels uncharacteristically crude for Signal. Instead of seamless protections, you just get handed 64 characters you’re told to “store securely.” That’s not reali…

  15. comment
    Comment #45171577

    This post says disappearing messages are included in the backups. You have to enable disappearing messages with a timer of less than 24 hours to ensure that you can opt out.

  16. comment
    Comment #45171074

    There's a difference between someone in your chats acting adversarially and Signal supporting/encouraging adversarial behavior as part of the way the app works. If Signal published…

  17. comment
    Comment #45170914

    I think the difference is that this is all happening in the app as a supported flow. If simply enabling a toggle in Signal (likely without understanding the implications) is now co…

  18. comment
    Comment #45170880

    There's a big difference to me between storing it on device and someone else's servers.

  19. comment
    Comment #45170770

    I can't believe Signal is doing this. Signal is known for its cutting-edge cryptographic protocol, but this feature has the effect of throwing that out the window and replacing it …

  20. comment
    Comment #6515786

    They are owned by Twitter. It's basically a spyware approach - Twitter wants to be able to track users across apps, but there are no cookies or tracking pixels in the mobile app ec…

  21. comment
    Comment #5753350

    I wonder why they decided to send codes over SMS that we have to manually type into a browser instead of a one-tap push notification to the Twitter app on the phone? Or Google Auth…

  22. comment
    Comment #5753337

    Yeah! I didn't even realize there were other grocery stores other than Berkeley Bowl in Berkeley.