Viewing profile — elvisloops
elvisloops
HN member- Joined
- Wed, May 22, 2013, 7:53 PM UTC
- HN karma
- 20
- Public activity
- 22 items
- HN profile
- View on Hacker News ↗
About elvisloops
Recent public activity
-
comment
Comment #45455644
Historically as long as everything remained "in the app," it was secure. It's an easy assumption to make and communicate to others. Now it's more complicated: there are things that…
-
comment
Comment #45455616
The history of Signal has been to provide the security properties we're talking about without users having to think about it or understand. To suddenly remove forward secrecy is a …
-
comment
Comment #45455566
Yes, if Signal has effectively removed ratcheting and forward secrecy from the logical "encryption protocol" by encrypting all messages (even disappearing messages) with a single s…
-
comment
Comment #45453926
It's not optional because you don't know whether the people you are communicating with have it enabled. One person in a group chat with the feature enabled undoes the forward secre…
-
comment
Comment #45453831
If the app takes your disappearing message, encrypts it with a static key that never changes and is never deleted, and uploads it to the cloud, then the message is never truly "dis…
-
comment
Comment #45453785
There's a difference between what Signal does in the app and a manual action a user performs outside of the app. It is not realistic to expect that people will see a feature Signal…
-
comment
Comment #45452821
Yes, but you don't need a complicated ratcheting protocol if you've eliminated forward secrecy in other ways. This post is about "post compromise security," but there is already no…
-
comment
Comment #45452800
I think this used to be true. Now one problem is that a Signal message goes through this whole forward secrecy protocol, but the receiving device has some probability of uploading …
-
comment
Comment #45452744
Strange that they are posting about the "signal ratchet" when they just removed it by launching cloud backups that use a static key? Since those cloud backups include disappearing …
-
comment
Comment #45175493
Giving people a 64-character key also feels uncharacteristically crude for Signal. It's not realistic to hand people 64 characters and tell them to “store this securely.” Most peop…
-
comment
Comment #45175446
It's not opt in: signal protocol for a group chat is eliminated if one person in the group chat turns this on, whether or not you do. Communicating with someone who acts adversaria…
-
comment
Comment #45175421
Yes, it undoes all of the security features of Signal's encryption protocol.
-
comment
Comment #45175409
That's not how forward secrecy works. Ciphertext isn't "deleted" unless the key used to encrypt it is also deleted. That's the point of Signal's cutting edge protocol. This undoes …
-
comment
Comment #45171974
The implementation feels uncharacteristically crude for Signal. Instead of seamless protections, you just get handed 64 characters you’re told to “store securely.” That’s not reali…
-
comment
Comment #45171577
This post says disappearing messages are included in the backups. You have to enable disappearing messages with a timer of less than 24 hours to ensure that you can opt out.
-
comment
Comment #45171074
There's a difference between someone in your chats acting adversarially and Signal supporting/encouraging adversarial behavior as part of the way the app works. If Signal published…
-
comment
Comment #45170914
I think the difference is that this is all happening in the app as a supported flow. If simply enabling a toggle in Signal (likely without understanding the implications) is now co…
-
comment
Comment #45170880
There's a big difference to me between storing it on device and someone else's servers.
-
comment
Comment #45170770
I can't believe Signal is doing this. Signal is known for its cutting-edge cryptographic protocol, but this feature has the effect of throwing that out the window and replacing it …
-
comment
Comment #6515786
They are owned by Twitter. It's basically a spyware approach - Twitter wants to be able to track users across apps, but there are no cookies or tracking pixels in the mobile app ec…
-
comment
Comment #5753350
I wonder why they decided to send codes over SMS that we have to manually type into a browser instead of a one-tap push notification to the Twitter app on the phone? Or Google Auth…
-
comment
Comment #5753337
Yeah! I didn't even realize there were other grocery stores other than Berkeley Bowl in Berkeley.