Live data from Hacker News

Viewing profile — infosechandbook

infosechandbook

HN member
Joined
Thu, Nov 04, 2021, 12:15 PM UTC
HN karma
40
Public activity
29 items

About infosechandbook

No profile information was provided.

Recent public activity

  1. comment
    Comment #29909971

    > You can save XMPP account IDs in any mobile address book. ... while the rest of the XMPP account remains on the XMPP server, inaccessible. There is no benefit as you can also sto…

  2. comment
    Comment #29907116

    Just one question as the rest was discussed numerous times before: > At least with XMPP, I can point the same client to some other server and potentially continue a conversation wi…

  3. comment
    Comment #29902816

    You just wrote it is "silly" to compare XMPP with Signal while constantly doing it yourself. > Signal admins too can ship you an app Or I could just use my own Signal client since …

  4. comment
    Comment #29902690

    Yes, Quicksy from the Conversations developer who bragged about copying main features of WhatsApp and Signal. Another one is Kontalk, https://www.kontalk.org/ . Both XMPP clients r…

  5. comment
    Comment #29902670

    > I can link a raspberry pi anywhere in the world to my XMPP server with a few lines of Python and some libraries. Once again, "I, as a tech-savvy person, can operate my highly-cus…

  6. comment
    Comment #29888864

    > The Signal protocol is neither an open (you cannot propose changes or extensions in an open process) nor has it been submitted to an standards body. Who defines "open standard" i…

  7. comment
    Comment #29888788

    > Comparing Signal with XMPP is silly. Could you please add your statement to any other comments by XMPP proponents that state "XMPP is better than Signal because ..."? Plus, could…

  8. comment
    Comment #29887921

    > If you start with an argument ..., it's strange that you don't apply same logic to Signal admins Where is this 1-to-1 comparison you demand in the OP's original article? Security…

  9. comment
    Comment #29877574

    > claiming XMPP is either the best ... Unfortunately, this seems to be the starting point of most discussions on XMPP. Somebody claims that XMPP solves all problems, and is secure …

  10. comment
    Comment #29877420

    > Signal operators can also inject messages to people. Did you check this, and can you demonstrate a server-side message injection so that the Signal clients display the injected m…

  11. comment
    Comment #29874403

    > Have you read the joinjabber.org security FAQ i linked? Not in detail as the OP linked to another article. We commented on OP's other article, not on your joinjabber.org security…

  12. comment
    Comment #29874013

    > How many of your contacts who use Signal used their real phone number? Most of them; however, there is no obligation to provide any personal data when registering a SIM card in m…

  13. comment
    Comment #29873889

    > disclosed to the server admin Please read the article before and after these items. The first finding isn't about the server admin but about external parties such as law enforcem…

  14. comment
    Comment #29873796

    Nobody claimed that they look the same. As mentioned in the linked article, the behavior upon receiving an injected message is client specific. In any way, the injected message is …

  15. comment
    Comment #29873719

    > I already responded to your "admin in the middle" article here And we already responded here: https://news.ycombinator.com/item?id=29106376 , and here: https://infosec-handbook.e…

  16. comment
    Comment #29873552

    > Anyway the problem of Signal is that you have to use your phone number and a phone number is a much stronger link to you than an ip for example. Signal requires access to a valid…

  17. comment
    Comment #29873459

    > How should that be possible if OMEMO is enabled (which is the default in more modern clients)? See https://infosec-handbook.eu/articles/xmpp-aitm/#t5 TL;DR: XMPP clients can't di…

  18. comment
    Comment #29873408

    > What would be your alternative? A good starting point would be more balanced articles also talking about downsides or not-so-secure/-private defaults; not only in case of XMPP bu…

  19. comment
    Comment #29873020

    > XMPP is as secure as Signal nowadays, it implements the same encryption scheme Signal enforces E2EE, you can't disable it. If XMPP supports E2EE depends on the XMPP clients and s…

  20. comment
    Comment #29872880

    The article describes XMPP as "secure" by highlighting TLS (protecting data in transit only) and experimental OMEMO (protecting a small part of an XMPP message only if enabled and …

  21. comment
    Comment #29158069

    The guide is outdated if you rely on the latest version of OpenSSH. You must update such guides with every new version of OpenSSH. Adding legacy configuration to your OpenSSH confi…

  22. comment
    Comment #29115871

    > Almost none of the XMPP clients use plain text connection nowadays. Everything shown in the article works with or without TLS enabled. It doesn't matter. The server-side party se…

  23. comment
    Comment #29115840

    Excellent example for what we mean: Our article doesn't discuss anything about "What is needed to register for service X." Discussing this is perfectly valid; however, it isn't abo…

  24. comment
    Comment #29109276

    > If you recommend X instead of Y, it seems reasonable to discuss not only the downsides of Y but also how X is better or worse in comparison to Y. Indeed. One should mention upsid…

  25. comment
    Comment #29106443

    > I believe you're slightly misunderstanding the details here (no surprise, as the article is not clear). The article clearly mentions that passwords are sent in cleartext to the s…