Live data from Hacker News

Viewing profile — jlund

jlund

HN member
Joined
Fri, Mar 29, 2013, 6:38 AM UTC
HN karma
741
Public activity
91 items

About jlund

Joshua Lund

Recent public activity

  1. comment
    Comment #31439191

    Hey, HN. While I was helping a friend set up their new iPhone, I noticed that they were prompted to upgrade to a newer version of iOS. When I checked my own phone, I saw that the u…

  2. story
  3. comment
    Comment #26029265

    The Nginx configs use modules that are not compiled by default, so most preexisting Nginx binaries in mainstream distros won't work.

  4. comment
    Comment #23435866

    Does this help? https://signal.org/docs/

  5. comment
    Comment #23435816

    Just to clarify, the bug you're talking about was in WebRTC. We submitted a patch upstream: https://webrtc-review.googlesource.com/c/src/+/175960

  6. comment
    Comment #21941647

    Google Play Services aren't required to run Signal on Android either.

  7. comment
    Comment #21938703

    https://signal.org/blog/license-update/

  8. comment
    Comment #21839394

    Nice breakdown! Just to clarify, in step 2 of your "Recovery of the secret (by the client)" section, the client is retrieving `split2`, not `split1`.

  9. comment
    Comment #18333732

    You can read more about the Registration Lock feature here: https://support.signal.org/hc/en-us/articles/360007059792-Re...

  10. comment
    Comment #17725621

    The Contacts permission is completely optional, and contact information is never stored: https://signal.org/blog/private-contact-discovery/

  11. comment
    Comment #17725510

    It does. Signal supports runtime permissions[1] and it requests them dynamically while you are using the app (e.g. the camera permission prompt appears the first time you try to ta…

  12. comment
    Comment #17725374

    Everything in Signal is end-to-end encrypted.

  13. comment
    Comment #17093662

    I was incorrect about this, and I apologize.

  14. comment
    Comment #17074169

    Just one additional note that might not be immediately clear from the advisory: Exploiting this requires the attacker to first manually place malware (a malicious JavaScript file) …

  15. comment
    Comment #16972201

    If the solution to censorship is to constantly switch to new hosts, it would be even easier to do this via a VPN (which wouldn't require you to rebuild your social graph at all, un…

  16. comment
    Comment #16971971

    > Time to look for another option then That's the plan. This is covered briefly in the second-to-last paragraph. > so it was never really viable Signal remained running for more th…

  17. comment
    Comment #16971439

    Let's say I have an account on a federated server and a censor then blocks my ability to access that server from my home country. While it's true that my friends on other servers m…

  18. comment
    Comment #16971097

    The loss of domain fronting as a viable strategy means that it will be possible to censor Signal in areas where the service was previously working.

  19. comment
    Comment #16971045

    An aspiring censor could also "easily connect to the broader network" and masquerade as a federated server in order to discover others. This process could even be automated. Federa…

  20. comment
    Comment #16970814

    The technique that Signal was using to circumvent censorship (domain fronting) will no longer be possible on Amazon: https://aws.amazon.com/blogs/security/enhanced-domain-protec...…

  21. comment
    Comment #16970732

    Unfortunately, federation is not an effective tactic against censorship: https://news.ycombinator.com/item?id=16871352

  22. comment
    Comment #16970674

    The relevant text is in the subject line of the email: "Notification of potential account suspension regarding AWS Service Terms"

  23. comment
    Comment #16871352

    It's trivial to block several distributed hosts simultaneously. An aspiring censor would simply find the most common federated endpoints for a given service and block all of them. …

  24. comment
    Comment #16869269

    Hey, everyone. We spent a decent amount of time at Signal trying to come up with alternatives when we first heard rumors that Google was disabling domain fronting on GAE. We're usi…

  25. comment
    Comment #16128865

    Signal takes metadata protection very seriously: https://signal.org/bigbrother/