Viewing profile — sandervenema
sandervenema
HN member- Joined
- Sat, Nov 05, 2016, 6:25 PM UTC
- HN karma
- 57
- Public activity
- 14 items
- HN profile
- View on Hacker News ↗
About sandervenema
No profile information was provided.
Recent public activity
-
comment
Comment #12883049
Yes, I agree that's more transparent. I've added an endnote, and linked to it from the place where the edit was made.
-
comment
Comment #12882853
Hmm. You seem to be right. Article corrected there to reflect that Signal is using empty GCM messages. I must have still had the old situation of TextSecure in my head when I wrote…
-
comment
Comment #12882597
As the previous links from STRATFOR etc. prove, Google is deeply embedded in the security/intelligence apparatus. That part is definitely willing and beneficial to both parties. Of…
-
comment
Comment #12882478
And Google became a PRISM partner in 2009, as the slides here from the Snowden collection prove: https://search.edwardsnowden.com/docs/PRISMUS-984XNOverview2...
-
comment
Comment #12882463
On this: https://wikileaks.org/Op-ed-Google-and-the-NSA-Who-s.html there are links on that page that point out multiple e-mails from the STRATFOR leaks and other files that point t…
-
comment
Comment #12882381
True, they are rare. On another unrelated project I'm working together with Bill Binney, the cryptographer who wrote ThinThread at NSA. That's all I can currently say about it.
-
comment
Comment #12882339
I see I haven't replied yet to your first point: here goes. Of course clearly an alternative has to be at least cryptographically secure . I fully agree with you on that. I'm not r…
-
comment
Comment #12882304
One thing I wanted to add, regarding the tech: of course I do that in cooperation with other people some of who are indeed trained cryptographers.
-
comment
Comment #12882292
Regarding qualifications: I spent years building secure technology (publication platforms, websites) for whistleblowers including Ed Snowden himself (I built his official website (…
-
comment
Comment #12881412
Agree. I'm not a cryptographer and never claimed to be either. -- and I think it would be difficult to mistake me for a hipster. For one, I don't have that snazzy majestic beard.. …
-
comment
Comment #12881372
Hi there! The Giphy thing is what set me off writing the blog post in the first place. Maybe I should've expanded a bit more on that in the article. As far as I can tell, the idea …
-
comment
Comment #12881278
Just a quick look, but this is the PackageManager.java file: https://android.googlesource.com/platform/frameworks/base/+/... for the Android base framework. It has the checkSignatu…
-
comment
Comment #12881212
Hi, author here. I don't think LibreSignal or indeed Signal will ever be the dominant mobile messenger out there. There's simply a lot of inertia to fight against. It's the same re…
-
comment
Comment #12881153
Hi, author here. Yes, my point with that sentence was that the average (non-technical) user (to which Signal is marketed btw), is not going to check signatures. Google has root on …