Live data from Hacker News

Signal Desktop

whispersystems.org

61–70 of 288 posts

Re: Signal Desktop

#61

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

The central server in Signal does not have the same role as the Telegram's.

If you care first and foremost about UX, use Telegram. If you care first and foremost about the security of your communications, use Signal; go out of your way to use Signal.

Re: Signal Desktop

#62
post #29

> Signal Desktop is a Chrome app which links with your [Android] phone,[...] Unless your "adversary" is not the NSA, I wonder what's the point of encrypting your communications when those coms are taking place on technologies (iOS, Android, Chrome) from companies that are members of the Prism program.

1. Billions of people live in countries which do not have jurisdiction over Apple, Google, etc. 2. You should learn more about PRISM before spreading FUD about its victims. I'm strongly critical of the NSA's actions but for all of their abuse, PRISM is not the bogeyman you're making it out to be: “The PRISM program collects stored internet communications based on demands made to internet companies such as Google Inc.…

> 1. Billions of people live in countries which do not have jurisdiction over Apple, Google, etc.

Alternatively, you could say that billions of people live in countries with no restrictions on espionage of these companies, and with no recourse. Has NK faced justice for the Sony hack? Has the US faced justice for taps of overseas cables? No on both counts. If anything, having your country be a member of PRISM grants you as a citizen greater protection over how that data is used against you by that government.

Re: Signal Desktop

#63

Earlier quoted context omitted.

moxie has stated previously someplace that the goals are 1. Simple encryption for everyone to prevent mass data collection 2. Prevent targeted collection for the crypto enthusiasts The main focus is on step 1. now and they are doing a great job at it. It's slow like anything new, but I managed to convince my parents to switch so that means it's working!

> 1. Simple encryption for everyone to prevent mass data collection Google might be the second biggest mass data collector, after the U.S. government. Using Chrome, one of Google's tools of collection (if I understand correctly), wouldn't seem to further that goal.

Can you articulate a _specific_ threat model under which this extension fails to protect against mass data collection by Google?

Or is this idle speculation.

Re: Signal Desktop

#64

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

I feel a lot of the same things. But, on the bright side:

1. It's early days yet -- let's give them some time to work out the bugs and build out more diverse platform support.

2. The code is open source. If we (or anybody else) gets motivated enough, we can add support for other browsers or build a "real" standalone app.

Re: Signal Desktop

#66
post #41

Earlier quoted context omitted.

Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security as a practical way of expanding its user base. Edit: Tried to word the above most neutrally; I believe this approach has both pros and cons.

> Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security Why is Telegram always under for their flawed security challenge despite the good-enough track record then? They also have perfect usability, native apps, 3rd party clients, etc. If the security is not the first priority then Signal isn't very attractive compared to the competition I think.

Signal doesn't have a history of cryptographic flaws and metadata leakage, and Telegram does. The equivalence you're drawing here is false.

Here's an example, from adc and Juliano Rizzo, who co-discovered the TLS BEAST and CRIME vulnerabilities:

http://www.alexrad.me/discourse/a-264-attack-on-telegram-and...

Re: Signal Desktop

#67
post #41

Earlier quoted context omitted.

Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security as a practical way of expanding its user base. Edit: Tried to word the above most neutrally; I believe this approach has both pros and cons.

> Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security Why is Telegram always under for their flawed security challenge despite the good-enough track record then? They also have perfect usability, native apps, 3rd party clients, etc. If the security is not the first priority then Signal isn't very attractive compared to the competition I think.

Telegram is closed source so we can't verify that they implemented encryption properly, and only Secret Chats have the messages encrypted.

https://telegram.org/faq#q-so-how-do-you-encrypt-data

Re: Signal Desktop

#69
post #61

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

The central server in Signal does not have the same role as the Telegram's. If you care first and foremost about UX, use Telegram. If you care first and foremost about the security of your communications, use Signal; go out of your way to use Signal.

> go out of your way to use Signal

With that mindset we will never get secure communications to the masses but will repeat the PGP dilemma again and again. UX is of utmost importance.

We would still be on 99.99% HTTP websites if HTTPS required going out of one's way.

Re: Signal Desktop

#70
post #69
post #61

Earlier quoted context omitted.

The central server in Signal does not have the same role as the Telegram's. If you care first and foremost about UX, use Telegram. If you care first and foremost about the security of your communications, use Signal; go out of your way to use Signal.

> go out of your way to use Signal With that mindset we will never get secure communications to the masses but will repeat the PGP dilemma again and again. UX is of utmost importance. We would still be on 99.99% HTTP websites if HTTPS required going out of one's way.

That's what the Cryptocat people said.
Post reply on HN