Live data from Hacker News

Signal Desktop

whispersystems.org

71–80 of 288 posts

Re: Signal Desktop

#71

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

To me, this announcement feels pre-mature, the software doesn't seem ready until it integrates with other clients. But I think, giving time, your concerns could be addressed:

-Integration with other devices, backing up and importing your back up between devices, are features that will come, eventually.

-There are several 3rd party standalone desktop apps being developed for Signal.

-You could maybe build a Textsecure server, and in the future, who knows, there may be documentation for doing so.

Maybe Signal isn't ready for you right now now but I wouldn't count it out!

Re: Signal Desktop

#72
post #61

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

The central server in Signal does not have the same role as the Telegram's. If you care first and foremost about UX, use Telegram. If you care first and foremost about the security of your communications, use Signal; go out of your way to use Signal.

Tbh, Signal's UX on Android is pretty good.

Is Telegram just better on iOS or am I missing something when you say it has better UX?

Re: Signal Desktop

#73

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

They don't like to admit it, but Signal has a metadata problem. It's fine if that's not their threat model, but I wish they would be more clear about it, especially when other chat systems get criticism more often for precisely that aspect.

Edit: "As far as we can determine, practical privacy preserving contact discovery remains an unsolved problem." -03 Jan 2014

[0] https://whispersystems.org/blog/contact-discovery/

The kind of data they hold is legally within the reach of authorities and would allow metadata analysis similar to the NSA's former phone metadata program.

Re: Signal Desktop

#74

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

[deleted]

Re: Signal Desktop

#75
post #41

Earlier quoted context omitted.

Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security as a practical way of expanding its user base. Edit: Tried to word the above most neutrally; I believe this approach has both pros and cons.

> Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security Why is Telegram always under for their flawed security challenge despite the good-enough track record then? They also have perfect usability, native apps, 3rd party clients, etc. If the security is not the first priority then Signal isn't very attractive compared to the competition I think.

despite [Telegram's] good-enough track record

You may have missed parts of their track record; part of the problem is that Telegram tends to hide these types of things in its past:

"Telegram protocol defeated. Authors are going to modify crypto-algorithm" https://news.ycombinator.com/item?id=6948742

Re: Signal Desktop

#76
post #41

Earlier quoted context omitted.

Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security as a practical way of expanding its user base. Edit: Tried to word the above most neutrally; I believe this approach has both pros and cons.

> Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security Why is Telegram always under for their flawed security challenge despite the good-enough track record then? They also have perfect usability, native apps, 3rd party clients, etc. If the security is not the first priority then Signal isn't very attractive compared to the competition I think.

Telegram has a tendency to mislead [intentionally or not] about the quality of its security.

Signal is pretty up front about being "good enough" security.

Re: Signal Desktop

#77
post #29

> Signal Desktop is a Chrome app which links with your [Android] phone,[...] Unless your "adversary" is not the NSA, I wonder what's the point of encrypting your communications when those coms are taking place on technologies (iOS, Android, Chrome) from companies that are members of the Prism program.

1. Billions of people live in countries which do not have jurisdiction over Apple, Google, etc. 2. You should learn more about PRISM before spreading FUD about its victims. I'm strongly critical of the NSA's actions but for all of their abuse, PRISM is not the bogeyman you're making it out to be: “The PRISM program collects stored internet communications based on demands made to internet companies such as Google Inc.…

> court-approved

Remember, this a secret court, whose judges are likely highly biased in favor the government, with secret proceedings where only the NSA gets to make a case. Not exactly a legitimate safeguard.

I also have reservations about the grandparent comment, but PRISM is still pretty awful.

Re: Signal Desktop

#78

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

They don't like to admit it, but Signal has a metadata problem. It's fine if that's not their threat model, but I wish they would be more clear about it, especially when other chat systems get criticism more often for precisely that aspect. Edit: "As far as we can determine, practical privacy preserving contact discovery remains an unsolved problem." -03 Jan 2014 [0] https://whispersystems.org/blog/contact-discovery/…

Your criticism would be stronger with a list of examples and evidence they are unfixed for at least 6 months.

EDIT:

That metadata problem is essentially unsolved and unsolvable. No system is immune to metadata contact discovery at present.

For instance, https://ricochet.im/, is attempting to solve that problem by relying on the user to make the initial exchange securely. However, in reality, any method of relaying that to their contact point is vulnerable to discovery of that kind of metadata.

Re: Signal Desktop

#79
post #69
post #61

Earlier quoted context omitted.

The central server in Signal does not have the same role as the Telegram's. If you care first and foremost about UX, use Telegram. If you care first and foremost about the security of your communications, use Signal; go out of your way to use Signal.

> go out of your way to use Signal With that mindset we will never get secure communications to the masses but will repeat the PGP dilemma again and again. UX is of utmost importance. We would still be on 99.99% HTTP websites if HTTPS required going out of one's way.

Signal is an order of magnitude easier to use than PGP. It's not even close.

The GP was comparing two apps that are actually both very easy to use, one maybe slightly moreso.

(That said, PGP isn't THAT hard either.)

Re: Signal Desktop

#80
post #32

Why are all these encrypted chat programs (Signal, Telegram, &c.) still centralized and not TOR-style onion-routed?

As much as I agree with your overall sentiment, the sad truth is that centralized architectures enable many of the UX affordances that users take for granted today in a modern chat app, many of which are much more difficult, sometimes simply impossible, to implement in a decentralized architecture (think features like automatic contact discovery, offline messaging, etc). Without some of these affordances, a chat app…

What kind of things are impossible?
Post reply on HN