Live data from Hacker News

Signal Desktop

whispersystems.org

81–90 of 288 posts

Re: Signal Desktop

#81

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

They don't like to admit it, but Signal has a metadata problem. It's fine if that's not their threat model, but I wish they would be more clear about it, especially when other chat systems get criticism more often for precisely that aspect. Edit: "As far as we can determine, practical privacy preserving contact discovery remains an unsolved problem." -03 Jan 2014 [0] https://whispersystems.org/blog/contact-discovery/…

Do you have time to share more details on Signal's metdata problem, especially if you have any ideas about what they could do to solve it?

Is this something that is going to require a Tor-like approach to even have a chance of fixing?

Re: Signal Desktop

#82
post #29

Earlier quoted context omitted.

1. Billions of people live in countries which do not have jurisdiction over Apple, Google, etc. 2. You should learn more about PRISM before spreading FUD about its victims. I'm strongly critical of the NSA's actions but for all of their abuse, PRISM is not the bogeyman you're making it out to be: “The PRISM program collects stored internet communications based on demands made to internet companies such as Google Inc.…

> court-approved Remember, this a secret court, whose judges are likely highly biased in favor the government, with secret proceedings where only the NSA gets to make a case. Not exactly a legitimate safeguard. I also have reservations about the grandparent comment, but PRISM is still pretty awful.

Again, I'm not defending them in any way but all we know about the program is that it allows the kangaroo courts to order searches of information stored on those servers. We have no reason to believe it includes the ability to e.g. compel Google to ship a compromised version of Chrome to a specific user and the fact that the NSA has an entire program to develop and deploy rookits supports that interpretation since it's far more expensive than just asking the company to do it for you.

Re: Signal Desktop

#83

Earlier quoted context omitted.

They don't like to admit it, but Signal has a metadata problem. It's fine if that's not their threat model, but I wish they would be more clear about it, especially when other chat systems get criticism more often for precisely that aspect. Edit: "As far as we can determine, practical privacy preserving contact discovery remains an unsolved problem." -03 Jan 2014 [0] https://whispersystems.org/blog/contact-discovery/…

Your criticism would be stronger with a list of examples and evidence they are unfixed for at least 6 months. EDIT: That metadata problem is essentially unsolved and unsolvable. No system is immune to metadata contact discovery at present. For instance, https://ricochet.im/ , is attempting to solve that problem by relying on the user to make the initial exchange securely. However, in reality, any method of relaying t…

[deleted]

Re: Signal Desktop

#84

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

If we were going to rank our priorities, they would be in this order:

1) Make mass surveillance impossible.

2) Stop targeted attacks against crypto nerds.

It's not that we don't find #2 laudable, but optimizing for #1 takes precedence when we're making decisions.

If you don't want to use your phone number, don't use it. You can register with any GV, Twilio, Voicepulse, or other throwaway VoIP number.

If you don't want to run Chrome, use Chromium instead.

If you don't want to use Google Play Services, use GcmCore.

The world you want this software for is not the world that everyone else lives in. You can certainly make it work in that world with a little effort, but because of how we've prioritized our objectives, that's not the default experience.

Re: Signal Desktop

#85

Earlier quoted context omitted.

moxie has stated previously someplace that the goals are 1. Simple encryption for everyone to prevent mass data collection 2. Prevent targeted collection for the crypto enthusiasts The main focus is on step 1. now and they are doing a great job at it. It's slow like anything new, but I managed to convince my parents to switch so that means it's working!

> 1. Simple encryption for everyone to prevent mass data collection Google might be the second biggest mass data collector, after the U.S. government. Using Chrome, one of Google's tools of collection (if I understand correctly), wouldn't seem to further that goal.

The android app already requires Google content manager to be installed, which is probably why the beta is android only. so its no different from the mobile app really.

Re: Signal Desktop

#86
post #32

Why are all these encrypted chat programs (Signal, Telegram, &c.) still centralized and not TOR-style onion-routed?

> Why are all these encrypted chat programs (Signal, Telegram, &c.) still centralized and not TOR-style onion-routed?

https://blog.torproject.org/blog/tor-messenger-beta-chat-ove...

> Tor Messenger builds on the networks you are familiar with, so that you can continue communicating in a way your contacts are willing and able to do. This has traditionally been in a client-server model, meaning that your metadata (specifically the relationships between contacts) can be logged by the server. However, your route to the server will be hidden because you are communicating over Tor.

That is essentially what happens with Signal and every other service as well.

No metadata, truly anonymous communication between trusted parties is an unsolved research problem.

Re: Signal Desktop

#87

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

Isn't Chrome app a standalone app which doesn't run inside Chrome browser, but instead only uses its engine? I don't know anything about security or privacy implications of using this tech though, anyone care to comment?

Re: Signal Desktop

#88

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

> I tend to repeat the 'central server' and 'a phone number is not an address and not public information, it certainly is no identity' criticism.

Your phone number is not your identity in Signal. If you change SIM cards then your friends won't notice and the app works as before.

Signal is based on asym encryption - your private key effectively encodes your identity in combination with your public key.

> And only if the first client is Android?

There is no point in dwelling on that. Android and its syblings are the only potentially secure popular smartphone OSs. Apple and Microsoft OSs are fundamentally flawed in that regard.

Re: Signal Desktop

#89
post #84

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

If we were going to rank our priorities, they would be in this order: 1) Make mass surveillance impossible. 2) Stop targeted attacks against crypto nerds. It's not that we don't find #2 laudable, but optimizing for #1 takes precedence when we're making decisions. If you don't want to use your phone number, don't use it. You can register with any GV, Twilio, Voicepulse, or other throwaway VoIP number. If you don't wan…

If someone was able to come up with a native equivalent, would you support that level of access or is that something you'd oppose?

It seems to me, at least, it might be possible to do so if the API was consistently exposed and versioned.

Re: Signal Desktop

#90
post #41

Earlier quoted context omitted.

Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security as a practical way of expanding its user base. Edit: Tried to word the above most neutrally; I believe this approach has both pros and cons.

> Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security Why is Telegram always under for their flawed security challenge despite the good-enough track record then? They also have perfect usability, native apps, 3rd party clients, etc. If the security is not the first priority then Signal isn't very attractive compared to the competition I think.

Signal's objective is to make mass surveillance impossible. Telegram stores the entire plaintext transcript of every user's entire conversation history server side by default, so if that's the objective, Telegram is definitely not "good enough." Just the opposite, there's nothing worse.
Post reply on HN