Live data from Hacker News

Signal Desktop

whispersystems.org

91–100 of 288 posts

Re: Signal Desktop

#91
post #66

Earlier quoted context omitted.

> Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security Why is Telegram always under for their flawed security challenge despite the good-enough track record then? They also have perfect usability, native apps, 3rd party clients, etc. If the security is not the first priority then Signal isn't very attractive compared to the competition I think.

Signal doesn't have a history of cryptographic flaws and metadata leakage, and Telegram does. The equivalence you're drawing here is false. Here's an example, from adc and Juliano Rizzo, who co-discovered the TLS BEAST and CRIME vulnerabilities: http://www.alexrad.me/discourse/a-264-attack-on-telegram-and...

I'm not drawing an equivalence at all (not saying that Telegram and Signal are equivalently insecure or flawed, etc.) -- I was only asking why would Signal make any compromise on security if that is their main selling point (and probably the only one). I don't think that releasing a Chrome app is a good strategy considering the audience (but I don't know for sure, they probably have a better overview of their user base).

I could have compared it to Threema as well, actually.

Re: Signal Desktop

#92

Earlier quoted context omitted.

> Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security Why is Telegram always under for their flawed security challenge despite the good-enough track record then? They also have perfect usability, native apps, 3rd party clients, etc. If the security is not the first priority then Signal isn't very attractive compared to the competition I think.

Telegram is closed source so we can't verify that they implemented encryption properly, and only Secret Chats have the messages encrypted. https://telegram.org/faq#q-so-how-do-you-encrypt-data

The end to end encryption is open source.

Re: Signal Desktop

#93

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

> I tend to repeat the 'central server' and 'a phone number is not an address and not public information, it certainly is no identity' criticism. Your phone number is not your identity in Signal. If you change SIM cards then your friends won't notice and the app works as before. Signal is based on asym encryption - your private key effectively encodes your identity in combination with your public key. > And only if t…

Approximately zero is the number of software security experts that would agree with that assessment of Android's security versus that of iOS.

There are a lot of totally fine reasons (shakes fist) that OWS would start with Android; they might all have Android phones, they might have ideological problems with app store review, it might have just been an easier platform to build for. But yours isn't one of the valid reasons.

Re: Signal Desktop

#94

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

They don't like to admit it, but Signal has a metadata problem. It's fine if that's not their threat model, but I wish they would be more clear about it, especially when other chat systems get criticism more often for precisely that aspect. Edit: "As far as we can determine, practical privacy preserving contact discovery remains an unsolved problem." -03 Jan 2014 [0] https://whispersystems.org/blog/contact-discovery/…

NSA only knows then that somebody with that phone number is using Signal ... so what?

They would find out anyway b/c your packets are sniffed on a regular basis and so they know your phone is communicating with the Signal server and maybe the packets itself are characteristic.

So in my humble opinion this criticism is irrelevant.

Re: Signal Desktop

#95

Earlier quoted context omitted.

> Whisper Systems has a track record of prioritizing 'good enough' ease-of-use ahead of 'perfect' security Why is Telegram always under for their flawed security challenge despite the good-enough track record then? They also have perfect usability, native apps, 3rd party clients, etc. If the security is not the first priority then Signal isn't very attractive compared to the competition I think.

Telegram is closed source so we can't verify that they implemented encryption properly, and only Secret Chats have the messages encrypted. https://telegram.org/faq#q-so-how-do-you-encrypt-data

I thought the Telegram client is open-source, it's even on F-droid. The server side being open or closed source is meaningless:

1. In Telegram's threat model the servers are not trusted.

2. You can't verify server side code anyway.

Re: Signal Desktop

#96
post #66

Earlier quoted context omitted.

Signal doesn't have a history of cryptographic flaws and metadata leakage, and Telegram does. The equivalence you're drawing here is false. Here's an example, from adc and Juliano Rizzo, who co-discovered the TLS BEAST and CRIME vulnerabilities: http://www.alexrad.me/discourse/a-264-attack-on-telegram-and...

I'm not drawing an equivalence at all (not saying that Telegram and Signal are equivalently insecure or flawed, etc.) -- I was only asking why would Signal make any compromise on security if that is their main selling point (and probably the only one). I don't think that releasing a Chrome app is a good strategy considering the audience (but I don't know for sure, they probably have a better overview of their user ba…

I don't concede that Signal has made any security compromises. That was someone else.

If you care about security, use Signal. If you care about UX, and Threema has a better UX, use Threema. Threema is a closed-source system that apparently relies on Nacl. That is a much better answer than the one Telegram can give, but it still leaves a whole lot of questions unanswered. There's a lot that can go wrong in the layers above Nacl.

Re: Signal Desktop

#97
post #93

Earlier quoted context omitted.

> I tend to repeat the 'central server' and 'a phone number is not an address and not public information, it certainly is no identity' criticism. Your phone number is not your identity in Signal. If you change SIM cards then your friends won't notice and the app works as before. Signal is based on asym encryption - your private key effectively encodes your identity in combination with your public key. > And only if t…

Approximately zero is the number of software security experts that would agree with that assessment of Android's security versus that of iOS. There are a lot of totally fine reasons (shakes fist) that OWS would start with Android; they might all have Android phones, they might have ideological problems with app store review, it might have just been an easier platform to build for. But yours isn't one of the valid rea…

Huh? Apple and MS have a record of communicating in sharing data with US government - plus as companies providing closed source software they are likely to introduce backdoors ... also something you might have heard of since Snowden.

Re: Signal Desktop

#98
post #93

Earlier quoted context omitted.

Approximately zero is the number of software security experts that would agree with that assessment of Android's security versus that of iOS. There are a lot of totally fine reasons (shakes fist) that OWS would start with Android; they might all have Android phones, they might have ideological problems with app store review, it might have just been an easier platform to build for. But yours isn't one of the valid rea…

Huh? Apple and MS have a record of communicating in sharing data with US government - plus as companies providing closed source software they are likely to introduce backdoors ... also something you might have heard of since Snowden.

I'm making an engineering point, and you're making a conspiracy-theoretic point.

Re: Signal Desktop

#99
post #87

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

Isn't Chrome app a standalone app which doesn't run inside Chrome browser, but instead only uses its engine? I don't know anything about security or privacy implications of using this tech though, anyone care to comment?

No, you're likely thinking of Electron[0]. A Chrome App[1] is a browser extension that tries to act more like a native app.

[0]: http://electron.atom.io/ [1]: https://developer.chrome.com/apps/about_apps

Re: Signal Desktop

#100

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

They don't like to admit it, but Signal has a metadata problem. It's fine if that's not their threat model, but I wish they would be more clear about it, especially when other chat systems get criticism more often for precisely that aspect. Edit: "As far as we can determine, practical privacy preserving contact discovery remains an unsolved problem." -03 Jan 2014 [0] https://whispersystems.org/blog/contact-discovery/…

They don't like to admit it, that is why the write a whole blog post about it? The app tells you when registering that is is about to send some contact information to the server and that it will not be stored.
Post reply on HN