Live data from Hacker News

Signal Desktop

whispersystems.org

111–120 of 288 posts

Re: Signal Desktop

#111
post #84

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

If we were going to rank our priorities, they would be in this order: 1) Make mass surveillance impossible. 2) Stop targeted attacks against crypto nerds. It's not that we don't find #2 laudable, but optimizing for #1 takes precedence when we're making decisions. If you don't want to use your phone number, don't use it. You can register with any GV, Twilio, Voicepulse, or other throwaway VoIP number. If you don't wan…

Thank you for your reply. I really appreciate it. As I stated earlier, I feel bad about 'expecting more' here - I certainly see the appeal of a popular ~decent~ option. Without trying to derail this further, let me look at those points:

If I use throwaway numbers: What happens if I lose access? Do I _need_ the number for anything in the future (say, device died)? Can someone else mess with me if they get access to this number, if the number gets reassigned? Searching for this kind of information is hard, because 'Signal' isn't exactly a word that search engines understand in context.

Chromium and Chrome are the same thing for me: A browser I don't care for and only install on a dev machine for some tests. I wouldn't install either on my personal rig, ignoring the suffixes. And certainly not for an 'app'. It's both 'Not liking Google' and 'No general web browser to run an IM client'. The latter isn't solved by Chromium.

As far as I'm aware there are no Google Play Services for FxOS (looking at this Flame right here) and I expect that there's no easy solution for SailfishOS either.

I understand that I'm not the target audience. Please believe me when I say that I don't feel that I can (as in, it suits me/feels okay to do so) use Signal right now. I'm writing these messages here not to hit on your work, but to express that there is an audience with other preferences/goals. It's Christmas soon, after all - consider this my public, unrealistic, idealistic wishlist.

(Edit: And I apologize that my critical comment ranks rather high right now. I might believe that I'm not completely bonkers and there are other people that feel the same way, but it still sucks to see this kind of feedback on an announcement post)

Re: Signal Desktop

#112

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

I just found it unreliably slow. Principles are all good, but if I message my gf saying "see you at the bus stop in 20 minutes" and she doesn't receive the message for 2 hours, that's majorly annoying and it happened so often I had to leave it. The basic functionality isn't fit for purpose, for me.

are you sure it's Signal? cause i have this problem with my husband too, but it happens with Hangouts as well as with Signal. my best guess is that his android phone, a cheaper LG model, has limited resources and puts some services to sleep...

Re: Signal Desktop

#113

Earlier quoted context omitted.

> 1. Simple encryption for everyone to prevent mass data collection Google might be the second biggest mass data collector, after the U.S. government. Using Chrome, one of Google's tools of collection (if I understand correctly), wouldn't seem to further that goal.

Can you articulate a _specific_ threat model under which this extension fails to protect against mass data collection by Google? Or is this idle speculation.

Google adds Google Analytics to their browser, to automatically report what a user does in Chrome apps, and "accidentally" your whole chat history ends up on Google’s servers?

This is not an unrealistic example.

Re: Signal Desktop

#114

Earlier quoted context omitted.

True. Although, I don't understand why it has to be a Chrome app. Why not just a NW.js app? Maybe for the whole "connect with your phone" functionality? Perhaps somebody could shed some light on this?

My guess is it uses Chrome's Native Client [1] for crypto. It's understandable why they might want to do this at this point in time, because the only other way to use native code for crypto in the browser is through the the Web Crypto API [2], which is still very young and implementations aren't very consistent across browsers yet anyways. [1] https://developer.chrome.com/native-client [2] http://www.w3.org/TR/WebCry…

So, effectively, they use native code anyway, but make debugging worse for users?

Great...

Re: Signal Desktop

#115
post #18
post #10

All good with the Android, but disappointed this is Chrome. You would think they would have a FF plugin by now!

It's easier to build Chrome apps, and they are also more secure. It's one of the reasons Mozilla is trying to move away from the add-on model and adopt WebExtensions. When it does that we should start seeing Chrome/Firefox apps appear likely at the same time. It's why I hope Mozilla dismisses the backlash against the switch because some people can't live without their "deep" themes.

It’s not just "deep themes".

What if I want thumbnails of tabs on hover?

What if I want the browser UI to be colored in the theme color of the current webpage (similar to chrome mobile)?

I can do that today with FF.

I can’t do that with WebExtensions.

Re: Signal Desktop

#116
post #84

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

If we were going to rank our priorities, they would be in this order: 1) Make mass surveillance impossible. 2) Stop targeted attacks against crypto nerds. It's not that we don't find #2 laudable, but optimizing for #1 takes precedence when we're making decisions. If you don't want to use your phone number, don't use it. You can register with any GV, Twilio, Voicepulse, or other throwaway VoIP number. If you don't wan…

What is GcmCore? It doesn't show up on ddg or google.

Re: Signal Desktop

#117
post #15
post #5

Earlier quoted context omitted.

I found myself thinking "WFT - this is Chrome, not desktop and with an Android dependency at that !" and then realizing that it may be time to question my assumptions about "desktop" meaning Linux/Windows/Macintosh

In this case "Chrome-only" means Windows, Mac, and Linux support.

No, it means "Support for people on Windows, Mac and x64 Linux who installed spyware".

Re: Signal Desktop

#118
post #112

Earlier quoted context omitted.

I just found it unreliably slow. Principles are all good, but if I message my gf saying "see you at the bus stop in 20 minutes" and she doesn't receive the message for 2 hours, that's majorly annoying and it happened so often I had to leave it. The basic functionality isn't fit for purpose, for me.

are you sure it's Signal? cause i have this problem with my husband too, but it happens with Hangouts as well as with Signal. my best guess is that his android phone, a cheaper LG model, has limited resources and puts some services to sleep...

Yes, because it happens on recent hardware (a 6s) and other messaging systems don't seem to have this issue at all under the same conditions.

Most of the time it would work fine, but quite frequently messages would be sent (have left my device) but not appear on the receiving device for ages, so i can only assume that sometimes the infra couldn't keep up.

Re: Signal Desktop

#119

Earlier quoted context omitted.

As much as I agree with your overall sentiment, the sad truth is that centralized architectures enable many of the UX affordances that users take for granted today in a modern chat app, many of which are much more difficult, sometimes simply impossible, to implement in a decentralized architecture (think features like automatic contact discovery, offline messaging, etc). Without some of these affordances, a chat app…

What kind of things are impossible?

Impossible is a strong word - one prefers to reserve that for provably doomed problems like DRM - but several common, simple paradigms do present an unexpected technical challenge, or even an open research problem, or need to be expressed slightly differently to be practical, in a distributed, privacy-preserving, untrusted-server kind of model.

For example, paraphrasing quite a lot - uniqueness of names requires ordering; ordering probably requires consensus; consensus has a Sybil problem for which some kind of countermeasure is needed. So a namespacing problem that seems simple, and is simple in a centralised/trusted context, may only be practical to solve with a blockchain-like structure with a computationally-heavy proof-of-work in a distributed trust architecture. Even that may still be vulnerable to attacks from someone who can outcompute the rest of the network: and a Nation State Adversary (as a friend snarkily puts it) may actually have enough budget to try that. There may be another way, but maybe not another way that satisfies all the security requirements or that would survive an attack. And there are still other niches you need to worry about, like homoglyph attacks.

That's a long way to go just to make sure that there aren't two ~bobs! So you end up thinking, maybe it's better to find another way that ~alice knows she's talking to the right ~bob? Then you have rephrased your security problem as more of a UX problem: how do I try to avoid impersonation? - which is perhaps more practical to solve another way. [Edit: Also, now your users won't have to fight over who gets to take ~bob first. This may or may not be an advantage, depending on how you feel about username exclusivity.]

It's going to require a lot of hard work to solve this type of problem comprehensively; in the meantime, Signal does more or less the best we can do practically right now, and there's a lot of value in a practical solution that's best-in-class, works and millions of people can just pick up and use now.

Re: Signal Desktop

#120
post #84

Earlier quoted context omitted.

If we were going to rank our priorities, they would be in this order: 1) Make mass surveillance impossible. 2) Stop targeted attacks against crypto nerds. It's not that we don't find #2 laudable, but optimizing for #1 takes precedence when we're making decisions. If you don't want to use your phone number, don't use it. You can register with any GV, Twilio, Voicepulse, or other throwaway VoIP number. If you don't wan…

What is GcmCore? It doesn't show up on ddg or google.

It's probably this http://o9i.de/2015/10/23/howto-gmscore.html
Post reply on HN