Live data from Hacker News

Signal Desktop

whispersystems.org

141–150 of 288 posts

Re: Signal Desktop

#141

Earlier quoted context omitted.

Can you articulate a _specific_ threat model under which this extension fails to protect against mass data collection by Google? Or is this idle speculation.

Google adds Google Analytics to their browser, to automatically report what a user does in Chrome apps, and "accidentally" your whole chat history ends up on Google’s servers? This is not an unrealistic example.

last time I checked Google Analytics doesn't record anything like that kind of data.

Re: Signal Desktop

#142

Earlier quoted context omitted.

It's one device to one device (as stated elsewhere in this thread. Apparently, only Android+Chrome combo is supported for multi-device). Put differently, I can't register the same number to an iPad and iPhone simultaneously at this time and hope to communicate with someone. It apparently gets things all confused. I was doing some more testing and it also appears that I'm unable to call someone with a greyed out name…

Oh I see. That is indeed annoying. So I guess this bit from the desktop announcement is a stretch: "....all incoming and outgoing messages are displayed consistently on all your devices." I mean I guess if you ONLY have one phone and a desktop that would be true? And I guess if Signal only allows you to register those two things, it is TECHNICALLY true, in the sense that "all" <= 2

And all = Android + Chrome (at least for now).

Since I'm not an Android user, I'm unable to confirm all > 2 scenarios. Someone should try and report back.

Re: Signal Desktop

#143
post #127

Earlier quoted context omitted.

That's a pretty big holiday wishlist. =) This is the world we live in: people do most of their communication on mobile devices running iOS or Android, use Chrome on the desktop, and expect contact discovery to be automatic in their social apps. The browser has won the desktop, iOS and Android have won mobile, and the velocity of the ecosystem is unlikely to make "distributed" communication mechanisms possible for som…

If we ever meet I'll buy you a beer for the year of the Linux desktop line. But honestly: I understand mobile support for iOS/Android only. I don't understand Chrome as a platform (FF isn't dead. And the biggest reason for that is that I fail to understand why that client needs to be 'web based' and then again not. A web app in a silo) Mobile numbers.. Why? I mean, if 90% of the population WANT mum to see that they u…

[deleted]

Re: Signal Desktop

#144
This is slightly off-topic, but I hope moxie (or an employee of WhisperSystems - nothing official needed) wouldn't mind chiming in:

Since I loved the fact that I can run my own TextSecure server, I'm wondering why Signal does not run a similar model?

I'm curious which considerations went into this decision.

Re: Signal Desktop

#145
post #141

Earlier quoted context omitted.

Google adds Google Analytics to their browser, to automatically report what a user does in Chrome apps, and "accidentally" your whole chat history ends up on Google’s servers? This is not an unrealistic example.

last time I checked Google Analytics doesn't record anything like that kind of data.

It records where you click, and when.

"Accidentally" logging keys is possible, as Google can modify the content of the JS on request – for example, in case of being served an NSL, Google can be forced to modify the JS to log that.

Re: Signal Desktop

#146
post #70
post #69

Earlier quoted context omitted.

> go out of your way to use Signal With that mindset we will never get secure communications to the masses but will repeat the PGP dilemma again and again. UX is of utmost importance. We would still be on 99.99% HTTP websites if HTTPS required going out of one's way.

That's what the Cryptocat people said.

Is it? It is also what Edward Snowden said.

Re: Signal Desktop

#147
post #51

I'm assuming this works similarly to WhatsApp Web ( https://web.whatsapp.com/ )

And actually, earlier this year, WhatsApp started using the encrpytion protocol developed by the signal folks (Axolotl) to encrypt message data, Which is super cool. (I think group chats and images are still not encrypted, or something) I wonder if in the future Signal will focus on integrating their encryption into other existing chat systems like Facebook messenger, and put the Signal apps on the backburner.

The problem I have is when these systems don't indicate whether their session or secure or not. Last time I checked, WhatsApp still didn't have it. This is especially problematic when the system has exceptions like the ones you've described. (Group chats, images, etc.)

Services like LINE also bragged about their secure chat feature, too [0] but honestly, without an active indication of whether their session is secured or not, it's fairly useless and I don't really like this "hide the complicated stuff" attitude that those services seems to be going toward...

[0]: http://developers.linecorp.com/blog/?p=3679

Re: Signal Desktop

#148
post #146
post #70

Earlier quoted context omitted.

That's what the Cryptocat people said.

Is it? It is also what Edward Snowden said.

In fact, he may have even said it on Cryptocat; Poitras and Greenwald used it to collaborate with him. Snowden also used Lavabit to send email. Why? Because Lavabit had superior UX to his other options --- because Lavabit handled all the crypto serverside. NSA has presumably read everything he sent on both of those systems. Despite the extreme ease of use both systems boasted, they were both so badly designed that they enabled retroactive decryption.

So I think, if that was an attempt at a rebuttal, it was not a very effective one.

Re: Signal Desktop

#149
Call it what it really is: "Signal Phone Remote". This is not Signal Desktop if you need a non-desktop to use it.

Re: Signal Desktop

#150

Earlier quoted context omitted.

The app is still in beta testing. I think this is their way to drum up support. Forces all the die-hards who want in to try and get some people interested. An app like this is only as useful as the number of people who use it.

Invite them to... not use it? That seems like a solid way to turn people off from using a service, not a way get them excited about it.

I don't feel strongly about the practice either way, but you're also indirectly prioritizing users who are most willing to share the product. So they're hoping their early users are also those most willing to spread. The "connectors" of the products ecosystem.
Post reply on HN