Live data from Hacker News

Signal Desktop

whispersystems.org

201–210 of 288 posts

Re: Signal Desktop

#201

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

They don't like to admit it, but Signal has a metadata problem. It's fine if that's not their threat model, but I wish they would be more clear about it, especially when other chat systems get criticism more often for precisely that aspect. Edit: "As far as we can determine, practical privacy preserving contact discovery remains an unsolved problem." -03 Jan 2014 [0] https://whispersystems.org/blog/contact-discovery/…

Phil Zimmermann gave it a stab:

https://github.com/SilentCircle/contact-discovery

I suggested this to Moxie, he said "it's not meaningfully privacy preserving", but there wasn't any more detail.

Re: Signal Desktop

#202

Earlier quoted context omitted.

So they used bad products because their UX was good. That seems to be grandparent's point?

Secure messaging products with good UX and bad security should wait to launch until they can have good security; the alternative puts people at risk, as it did to Snowden.

They should but they don't. That's why have competitive UX is important for the good tools or people won't even consider using them. We have seen that happen countless times.

Re: Signal Desktop

#203
post #84

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

If we were going to rank our priorities, they would be in this order: 1) Make mass surveillance impossible. 2) Stop targeted attacks against crypto nerds. It's not that we don't find #2 laudable, but optimizing for #1 takes precedence when we're making decisions. If you don't want to use your phone number, don't use it. You can register with any GV, Twilio, Voicepulse, or other throwaway VoIP number. If you don't wan…

Regarding #2, since it's worded somewhat ambiguously, should we read that as wanting to stop targeted attacks in general (I'm thinking specifically of criminal suspects/etc. when a valid warrant exists) or targeted attacks against specific targets (i.e. people being illegitimately targeted like crypto nerds)? As a follow-up, are there any situations in which you think it would be appropriate to give information or the plaintext content of encrypted messages for a specific user to a law enforcement agency?

Re: Signal Desktop

#204

Earlier quoted context omitted.

> I understand mobile support for iOS/Android only. I don't understand Chrome as a platform > Mobile numbers.. Why? Pidgin + OTR works on Linux, and doesn't relate to mobile numbers or Chrome at all. This might be a better fit for you.

I'm aware of that. I used to run an xmpp server and recently switched to Telegram for inter-family conversations (wife, brother, intimate friends) because the xmpp UX story is unfortunately not perfect (you need message carbons, you need stream management and you probably want MAM to have a usable system that can be used on mobiles as well).

This is great news! Such a big fan of the work you guys are doing at Whisper Systems. We are in the middle of an update to Umbrella App (which contains lessons on digital and physical), so will add the latest Signal changes to it in the next few days.

If anyone is interested in taking a look (free, open source, code reviewed, Android) please feel free: https://play.google.com/store/apps/details?id=org.secfirst.u...

Re: Signal Desktop

#205
post #127

Earlier quoted context omitted.

That's a pretty big holiday wishlist. =) This is the world we live in: people do most of their communication on mobile devices running iOS or Android, use Chrome on the desktop, and expect contact discovery to be automatic in their social apps. The browser has won the desktop, iOS and Android have won mobile, and the velocity of the ecosystem is unlikely to make "distributed" communication mechanisms possible for som…

If we ever meet I'll buy you a beer for the year of the Linux desktop line. But honestly: I understand mobile support for iOS/Android only. I don't understand Chrome as a platform (FF isn't dead. And the biggest reason for that is that I fail to understand why that client needs to be 'web based' and then again not. A web app in a silo) Mobile numbers.. Why? I mean, if 90% of the population WANT mum to see that they u…

This is my question exactly. What features does Chrome have that are worth making the app completely incompatible with other browsers? Why is it not just a "Web app" and it's a "Chrome app" instead?

Re: Signal Desktop

#206

Earlier quoted context omitted.

They don't like to admit it, but Signal has a metadata problem. It's fine if that's not their threat model, but I wish they would be more clear about it, especially when other chat systems get criticism more often for precisely that aspect. Edit: "As far as we can determine, practical privacy preserving contact discovery remains an unsolved problem." -03 Jan 2014 [0] https://whispersystems.org/blog/contact-discovery/…

> "As far as we can determine, practical privacy preserving contact discovery remains an unsolved problem." This reminds me of an idea I had which I would love for people to tear apart (I know that the obvious bandwidth problem makes it completely impractical, but I wonder if there are theoretical flaws): Have a central server which everybody connects to. All clients send a constant stream of data, 24/7 - if they don…

/dev/random has a nonzero chance of emitting a valid GPG public-key-encrypted message. How does the server tell the two apart? How do you make sure that an external watcher can't tell them apart?

Re: Signal Desktop

#207
Sadly, as much as I'd like to use Telegram or Signal rather than the usual suspects (sms, whatsapp, facebook messenger), it would require someone on the other end to receive my messages.

The likelihood of convincing my friends/family to use a messaging app that isn't any of the usual suspects is low to none. And none of my bleating about privacy issues will convince them otherwise ("I've got nothing to hide, doesn't bother me").

Re: Signal Desktop

#208
post #138

Earlier quoted context omitted.

I do have an "invite" prompt on my SMS contacts that don't yet have Signal: "Invite to Signal: Take your conversation with %s to the next level.". Perhaps it's a function in the beta version that isn't in the live version yet? I haven't seen a message with a double-tick that's been dropped yet , at least not on a recent version. It can sometimes behave poorly with Android battery-saving mode - however, so does plain…

Surely battery saving modes should not drop messages? It could delay them but should never (well, almost never) drop them.

With no knowledge of how signal's servers actually implement this, I would like to ask you... how long should the central server hold on to the (encrypted) message that Alice sends to Bob if Bob never becomes available again?

Re: Signal Desktop

#209
post #25

I don't understand why it prompts me to invite other people after putting me in line. Why would I email/tweet my friends to join this service if it isn't even ready for me? Seems rude to bother a friend with joining an internet line just so that I can get a better position in the line. I love signal on android and have been looking forward to this, kind of rubs me the wrong way when I'm put in "line"

The app is still in beta testing. I think this is their way to drum up support. Forces all the die-hards who want in to try and get some people interested. An app like this is only as useful as the number of people who use it.

Ya, but it could go the way of Wave by not actually having people use it too.

Re: Signal Desktop

#210
post #127

Earlier quoted context omitted.

That's a pretty big holiday wishlist. =) This is the world we live in: people do most of their communication on mobile devices running iOS or Android, use Chrome on the desktop, and expect contact discovery to be automatic in their social apps. The browser has won the desktop, iOS and Android have won mobile, and the velocity of the ecosystem is unlikely to make "distributed" communication mechanisms possible for som…

"most people" in "the world we live in" are completely hopeless. You won't get to them until you sink completely to the level of the services you are trying to replace. So you won't help people who can be helped because you're trying so hard to get to the people who just can't be. By the way - the biggest problem with textsecure^Wsignal right now is the lack of encrypted export and import of the private key. Forget t…

I would argue that the removal of SMS encryption is a worse failing. Accepting all key changes without question renders you vulnerable to active attacks, but you remain safe from mere passive collection (the most common case). On the other hand, whatever Whisper Systems would have you believe, people really do still use SMS. A lot.

I will never convince my friends to use an internet-based messenger - I might as well try and get them to use Pidgin+OTR if that's the ball game. I have, however, switched a few of them over to SMSSecure, the SMS-only TextSecure fork, which is a perfectly serviceable SMS client.

Post reply on HN