Live data from Hacker News

Signal Desktop

whispersystems.org

241–250 of 288 posts

Re: Signal Desktop

#241

Earlier quoted context omitted.

> "As far as we can determine, practical privacy preserving contact discovery remains an unsolved problem." This reminds me of an idea I had which I would love for people to tear apart (I know that the obvious bandwidth problem makes it completely impractical, but I wonder if there are theoretical flaws): Have a central server which everybody connects to. All clients send a constant stream of data, 24/7 - if they don…

You don't even need a central server for that. Just set up a p2p network and have all peers broadcast their messages (¶) to everyone they're connected to. Those peers in turn forward everything they receive to everyone they are connected to and so on. (And, of course, they try to decrypt everything in the meantime to see if any message is meant for them.) (¶) I think you could do without sending random data unless ne…

>broadcast their messages (¶) to everyone they're connected to. Those peers in turn forward everything they receive to everyone they are connected to and so on.

That sounds like a great way to DDoS everyone using it and every network in between.

Re: Signal Desktop

#242
post #127

Earlier quoted context omitted.

That's a pretty big holiday wishlist. =) This is the world we live in: people do most of their communication on mobile devices running iOS or Android, use Chrome on the desktop, and expect contact discovery to be automatic in their social apps. The browser has won the desktop, iOS and Android have won mobile, and the velocity of the ecosystem is unlikely to make "distributed" communication mechanisms possible for som…

If we ever meet I'll buy you a beer for the year of the Linux desktop line. But honestly: I understand mobile support for iOS/Android only. I don't understand Chrome as a platform (FF isn't dead. And the biggest reason for that is that I fail to understand why that client needs to be 'web based' and then again not. A web app in a silo) Mobile numbers.. Why? I mean, if 90% of the population WANT mum to see that they u…

> FF isn't dead

From http://www.computerworld.com/article/2893514/an-incredibly-s...:

> In the last 12 months, Firefox's user share -- an estimate of the portion of all those who reach the Internet via a desktop browser -- has plummeted by 34%. Since Firefox crested at 25.1% in April 2010, Firefox has lost 13.5 percentage points, or 54% of its peak share.

I love Firefox, but having used FxOS and mobile versions of Mobile Firefox, the Mozilla Foundations new products feel like the Netscape 6 / Mozilla Browser Firefox was created to replace, rather than the lightweight, user focused alternative.

Re: Signal Desktop

#243
post #25

I don't understand why it prompts me to invite other people after putting me in line. Why would I email/tweet my friends to join this service if it isn't even ready for me? Seems rude to bother a friend with joining an internet line just so that I can get a better position in the line. I love signal on android and have been looking forward to this, kind of rubs me the wrong way when I'm put in "line"

I think it might be related to a restriction google groups has (https://twitter.com/liliakai/status/672219521654980608) "Waiting for Signal Desktop beta access? Know any googlers who can lift the 100-person daily limit on google group invites?"

Re: Signal Desktop

#244
post #210

Earlier quoted context omitted.

"most people" in "the world we live in" are completely hopeless. You won't get to them until you sink completely to the level of the services you are trying to replace. So you won't help people who can be helped because you're trying so hard to get to the people who just can't be. By the way - the biggest problem with textsecure^Wsignal right now is the lack of encrypted export and import of the private key. Forget t…

I would argue that the removal of SMS encryption is a worse failing. Accepting all key changes without question renders you vulnerable to active attacks, but you remain safe from mere passive collection (the most common case). On the other hand, whatever Whisper Systems would have you believe, people really do still use SMS. A lot. I will never convince my friends to use an internet-based messenger - I might as well…

Why do your friends care about the underlying transport?

I too think SMS transport should have been maintained, but I believe it only really matters when you're stuck without mobile data access (for example, when I was on a cruise ship earlier this year I had roaming SMS/voice but not data).

As long as you _do_ have mobile data access at both ends, then a message to another TextSecure user will be sent encrypted over the data connection; and a message to a non-TextSecure user wouldn't have been encrypted anyhow.

Re: Signal Desktop

#245

Earlier quoted context omitted.

EDIT: I apologise, I'm wrong. It appears github has been updated to remove this warning. and as it pretty says on github, the github repo is confiugred to connect to the development server. So yea, trying to jump the queue by installing the dev blob from github won't work.

I made it working: 1. Clone the Signal-Desktop Repo 2. Edit the File: "js/background.js" Line 56 SERVER_URL to ' https://textsecure-service.whispersystems.org' and Line 57 ATTACHMENT_SERVER_URL to ' https://whispersystems-textsecure-attachments.s3.amazonaws.c... and save it 3. Open chrome://extensions/ 4. Activate Developer mode 5. Click "Load unpacked extension..." and select the Signal-Desktop directory 6. Open htt…

> and accept the cert

... sigh... Trusted encryption fail.

Is there some way to verify this cert?

Re: Signal Desktop

#246

Earlier quoted context omitted.

This is my question exactly. What features does Chrome have that are worth making the app completely incompatible with other browsers? Why is it not just a "Web app" and it's a "Chrome app" instead?

Similar to Firefox extensions, Chrome has "apps" and "extensions". Both are locally-saved packages of locally-run JS/HTML/CSS, differing in what capabilities they have w.r.t. chrome api access.

So... I think the question still stands.

Re: Signal Desktop

#247

I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…

I feel the same but in a bit other way. They tied up everything very closely to google services and they tell me "we really care about your privacy so use our app that requires google play frameworks on your android device". Those are two completely different things, use gapps or opensystem apps? It's 100% no-go for me and the whole idea seems to be a bit sarcastic for me. It hurt me when they removed content encryption from TextSecure because "NSA cares about metadata not content", yea, but European agencies like GCHQ care about content not meta-data.

Re: Signal Desktop

#248
post #242

Earlier quoted context omitted.

If we ever meet I'll buy you a beer for the year of the Linux desktop line. But honestly: I understand mobile support for iOS/Android only. I don't understand Chrome as a platform (FF isn't dead. And the biggest reason for that is that I fail to understand why that client needs to be 'web based' and then again not. A web app in a silo) Mobile numbers.. Why? I mean, if 90% of the population WANT mum to see that they u…

> FF isn't dead From http://www.computerworld.com/article/2893514/an-incredibly-s... : > In the last 12 months, Firefox's user share -- an estimate of the portion of all those who reach the Internet via a desktop browser -- has plummeted by 34%. Since Firefox crested at 25.1% in April 2010, Firefox has lost 13.5 percentage points, or 54% of its peak share. I love Firefox, but having used FxOS and mobile versions of M…

Chrome is not any better at all. Speedwise they're about the same, but Chrome has better separation between tabs. However it allocates ram like there is an infinite supply of it, and it absolutely kills the battery on my computer. This is with the same extensions installed in both browsers, uBlock Origin, Privacy Badger, No Script, Last Pass, and Wunderlist.

Re: Signal Desktop

#249
post #127

Earlier quoted context omitted.

Thank you for your reply. I really appreciate it. As I stated earlier, I feel bad about 'expecting more' here - I certainly see the appeal of a popular ~decent~ option. Without trying to derail this further, let me look at those points: If I use throwaway numbers: What happens if I lose access? Do I _need_ the number for anything in the future (say, device died)? Can someone else mess with me if they get access to th…

That's a pretty big holiday wishlist. =) This is the world we live in: people do most of their communication on mobile devices running iOS or Android, use Chrome on the desktop, and expect contact discovery to be automatic in their social apps. The browser has won the desktop, iOS and Android have won mobile, and the velocity of the ecosystem is unlikely to make "distributed" communication mechanisms possible for som…

I don't really know anybody who uses "Chrome apps", technical or non-technical. I agree that was an odd choice, and will probably exclude a lot of people.

It's also odd to me that privacy advocates would push people to Google's ecosystem.

I hope one day there will be Windows and Mac apps. And that instead of phone numbers, we can use email addresses.

Re: Signal Desktop

#250

Earlier quoted context omitted.

Perhaps Signal just isn't for you. No one who I've introduced signal to has ever had a problem with it. Now if you add a randomly generated 128 bit account identifier, then people WILL have problems with it. Not with you, but with your mum/grandma. I really think Signal might not be for you. Signal is not about building the most secure or private system, it's about building the first mass-market encrypted that that's…

Non-technical people I've introduced to Signal on iOS stop at the "upload your contacts" stage and go "I don't want this random little company to have access to my contacts". These are non-technical people who understand the importance of keeping their contact list private, and there are a lot of them. Making it a de facto requirement that users on your network be personally identified via a phone number ("get a burn…

> These are non-technical people who understand the importance of keeping their contact list private

Do you take this opportunity to point out to them that they do away with this privacy every time they install whatsapp / fb messenger / hangouts / skype / practically anything that asks for contacts permissions?

Post reply on HN