Live data from Hacker News

Signal Desktop

whispersystems.org

261–270 of 288 posts

Re: Signal Desktop

#261
I love Signal and advocate it wherever possible. After following along on the GitHub tickets for this project, I'm happy to say thank you and congratulations on the beta release folks!

I'm probably about to ask this on the mailing list soon anyway, but in case there is any hidden knowledge here:

1. There was talk of server federation long ago. Is this still part of the long term plan?

2. There was talk of not using a phone number as a required identifier. Is this still part of the long term plan?

Re: Signal Desktop

#262
post #127

Earlier quoted context omitted.

Thank you for your reply. I really appreciate it. As I stated earlier, I feel bad about 'expecting more' here - I certainly see the appeal of a popular ~decent~ option. Without trying to derail this further, let me look at those points: If I use throwaway numbers: What happens if I lose access? Do I _need_ the number for anything in the future (say, device died)? Can someone else mess with me if they get access to th…

That's a pretty big holiday wishlist. =) This is the world we live in: people do most of their communication on mobile devices running iOS or Android, use Chrome on the desktop, and expect contact discovery to be automatic in their social apps. The browser has won the desktop, iOS and Android have won mobile, and the velocity of the ecosystem is unlikely to make "distributed" communication mechanisms possible for som…

Please make it possible to use public keys as identifiers somehow, maybe linked via for example keybase.io to provide simplicity in lookups and tracking usernames.

It would also be much easier to allow federation with that mechanism, as your keybase.io account even could point to your chosen server together with the public key.

Re: Signal Desktop

#263
post #127

Earlier quoted context omitted.

That's a pretty big holiday wishlist. =) This is the world we live in: people do most of their communication on mobile devices running iOS or Android, use Chrome on the desktop, and expect contact discovery to be automatic in their social apps. The browser has won the desktop, iOS and Android have won mobile, and the velocity of the ecosystem is unlikely to make "distributed" communication mechanisms possible for som…

First, congratulations on shipping. Usable E2E encryption is something I care deeply about and Signal is the best Ive ever used. Completely agree fighting mass surveillance for avg users is highest priority. What do you mean by "the velocity of the ecosystem is unlikely to make distributed communication mechanisms possible for some time"?

Ecosystem - tools and services with network effects, like Google Cloud Messaging.

Lots of phone carriers whitelist that server of theirs to allow it to wake up phone unprompted from idle while typically only allowing phone-initiated connection to stay active, and they also tend to block most incoming connections once the phone has been inactive for a while.

While it isn't technically hard to make something distributed, to also make it work well can be troublesome...

Yet another reason I want home servers to become common, as your phone could automatically request that your carrier whitelist your chosen trusted nodes such as your home server.

Re: Signal Desktop

#264
post #140
post #127

Earlier quoted context omitted.

That's a pretty big holiday wishlist. =) This is the world we live in: people do most of their communication on mobile devices running iOS or Android, use Chrome on the desktop, and expect contact discovery to be automatic in their social apps. The browser has won the desktop, iOS and Android have won mobile, and the velocity of the ecosystem is unlikely to make "distributed" communication mechanisms possible for som…

I like the fact that Signal makes good cryptography available to the masses. But I also share the OP concern about Chromium (and about a central server, but this is technically much harder to fix). Perhaps it would be possible to have a simple CLI app that is free from these dependencies (which should also be quite simple to develop).

some signal cli clients were discussed on the mailing list yesterday: https://lists.riseup.net/www/arc/whispersystems/2015-12/msg0...

Re: Signal Desktop

#265
post #50

Why do I need a phone number?

Yeah, this makes Signal a total non-starter for me. It is doing the same thing WhatsApp does: you need a smartphone to use it. Even the desktop version requires a smartphone to create an account.

If privacy is so important for Signal, why forbid using it without a phone number? It makes no sense.

Re: Signal Desktop

#266
post #157
post #127

Earlier quoted context omitted.

That's a pretty big holiday wishlist. =) This is the world we live in: people do most of their communication on mobile devices running iOS or Android, use Chrome on the desktop, and expect contact discovery to be automatic in their social apps. The browser has won the desktop, iOS and Android have won mobile, and the velocity of the ecosystem is unlikely to make "distributed" communication mechanisms possible for som…

The problem of course being that those users that use the closed source Google browser and iOS won't care much about what Signal is offering either. They're already using Hangouts, iMessage and Signal is pretty much a downgrade from those.

nope!

Re: Signal Desktop

#267

Earlier quoted context omitted.

Oldschool Communist revolutionaries, to be exact. Yeah, it's no mystery where Moxie's politics lie given those allusions and the not-a-company company, eat together, do push ups together, open salary policies.

Fortunately for most of the human population, the politics of the author of the software we use isn't really a consideration.

I'm sure most people wouldn't use software created by Nazis. Considering Communism has arguably worse track record, I would definitely avoid any software created by its proponents if it's at all possible.

Re: Signal Desktop

#268
post #244
post #210

Earlier quoted context omitted.

I would argue that the removal of SMS encryption is a worse failing. Accepting all key changes without question renders you vulnerable to active attacks, but you remain safe from mere passive collection (the most common case). On the other hand, whatever Whisper Systems would have you believe, people really do still use SMS. A lot. I will never convince my friends to use an internet-based messenger - I might as well…

Why do your friends care about the underlying transport? I too think SMS transport should have been maintained, but I believe it only really matters when you're stuck without mobile data access (for example, when I was on a cruise ship earlier this year I had roaming SMS/voice but not data). As long as you _do_ have mobile data access at both ends, then a message to another TextSecure user will be sent encrypted over…

I am farting in a thunderstorm, since this argument has been had a million times. Nevertheless, i will explain why i personally worry about the transport. Perhaps the other commenter has different reasons, i don't know.

I currently pay €2 per month for my mobile bill. That is very little money. Notably, that includes no internet/data, but it does include unlimited text messages. Can you see why SMSSecure is something i would want?

Re: Signal Desktop

#269
post #238

Earlier quoted context omitted.

> 1) Make mass surveillance impossible. That's an extremely noble goal, and it seems you've made great progress towards it, but.. Will the US government really just let you do it? Have they not interfered yet? It seems highly unlikely that they wouldn't somehow neutralize the threat your work represents, so I'm just.. cautiously optimistic instead of really excited.

> Will the US government really just let you do it? Have they not interfered yet? Of course they did: the recent propaganda wave against "encryption" is all about preventing the next wave of privacy-conscious communication tools, to which Signal belongs. Smart governments don't have to "interfere": they just have to pass laws.

Making encryption illegal would certainly count as "interference".

Re: Signal Desktop

#270
post #267

Earlier quoted context omitted.

Fortunately for most of the human population, the politics of the author of the software we use isn't really a consideration.

I'm sure most people wouldn't use software created by Nazis. Considering Communism has arguably worse track record, I would definitely avoid any software created by its proponents if it's at all possible.

> I'm sure most people wouldn't use software created by Nazis

Best selling car of all time; star of several (very popular) movies: http://www.bbc.com/culture/story/20130830-the-nazi-car-we-ca...

Post reply on HN