Live data from Hacker News

WhatsApp's Signal Protocol integration is now complete

whispersystems.org

201–210 of 386 posts

Re: WhatsApp's Signal Protocol integration is now complete

#202
post #136
post #114

Is it still the case that verifying a user's text identity does not verify their voice identity and vice versa? IMO it would be very nice if calling someone and verifying the short code would confirm their text identity as well and if, once someone's text identity is verified, if voice calls to that person were protected by the verified text identity. (IIRC the reason that Signal does not work this way is that texts…

WhatsApp uses a shared identity across text and voice, so Signal Protocol is used to secure both connections. We've long planned to do the same thing in Signal, but WhatsApp is ahead of Signal here. Axolotl is now called Signal Protocol, btw.

Speaking of voice calls, are there near-to-medium-term plans to do multi-party voice calls in Signal, or would such calls be too awkward for various reasons?

Re: WhatsApp's Signal Protocol integration is now complete

#204

absolutely no proof it is e2e encrypted without the source.

Can you stop spamming your comment into every single thread? If you have a smart comment post it at the top level.

A smart comment would be a detailed analysis of the pros and cons of OpenSource in terms of verification. Your are barly more then a troll.

Re: WhatsApp's Signal Protocol integration is now complete

#205
post #34
post #20

Earlier quoted context omitted.

> They seem to have replaced TLS/SSL between client and server with "Noise Pipes". WhatsApp was already using a custom protocol instead of TLS. We worked with them to transition over to Noise Pipes, which has some advantages over what they were doing before. Also, we've renamed Axolotl to Signal Protocol: https://whispersystems.org/blog/signal-inside-and-out/

It is killing me that you didn't rename Signal to Axolotl.

If user growth and mainstream adoption are your goals then calling the product 'Signal' is the better choice by leaps and bounds.

Axolotl is cool in a techy/underground sort of way (if your into that) but completely misses the boat on being 1) Easy to spell, 2) easy to pronounce, 3) easy to understand.

Mainstream users would just say "wtf" and move on to whatsapp/telegram/facebook messenger.

Re: WhatsApp's Signal Protocol integration is now complete

#206

This is really excellent. A few thoughts: 1) They seem to have replaced TLS/SSL between client and server with "Noise Pipes". Based on a couple of minutes Googling this seems to be a brand new one-man protocol from Trevor Perrin (the same guy who did Axoltl on which Signal is based). At least, I'd never heard of it. I wonder if this is the first inkling of a post-TLS future? http://noiseprotocol.org/noise.html 2) It'…

Could someone explain the benefit of the noise protocol? Some of us are not well-versed in the problems or attack vectors of modern crypto.

Re: WhatsApp's Signal Protocol integration is now complete

#207
post #20

This is really excellent. A few thoughts: 1) They seem to have replaced TLS/SSL between client and server with "Noise Pipes". Based on a couple of minutes Googling this seems to be a brand new one-man protocol from Trevor Perrin (the same guy who did Axoltl on which Signal is based). At least, I'd never heard of it. I wonder if this is the first inkling of a post-TLS future? http://noiseprotocol.org/noise.html 2) It'…

> They seem to have replaced TLS/SSL between client and server with "Noise Pipes". WhatsApp was already using a custom protocol instead of TLS. We worked with them to transition over to Noise Pipes, which has some advantages over what they were doing before. Also, we've renamed Axolotl to Signal Protocol: https://whispersystems.org/blog/signal-inside-and-out/

What exactly is wrong with TLS? Why the switch?

Re: WhatsApp's Signal Protocol integration is now complete

#208
post #181
post #96

Earlier quoted context omitted.

> From that perspective, I'm still inclined to trust apple's iMessage a bit more especially after recent events. // edit: got my answer here: https://news.ycombinator.com/item?id=11432629 I'm curious, is that because of what they did in the FBI case, or for technical reasons? IIRC iMessage would allow Apple to add public keys which they (or the FBI/$ADVERSARY) control as a sort-of backdoor as well. I can't say that I…

The unfortunate reality too is that average users will never go to the extra trouble of authenticating keys themselves. I'm also more likely to trust a company like Apple or Google with key management than a "trusted third party" (simply because they're bigger companies, with more valuable brands to protect, and resources to throw at the problem). So, it feels like for the average consumer, a product like iMessage ti…

The good thing about verification is that if only a few people do it, it already profieds a benefit.

Re: WhatsApp's Signal Protocol integration is now complete

#209
post #178

Earlier quoted context omitted.

Cool. So FB/WhatsApp can't even decrypt messages themselves?

If they actually do what they say the do, then yes. Thier is no evidence that they are lying, so for now its probebly save to assume that they can not read your messages.

No, it is not safe to assume that. Edward Snowden already proved that we cannot trust large US corporations.
Post reply on HN