Live data from Hacker News

Disappearing messages for Signal

whispersystems.org

61–70 of 187 posts

Re: Disappearing messages for Signal

#61

Earlier quoted context omitted.

Did FB/WA clarify that they use the OW audio encryption algos, or did they just put the OW 'trophy' on the wall without the actual implementation? WhatsApp is, I agree, very good quality for what it is, but I would never trust it or FB with anything but social/personal calls. Social Media platforms are for other people to hand over their lives to. Let them subsidize my detachment from their usage, and I thank them fo…

Looking at WhatsApps security whitepaper: "WhatsApp calls are also end-to-end encrypted When a WhatsApp user initiates a call: 1 The initiator builds an encrypted session with the recipient (as outlined in Section Initiating Session Setup), if one does not already exist 2 The initiator generates a random 32-byte SRTp master secret 3 The initiator transmits an encrypted message to the recipient that signals an incomin…

Forgive me for being a layman in these matters

Are you saying "maybe/maybe not"?

If they seem to be doing something that is "more or less" the same then my radar is triggered for them not actually declaring they are delivering totally encrypted (ie no backdoor tomfoolery) voice calls.

Re: Disappearing messages for Signal

#62
post #58
post #50

Now if they would drop the ridiculous requirement of having a phone number and go with usernames and not require access to my contact list like most other services, you could actually be safer and not rely on _their word_ alone.

If you really want to be secure, get a disposable prepaid phone and use its phone number with signal.

That is increasingly hard to do these days. Verified addresses etc are now minimum requirements to get the handset.

Of course you can pay cash and make up an address

Re: Disappearing messages for Signal

#63
post #50

Now if they would drop the ridiculous requirement of having a phone number and go with usernames and not require access to my contact list like most other services, you could actually be safer and not rely on _their word_ alone.

Indeed. It's not just crypto nerds would want to use the service without having to have a smartphone with a phone number. The phone requirement is beyond ridiculous. How did Signal get the reputation it enjoys in the tech community anyway?

> How did Signal get the reputation it enjoys in the tech community anyway?

You can thank Edward Snowden for that. In fact, they have his picture and testimonial on their front page:

https://whispersystems.org

Re: Disappearing messages for Signal

#64

Earlier quoted context omitted.

Looking at WhatsApps security whitepaper: "WhatsApp calls are also end-to-end encrypted When a WhatsApp user initiates a call: 1 The initiator builds an encrypted session with the recipient (as outlined in Section Initiating Session Setup), if one does not already exist 2 The initiator generates a random 32-byte SRTp master secret 3 The initiator transmits an encrypted message to the recipient that signals an incomin…

Forgive me for being a layman in these matters Are you saying "maybe/maybe not"? If they seem to be doing something that is "more or less" the same then my radar is triggered for them not actually declaring they are delivering totally encrypted (ie no backdoor tomfoolery) voice calls.

Over the past year, we've been progressively rolling out Signal Protocol support for all WhatsApp communication across all WhatsApp clients. This includes chats, group chats, attachments, voice notes, and voice calls across Android, iPhone, Windows Phone, Nokia S40, Nokia S60, Blackberry, and BB10.

https://www.whispersystems.org/blog/whatsapp-complete/

Re: Disappearing messages for Signal

#65
> They're relatively compact. Users compare 12 groups of 5 digits with each other, which is half the size of our previous hexadecimal format.

60 digits have 199 bits of security, so I suppose that's mostly okay, right? Does the birthday paradox apply here, reducing it to 98 bits?

Re: Disappearing messages for Signal

#67
post #39

I love Signal and this seems to be a stab at Wickr since from what I've heard that is the reason people prefer it to Signal sometimes. Having said that, it has a couple of problems: 1. Images are downsampled without warning. There should be some sort of warning or mini info box for the times when the images are downsampled and there should be information about the changes in resolution. 2. If one uses it as the main…

It'd also be nice if the iOS or Chrome client had a chat history backup feature like they have on android. This is one of my biggest complaint with messaging apps in general. I'd like to be able to preserve and archive my chat history with people close to me.

Re: Disappearing messages for Signal

#68
post #65

> They're relatively compact. Users compare 12 groups of 5 digits with each other, which is half the size of our previous hexadecimal format. 60 digits have 199 bits of security, so I suppose that's mostly okay, right? Does the birthday paradox apply here, reducing it to 98 bits?

No, since you presumably want to match a specific user's key, not just find two users with the same key.

Re: Disappearing messages for Signal

#69

Signal keeps getting better with each release, great job at everyone from Whisper Systems.

I love using Signal and will continue to make modest donations, but I would really appreciate an improvement in audio call quality. I still use Silent Circle for calls because it is so tiring to talk when the bitrate is low.

> I still use Silent Circle for calls because it is so tiring to talk when the bitrate is low.

To be fair, that's a high bar. Our (SC) phone guys are masters at optimizing audio quality. I would be extremely surprised if any other app (encrypted or not) had significantly better audio quality than Silent Phone.

Re: Disappearing messages for Signal

#70
post #52
post #47

Earlier quoted context omitted.

No one is forcing you to use proprietary software. See this comment from moxie https://news.ycombinator.com/item?id=10665520 Using GCM is only a problem for people running a custom Android ROM without Google Play Services. Using GCM doesn't make Signal less private. Google doesn't see any data via gcm, it's just a tickle. If you want push messages, you gotta use a push network. https://twitter.com/whispersystems/stat…

Actually, Moxie has threatened to shut LibreSignal down if they allow LibreSignal users to message normal Signal users, and refused to even discuss alternative solutions. He also uses the GCM library from Google, which pulls in several analytics libraries into the APK, so "Using GCM doesn't make Signal less private." is objectively false. (And in addition to that, Moxie even refuses to allow any distribution that doe…

Downvoting this comment without offering a counterpoint is very bad etiquette. Can someone provide a counterargument? Otherwise it's just pretty much censorship.
Post reply on HN