Live data from Hacker News

Signal and Giphy

whispersystems.org

11–20 of 125 posts

Re: Signal and Giphy

#11
post #7

It would be interesting for services to publish a public encryption key, so the signal client could encrypt the payload with that. However, that has very limited usefulness, so I don't see it happening soon.

That's more or less what TLS+pinning does. Also DNSSEC+DANE+TLS if you want to argue about that.

Re: Signal and Giphy

#12
post #9

"For instance, if someone messages you with an invitation, you might want to write back with a message that says "I'm excited." With integrated GIF search, you could instead do a GIF search for "I'm excited" and send one of the results instead." What? Why? Is it some kind of attempt to become a new "cool" app? Sounds totally useless function to me, but if it helps to get more users, well, maybe that's a good thing.

[deleted]

Re: Signal and Giphy

#13
post #9

"For instance, if someone messages you with an invitation, you might want to write back with a message that says "I'm excited." With integrated GIF search, you could instead do a GIF search for "I'm excited" and send one of the results instead." What? Why? Is it some kind of attempt to become a new "cool" app? Sounds totally useless function to me, but if it helps to get more users, well, maybe that's a good thing.

Why? Because lots of people like sending gifs and prefer to use messaging apps that support them. If it's totally useless to you then fine: don't use it.

It clutters the UI with unecessary stuff. Wire also provides such a misfeature. I would rather disable it, but cannot.

Re: Signal and Giphy

#14
post #2

This is a clever way to do this, but it still seems like someone caring about their privacy should just do without gifs. Edit: I should rephrase - I mean someone with a larger-than-usual need for privacy, someone paranoid for a reason. This is great for the typical privacy concious user. But if I was sending documents to WikiLeaks, I would not sum them up with a cute GIF.

[deleted]

Re: Signal and Giphy

#16
post #11
post #7

It would be interesting for services to publish a public encryption key, so the signal client could encrypt the payload with that. However, that has very limited usefulness, so I don't see it happening soon.

That's more or less what TLS+pinning does. Also DNSSEC+DANE+TLS if you want to argue about that.

Yes, but it's done at a lower level, which enables a host of attacks, like the announcement says. What I'm talking about would just encrypt the payload, so none of the metadata would be encrypted (and thus preserved).

Although I guess you'd also need to specify a "reply" public key in the encrypted data, so this is becomes more of a protocol.

Re: Signal and Giphy

#18
post #2

This is a clever way to do this, but it still seems like someone caring about their privacy should just do without gifs. Edit: I should rephrase - I mean someone with a larger-than-usual need for privacy, someone paranoid for a reason. This is great for the typical privacy concious user. But if I was sending documents to WikiLeaks, I would not sum them up with a cute GIF.

Except that history has shown us that theoretically secure but feature deficient systems lose out to less ideologically pure systems that provide what users want, leaving the sum total amount of security provided to be less.

EDIT: Deleted the comment because the of attacks in responses, which I can’t respond to due to "Submitting too fast".

@dang: If you want users to be able to actually discuss things, allow them to respond to comments attacking them. This is a retarded system.

Re: Signal and Giphy

#20
post #2

This is a clever way to do this, but it still seems like someone caring about their privacy should just do without gifs. Edit: I should rephrase - I mean someone with a larger-than-usual need for privacy, someone paranoid for a reason. This is great for the typical privacy concious user. But if I was sending documents to WikiLeaks, I would not sum them up with a cute GIF.

Except that history has shown us that theoretically secure but feature deficient systems lose out to less ideologically pure systems that provide what users want, leaving the sum total amount of security provided to be less.

History shows us that you can't compete by being a lesser version of something else. There's nothing wrong with trying to make the application more attractive, but at the same time trying to shoehorn in features rather than doing things where you have an advantage is less likely to be meaningful.
Post reply on HN