Live data from Hacker News

Signal and Giphy

whispersystems.org

41–50 of 125 posts

Re: Signal and Giphy

#41
post #21
post #13

Earlier quoted context omitted.

It clutters the UI with unecessary stuff. Wire also provides such a misfeature. I would rather disable it, but cannot.

You have to specifically click a button to use it. That's a good compromise between jumping through hoops to enable it if opt-in.

I think it would be acceptable if these types of things were on by default, and have the option to disable it or opt-out.

Re: Signal and Giphy

#42

Is there a federated and/or self-hosted alternative to Signal with similar privacy and security properties? Even if it supports fewer platforms? I've been getting more and more interested in running my own (and perhaps my friends') infrastructure, but I haven't found anything better than IRC for chat.

I run a Synapse server ( http://matrix.org/ ) which is federated and works very well. There are many clients but the nicest at the moment is Riot. Full encryption is now available in the Riot webclient and it's coming to the app soon.

Came in to suggest Matrix and its client http://riot.im. Otherwise XMPP with http://conversations.im is also a great option.

Re: Signal and Giphy

#43

Still no desktop client?

The desktop app is available since almost 1 year (in closed beta at the beginning), and recently apparently it's also working with iOS https://whispersystems.org/blog/signal-desktop/ It's also a real app[1], independent from the phone's: after the initial key exchange, you can send/receive messages even when your phone is off [1] Compare with the Whatsapp webapp, which solves/sidesteps the E2E encryption among multip…

Are you kidding me? Do you consider this Chrome extension as a 'real app' (sic!)?

I won't install Chrome just to host Signal extension.

Re: Signal and Giphy

#44
post #2

This is a clever way to do this, but it still seems like someone caring about their privacy should just do without gifs. Edit: I should rephrase - I mean someone with a larger-than-usual need for privacy, someone paranoid for a reason. This is great for the typical privacy concious user. But if I was sending documents to WikiLeaks, I would not sum them up with a cute GIF.

https://twitter.com/isislovecruft/status/793796012506750977

"Lol dude, I don't know what kind of whistleblowers, dissidents, spies, and revolutionaries you're messaging but mine send all the best gifs."

Re: Signal and Giphy

#45
post #3
post #2

This is a clever way to do this, but it still seems like someone caring about their privacy should just do without gifs. Edit: I should rephrase - I mean someone with a larger-than-usual need for privacy, someone paranoid for a reason. This is great for the typical privacy concious user. But if I was sending documents to WikiLeaks, I would not sum them up with a cute GIF.

Why should those of us who care about privacy be required to limit the media we use to express ourselves? By including this functionality Open Whisper Systems is giving the privacy conscious a way (albeit experimental) to have our cake and eat it too.

I also think it's fine as long as they clearly communicate to the user that their search queries will be transmitted to a server not controlled by OWS.

Re: Signal and Giphy

#46
post #20

Earlier quoted context omitted.

Except that history has shown us that theoretically secure but feature deficient systems lose out to less ideologically pure systems that provide what users want, leaving the sum total amount of security provided to be less.

History shows us that you can't compete by being a lesser version of something else. There's nothing wrong with trying to make the application more attractive, but at the same time trying to shoehorn in features rather than doing things where you have an advantage is less likely to be meaningful.

Surely missing features would make it the "lesser version of something else."

Re: Signal and Giphy

#47

> The GIPHY service could use subtleties like TLS session resume or cache hits to try to correlate multiple requests as having come from the same client, even if they don't know the origin. How would a cache hit mean same user tried to search? TLS session resume, I can understand but cache hit only means same resource was accessed not same user tried to access.

You cache a unique ID and then see if you get a hit.

Re: Signal and Giphy

#48
post #18

Earlier quoted context omitted.

EDIT: Deleted the comment because the of attacks in responses, which I can’t respond to due to "Submitting too fast". @dang: If you want users to be able to actually discuss things, allow them to respond to comments attacking them. This is a retarded system.

You keep repeating untrue claims in every thread about Signal, despite having been proven wrong before. At this point, I'll just have to assume that you're not interested in having a factual discussion. See, for example, https://news.ycombinator.com/item?id=12689390 and its descendant posts.

Ah? Which of the claims is untrue then?

Moxie originally said federation and forked clients would be possible in the future.

Also, Signal does allow you the same rights for the client that WhatsApp does – you can take it apart, modify it for yourself, but you can’t distribute the modification while still having it connect to the same servers as the official one.

Please tell me which of my claims is wrong.

EDIT: Using a second account because otherwise I wouldn’t be able to answer within of a few hours, and by then this discussion would be over.

Re: Signal and Giphy

#49
post #31
post #24

Earlier quoted context omitted.

Empirically, absolutely nothing. You can't judge the security of a software based on its marketing material.

But you can determine that nobody at signal has used or even seen an android phone.

What? Signal/OWS seems to develop new features on Android first, and that animation up top is an Android phone...

Re: Signal and Giphy

#50
post #22
post #18

Earlier quoted context omitted.

EDIT: Deleted the comment because the of attacks in responses, which I can’t respond to due to "Submitting too fast". @dang: If you want users to be able to actually discuss things, allow them to respond to comments attacking them. This is a retarded system.

Basically everything in your comment is wrong. > The prebuilt Signal APK might in fact be completely malicious, you can’t verify anything. https://whispersystems.org/blog/reproducible-android/ This is already more then for all other options. > And as Signal only tries to copy the features WhatsApp and co already have Thats simply not true. WhatsApp does not support gifs, for example. Signal also has some features tha…

> Thats simply not true. WhatsApp does not support gifs, for example. Signal also has some features that others don't.

Those are the most minor features. Most competitors have the exact same set of features.

> Telegram is less secure by miles. Threema is less secure by yards. WhatApp is less secure by inches.

With Signal, Telegram, WhatsApp, and Threema I have to trust their servers, but can verify the client is secure by reading source or reversing it.

In neither case can I fork the client to make it more secure, and distribute that fork, while keeping the ability to communicate with users of the official client.

> Signal has never claimed that you can "federate" the server.

They claimed it would be possible in the future, and I – and many others – only switched to it because of that promise. Because we saw it as something with as much security and customisability as XMPP with OMEMO, but a nicer client.

What niche does Signal fill that isn’t already filled by others? It has only minor feature advantages over competitors, and no trust or security advantages.

EDIT: Using a second account because otherwise I wouldn’t be able to answer within of a few hours ("You are submitting too fast"...), and by then this discussion would be over.

Post reply on HN