Live data from Hacker News

Signal and Giphy

whispersystems.org

51–60 of 125 posts

Re: Signal and Giphy

#51

Is there a federated and/or self-hosted alternative to Signal with similar privacy and security properties? Even if it supports fewer platforms? I've been getting more and more interested in running my own (and perhaps my friends') infrastructure, but I haven't found anything better than IRC for chat.

> "but I haven't found anything better than IRC for chat" If IRC was your best bet so far, you might want to have a look at good ol' XMPP aka Jabber. If you're into Android, with Conversations [0] there's a suitable client which supports end-to-end encryption. For other OS there are many other choices with different encryption options. While OTR (Off-The-Record Messaging) might be the most popular one, it unfortunate…

Conversations is one of the highest-quality apps I've ever used. Buy it!

It's XMPP with everything you'd expect. Inline image, videos, presence, everything.

(if you cannot buy it, you can get it for free from FDroid but really, buy it!)

Re: Signal and Giphy

#52
post #3
post #2

This is a clever way to do this, but it still seems like someone caring about their privacy should just do without gifs. Edit: I should rephrase - I mean someone with a larger-than-usual need for privacy, someone paranoid for a reason. This is great for the typical privacy concious user. But if I was sending documents to WikiLeaks, I would not sum them up with a cute GIF.

Why should those of us who care about privacy be required to limit the media we use to express ourselves? By including this functionality Open Whisper Systems is giving the privacy conscious a way (albeit experimental) to have our cake and eat it too.

Someone else made that media. They're the one expressing something. You, the consumer of that media, are just a distributor of their work.

Re: Signal and Giphy

#53
post #18

Earlier quoted context omitted.

EDIT: Deleted the comment because the of attacks in responses, which I can’t respond to due to "Submitting too fast". @dang: If you want users to be able to actually discuss things, allow them to respond to comments attacking them. This is a retarded system.

You keep repeating untrue claims in every thread about Signal, despite having been proven wrong before. At this point, I'll just have to assume that you're not interested in having a factual discussion. See, for example, https://news.ycombinator.com/item?id=12689390 and its descendant posts.

Ah? Which of the claims is untrue then?

Moxie originally said federation and forked clients would be possible in the future.

Also, Signal does allow you the same rights for the client that WhatsApp does – you can take it apart, modify it for yourself, but you can’t distribute the modification while still having it connect to the same servers as the official one.

Please tell me which of my claims is wrong.

EDIT: Can the "you are submitting too fast" at least not apply to answering children of own comments? Otherwise it ends up with attacks and claims that one can’t respond to.

Re: Signal and Giphy

#54
post #2

This is a clever way to do this, but it still seems like someone caring about their privacy should just do without gifs. Edit: I should rephrase - I mean someone with a larger-than-usual need for privacy, someone paranoid for a reason. This is great for the typical privacy concious user. But if I was sending documents to WikiLeaks, I would not sum them up with a cute GIF.

https://twitter.com/isislovecruft/status/793796012506750977 "Lol dude, I don't know what kind of whistleblowers, dissidents, spies, and revolutionaries you're messaging but mine send all the best gifs."

So, I am an "HN bro" now... Because I don't think this feature can possibly be up to the highest standards of security, despite being very cool and clever? I guess there are worse things to be called.

Re: Signal and Giphy

#55

Good They know that for a bigger adoption they need those usability improvements, at the same time, they make sure additional features don't compromise the security expected from their app

I've been really impressed with Open Whisper's focus on usability and functionality. So many privacy products take the stance of "if you care about privacy, you won't want to do this", and it seriously harms uptake.

Re: Signal and Giphy

#56
post #20

Earlier quoted context omitted.

History shows us that you can't compete by being a lesser version of something else. There's nothing wrong with trying to make the application more attractive, but at the same time trying to shoehorn in features rather than doing things where you have an advantage is less likely to be meaningful.

Surely missing features would make it the "lesser version of something else."

A feature like this doesn't really matter in the context of competing with mainstream messaging services because their value is to a large extent in things like brand and network effect. The notion that you're just one feature away from mainstream adaptation is often a misconception. In reality there's limited potential in living in the shadow of something else.

Re: Signal and Giphy

#57
post #31

Earlier quoted context omitted.

But you can determine that nobody at signal has used or even seen an android phone.

What? Signal/OWS seems to develop new features on Android first, and that animation up top is an Android phone...

It's not an Android phone. Android has either on screen Navigation Bar or Physical Navigation Bar not both.

Re: Signal and Giphy

#58

> The GIPHY service could use subtleties like TLS session resume or cache hits to try to correlate multiple requests as having come from the same client, even if they don't know the origin. How would a cache hit mean same user tried to search? TLS session resume, I can understand but cache hit only means same resource was accessed not same user tried to access.

You cache a unique ID and then see if you get a hit.

Which unique id? I thought the point of sending it via Signal was to not include any user id or any other id.

Re: Signal and Giphy

#59

> The GIPHY service could use subtleties like TLS session resume or cache hits to try to correlate multiple requests as having come from the same client, even if they don't know the origin. How would a cache hit mean same user tried to search? TLS session resume, I can understand but cache hit only means same resource was accessed not same user tried to access.

Presumably the clients cache GIFs, maybe even search results, instead of re-fetching them every single time.

Re: Signal and Giphy

#60
It makes me sad so see that they waste time on decoration like gif search but they don't have a client I can use on my PC for example.
Post reply on HN