Live data from Hacker News

Worried About the Privacy of Your Messages? Download Signal

nytimes.com

11–20 of 247 posts

Re: Worried About the Privacy of Your Messages? Download Signal

#11

Use Signal and give them access to all your contacts who may or may not be using Signal. Use their proprietary client and trust them on their pinky promise that they "can't" look at your messages. The deceptive pretense of privacy is worse than no privacy at all. [Edit] - "Use their proprietary client and trust them on their pinky promise" was factually wrong. But, they still expect me to trust the signed binary they…

But.. But!

Everyone in the geek press said it's "end to end" encrypted! That must mean it's totally safe! I'm sure everyone is reading the source code and building their own clients all the time, yea? Didn't some uber hacker somewhere with a big beard say that he read all the code and it's totally fucking solid and government proof?

Surely you don't mistrust all that do you... I mean... Your seem a bit dubious. You can't be trying to say that there are people out there who are actually not buying this horseshit, that are genuinely withholding trust in these sort of 'services'?

Blasphemy! You think that there are people out there, with a basic grasp of security and cynicism, might feel offended and depressed at how easy it's been to dupe everyone like this.. Again?

Nah. I'm sure we're all totally sold on signal. Seems legit.

I mean, since all the users of such a service have pretty much zero control/visability over the code that's actually running even on their own devices which is talking to this 'service', let alone what's going on on the servers (in some N.American datacentre, probably super secure...) might raise a few eyebrows, but it doesn't really change the fact that we're talking abiut END TO END encryption that someone said was totally 'secure'. And even the media have pushed a few stories about how evil criminals are using it to evade monitoring..

No, I'm not sure I'm on your side. This is clearly totally secure and no one could possibly abuse this kind of thing..

Right?.... Right?

starts crying and loads the rifle

Re: Worried About the Privacy of Your Messages? Download Signal

#12

Use Signal and give them access to all your contacts who may or may not be using Signal. Use their proprietary client and trust them on their pinky promise that they "can't" look at your messages. The deceptive pretense of privacy is worse than no privacy at all. [Edit] - "Use their proprietary client and trust them on their pinky promise" was factually wrong. But, they still expect me to trust the signed binary they…

It's an open source client[0]. It's not a "pinky promise". There are valid criticisms of Signal (primarily around the use of the Google Play Services Framework), but your comment seems to be jumping to a lot of conclusions without any research. https://github.com/whispersystems

But, they still expect me to trust the signed binary they send through the App store right? How is that anyway non-proprietary just because there is a Git repo somewhere that may or may not be the same code running on your phone? Can I run a client from the Git repo and still use all of their infrastructure?

Until I'm able to do that, it is still their "pinky promise".

Re: Worried About the Privacy of Your Messages? Download Signal

#13

Or you could download https://wire.com/ which allows developers to build their own clients and still use their infrastructure. Also, it doesn't force you to use a phone number for registration. It supports audio/video calls. Also, if you're really privacy minded, it doesn't need Google Play Services. That way it can be used in CopperheadOS.

Do you know how Wire makes money to sustain what they are doing? Don't want to invest my time into something that will eventually sell out and do that opposite of what they stand for today.

Last time i checked they have no revenue possibility. So I decided to skip, I am curious on this too

Re: Worried About the Privacy of Your Messages? Download Signal

#14
All the privacy solutions on the market are varying degrees of bad (from a privacy/security/freedom perspective), by which I mean they're all flawed in their own ways.

Signal requires Google Play Services on Android. That means it's put simply not a privacy messenger. Yes there's crypto, but it's also tied into Whisper Systems' infrastructure, there's no federation. I use Signal reluctantly, and only on IOS.

Threema, which is popular in parts of Europe (and is what I use to an extent) is well established, but not open source, doesn't do voice chat or federation.

Wire is moving in the right direction with respect to being open source and having lots of good features, but is still not open source.

It's 2016 and our best crypto messenger options are worse than what we had 10 years ago when Skype was peer to peer, or Jabber with federation.

I can understand the reasons for not supporting federation, but I disagree. The Internet was built to be decentralised, literally to withstand nuclear war. A walled garden does not provide us with the redundancy or control the Internet offers.

There are other metadata related issues that pretty much every messenger suffers from but I'll leave this out of the scope of this comment.

What Open Whisper Systems and Wire need to do is open source the server components of their solutions, and try to remove the reliance on servers as much as possible. Only then will we have proper message privacy.

Re: Worried About the Privacy of Your Messages? Download Signal

#15

Use Signal and give them access to all your contacts who may or may not be using Signal. Use their proprietary client and trust them on their pinky promise that they "can't" look at your messages. The deceptive pretense of privacy is worse than no privacy at all. [Edit] - "Use their proprietary client and trust them on their pinky promise" was factually wrong. But, they still expect me to trust the signed binary they…

I think as long as they are GPL, you can use the infrastructure.

https://github.com/WhisperSystems/Signal-Android/issues/282

Re: Worried About the Privacy of Your Messages? Download Signal

#16

Earlier quoted context omitted.

It's an open source client[0]. It's not a "pinky promise". There are valid criticisms of Signal (primarily around the use of the Google Play Services Framework), but your comment seems to be jumping to a lot of conclusions without any research. https://github.com/whispersystems

But, they still expect me to trust the signed binary they send through the App store right? How is that anyway non-proprietary just because there is a Git repo somewhere that may or may not be the same code running on your phone? Can I run a client from the Git repo and still use all of their infrastructure? Until I'm able to do that, it is still their "pinky promise".

https://github.com/WhisperSystems/Signal-Android/wiki/Reprod...

Re: Worried About the Privacy of Your Messages? Download Signal

#17

Earlier quoted context omitted.

It's an open source client[0]. It's not a "pinky promise". There are valid criticisms of Signal (primarily around the use of the Google Play Services Framework), but your comment seems to be jumping to a lot of conclusions without any research. https://github.com/whispersystems

But, they still expect me to trust the signed binary they send through the App store right? How is that anyway non-proprietary just because there is a Git repo somewhere that may or may not be the same code running on your phone? Can I run a client from the Git repo and still use all of their infrastructure? Until I'm able to do that, it is still their "pinky promise".

Survey says: NOPE.

Realistically, the code in that repo probably isn't even everything that would run on your device even provided you built it yourself.

Bets on some 'fetch js from somewhere' code in there which could completely unfuck the whole thing which acts as a help screen or something that would be very hard to find...

There is literally no way this sort of thing can ever be trusted. Christ, we barely trust PGP anymore...

Re: Worried About the Privacy of Your Messages? Download Signal

#18

Earlier quoted context omitted.

It's an open source client[0]. It's not a "pinky promise". There are valid criticisms of Signal (primarily around the use of the Google Play Services Framework), but your comment seems to be jumping to a lot of conclusions without any research. https://github.com/whispersystems

But, they still expect me to trust the signed binary they send through the App store right? How is that anyway non-proprietary just because there is a Git repo somewhere that may or may not be the same code running on your phone? Can I run a client from the Git repo and still use all of their infrastructure? Until I'm able to do that, it is still their "pinky promise".

You could just look into their APK.

Re: Worried About the Privacy of Your Messages? Download Signal

#19
I found a weird issue on a friends phone when I suggested they download it for iOS. It says "This item is no longer available". They were able to download other apps from the store. When emailing Signal support they said nothing was wrong on their end.

Still havent figured out why my friend cant download Signal from Apple App Store.

Re: Worried About the Privacy of Your Messages? Download Signal

#20
post #14

All the privacy solutions on the market are varying degrees of bad (from a privacy/security/freedom perspective), by which I mean they're all flawed in their own ways. Signal requires Google Play Services on Android. That means it's put simply not a privacy messenger. Yes there's crypto, but it's also tied into Whisper Systems' infrastructure, there's no federation. I use Signal reluctantly, and only on IOS. Threema,…

Matrix has the crypto and the federation. But of course its still not hiding metadata.

The Signal Server is open source, as far as I know.

Post reply on HN