Why isn't anyone talking about Wire? https://wire.com/ The little I've used it, I found it pleasant and effective. But it almost seems like there is a campaign to ignore Wire; nearly every article written about Signal and alternatives fails to even mention Wire.
Worried About the Privacy of Your Messages? Download Signal
41–50 of 247 posts
Re: Worried About the Privacy of Your Messages? Download Signal
#42A problem for some people with Signal is that it requires you to use a phone number, and they may not want to disclose theirs. You can set up an SMS gateway number just for this purpose, but you shouldn't need such workarounds.
That's true, although those of us with unlocked phones can purchase "throwaway" SIM cards with distinct phone-numbers fairly easily with cash, use the number for secure communications only, throw the card away, and then go back to our public lives.
Re: Worried About the Privacy of Your Messages? Download Signal
#43All the privacy solutions on the market are varying degrees of bad (from a privacy/security/freedom perspective), by which I mean they're all flawed in their own ways. Signal requires Google Play Services on Android. That means it's put simply not a privacy messenger. Yes there's crypto, but it's also tied into Whisper Systems' infrastructure, there's no federation. I use Signal reluctantly, and only on IOS. Threema,…
I think it's time we just admitted that everything we type/tap/say into any device, regardless of how it's being wrapped up in transit, is absolutely and irrepairably insecure and we're not going to be able to fix that anytime soon.
Even with really smart crypto or some slick app; what makes you think that your messages aren't just being read by your os? Would you really notice? Why would you assume that the api this app talks to is trustworthy? There's no way to even tell if the code for the client on your device is the same as what's in that repo, as if it would make any kind of difference anyway since we can just load code from anywhere at runtime and you'd probably not even notice.
This whole thing is a fucking stageshow, I can only assume we're here to create an illusion that we still have any kind of security. Why? Is it to get some low hanging fruit/tech amateurs who will trust it and expose themselves? I don't know. But, HN, I don't know why WE aren't admitting this to ourselves or why we defend such obvious ruses.
Well, maybe some of you have signal stock I guess.
It's over, we lost, we have no security, we will probably never be able to reverse that situation, things are getting worse rapidly, we can't even know what any of our devices are really doing anymore (even the switches in your dc, the firmware on the UPS's, whatever), and apps like signal are obviously, to me, impossible to trust and I don't know why that's not obvious to anyone who has spent a moment looking at our situation..
Argh.
Re: Worried About the Privacy of Your Messages? Download Signal
#44All the privacy solutions on the market are varying degrees of bad (from a privacy/security/freedom perspective), by which I mean they're all flawed in their own ways. Signal requires Google Play Services on Android. That means it's put simply not a privacy messenger. Yes there's crypto, but it's also tied into Whisper Systems' infrastructure, there's no federation. I use Signal reluctantly, and only on IOS. Threema,…
What about WhatsApp, Telegram? I don't use them, but saying that there are no options today for secure, encrypted communication raises my eyebrow.
WhatsApp at least has end to end encryption- though that alone isn't enough, but it is not open source and is owned by Facebook. By default, it shares your number and your contacts' numbers with Facebook.
Neither Telegram nor WhatsApp are viable alternatives to anyone interested in privacy.
Re: Worried About the Privacy of Your Messages? Download Signal
#45Re: Worried About the Privacy of Your Messages? Download Signal
#46Earlier quoted context omitted.
You can, but moxie will throw a temper tantrum about it. https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
You call that a temper tantrum? I thought he was being very reasonable.
If he said "Please don't use our servers with your custom client, shit might break. You could run your own infra and keep it up to date with us and we'll federate", this would be reasonable.
Instead, if you read that thread a bit more he throws up his hands and says federation is a thing of the past because he had a bad experience with CM. Yeah, because we don't still use federated standards like email and telephony every day. Come on.
https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
Re: Worried About the Privacy of Your Messages? Download Signal
#47Re: Worried About the Privacy of Your Messages? Download Signal
#48Or you could download https://wire.com/ which allows developers to build their own clients and still use their infrastructure. Also, it doesn't force you to use a phone number for registration. It supports audio/video calls. Also, if you're really privacy minded, it doesn't need Google Play Services. That way it can be used in CopperheadOS.
Re: Worried About the Privacy of Your Messages? Download Signal
#49All the privacy solutions on the market are varying degrees of bad (from a privacy/security/freedom perspective), by which I mean they're all flawed in their own ways. Signal requires Google Play Services on Android. That means it's put simply not a privacy messenger. Yes there's crypto, but it's also tied into Whisper Systems' infrastructure, there's no federation. I use Signal reluctantly, and only on IOS. Threema,…
> It's 2016 and our best crypto messenger options are worse than what we had 10 years ago when Skype was peer to peer, or Jabber with federation. I strongly disagree, Skype has always been a black box. The usability of Signal's crypto is a lot better than it has ever been for Jabber. > I can understand the reasons for not supporting federation, but I disagree. Yet you don't address any of the problems with federation…
I saw a BBC documentary in the mid-early 2000s (sorry, can't cite it right now) about law enforcement and intel having a really tough time with suspects using Skype, only being able to collect metadata and not call content due to its split routing protocols.
Now, there's nothing to say the whole service wasn't backdoored at some point, but it appeared to be a real concern, at least to LE. A few security audits at the time also gave it a very positive report (ditto for citation). In the post-MS sale era, of course there's zero trust. Prior to that though, things seemed different.
Re: Worried About the Privacy of Your Messages? Download Signal
#50Earlier quoted context omitted.
What about WhatsApp, Telegram? I don't use them, but saying that there are no options today for secure, encrypted communication raises my eyebrow.
Telegram is a farce. They don't have end-to-end encryption by default, and their encryption protocol(MTProto) is home-made and basically a secret. They haven't opened it up to testing or open sourced it, so it's pretty useless at ensuring 'privacy'. Plus recently 15 million phone numbers linked to Telegram accounts were hacked because of an SMS verification loophole. WhatsApp at least has end to end encryption- thoug…
Why? I'm not trying to nitpick, I just don't know much on the subject. Not being open source doesn't really concern me nor the fact that my number is known by Facebook. My telecom company knows it, my mother knows it and all my friends know it + also all the companies know it who are used by my friends.