Live data from Hacker News

Signal partners with Microsoft to bring end-to-end encryption to Skype

signal.org

31–40 of 350 posts

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#31
post #14

While on topic of Skype: My God the latest Skype design update is abysmal, whoever come up with that horrible mess should be fired and never touch any design or management role at all. And it’s not only design but the ux is horrible too, when you switch between conversation - it does not focus on the chat box field so you can start typing right away, instead you have to click it first. This is a basic stuff for a cha…

Speaking strictly about the "look and feel," I must say I love it. It's one of the most well-designed apps I've ever seen.

Per-UX, I've found Skype very difficult to use since the last major redesign a few(?) years ago. I'm not sure if the update made it worse. I feel generally confused just the same.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#32
post #4
post #2

I can't help but read this with a cynical voice in my head: Skype used to have an incredibly bleeding edge P2P E2E encrypted protocol, and Microsoft threw it all away. Some might say for good reasons (mobile use case, supernodes straining routers, legal wiretap compliance issues); I'd respectfully disagree and observe that there's just going full-circle.

Yeah, Microsoft moving to a model where "lawful intercept" is no longer possible would be hugely surprising.

They can still lawful intercept. All they have to do is push a MITMed version to suspected law breakers. It's going to be closed source just like WhatsApp, so of course, it will be easy for LE to defeat while shedding crocodile tears publicly about how it's uncrackable.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#34

I guess I'll be downvoted to hell, but.... This absolutely stinks. Signal is most likely blessed by the NSA. This is a ruse to get people comfortable with using Skype again for confidential conversations. Ever since Microsoft bought Skype and completely gutted it, it's been an open secret that they only did so to fulfill an $8B RFP by the NSA to break Skype's encryption. https://news.ycombinator.com/item?id=8106721 h…

Maybe they have an 'understanding' about the implementation of the cryptography as they do with WhatsApp, meaning the program doesn't notify you when your opposite's keys change, leaving unscrupulous users (most) susceptible to MitM attacks, which could be used by law enforcement or three-letter-agencies. Plus, Skype probably still makes extensive use of meta-data, Signal allege that they don't, but we can't really a…

Why would you want to assess what's actually running on their servers? Even if you know the code on it, you have no guarantee it's not running inside a hypervisor that logs the contents of memory, or something.

In terms of cryptographic robustness, it's good for an app like Signal to have a closed-source server, because it forces you to not trust the server.

(This is of course separate from whether it's good for the Signal server to be free software for inherent free-software morality reasons.)

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#35
post #14

While on topic of Skype: My God the latest Skype design update is abysmal, whoever come up with that horrible mess should be fired and never touch any design or management role at all. And it’s not only design but the ux is horrible too, when you switch between conversation - it does not focus on the chat box field so you can start typing right away, instead you have to click it first. This is a basic stuff for a cha…

That update pushed me away from Skype to Signal.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#38
post #21

Earlier quoted context omitted.

Yes, more people than ever.

Did Skype for Business already have E2E encryption or no? Would seem like a no-brainer.

Depending on your industry, E2E encryption is actively not a thing you want because you have legal requirements to keep logs of conversations.

Also, it's not clear it makes much sense, even if you don't have that requirement - in just about every company, you want the helpdesk / IT department / some other central authority to be able to do password resets, which means that the central authority has the cryptographic ability to impersonate any user in the company. (Maybe this triggers logs, but protocol-wise, they can still read and write messages.) So E2E isn't really helping you; you might as well just encrypt all the messages to a key held by the central authority.

E2E is great for conversations between members of the public, where there isn't a central authority that determines identities, and where if you forget your password, the right way to regain access to the conversation is to meet your conversation partner in person and re-exchange cryptographic identities with them, end-to-end.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#39
post #14

While on topic of Skype: My God the latest Skype design update is abysmal, whoever come up with that horrible mess should be fired and never touch any design or management role at all. And it’s not only design but the ux is horrible too, when you switch between conversation - it does not focus on the chat box field so you can start typing right away, instead you have to click it first. This is a basic stuff for a cha…

Have you tried the skype mobile app latest update ? It makes the desktop version look amazing. Somehow, they thought we wanted skype to be a clone of whatsapp stories or whatever. Nothing works properly, it's slow as hell, but goody you can like and put a smiley on each individual message !

I used to really like skype but it has now become one of the worst, and I'm still forced to use it due to several of my contacts being on it. Imho network effect is the only reason they aren't being mass dumped by users.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#40
post #2

I can't help but read this with a cynical voice in my head: Skype used to have an incredibly bleeding edge P2P E2E encrypted protocol, and Microsoft threw it all away. Some might say for good reasons (mobile use case, supernodes straining routers, legal wiretap compliance issues); I'd respectfully disagree and observe that there's just going full-circle.

Some ex-Skype developers created http://Wire.com with open-source E2E encryption and mobile apps that are usable by regular people.

Wire's cryptography is cribbed from Signal, so Skype's original crypto couldn't have been all that bleeding edge.
Post reply on HN