Live data from Hacker News

Signal partners with Microsoft to bring end-to-end encryption to Skype

signal.org

41–50 of 350 posts

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#41

I guess I'll be downvoted to hell, but.... This absolutely stinks. Signal is most likely blessed by the NSA. This is a ruse to get people comfortable with using Skype again for confidential conversations. Ever since Microsoft bought Skype and completely gutted it, it's been an open secret that they only did so to fulfill an $8B RFP by the NSA to break Skype's encryption. https://news.ycombinator.com/item?id=8106721 h…

You don't think, maybe, Radio Free Asia (funding from the Broadcasting Board of Governors) is providing funding to Signal so Asians (like the Chinese) have a surveillance free communication option? The US government is bigger than the NSA.

The Chinese, using Signal, which DEPENDS on Google services to work? Right...

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#42

I guess I'll be downvoted to hell, but.... This absolutely stinks. Signal is most likely blessed by the NSA. This is a ruse to get people comfortable with using Skype again for confidential conversations. Ever since Microsoft bought Skype and completely gutted it, it's been an open secret that they only did so to fulfill an $8B RFP by the NSA to break Skype's encryption. https://news.ycombinator.com/item?id=8106721 h…

If RFA funding means "blessed by the NSA" it will be hard to find an open source cryptography project that isn't blessed by the NSA, because RFA funds (or funded) audits of everything. Source: ran a security consultancy, was offered (and sometimes accepted) RFA funding to do crypto audits. I don't think you understand the cites you're providing.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#43
post #40

Earlier quoted context omitted.

Some ex-Skype developers created http://Wire.com with open-source E2E encryption and mobile apps that are usable by regular people.

Wire's cryptography is cribbed from Signal, so Skype's original crypto couldn't have been all that bleeding edge.

You have to remember Skype is 14 years old. Skype's encryption was pretty cutting-edge in 2003.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#44
post #38
post #21

Earlier quoted context omitted.

Did Skype for Business already have E2E encryption or no? Would seem like a no-brainer.

Depending on your industry, E2E encryption is actively not a thing you want because you have legal requirements to keep logs of conversations. Also, it's not clear it makes much sense, even if you don't have that requirement - in just about every company, you want the helpdesk / IT department / some other central authority to be able to do password resets, which means that the central authority has the cryptographic…

E2E doesn't mean no logs, your Skype logs can usually be exported locally.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#46
post #32
post #4

Earlier quoted context omitted.

Yeah, Microsoft moving to a model where "lawful intercept" is no longer possible would be hugely surprising.

They can still lawful intercept. All they have to do is push a MITMed version to suspected law breakers. It's going to be closed source just like WhatsApp, so of course, it will be easy for LE to defeat while shedding crocodile tears publicly about how it's uncrackable.

How could Skype target binaries to individual users?

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#47
post #27
post #19

Earlier quoted context omitted.

2/4 of the links in your sources don't work. I don't see any evidence that the OTF is a front for the NSA, or that you think somebody with the capability to make that in a year would sell their soul for $455,000.

The OTF is specifically a (non-secret) front for Radio Free Asia, whose mission is to work in other countries against their NSA equivalents. The best thing the OTF can do is to fund actually honestly secure crypto, because if there's a hidden weakness the NSA can use, there's too much of a risk that one of the countries Radio Free Asia is trying to work against is going to find it. (Yes, technically, a keyed "backdoo…

whose mission is to work in other countries against their NSA equivalents.

That's not really a sensible way to describe either their officially stated or inferred mission.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#48
post #38

Earlier quoted context omitted.

Depending on your industry, E2E encryption is actively not a thing you want because you have legal requirements to keep logs of conversations. Also, it's not clear it makes much sense, even if you don't have that requirement - in just about every company, you want the helpdesk / IT department / some other central authority to be able to do password resets, which means that the central authority has the cryptographic…

E2E doesn't mean no logs, your Skype logs can usually be exported locally.

Sure, but the compliance requirement is that logs need to be automatically exported and archived by the IT department, without an option for the user to avoid giving logs. What does E2E benefit you at that point? The message contents, which are what E2E protects, are being copied off to some separate server.

(I'd buy the argument "You should design all your protocols E2E first, and then add logging/escrow, instead of designing them less secure and bolting E2E on later," but Skype for Business already exists without E2E so that's a lost cause in this particular case.)

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#49
post #45

Just to get a sense of the track record here, Signal Protocol powers: * Facebook/WhatsApp * Google/Allo * Microsoft/Skype * Signal Signal is also the basis for the protocols for Wire (Proteus) and Matrix (Olm).

Do you have an opinion on how Keybase handles their encrypted chat?

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#50
post #14

While on topic of Skype: My God the latest Skype design update is abysmal, whoever come up with that horrible mess should be fired and never touch any design or management role at all. And it’s not only design but the ux is horrible too, when you switch between conversation - it does not focus on the chat box field so you can start typing right away, instead you have to click it first. This is a basic stuff for a cha…

I'll second this. I recently moved to a project that uses Outlook/Skype/Exchange for everything, and Skype is the bane of my experience. Why do I need a window for contacts separate from the actual conversations? Why do I need email recaps of every conversion, often times with redundant messages? Why can't I have a group chat that's intended to be a permanent 'room', and not just a collection of people who are virtually meeting? Skype intends you to exit the chat windows, and that's not how I use chat apps.
Post reply on HN