Live data from Hacker News

Signal partners with Microsoft to bring end-to-end encryption to Skype

signal.org

171–180 of 350 posts

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#171
post #163

Earlier quoted context omitted.

Don't forget EFF also gave it high grades. What I also would like to see is meta-data eliminated in chat, without having to bring up a Tor server on your phone. Build it into the client/software, make it invisible.

The EFF's handing out of 'grades' for this stuff is probably something everyone is better off forgetting.

Their grades are based on objective assessment of properties of underlying technologies. They are very useful for most people, who are not going to study cryptography for several years and then manually reading and checking source code of every communications software product out there.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#172
post #167

Earlier quoted context omitted.

Unfortunately most of this is opt-in and not opt-out. Opting in for E2E encryption in a Facebook message really stands out.

Facebook has that? I can't find it.

It's called secret messages or something similar. May only be available in the messenger app...

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#174
post #90
post #45

Just to get a sense of the track record here, Signal Protocol powers: * Facebook/WhatsApp * Google/Allo * Microsoft/Skype * Signal Signal is also the basis for the protocols for Wire (Proteus) and Matrix (Olm).

Can't say I am really happy about it. The more the Signal protocol is used the more money is spend on attacking it.

But being battle-tested early on is the only way to ensure there are no bugs later on when everybody is using it.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#175

Earlier quoted context omitted.

Or Posteo, Mailbox.org, Tutanota, Riseup.net, etc.

Or self-hosted.

A lot of people are listing plenty of alternatives for email, but the majority of people aren't going to be this broad in email usage.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#176
post #163

Earlier quoted context omitted.

The EFF's handing out of 'grades' for this stuff is probably something everyone is better off forgetting.

Their grades are based on objective assessment of properties of underlying technologies. They are very useful for most people, who are not going to study cryptography for several years and then manually reading and checking source code of every communications software product out there.

No. They're not useful. They were a disaster, and EFF should stop doing them (I think they have?)

https://news.ycombinator.com/item?id=10525266

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#177

The thing is. How will Microsoft and Skype handle backdoors now. As far as I understood the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. Not always the good countries. But this. This baffles me. Deeply.

Microsoft used centralised servers because the Skype prior to that was a curse to mobile devices running on battery power. Particularly cellphones.

Skype worked as a p2p network, where some peers where marked as super peers and would help with peers behind firewalls (UDP-holepunching), and routing through the super peer. If your phone became a super peer, you could expect to essentially work like a server, with the "benefits" of increased bandwidth usage and power usage. Not exactly what you want as a mobile user.

So Microsoft had to change the architecture (which wasn't designed with mobile devices in mind) into a more centralised approach that could work with mobile devices.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#178

Earlier quoted context omitted.

I'm not knowledgeable about this -- is signal's e2e encryption even viable for a service with N users, and one where new users are being added? Put another way, if I have a group with 10 users and it's encrypted and then another person joins and can see the old messages, was it actually securely encrypted in the first place?

I don't think Discord gives people access to past message history when joining a group. I don't know of any limitations of Signal's group chats that would be a problem for Discord's group chat behavior.

It does give access to past messages.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#179

The thing is. How will Microsoft and Skype handle backdoors now. As far as I understood the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. Not always the good countries. But this. This baffles me. Deeply.

Wikipedia: "Signal relies on centralized servers that are maintained by Open Whisper Systems."

Totally uninformed comment. Signal the app relies on centralized servers to route messages & discover contacts. Signal the protocol (which is what Skype is rolling out) is a messaging encryption library that encrypts messages on the client using the other client's public key. Central servers (and anyone else in between the two clients) only sees encrypted gibberish, never plain text.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#180
post #90
post #45

Just to get a sense of the track record here, Signal Protocol powers: * Facebook/WhatsApp * Google/Allo * Microsoft/Skype * Signal Signal is also the basis for the protocols for Wire (Proteus) and Matrix (Olm).

Can't say I am really happy about it. The more the Signal protocol is used the more money is spend on attacking it.

That's the opposite of how you should feel. The more money spent attacking Signal, the stronger secure messaging gets. The best thing that could possibly happen for messaging security is for someone to discover a flaw in Signal. Unlike a lot of messengers, where a flaw is unlikely to teach us something other than "people should use Signal Protocol instead of terrible ad hoc protocols", a Signal flaw advances the state of the art.
Post reply on HN