Live data from Hacker News

Signal partners with Microsoft to bring end-to-end encryption to Skype

signal.org

191–200 of 350 posts

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#191

The thing is. How will Microsoft and Skype handle backdoors now. As far as I understood the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. Not always the good countries. But this. This baffles me. Deeply.

>the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them.

That seems like pretty unreasonable tinfoil. There is no reason for Microsoft to want to give information to governments. I assume they don't pay, and the cost is consumer trust. Makes a lot of sense to rearchitect such that you can't give in to government demands.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#192

Earlier quoted context omitted.

Their grades are based on objective assessment of properties of underlying technologies. They are very useful for most people, who are not going to study cryptography for several years and then manually reading and checking source code of every communications software product out there.

No. They're not useful. They were a disaster, and EFF should stop doing them (I think they have?) https://news.ycombinator.com/item?id=10525266

Yes they have. Now they have a set of (kind of weird) guides.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#193

Over the last couple of years, there's been huge progress in making end-to-end encryption practical for "real world" apps -- especially stuff running in web browsers. Signal is part of that, of course, as is WebRTC, a standard that to its great credit did an excellent job with the encryption pieces from the very beginning. We built our video calling app, Daily.co, on top of WebRTC and so we could relatively easily in…

Why not just forward the e2e encrypted video streams through your servers? Encrypted or not, wouldn’t the amount of traffic be the same?

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#194
post #119
post #39

Earlier quoted context omitted.

Have you tried the skype mobile app latest update ? It makes the desktop version look amazing. Somehow, they thought we wanted skype to be a clone of whatsapp stories or whatever. Nothing works properly, it's slow as hell, but goody you can like and put a smiley on each individual message ! I used to really like skype but it has now become one of the worst, and I'm still forced to use it due to several of my contacts…

There's not a "Skype Lite" for Android... which returns back to previous form. Why that was necessary only Microsoft knows.

Oh god there really is.

Installed it to try, and it starts by asking sms and contacts permissions, which seems innocent enough to integrate with your contact list, only to realize "upload all your contacts to microsoft periodically" is on without asking.

Microsoft, you're really terrible at this.

(bonus point that I can't fully uninstall regular Skype because it's a "native app" on my samsung s7 edge, so at best I can disable it and remove all permissions from it, awesome)

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#195

The thing is. How will Microsoft and Skype handle backdoors now. As far as I understood the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. Not always the good countries. But this. This baffles me. Deeply.

Microsoft used centralised servers because the Skype prior to that was a curse to mobile devices running on battery power. Particularly cellphones. Skype worked as a p2p network, where some peers where marked as super peers and would help with peers behind firewalls (UDP-holepunching), and routing through the super peer. If your phone became a super peer, you could expect to essentially work like a server, with the "…

I think it was a patent issue. No one is allowed to use p2p for chat.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#196

The thing is. How will Microsoft and Skype handle backdoors now. As far as I understood the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. Not always the good countries. But this. This baffles me. Deeply.

>the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. That seems like pretty unreasonable tinfoil. There is no reason for Microsoft to want to give information to governments. I assume they don't pay, and the cost is consumer trust. Makes a lot of sense to rearchitect such that you can't give in to government demands.

If only consumers cared. As it stands there's very little downside to handing information over to government(s), and I would assume some upsides (back scratching).

Apple might actually be making consumers care in an odd way by making it such a public issue.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#198
post #190

Earlier quoted context omitted.

Microsoft used centralised servers because the Skype prior to that was a curse to mobile devices running on battery power. Particularly cellphones. Skype worked as a p2p network, where some peers where marked as super peers and would help with peers behind firewalls (UDP-holepunching), and routing through the super peer. If your phone became a super peer, you could expect to essentially work like a server, with the "…

> So Microsoft had to change the architecture (which wasn't designed with mobile devices in mind) into a more centralised approach that could work with mobile devices. As an engineer and software developer, I find this to be extremely unlikely. If "super-peers" can already route traffic for others, it seems very likely they could simply route all traffic for Mobile users through some "super-duper peer", instead of ro…

Operators have no interest in being reduced to "dumb pipes" (as the industry calls it). So OP is correct, P2P overlay routing has traditionally caused headaches for network operators traffic shaping. Any P2P tech that reaches this kind of scale would run into serious scalability challenges due to operator throtteling.

- http://ieeexplore.ieee.org/document/6488287/

- https://www.computer.org/csdl/proceedings/p2p/2008/3318/00/3...

- http://www1.huawei.com/enapp/198/hw-079351.htm

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#199
post #188

Earlier quoted context omitted.

You might use GMail, but I can communicate with you perfectly fine even if I don't use GMail.

If by "perfectly fine" you mean highly likely to get into your recipient's spam folder - you're probably right. Having tried to self host my own mail server I can tell you it's never an easy task to actually get your message across.

This comes up a lot but the reality is that its really only nerds and spammers that self-host. It's hard to fault spam filters of being suspicious of random domains. This doesn't mean there aren't many alternatives -- just about any personal email provider will make sure they're off the blacklists.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#200
post #116

Earlier quoted context omitted.

I love this. The more encryption is used, the less journalists talking to their sources, lawyers talking to their clients, etc. will stand out.

Unfortunately most of this is opt-in and not opt-out. Opting in for E2E encryption in a Facebook message really stands out.

Yes, that is indeed a shame, although I'm glad at least WhatsApp has it by default, which is a lot of messages already.
Post reply on HN