Live data from Hacker News

Signal partners with Microsoft to bring end-to-end encryption to Skype

signal.org

271–280 of 350 posts

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#272

Earlier quoted context omitted.

I think it was a patent issue. No one is allowed to use p2p for chat.

It does look like IBM does own a p2p instant messaging patent[1]. So I think this checks out. - https://www.google.ms/patents/US7675874

The claims in that patent seem to be fairly easy to work around.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#273

Earlier quoted context omitted.

Please note that of the technologies tptacek listed, the only one which can operate in distributed fashion is Matrix.[0] Wire is attempting to pursue decentralization, but federation is not (yet) in their roadmap.[1] [0] https://github.com/matrix-org/synapse [1] https://medium.com/@wireapp/wire-server-code-now-100-open-so...

I don't know why but Signal has always scared me - I think it was when I noticed it sharing my contacts with their server to "find my friends" when I never consented. Matrix is looking good, but again not P2P only federated. This is why we are trying to do fully P2P end-to-end encryption like with https://hackernoon.com/so-you-want-to-build-a-p2p-twitter-wi... .

> my contacts with their server to "find my friends" when I never consented.

I installed Signal a few days ago for the first time and there was definitely a prompt, with an easy way to skip it, before it did the find my friends thing.

The wording also seemed to indicate that only the hashes of the numbers would be uploaded but not sure if thats actually true.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#274

The thing is. How will Microsoft and Skype handle backdoors now. As far as I understood the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. Not always the good countries. But this. This baffles me. Deeply.

That was my first thought. This is how they kill Signal. It was how they killed Skype. Take a P2P communication system that is difficult to spy on, give Microsoft a big pile of money on the sly to buy it and re-engineer it to be a centralized system and restore spy-ability. It almost seems so laughably obvious as to be childishly unwise to attempt.

How would Signal working with Microsoft to implement the Signal protocol in Skype somehow kill Signal?

Signal (the organization) has worked with other companies, like Facebook and WhatsApp (owned by FaceBook, I know), to implement the Signal protocol on their respective messaging services. It appears that's precisely what they're doing with Skype in this case. It's not like Microsoft is buying out Signal.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#276
post #154

Earlier quoted context omitted.

Keybase doesn’t support forward secrecy. The signal protocol does, though I can’t say whether that’s true for Skype's implementation of the protocol

Some docs here: https://keybase.io/docs/crypto/chat To add a little bit, avoiding forward secrecy was a design decision. We wanted to support adding and removing devices from your account (including removing all of your original devices, if you want), and we wanted new devices to be able to read your message history. I think those two things put together are in conflict with forward secrecy. That said, we'd like to a…

It seems like a reasonable design decision to have a time horizon beyond which a device which has been out of communication loses access to more recent messages. That could be significantly less than 3 years - probably a week or two is fine.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#277
post #170

Maybe a good opportunity to remember what is the main mission of Signal/Open Whisper Systems: they realized at the time that it was extremely complicated for non-technical people to use tools secure enough and respecting your privacy (PGP...), and that the tools used by everyone (Whatsapp, Messenger...) were popular because they were fun and easy to use. They believed that everyone should be able to have an easy way…

While on the topic of things to remember, also remember that they're making compromises in order to keep things hidden from users.

The Signal protocol may be sound, but as we've seen with today's WhatsApp news, there are still implementation-specific compromises being made. Not to mention that many of those companies ship a closed source product. They could publish a spec of what should be going over the wire to make it auditable without needing to go all open source, but they don't do that either. Things are really kept closed. I am not sure whether it's a net positive or a net negative when another user joins WhatsApp or a similar service, versus Telegram where encryption is opt-in but at least it's open source and not leaking metadata to BigCorps whose profit model is knowing you.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#278
post #89

Earlier quoted context omitted.

What does E2E benefit you at that point? Message confidentiality between businesses. Did you perhaps think SfB only works between users in the same organization?

> Did you perhaps think SfB only works between users in the same organization? Yes? Doesn't the client connect to exactly one server [pool], which hosts exactly one organization?

The servers can federate.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#279
post #197
post #137

Now if only they can partner with someone to get chat working as well as it used to or get syncing between multiple devices working...

They're hiring: https://news.ycombinator.com/item?id=16054356

I'm not sure I'd want to work for a company that makes compromises at every turn and works together with companies that have their user's privacy definitely not at heart (but claim to by using this encryption publicity stunt).

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#280
post #137

Now if only they can partner with someone to get chat working as well as it used to or get syncing between multiple devices working...

This. I wish Signal's own native apps had the user experience of Telegram.

or that telegram just used the signal protocol; either is fine in my book
Post reply on HN