Live data from Hacker News

Signal Foundation

signal.org

91–100 of 298 posts

Re: Signal Foundation

#91
post #8

This is freakin' awesome: A non-profit foundation with $50 million in the bank dedicated to providing usable encryption to the general public, with no other agenda other than the public good. Go read the blog post by Moxie and Brian Acton (who is joining Signal). Very exciting!

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

> I hope they eventually develop a federated, privacy oriented messaging protocol, once the rapid technological evolution settles down.

Like matrix[1]? That uses signals encryption.

[1] https://matrix.org/

Re: Signal Foundation

#92
post #27

Any reason Signal isn't available through F-Droid? It may be unjustified but I'm not a big fan of installing privacy conscious apps through Play. Edit: Wait, haven't installed anything yet, but I read the getting started guide. I have to sign up using a phone number? That throws all expectation of anonymity and thus privacy out the window.

The reasons why have been given by others, but you might also like to know that you can download the APK yourself and that it includes its own updater: https://signal.org/android/apk/

Re: Signal Foundation

#93
post #76

Earlier quoted context omitted.

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

Users don’t want federation. See also: Adoption failure of Google Talk XMPP, massive adoption of Facebook Messenger and Whatsapp, and AIM before it. I wish it were different, too.

> Users don’t want federation.

I don't care what users want. I want it!

That is the beauty in narcissism: You can use the best technology to chat with yourself. :)

Re: Signal Foundation

#94
post #2

When is the ICO? No, I'm not kidding. Look at Telegram. Who would've thought an open source project would ever get close to a billion dollars in funding ? I don't want Signal to wither away or forever remain a niche chat application because of lack of funding, especially if Moxie one day decides he wants to pursue some other dreams of his and doesn't have time to deal with Signal anymore.

Such a sum can be dangerous, especially if you're used to a team of 7. But it's also dangerous to dismiss or discourage this kind of experiments. > We believe there is an opportunity to act in the public interest and make a meaningful contribution to society by building sustainable technology that respects users and does not rely on the commoditization of personal data.

That sum is only dangerous if they aren't getting good advice from people with experience in nonprofits.

If they treat a big chunk of that as an endowment and go after more funding every few years to top off the coffers, they could live on that kind of money for ages.

Re: Signal Foundation

#95
post #27

Any reason Signal isn't available through F-Droid? It may be unjustified but I'm not a big fan of installing privacy conscious apps through Play. Edit: Wait, haven't installed anything yet, but I read the getting started guide. I have to sign up using a phone number? That throws all expectation of anonymity and thus privacy out the window.

You can get a phone number from https://jmp.chat/ if you like. The signup process can be done entirely over Tor.

If you don't use it beyond the trial, it's like the public payphone option mentioned by another commenter - someone could take your number. But if you choose to get a paid account (which, among other methods, can be acquired using Bitcoin, Bitcoin Cash, or a prepaid gift card purchased with cash), then the number will be yours. JMP is probably the most anonymous way of getting a phone number.

Re: Signal Foundation

#96
post #76

Earlier quoted context omitted.

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

Users don’t want federation. See also: Adoption failure of Google Talk XMPP, massive adoption of Facebook Messenger and Whatsapp, and AIM before it. I wish it were different, too.

Why does every product always have to conform to the most general use-case? Who cares what "users" want?

Re: Signal Foundation

#97

> Over the lifetime of the project, there have only been an average of 2.3 full-time software developers, and the entire Signal team has never been more than 7 people. This is awesome. Amazing what an excellent small team can build.

Don't tell SV!

Re: Signal Foundation

#98
post #2

When is the ICO? No, I'm not kidding. Look at Telegram. Who would've thought an open source project would ever get close to a billion dollars in funding ? I don't want Signal to wither away or forever remain a niche chat application because of lack of funding, especially if Moxie one day decides he wants to pursue some other dreams of his and doesn't have time to deal with Signal anymore.

What would be the incentive to buy?

Re: Signal Foundation

#99
post #73

This is a bit of a tangent, but I first heard of Intel SGX (Secure Guard Extensions) via Signal's blog post about secure contact sharing[0], so it's almost relevant :p From what I've read[1][2][3], Intel SGX is vulnerable to Spectre exploits. Does anyone know if this has changed Signal's approach to security at all? Granted, contact sharing was a technology preview, but I'm curious if SGX is still considered a feasib…

Regarding the SGX enclave and contacting sharing, the blog post announcement dated 26 Sept 2017 says 'deploying into production...over the next few months'. Can we assume that's happened already? Or are contacts still being exchanged in a way that would allow a middle man to reconstruct an individual's social graph?

Given that it now takes an order of magnitude more time than it used to for newly added contacts to appear in my list of Signal contacts, I assume /something/ has changed with the way they exchange contact data.

Re: Signal Foundation

#100
post #76

Earlier quoted context omitted.

Users don’t want federation. See also: Adoption failure of Google Talk XMPP, massive adoption of Facebook Messenger and Whatsapp, and AIM before it. I wish it were different, too.

I think users would prefer federated systems. Who wouldn't? Even though most people have probably never heard the word before, they almost certainly use and appreciate federated systems like phones and email. Do people want federation enough to have to take a principled stance in order to force change? Heck no. And that's the problem: there's no reasonable way for their desire to impact the producer side of the marke…

> Now most people don't even use those kinds of consolidation apps either, and resign themselves to literally running many separate apps.

IMO that is really one personal hell for me. I blame android and apple for this. I was happy with my N900 where you got one chat application that supported SMS, Skype, XMPP, AIM, ICQ, whatever. The world was so simple back then. Now everything has to be a separate "app", where previous there where just plugins. Such a decline in usability.

Post reply on HN