Live data from Hacker News

Signal Foundation

signal.org

111–120 of 298 posts

Re: Signal Foundation

#111
post #3
post #2

When is the ICO? No, I'm not kidding. Look at Telegram. Who would've thought an open source project would ever get close to a billion dollars in funding ? I don't want Signal to wither away or forever remain a niche chat application because of lack of funding, especially if Moxie one day decides he wants to pursue some other dreams of his and doesn't have time to deal with Signal anymore.

Moxie is already working on a cryptocurrency project: https://www.mobilecoin.com/

yes, he's working on Mobilecoin since the beginning. I'm wondering when it will ship and if it will be the first project of the Signal foundation.

Re: Signal Foundation

#112
post #65

Pretty amazing and absolutely deserved. After the failures of systems like PGP, which aren't really suitable for the masses, the Signal protocol did a great job at spreading end-to-end encryption. I'm happy to hear that they got some philanthropic funding, even though I don't doubt that Moxie and the others did the work out of principle anyway and might have continued to do so even without the money.

IMO, saying PGP has failed is like saying cryptocurrencies have failed.

Re: Signal Foundation

#113

> Over the lifetime of the project, there have only been an average of 2.3 full-time software developers, and the entire Signal team has never been more than 7 people. This is awesome. Amazing what an excellent small team can build.

Don't tell SV!

When WhatsApp was acquired by Facebook for $19B they only had a little over 50 people.

Re: Signal Foundation

#115

Earlier quoted context omitted.

is it for profit?

Nothing is monetized yet as far as I can see. I like Keybase more though, it doesn't force me to have a phone (what the hell, Signal's Linux desktop client requires that at least).

I also like the keybase product. But when I see an ambitious, well-funded startup without a paid product or clear business model... that tells me I cannot yet trust their product, strategy or management team to endure. Next year they might be a completely different company, or might not exist at all. Since they haven't open-sourced their server, that makes it risky to rely on their products, because I don't really know what it is I'm relying on.

Signal in comparison is very clear about their goals, management and business model, and I believe are 100% open-source. That gives me confidence to adopt it now, even though it's a less feature-rich product.

I would love to see Signal adopt the Keybase identity-by-proof model, I think it's very clever and pragmatic.

Re: Signal Foundation

#116
Maybe they can use their $50,000,000 to make it possible to sign up for their service without a phone number.

The hype around Signal is insane to me considering this lack of basic functionality.

Re: Signal Foundation

#117
post #56

Earlier quoted context omitted.

A null vision. Moxie is against federation, and he's against interoperable clients. https://signal.org/blog/the-ecosystem-is-moving/ https://github.com/LibreSignal/LibreSignal/issues/37

I really, really wish that he'd reconsider. Interoperability is a huge Good Deal.

Signal now has the resources to compete with the IETF effort by Mozilla, Google, Cisco, Facebook, Wire, Twitter, MIT and INRIA: https://news.ycombinator.com/item?id=16325803

Re: Signal Foundation

#118
post #91

Earlier quoted context omitted.

> I hope they eventually develop a federated, privacy oriented messaging protocol, once the rapid technological evolution settles down. Like matrix[1]? That uses signals encryption. [1] https://matrix.org/

You mean, Matrix does not pose arbitrary limitations to clients that want to use end-to-end encryption. Clients that do not yet feature it by default, and that give huge warnings when you try to enable it. Clients that have problems with complex navigation when trying to verify fingerprints. Matrix is not the future, because at some point you're going to need to defeat metadata, and decentralized platforms can't do t…

To be fair; Matrix's crypto is fairly solid. The key management however is a mess, and we have run late on fixing it - but we're working on it currently. The metadata concern is bogus however: we designed Matrix to evolve into a hybrid p2p/decentralised architecture in future without changing a line of clientside code, so folks who want to store their metadata on their client rather than their server can do so - https://matrix.org/~matthew/2016-12-22%20Matrix%20Balancing%... has some notes on that. In practice, we think neither pure federation (like XMPP) or pure p2p (like Riocochet) or pure centralisation (like Signal) is desirable - you want to have a hybrid of decentralisation & p2p so you can get the best of both worlds.

Re: Signal Foundation

#119
post #89

Earlier quoted context omitted.

A null vision. Moxie is against federation, and he's against interoperable clients. https://signal.org/blog/the-ecosystem-is-moving/ https://github.com/LibreSignal/LibreSignal/issues/37

I don't think he's against federation, it just doesn't make sense to federate an experiment. Once you've got something really really really solid, then it does make sense. They've been able to iterate their protocol really fast thanks to it not being an RFC or something.

Fully agree and I want to elaborate. After SHA-1 broke, IETF's OpenPGP work group have failed the community by wrestling hand over what hash function should be in 5th revision of fingerprint protocol. When they couldn't reach an agreement, the development of the next standard was abandoned, leaving all users vulnerable with no date for fix.

And FFS, it hasn't even got anything to do with protocol, it's something the client can do by itself. Having worked on secure messaging apps, I would never go to federated protocols. Signal's infrastructure allows rapid improvement of protocol and fast elimination of insecure protocol revisions. That's where we need to be at. Just look at the history of TLS and the potential in downgrade attacks. Old revisions die slowly. Signal can easily monitor what versions are still running, push updates to users and ensure codebase isn't bloated by code that merely represents insecure protocols.

Signal succeeds because of it's "closed" ecosystem, it doesn't suffer from the tyranny of the majority that occurs when there's disagreement about e.g. seriousness of some attack, when some feature might be risky. With Matrix, I worry developers of clients can affect choices, and the protocol is already dangerous, to ensure (backwards) compatibility with older clients and (other) protocols, Matrix is not end-to-end encrypted by default. I will eat my hat with mustard the day I see all Matrix clients support only end-to-end encryption for everything.

Re: Signal Foundation

#120

I'm hoping they can use some of this cash to make a better desktop client: 1. That can be minimized to the system tray. 2. That can be used when behind an http proxy server. 3. Doesn't require a phone to use. 4. Doesn't take 200MB ram to run.

So, what are you using the 15,800 MB of RAM for?
Post reply on HN