Live data from Hacker News

Signal Foundation

signal.org

131–140 of 298 posts

Re: Signal Foundation

#131
post #8

This is freakin' awesome: A non-profit foundation with $50 million in the bank dedicated to providing usable encryption to the general public, with no other agenda other than the public good. Go read the blog post by Moxie and Brian Acton (who is joining Signal). Very exciting!

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

If federated communcations is a desire, OMEMO[1] is a thing.

However, there are issues with federated protocols beyond the velocity issue that Moxie mentions. Some of them are technical and some of them are not (see conversations.im comment on doing xmpp notifications on iOS for example), but they do exist.

1: https://xmpp.org/extensions/xep-0384.html

Re: Signal Foundation

#132
post #71

This is very very good news. As a heavy Signal user, from where I sit I personally see the following clear needs: -Better group support. Right now, to do a group in Signal you have to name the group, which makes it kind of a pain to create ad hoc quick groups. I'm forever naming them "John Sue Bill" or "Jane Roger Amanda". iMessage, by contrast, just automatically makes a group without a name. You get a thread for th…

I'd love to use Signal, but in order for me to do so there's a lot that has to be added. - Real multi device support. I want my messages on all my devices, without having to have my phone on. - An iPad app. - A desktop app. I'd pay for a native one, without Electron. These things are basically table stakes for competing with Facebook Messenger, Telegram, and iMessage. If Signal's goal is to bring encryption to the ma…

For #1, Multi device support already exists. I can put my phone on airplane mode and still send and receive messages just fine on my laptop

Re: Signal Foundation

#133

What is Signal Foundation's vision for interoperable, open-standard E2E messaging between different central services?

A null vision. Moxie is against federation, and he's against interoperable clients. https://signal.org/blog/the-ecosystem-is-moving/ https://github.com/LibreSignal/LibreSignal/issues/37

The axolotl ratchet has been used in at least two different federated protocols that I am aware of. There is no plan to federate signal itself, but he not only allows, but seems to encourage the protocol's use elsewhere.

Re: Signal Foundation

#134
post #132

Earlier quoted context omitted.

I'd love to use Signal, but in order for me to do so there's a lot that has to be added. - Real multi device support. I want my messages on all my devices, without having to have my phone on. - An iPad app. - A desktop app. I'd pay for a native one, without Electron. These things are basically table stakes for competing with Facebook Messenger, Telegram, and iMessage. If Signal's goal is to bring encryption to the ma…

For #1, Multi device support already exists. I can put my phone on airplane mode and still send and receive messages just fine on my laptop

That's cool. When I tried it last it required my phone to be on just like WhatsApp. I'll check it out again.

I still hope they use some of this cash to make a real iPad and Desktop app, though. I'd really love to use the service but those are deal breakers for me.

Re: Signal Foundation

#135
post #7

I'm really excited about the possibility of a better client. I want to switch to Signal with my friends but the clients feel so behind Facebook Messenger

I've assimilated most friends and all family very easily by educating them about the why. Not to mention if you're a parent explicitly banning sharing of photos with relatives via social media. People accept any small inconvenience or lack of feature quickly. But at this point I'm not following on the "so behind" comment. Care to elaborate?

Their Android app at least is way too difficult to use.

I tried it with my friend some time ago and we just couldn't figure out in a reasonable amount of time how to add each other etc.

I consider both of us tech savvy and we have absolutely no trouble with other IM clients or more archaic stuff like IRC.

Re: Signal Foundation

#136
post #7

I'm really excited about the possibility of a better client. I want to switch to Signal with my friends but the clients feel so behind Facebook Messenger

I've assimilated most friends and all family very easily by educating them about the why. Not to mention if you're a parent explicitly banning sharing of photos with relatives via social media. People accept any small inconvenience or lack of feature quickly. But at this point I'm not following on the "so behind" comment. Care to elaborate?

It's small things like gif/emoji support, @-ing people with their nickname/username sends them a dedicated notification on facebook messenger.

As much as I hate fb, messenger is a pretty decent application.

Re: Signal Foundation

#137

Earlier quoted context omitted.

I'm not sure of your assumption that lack of total anonymity implies no privacy. They are independently important concepts. You can have privacy (no knowledge of information shared) without anonymity.

That's true, but I believe the concern would be that there's information just in knowing: 1) what's your number, and 2) with whom you connect or communicate. That is, there's still the danger of social graph analysis: "Oh look, this person's communicating with a known journalist!"

Of course there is. That's why one of the cleverest parts of signal is the engineering to invalidate number 2. Moxie and signal are the world leaders in trying to make it impossible for the service to know who you communicate with... Even to the point of using the Intel secure enclave to audit the server software and validate that it doesn't peek.

Re: Signal Foundation

#138
post #109

Earlier quoted context omitted.

Xmpp was pretty popular. Fb messenger and Google talk never allowed federation, but they did for a while allow access by xmpp clients. Apparently WhatsApp still use xmpp, but afaik also never supported federation. Aim didn't allow federation. So I'm not sure what you're trying to say? You could claim the rotting corpse of duckduckgo's xmpp service is evidence that users don't want federation - but I thinks more just…

Google Talk absolutely federated: http://googletalk.blogspot.com/2006/01/xmpp-federation.html Unfortunately they were the only major service provider to do so, and the capability was later discontinued.

[ed: aha! They didn't really support federation in a standards compliant way:

"However, since the Google Talk Service does not support server-to-server encryption via TLS (something that was required by RFC 3920 in 2004), a number of servers (including jabber.org) refuse to establish a connection since May 2014."

https://xmpp.org/2015/03/no-its-not-the-end-of-xmpp-for-goog...

I recall there were issues...]

Wait, what? You could chat from you@example.com on your bespoke xmpp server and send messages to user@gmail without needing a Google account and vice-versa?

Was Google talk really so unpopular that I didn't seriously try to use it until it became the walled garden that didn't support server federation?

Re: Signal Foundation

#139

Earlier quoted context omitted.

To be fair; Matrix's crypto is fairly solid. The key management however is a mess, and we have run late on fixing it - but we're working on it currently. The metadata concern is bogus however: we designed Matrix to evolve into a hybrid p2p/decentralised architecture in future without changing a line of clientside code, so folks who want to store their metadata on their client rather than their server can do so - http…

What are the benefits of decentralized servers over p2p? "Metadata concern is bogus" yet the linked documentation explicitly says bridges expose metadata, and that home servers expose metadata. One advantage of Pond-hybrid is "Supports any and all Matrix clients via the existing standard client-server API". This means the issue is desire to remain compatible with insecure clients. This is lack of agility is not neede…

> What are the benefits of decentralized servers over p2p?

* A server-based system gives you a well-defined secure place to keep an always-on copy of your data, with whatever physical/geographic/network security model you prefer... rather than smearing it across a bunch of handsets or laptops which could get lost/stolen/run-out-of-storage etc.

* Thin-client protocols like Matrix or XMPP are going to typically use way less battery and bandwidth than maintaining a full p2p mesh on a mobile device, which is generally desirable. The way to fix that in p2p is to introduce master nodes of some flavour... at which point you're back in a hybrid p2p/federated architecture again.

* A thin-client-first approach also means that you can easily support different clients (and bots/bridges etc) rather than the client being tightly coupled to a complicated p2p protocol.

To repeat: i'm advocating a hybrid p2p/decentralised approach - not religiously pure decentralisation, nor religiously pure p2p either.

> "Metadata concern is bogus" yet the linked documentation explicitly says bridges expose metadata, and that home servers expose metadata.

My point was that in the medium/long term we have a clear route to avoid having to expose metadata on servers.

> One advantage of Pond-hybrid is "Supports any and all Matrix clients via the existing standard client-server API". This means the issue is desire to remain compatible with insecure clients. This is lack of agility is not needed.

You're missing the point. There's nothing insecure about the clients. The whole idea of the PDF is to spell out that you could swap out a federated server for a local p2p-based server (perhaps even running in the client) whilst reusing all the same clients... which now magically become p2p (if desired). This agility is very desirable indeed, given the huge amount of effort which has now gone into writing good Matrix clients like Riot, nheko, Quaternion etc.

Re: Signal Foundation

#140
post #42

Earlier quoted context omitted.

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

Signal Protocol is one of the best documented cryptographic message protocols on the planet, and is accompanied by multiple GPL'd implementations. https://signal.org/docs/

And yet even the best of the best cryptographic protocols provide little to no value on very insecure systems like iphone and android.

It's like bike shedding of security, where Moxi focuses on the things he can do but for the systems where it doesn't matter.

Post reply on HN