Live data from Hacker News

Signal Foundation

signal.org

141–150 of 298 posts

Re: Signal Foundation

#141
post #7

I'm really excited about the possibility of a better client. I want to switch to Signal with my friends but the clients feel so behind Facebook Messenger

I've assimilated most friends and all family very easily by educating them about the why. Not to mention if you're a parent explicitly banning sharing of photos with relatives via social media. People accept any small inconvenience or lack of feature quickly. But at this point I'm not following on the "so behind" comment. Care to elaborate?

On top of the myriad of missing features that for example Telegram has, the UI/UX for Signal (at least on the iOS app) is far behind. The app feels laggy and slow in comparison to Telegram or Messages (only other apps I use). It has giant text bubbles with large padding which IMO looks terribly ugly. Also, Telegram now has dark mode which I find very useful. And as mentioned, as silly as gif support is, it's a nice feature to have. If only Telegram used Signal's encryption by default.

Re: Signal Foundation

#142
post #76

Earlier quoted context omitted.

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

Users don’t want federation. See also: Adoption failure of Google Talk XMPP, massive adoption of Facebook Messenger and Whatsapp, and AIM before it. I wish it were different, too.

User want federation. See the adoption of email.

Re: Signal Foundation

#143
post #138

Earlier quoted context omitted.

Google Talk absolutely federated: http://googletalk.blogspot.com/2006/01/xmpp-federation.html Unfortunately they were the only major service provider to do so, and the capability was later discontinued.

[ed: aha! They didn't really support federation in a standards compliant way: "However, since the Google Talk Service does not support server-to-server encryption via TLS (something that was required by RFC 3920 in 2004), a number of servers (including jabber.org) refuse to establish a connection since May 2014." https://xmpp.org/2015/03/no-its-not-the-end-of-xmpp-for-goog... I recall there were issues...] Wait, what…

> Wait, what? You could chat from you@example.com on your bespoke xmpp server and send messages to user@gmail without needing a Google account and vice-versa?

For some glorious years between 2006 and 2013 (Hangouts), this was indeed possible. I run my own XMPP server and I used to chat with GTalk users all the time. For literally years.

> They didn't really support federation in a standards compliant way

It was standards compliant enough. In the original RFC, server-to-server TLS was mandatory to implement but not mandatory to enable/deploy. The XMPP community later moved towards enforced server-to-server encryption, but this was many years later and had little impact on GTalk federation during the time that it was supported.

Re: Signal Foundation

#144
post #42

Earlier quoted context omitted.

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

Signal Protocol is one of the best documented cryptographic message protocols on the planet, and is accompanied by multiple GPL'd implementations. https://signal.org/docs/

Unfortunately, it looks like the signal people are possibly not friendly to third-party devs and have levied seemingly spurious IP threats against third-party implementations: https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7

Obviously this is just one side of the story, but it sounds rather alarming.

Re: Signal Foundation

#145

Let's hope they don't backdoor it like they did with WA. Probably already has one. Long time signal and WA user here

WhatsApp was never backdoored.

Even The Guardian backed down after a review of its research process: https://www.theguardian.com/technology/commentisfree/2017/ju...

Quote:

> The most serious inaccuracy was a claim that WhatsApp had a “backdoor”, an intentional, secret way for third parties to read supposedly private messages. This claim was withdrawn within eight hours of initial publication online, but withdrawn incompletely. The story retained material predicated on the existence of a backdoor, including strongly expressed concerns about threats to freedom, betrayal of trust and benefits for governments which surveil. In effect, having dialled back the cause for alarm, the Guardian failed to dial back expressions of alarm.

Re: Signal Foundation

#146
post #76

Earlier quoted context omitted.

Users don’t want federation. See also: Adoption failure of Google Talk XMPP, massive adoption of Facebook Messenger and Whatsapp, and AIM before it. I wish it were different, too.

I think users would prefer federated systems. Who wouldn't? Even though most people have probably never heard the word before, they almost certainly use and appreciate federated systems like phones and email. Do people want federation enough to have to take a principled stance in order to force change? Heck no. And that's the problem: there's no reasonable way for their desire to impact the producer side of the marke…

“they almost certainly use and appreciate federated systems like phones and email”

Two channels which have become saturated with spam and junk once the federated network starts to include players who are willing to permit bad actors to access the network in exchange for money.

People enjoy federated networks of regulated, good faith players; wide open federated networks tend towards anarchy.

Re: Signal Foundation

#147
post #76

Earlier quoted context omitted.

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

Users don’t want federation. See also: Adoption failure of Google Talk XMPP, massive adoption of Facebook Messenger and Whatsapp, and AIM before it. I wish it were different, too.

Parent's downvotes are undeserved as they are spot on.

Users don't want federation in a sense that they don't _care_ if it's federated or not. Not that they actively decide against it.

They only care if they can start chatting with people from their address book right after installing a chat app.

Re: Signal Foundation

#148
post #79

Since you are in the US how do you keep the US government from interfering with your mission because Signal uses strong encryption? How do you address the EARs (Export Administration Regulations) and ITARs (International Traffic in Arms Regulations)? These regulations look like a tar pit to me.

Chrome, Firefox and IE ship with very strong encryption (128 bit AES) just fine for many years now. That cat is out of the bag.

I read in the CFR (Code of Federal Regulations) somewhere that 128-bit AES is under the threshold so can be self-classified (but IANAL!). Anything stronger and the legal constraints seemed to be more than onerous.

Cat is quantum undetermined in my book - maybe someone from Open Whisper Systems, Signal Foundation, or the Freedom of the Press Foundation will share some wisdom.

Re: Signal Foundation

#149
post #86
post #82

Earlier quoted context omitted.

Theoretically, but when you throw in things like build systems often not being deterministic, minor versions of dependencies changing, different OS or slightly different OS version with different libraries; there's a multitude of places to throw the final binary off by a few bytes or more and end up with a different checksum. Signal wants to distribute a binary with a checksum. Once the checksum is different all bets…

So why don't they just also list checksum of the F-Droid binary?

They don't trust F-Droid.

Re: Signal Foundation

#150

Since you are in the US how do you keep the US government from interfering with your mission because Signal uses strong encryption? How do you address the EARs (Export Administration Regulations) and ITARs (International Traffic in Arms Regulations)? These regulations look like a tar pit to me.

The US government doesn't need to break the encryption of the application to monitor it. It can do remote screen grabs.
Post reply on HN