Live data from Hacker News

Signal Foundation

signal.org

151–160 of 298 posts

Re: Signal Foundation

#151
post #81
post #71

This is very very good news. As a heavy Signal user, from where I sit I personally see the following clear needs: -Better group support. Right now, to do a group in Signal you have to name the group, which makes it kind of a pain to create ad hoc quick groups. I'm forever naming them "John Sue Bill" or "Jane Roger Amanda". iMessage, by contrast, just automatically makes a group without a name. You get a thread for th…

Signal has no per-group notification settings Yes it has, at least on Android. Within a group, press the three-dots-menu on top and choose mute notifications. You can choose for how long they shall be muted, similarly to other apps. Adding to your list: - Working backups for text and media.

> - Working backups for text and media.

Yes pretty please! For Android, any kind of media (bulk) backup option would help, for example. (IIRC iOS doesn't even have plain text backup). This is affecting a lot of everyday common users who cannot move to a new phone (or uninstall and then later install again) without losing all the media in the conversations. Saving the media items one by one (and detached from conversation and context) is not the same and sometimes impossible due to the sheer quantities involved. And so on.

I know the resources have been really scarce but since this is hopefully changing now, this would be greatly appreciated. There's been some recent related work[1] required for encrypted backups to work, though. Also see ongoing discussion[2], GH issue thread[3] and possible implementation PR[4] etc., for anyone curious. Alpha testing[5] may help, too. (Me, I'm trying to find time and energy to help with this, but so far have only be able to grovel and complain). :)

[1]: https://github.com/signalapp/Signal-Android/commit/f36b296e2... [2]: https://whispersystems.discoursehosting.net/t/encrypted-back... [3]: https://github.com/signalapp/Signal-Desktop/issues/522 [4]: https://github.com/signalapp/Signal-Android/pull/7380 [5]: https://whispersystems.discoursehosting.net/t/signal-android...

Re: Signal Foundation

#152
post #3

Earlier quoted context omitted.

Moxie is already working on a cryptocurrency project: https://www.mobilecoin.com/

yes, he's working on Mobilecoin since the beginning. I'm wondering when it will ship and if it will be the first project of the Signal foundation.

Last paragraph in the whitepaper:

> MobileCoin is designed so that a mobile messaging application like WhatsApp, Facebook Messenger, or Signal could integrate with a MobileCoin wallet.

Pretty sure we're gonna see a separate product that works with IM apps when installed simultaneously.

Re: Signal Foundation

#153
post #31

Earlier quoted context omitted.

I think the US still requires cryptography products to be registered with the Department of Commerce, but that's about it for non-military products.

I've tried reading the regulations (but IANAL) and am almost certain that over a key-length for given algorithms its a munition and an export license or similar is required with regular updates. And then still there is the issue of the OFAC banned countries list. I'm hoping Signal's compliance can show other hackers how to also comply without hassle or fear.

I think this is the one: https://www.bis.doc.gov/index.php/documents/regulations-docs...

> You must submit a classification request or self-classification report to BIS for mass market encryption commodities and software eligible for the Cryptography Note employing a key length greater than 64 bits for the symmetric algorithm (or, for commodities and software not implementing any symmetric algorithms, employing a key length greater than 768 bits for asymmetric algorithms or greater than 128 bits for elliptic curve algorithms) in accordance with the requirements of § 740.17(b) of the EAR in order to be released from the “EI” and “NS” controls of ECCN 5A002 or 5D002.

Re: Signal Foundation

#154

I'm hoping they can use some of this cash to make a better desktop client: 1. That can be minimized to the system tray. 2. That can be used when behind an http proxy server. 3. Doesn't require a phone to use. 4. Doesn't take 200MB ram to run.

So, what are you using the 15,800 MB of RAM for?

Running Slack. Gosh

Re: Signal Foundation

#155

I'm hoping they can use some of this cash to make a better desktop client: 1. That can be minimized to the system tray. 2. That can be used when behind an http proxy server. 3. Doesn't require a phone to use. 4. Doesn't take 200MB ram to run.

So, what are you using the 15,800 MB of RAM for?

100 tabs on Chrome?

Re: Signal Foundation

#156
post #71

This is very very good news. As a heavy Signal user, from where I sit I personally see the following clear needs: -Better group support. Right now, to do a group in Signal you have to name the group, which makes it kind of a pain to create ad hoc quick groups. I'm forever naming them "John Sue Bill" or "Jane Roger Amanda". iMessage, by contrast, just automatically makes a group without a name. You get a thread for th…

I'd love to use Signal, but in order for me to do so there's a lot that has to be added. - Real multi device support. I want my messages on all my devices, without having to have my phone on. - An iPad app. - A desktop app. I'd pay for a native one, without Electron. These things are basically table stakes for competing with Facebook Messenger, Telegram, and iMessage. If Signal's goal is to bring encryption to the ma…

> - A desktop app. I'd pay for a native one, without Electron.

I'm working on a native app that supports Signal, Slack, Twitter etc. It's only 90 KB (!).

https://eul.im

*edit Signal support is coming in early March.

Re: Signal Foundation

#157
post #42

Earlier quoted context omitted.

Signal Protocol is one of the best documented cryptographic message protocols on the planet, and is accompanied by multiple GPL'd implementations. https://signal.org/docs/

And yet even the best of the best cryptographic protocols provide little to no value on very insecure systems like iphone and android. It's like bike shedding of security, where Moxi focuses on the things he can do but for the systems where it doesn't matter.

I find it odd that someone would say an iPhone is “very insecure” after the USG, of all players, very publicly couldn’t get into a model from right before the security design hardened, not to mention the also very public panic in the IC about losing access to intelligence due to mobile phone developments. That’s a strange position to tout with the underlying implication that PC platforms are better.

Are you broadening “insecure” to mean “centralized, opinionated security architecture designed for tech-illiterate masses that I don’t like?” Because that isn’t what it means.

Re: Signal Foundation

#158

Earlier quoted context omitted.

And yet even the best of the best cryptographic protocols provide little to no value on very insecure systems like iphone and android. It's like bike shedding of security, where Moxi focuses on the things he can do but for the systems where it doesn't matter.

I find it odd that someone would say an iPhone is “very insecure” after the USG, of all players, very publicly couldn’t get into a model from right before the security design hardened , not to mention the also very public panic in the IC about losing access to intelligence due to mobile phone developments. That’s a strange position to tout with the underlying implication that PC platforms are better. Are you broadeni…

I thought that ended with the government getting into the phone using an exploit, just without forcing Apple's cooperation.

Re: Signal Foundation

#159

Earlier quoted context omitted.

I find it odd that someone would say an iPhone is “very insecure” after the USG, of all players, very publicly couldn’t get into a model from right before the security design hardened , not to mention the also very public panic in the IC about losing access to intelligence due to mobile phone developments. That’s a strange position to tout with the underlying implication that PC platforms are better. Are you broadeni…

I thought that ended with the government getting into the phone using an exploit, just without forcing Apple's cooperation.

Hence the hardened part. That exploit doesn’t work against any later model, and they spent a lot of money to get into that particular phone. Even with that observation, how can one claim “very insecure?” Do you think it’s that difficult to compromise a PC with physical access? What does secure even mean to people any more?

I trust my phone a hell of a lot more than any general purpose computing platform, and I’d say the same if I owned any number of a significant collection of Android devices. This isn’t phone vs. phone advocacy, just annoyance at opinions that people disingenuously consider factual, useful observations on security.

Re: Signal Foundation

#160
post #142
post #76

Earlier quoted context omitted.

Users don’t want federation. See also: Adoption failure of Google Talk XMPP, massive adoption of Facebook Messenger and Whatsapp, and AIM before it. I wish it were different, too.

User want federation. See the adoption of email.

you mean that means of communication where spam problems effectively forced a centralized infrastructure provided by a few providers and that now is relegated to mostly being used as a poor man's notification service?

running your own smtp server these days is painful.

Post reply on HN