Live data from Hacker News

Signal Foundation

signal.org

181–190 of 298 posts

Re: Signal Foundation

#181
post #170
post #144

Earlier quoted context omitted.

Unfortunately, it looks like the signal people are possibly not friendly to third-party devs and have levied seemingly spurious IP threats against third-party implementations: https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 Obviously this is just one side of the story, but it sounds rather alarming.

I believed this was debunked by moxie somewhere on HN

Would you mind linking it? I've tried to see his past comments but couldn't find anything dated after the blog post on a first look. Just a lot of LibreSignal stuff.

Re: Signal Foundation

#182
post #8

This is freakin' awesome: A non-profit foundation with $50 million in the bank dedicated to providing usable encryption to the general public, with no other agenda other than the public good. Go read the blog post by Moxie and Brian Acton (who is joining Signal). Very exciting!

Morally, how does one weigh the implications of this, in that it will be easier for general citizens to use strong encryption, but also be easier for terrorists/ne'er-do-wells as well?

Re: Signal Foundation

#183
post #76

Earlier quoted context omitted.

Users don’t want federation. See also: Adoption failure of Google Talk XMPP, massive adoption of Facebook Messenger and Whatsapp, and AIM before it. I wish it were different, too.

I think users would prefer federated systems. Who wouldn't? Even though most people have probably never heard the word before, they almost certainly use and appreciate federated systems like phones and email. Do people want federation enough to have to take a principled stance in order to force change? Heck no. And that's the problem: there's no reasonable way for their desire to impact the producer side of the marke…

> I think users would prefer federated systems. Who wouldn't? Even though most people have probably never heard the word before, they almost certainly use and appreciate federated systems like phones and email.

Except that they don't; they mostly use Facebook Messenger, iMessage, and Whatsapp. Those that do use email use gmail, which barely federates (most gmail users never see messages from my personal email address, because google routes them to spam despite my IP never having spammed).

Re: Signal Foundation

#184
post #142
post #76

Earlier quoted context omitted.

Users don’t want federation. See also: Adoption failure of Google Talk XMPP, massive adoption of Facebook Messenger and Whatsapp, and AIM before it. I wish it were different, too.

User want federation. See the adoption of email.

And see the subsequent flocking to APNS, its child iMessage, Firebase Messaging, and Facebook Messenger.

Email is obsolete.

Re: Signal Foundation

#185

Earlier quoted context omitted.

And yet even the best of the best cryptographic protocols provide little to no value on very insecure systems like iphone and android. It's like bike shedding of security, where Moxi focuses on the things he can do but for the systems where it doesn't matter.

I find it odd that someone would say an iPhone is “very insecure” after the USG, of all players, very publicly couldn’t get into a model from right before the security design hardened , not to mention the also very public panic in the IC about losing access to intelligence due to mobile phone developments. That’s a strange position to tout with the underlying implication that PC platforms are better. Are you broadeni…

I would question how much of this was not being able to get into it and how much was a platform for "we need backdoors into everything".

Re: Signal Foundation

#186
post #181
post #170

Earlier quoted context omitted.

I believed this was debunked by moxie somewhere on HN

Would you mind linking it? I've tried to see his past comments but couldn't find anything dated after the blog post on a first look. Just a lot of LibreSignal stuff.

https://news.ycombinator.com/item?id=11727870

Re: Signal Foundation

#188
I hope they rebadge an android phone the way Fairphone has.

Signal would only need to make a small profit to keep it sustainable and that would bring down the handset retail cost pretty significantly. It would be like the Raspberry PI of phones.

Signal guys: if you are toying with this idea, hit me up (email in profile), I've put way too much time into researching how to do this as quickly and miserly as possible.

Re: Signal Foundation

#189
post #138

Earlier quoted context omitted.

[ed: aha! They didn't really support federation in a standards compliant way: "However, since the Google Talk Service does not support server-to-server encryption via TLS (something that was required by RFC 3920 in 2004), a number of servers (including jabber.org) refuse to establish a connection since May 2014." https://xmpp.org/2015/03/no-its-not-the-end-of-xmpp-for-goog... I recall there were issues...] Wait, what…

> Wait, what? You could chat from you@example.com on your bespoke xmpp server and send messages to user@gmail without needing a Google account and vice-versa? For some glorious years between 2006 and 2013 (Hangouts), this was indeed possible. I run my own XMPP server and I used to chat with GTalk users all the time. For literally years. > They didn't really support federation in a standards compliant way It was stand…

Actually, it still worked for existing contacts until half a year or so ago, when they seem to have silently dropped it completely (I haven't really investigated, contacts I had on google simply moved to other servers, that fixed that).
Post reply on HN