Live data from Hacker News

Signal Foundation

signal.org

191–200 of 298 posts

Re: Signal Foundation

#191
That an account is linked to the phone number is the major problem for me because once you are in another country where you can't receive SMS with that number, you need to create a new account! Matrix is more friendly in this regard, but not as good as Signal in terms of privacy features.

Re: Signal Foundation

#194
post #71

This is very very good news. As a heavy Signal user, from where I sit I personally see the following clear needs: -Better group support. Right now, to do a group in Signal you have to name the group, which makes it kind of a pain to create ad hoc quick groups. I'm forever naming them "John Sue Bill" or "Jane Roger Amanda". iMessage, by contrast, just automatically makes a group without a name. You get a thread for th…

I'd love to use Signal, but in order for me to do so there's a lot that has to be added. - Real multi device support. I want my messages on all my devices, without having to have my phone on. - An iPad app. - A desktop app. I'd pay for a native one, without Electron. These things are basically table stakes for competing with Facebook Messenger, Telegram, and iMessage. If Signal's goal is to bring encryption to the ma…

I've slowly been working on a native version for Windows 10, source available here: https://github.com/signal-csharp/Signal-Windows

Re: Signal Foundation

#195
Hm. $50 million when the team has already been successful. Why, when only $1M would suffice? What on earth could $50M do? Remember the old saying: "Mo money mo problems" B.S.

Re: Signal Foundation

#196

Earlier quoted context omitted.

> - A desktop app. I'd pay for a native one, without Electron. I'm working on a native app that supports Signal, Slack, Twitter etc. It's only 90 KB (!). https://eul.im *edit Signal support is coming in early March.

Although you claim Wireshark, etc. can be used to verify the lack of external communication, the fact of the matter is that it only verifies you aren't sending data to third-parties all the time. It does not mean that it won't do so occasionally, or that (say, if triggered via a message in an existing platform) it won't suddenly send your credentials to someone else and then erase its tracks, or do anything more soph…

It will be open-sourced at some point within the next 2 years without a doubt.

Like I explained in the FAQ, the plans and the potential are huge, and it would be really silly to risk it all just to become another data miner. Even if it's very sophisticated, and there's a 0.01% change it's found out, why risk everything? Besides, it's simply illegal. All the information about me and the company is public.

I wonder if you have the same concerns about other closed source software like Sublime Text.

Re: Signal Foundation

#198
post #8

This is freakin' awesome: A non-profit foundation with $50 million in the bank dedicated to providing usable encryption to the general public, with no other agenda other than the public good. Go read the blog post by Moxie and Brian Acton (who is joining Signal). Very exciting!

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

> I hope they eventually develop a federated, privacy oriented messaging protocol, once the rapid technological evolution settles down.

Yes. It's hard to get too excited for the 'expansion' of Yet Another Walled Garden. I say this as a long time user of Signal. It's currently the lesser of most evils, but it still has a lot of room for improvement.

Re: Signal Foundation

#199
post #8

This is freakin' awesome: A non-profit foundation with $50 million in the bank dedicated to providing usable encryption to the general public, with no other agenda other than the public good. Go read the blog post by Moxie and Brian Acton (who is joining Signal). Very exciting!

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

> once the rapid technological evolution settles down

Why wait?

Re: Signal Foundation

#200

Earlier quoted context omitted.

Although you claim Wireshark, etc. can be used to verify the lack of external communication, the fact of the matter is that it only verifies you aren't sending data to third-parties all the time. It does not mean that it won't do so occasionally, or that (say, if triggered via a message in an existing platform) it won't suddenly send your credentials to someone else and then erase its tracks, or do anything more soph…

It will be open-sourced at some point within the next 2 years without a doubt. Like I explained in the FAQ, the plans and the potential are huge, and it would be really silly to risk it all just to become another data miner. Even if it's very sophisticated, and there's a 0.01% change it's found out, why risk everything? Besides, it's simply illegal. All the information about me and the company is public. I wonder if…

> I wonder if you have the same concerns about other closed source software like Sublime Text.

This was an unnecessary personal jab, but I'll respond. Sublime? I don't use it. Software that deals with my credentials just like you do? Yeah, I definitely do. That's why I don't trust closed source password managers either. Text editors? Mine are open source so the thought has never crossed my mind. Other random software like my OS or Visual Studio? Depends; e.g. Microsoft is a huge corporation that has nothing to gain and a lot to lose from keylogging my passwords, but e.g. I wouldn't trust Facebook not to record my audio or fish out my contacts behind my back. Smaller utilities? Yeah, but again, they don't have my credentials at their fingertips, or need Internet access at all for that matter (I turn off auto updates so I can just block internet access for them entirely).

All of which is to say, yeah, I'm not picking on you specifically, but this isn't about me, or about you. I'm just a messenger. Verifiability is the requirement many people have for software that manages their credentials; pinkie promised aren't enough. For some of them, you can make up for some of it by having a big enough reputation to lose, and criminal history to jeopardize in their jurisdictions. For others, you can't. In your case, you don't seem to have that going for you either.

Post reply on HN