Live data from Hacker News

Signal Foundation

signal.org

211–220 of 298 posts

Re: Signal Foundation

#211
As a complete layman, I don't understand why this is different than WhatsApp (they claim to fully encrypt stuff, right? Is it worse than this?). If I don't understand encryption and computers, why should I be sold on this? It seems to be aimed towards CS majors who understand the backend benefits. To an end user, it looks like an ordinary chat app. Am I wrong? This seems to have been heavily upvoted; is there a 10x improvement I'm missing?

Re: Signal Foundation

#212

Earlier quoted context omitted.

I think users would prefer federated systems. Who wouldn't? Even though most people have probably never heard the word before, they almost certainly use and appreciate federated systems like phones and email. Do people want federation enough to have to take a principled stance in order to force change? Heck no. And that's the problem: there's no reasonable way for their desire to impact the producer side of the marke…

“they almost certainly use and appreciate federated systems like phones and email” Two channels which have become saturated with spam and junk once the federated network starts to include players who are willing to permit bad actors to access the network in exchange for money. People enjoy federated networks of regulated, good faith players; wide open federated networks tend towards anarchy.

>People enjoy federated networks of regulated, good faith players; wide open federated networks tend towards anarchy.

Like... email and the phone system? both of those have huge amounts of bad actors and spam, and people still use them as primary means of communication. Email and phone are generally expected to be more reliable, I think, than any of the walled garden communication protocols.

(Speaking of, if you have ideas about curbing phone spam other than keeping the number secret, do let me know.)

Re: Signal Foundation

#213
post #27

Any reason Signal isn't available through F-Droid? It may be unjustified but I'm not a big fan of installing privacy conscious apps through Play. Edit: Wait, haven't installed anything yet, but I read the getting started guide. I have to sign up using a phone number? That throws all expectation of anonymity and thus privacy out the window.

Search for Noise. I believe Copperhead OS is working on a fork that's compatible, but doesn't rely on Google Play Services.

Re: Signal Foundation

#214
post #138

Earlier quoted context omitted.

[ed: aha! They didn't really support federation in a standards compliant way: "However, since the Google Talk Service does not support server-to-server encryption via TLS (something that was required by RFC 3920 in 2004), a number of servers (including jabber.org) refuse to establish a connection since May 2014." https://xmpp.org/2015/03/no-its-not-the-end-of-xmpp-for-goog... I recall there were issues...] Wait, what…

> Wait, what? You could chat from you@example.com on your bespoke xmpp server and send messages to user@gmail without needing a Google account and vice-versa? For some glorious years between 2006 and 2013 (Hangouts), this was indeed possible. I run my own XMPP server and I used to chat with GTalk users all the time. For literally years. > They didn't really support federation in a standards compliant way It was stand…

I remember looking into it, and discovering that it didn't work in a sane way (ie: no server tls support). Why would I want to expose traffic unencrypted? Especially considering dangerous content, like attachments etc.

Now I see that Ms allows federation for on-premise lync - but not for office 365. :-(

Everyone wants their own silo, and force their multitude of awful clients on people.

Re: Signal Foundation

#215
post #212

Earlier quoted context omitted.

“they almost certainly use and appreciate federated systems like phones and email” Two channels which have become saturated with spam and junk once the federated network starts to include players who are willing to permit bad actors to access the network in exchange for money. People enjoy federated networks of regulated, good faith players; wide open federated networks tend towards anarchy.

>People enjoy federated networks of regulated, good faith players; wide open federated networks tend towards anarchy. Like... email and the phone system? both of those have huge amounts of bad actors and spam, and people still use them as primary means of communication. Email and phone are generally expected to be more reliable, I think, than any of the walled garden communication protocols. (Speaking of, if you have…

At least in my country, incoming call filters do wonders, in particular those which query the incoming number at an online database to show you who's the caller.

Re: Signal Foundation

#216

As a complete layman, I don't understand why this is different than WhatsApp (they claim to fully encrypt stuff, right? Is it worse than this?). If I don't understand encryption and computers, why should I be sold on this? It seems to be aimed towards CS majors who understand the backend benefits. To an end user, it looks like an ordinary chat app. Am I wrong? This seems to have been heavily upvoted; is there a 10x i…

While whatsapp messages are, apparently, e2e encrypted - your phonebook and metadata are slurped up by facebook.

Signal does not have that goal and have been shown by courts documents to not store the metadata.

Re: Signal Foundation

#217
post #202

Earlier quoted context omitted.

That's cool. When I tried it last it required my phone to be on just like WhatsApp. I'll check it out again. I still hope they use some of this cash to make a real iPad and Desktop app, though. I'd really love to use the service but those are deal breakers for me.

Signal Desktop has never worked that way. After the initial linking process, Signal Desktop has always functioned independently of your phone being on.

I must be misremembering it. I'd edit my comment but it's timed out.

Re: Signal Foundation

#218

Earlier quoted context omitted.

I thought that ended with the government getting into the phone using an exploit, just without forcing Apple's cooperation.

Only after they paid an Israeli security company for a 0-day vulnerability, which allegedly cost north of $1m. Interested to know how that amount compares to other OSes, I really don't know what the going rate is on Windows/Linux.

And this was a vulnerability that concerned an iPhone 5c, which did not have a secure enclave. The iPhone 5s was the first model with Touch ID and an secure enclave.

https://www.extremetech.com/mobile/226164-fbis-iphone-hack-l...

Re: Signal Foundation

#219

Hm. $50 million when the team has already been successful. Why, when only $1M would suffice? What on earth could $50M do? Remember the old saying: "Mo money mo problems" B.S.

Foundations are supposed to be self sustaining without actually selling anything, so they require large endowments to endure. That $50M could sustainably spit off as much as $2.5M/year, funding ongoing development indefinitely.

Re: Signal Foundation

#220

Since you are in the US how do you keep the US government from interfering with your mission because Signal uses strong encryption? How do you address the EARs (Export Administration Regulations) and ITARs (International Traffic in Arms Regulations)? These regulations look like a tar pit to me.

They don't need to break encryption.

They can just "ask" any of the softkeyboard makers like Swiftkey, Swipe (Rip), Hacker's Keyboard, Google, Apple, Samsung etc.

Post reply on HN