Live data from Hacker News

Signal Foundation

signal.org

221–230 of 298 posts

Re: Signal Foundation

#221
post #71

This is very very good news. As a heavy Signal user, from where I sit I personally see the following clear needs: -Better group support. Right now, to do a group in Signal you have to name the group, which makes it kind of a pain to create ad hoc quick groups. I'm forever naming them "John Sue Bill" or "Jane Roger Amanda". iMessage, by contrast, just automatically makes a group without a name. You get a thread for th…

Completely agreed on all of these (the lack of search, in particular) is just atrocious. I'd also like to see:

- Improved export functionality on all platforms :: I should be able to export my chats in some readable format from any client.

- More clients :: I should be able to read my Signal messages within emacs.

- Support for non-phone-number identifiers :: I shouldn't need to purchase a new phone number in order to get another Signal account. I completely get how valuable this is in limiting certain forms of abuse, but it also limits certain forms of legitimate use (e.g. Haven).

- Better privacy for contacts :: I shouldn't be sending my contacts to Signal's servers. I don't trust Intel's secure enclave technology any more than I trust Intel's ME. There are ways to discover mutual contacts privately.

Re: Signal Foundation

#222
post #186
post #181

Earlier quoted context omitted.

Would you mind linking it? I've tried to see his past comments but couldn't find anything dated after the blog post on a first look. Just a lot of LibreSignal stuff.

https://news.ycombinator.com/item?id=11727870

Extract from that comment:

> We haven't patented any of the concepts here, and we've done a lot to explain and popularize them. We're happy for people to use these concepts to build their own implementations of similar protocols, but we don't want people slapping things together and calling that Signal Protocol.

That doesn't debunk anything in the blog post - it reinforces the point that moxie doesn't want any third-party implementations of the protocol.

Re: Signal Foundation

#223
post #87

Earlier quoted context omitted.

That's an argument for reproducible builds; building the same source should give the same checksum.

The funny part is that Signal and F-Droid both have their own reproducible build system, but they’re incompatible (part of that is that Signal requires proprietary code in its binary)

Can you elaborate more on this? What is the proprietary code used by Signal?

Re: Signal Foundation

#224
post #186

Earlier quoted context omitted.

https://news.ycombinator.com/item?id=11727870

Extract from that comment: > We haven't patented any of the concepts here, and we've done a lot to explain and popularize them. We're happy for people to use these concepts to build their own implementations of similar protocols, but we don't want people slapping things together and calling that Signal Protocol. That doesn't debunk anything in the blog post - it reinforces the point that moxie doesn't want any third-…

It sounds like they'll defend the Signal trademark, but not the implementation concepts. I don't see how that's bad.

Re: Signal Foundation

#225

As a complete layman, I don't understand why this is different than WhatsApp (they claim to fully encrypt stuff, right? Is it worse than this?). If I don't understand encryption and computers, why should I be sold on this? It seems to be aimed towards CS majors who understand the backend benefits. To an end user, it looks like an ordinary chat app. Am I wrong? This seems to have been heavily upvoted; is there a 10x i…

WhatsApp uses the Signal Protocol, so its encryption is the same as this. The Foundation will continue to advance the Signal Protocol, and presumably WhatsApp can benefit from any improvements.

Re: Signal Foundation

#226
post #86

Earlier quoted context omitted.

So why don't they just also list checksum of the F-Droid binary?

They don't trust F-Droid.

Yeah, figured. They seem very inconsistent in applying their trust. At times they'll do strange things like build app on Chrome Apps platform / mandatory phone ID and on other times they'll make user-hostile decisions like hijacking SMS messages and refusing to publish to F-Droid due to "security".

The end result is an app that keeps shooting itself in the foot and being beaten by Messenger and WhatsApp.

Re: Signal Foundation

#227
post #84
post #58

Earlier quoted context omitted.

which sounds like it could be used to develop a federated protocol. I've heard there is an effort to do an RFC on the subject, but I'm not sure it uses the Signal protocols (for some reason), also there are two of them (I'm confused): * https://tools.ietf.org/html/draft-barnes-mls-protocol-00 * https://tools.ietf.org/html/draft-omara-mls-architecture-01

Using OMEMO on XMPP is a federated implementation of the Signal protocol. I believe Matrix' e2e encryption is also based on it.

I’m really hoping OMEMO makes it into Openfire (XMPP Server) and Adium (XMPP Client) sooner rather than later, we current use OTR but OMEMO is objectively superior in every way I can see.

Re: Signal Foundation

#228
post #216

As a complete layman, I don't understand why this is different than WhatsApp (they claim to fully encrypt stuff, right? Is it worse than this?). If I don't understand encryption and computers, why should I be sold on this? It seems to be aimed towards CS majors who understand the backend benefits. To an end user, it looks like an ordinary chat app. Am I wrong? This seems to have been heavily upvoted; is there a 10x i…

While whatsapp messages are, apparently, e2e encrypted - your phonebook and metadata are slurped up by facebook. Signal does not have that goal and have been shown by courts documents to not store the metadata.

The Signal app asks for a ton of permissions. Apparently this isn't decentralized either, so how is it different than Facebook? Did they prove it was mathematically hard/impossible for them to see any of the (meta)data? Have they proven that they are a 100% oblivious broker?

Re: Signal Foundation

#229
post #224

Earlier quoted context omitted.

Extract from that comment: > We haven't patented any of the concepts here, and we've done a lot to explain and popularize them. We're happy for people to use these concepts to build their own implementations of similar protocols, but we don't want people slapping things together and calling that Signal Protocol. That doesn't debunk anything in the blog post - it reinforces the point that moxie doesn't want any third-…

It sounds like they'll defend the Signal trademark, but not the implementation concepts. I don't see how that's bad.

Especially with crypto, one small implementation error could ruin any security value. It's completely reasonable that they don't want their trademark used with code they aren't responsible for.

Re: Signal Foundation

#230
I hate to be the one naysayer, but it seems to me like the benefits of this influx of funding and scope has very few tangible benefits, while predisposing them to a standard failure mode of large and well-funded tech activist organisations where the means (the organisation) are confused for and eventually put ahead of whatever goal they were founded for: see e.g. Mozilla support for EME, the continuing negative news pertaining to Pocket and trying to collect user data. (On the ground, part of the problem may be something of the form: imagine you are the CEO of $foundation, are employing dozens of people and hundreds of volunteers who you have to keep motivated and now you are supposed to tell them they can't do the one thing that might keep their employer going and relevant just because of some philosophical considerations about how compatible it is with the core mission.)
Post reply on HN