Live data from Hacker News

Signal Foundation

signal.org

231–240 of 298 posts

Re: Signal Foundation

#231
post #100

Earlier quoted context omitted.

I think users would prefer federated systems. Who wouldn't? Even though most people have probably never heard the word before, they almost certainly use and appreciate federated systems like phones and email. Do people want federation enough to have to take a principled stance in order to force change? Heck no. And that's the problem: there's no reasonable way for their desire to impact the producer side of the marke…

> Now most people don't even use those kinds of consolidation apps either, and resign themselves to literally running many separate apps. IMO that is really one personal hell for me. I blame android and apple for this. I was happy with my N900 where you got one chat application that supported SMS, Skype, XMPP, AIM, ICQ, whatever. The world was so simple back then. Now everything has to be a separate "app", where prev…

As a former user of N900 I get your point, but frankly I don't mind at all. For me it makes no difference if I need to open one app or another, it's the same amount of tapping. So I'm in the camp who wouldn't mind federation, but won't bother to lift a finger for it either.

Re: Signal Foundation

#232
post #84

Earlier quoted context omitted.

Using OMEMO on XMPP is a federated implementation of the Signal protocol. I believe Matrix' e2e encryption is also based on it.

I’m really hoping OMEMO makes it into Openfire (XMPP Server) and Adium (XMPP Client) sooner rather than later, we current use OTR but OMEMO is objectively superior in every way I can see.

In general, servers should have nothing to do with end-to-end encryption, except for not actively breaking it.

OMEMO in particular uses:

- Personal Eventing Protocol (PEP, XEP-0163) to transport key material; and

- core RFC3920/RFC6120 XMPP protocol to transport encrypted messages.

Both of which are already supported by Openfire [see JM-1122]. So, as far as I can tell, Openfire is fully capable of delivering OMEMO messages right now.

https://issues.igniterealtime.org/browse/JM-1122

[EDIT] For Adium OMEMO support, have a look at Lurch: https://github.com/shtrom/Lurch4Adium

Re: Signal Foundation

#233

I don’t think I feel good about this. The comments are nice and seem true, but whenever there is so much money involved, even a non profit label I would be suspicious. Are all funding and allocations going to be made public for the organization? People always seem to have a hidden self interest, especially when money is involved.

I'm neutral, but I was never convinced by Signal's PR pieces. Call me a skeptic but a lucrative field like messaging is always about money. Signal's gimmick was privacy to gain market share, but even if they had a slight edge there back then, the majority did care.

even a non profit label I would be suspicious

Could be about account optimization purposes. The 50M funding was probably deducted from taxes to begin with.

Re: Signal Foundation

#234
post #230

I hate to be the one naysayer, but it seems to me like the benefits of this influx of funding and scope has very few tangible benefits, while predisposing them to a standard failure mode of large and well-funded tech activist organisations where the means (the organisation) are confused for and eventually put ahead of whatever goal they were founded for: see e.g. Mozilla support for EME, the continuing negative news…

It's easier to criticize than it is to build.

Mozilla has been doing a lot of awesome stuff and people keep forgetting that their direct competition and threat are Google, Apple and Microsoft, the world's largest tech companies. Mozilla basically had no choice with EME, but to comply.

When the majority of HN's userbase has been using Chrome for years, power users, nay, freaking developers which should know what EME means, when Chrome is approaching the monopoly of IExplorer, good luck selling your values to the general public, who don't give a shit as long as their Netflix stream ain't working.

Open Whisper Systems has been delivering the best encrypted chat protocol to the masses, their tech being used now in WhatsApp for example.

So you can be the naysayer, but IMO these foundations are building and releasing products with a measurable positive impact on the world, whereas most of us here don't ;-)

Re: Signal Foundation

#235
post #58
post #42

Earlier quoted context omitted.

Signal Protocol is one of the best documented cryptographic message protocols on the planet, and is accompanied by multiple GPL'd implementations. https://signal.org/docs/

which sounds like it could be used to develop a federated protocol. I've heard there is an effort to do an RFC on the subject, but I'm not sure it uses the Signal protocols (for some reason), also there are two of them (I'm confused): * https://tools.ietf.org/html/draft-barnes-mls-protocol-00 * https://tools.ietf.org/html/draft-omara-mls-architecture-01

Do you consider SMS a federated protocol?

https://silence.im/

Re: Signal Foundation

#236
post #223
post #87

Earlier quoted context omitted.

The funny part is that Signal and F-Droid both have their own reproducible build system, but they’re incompatible (part of that is that Signal requires proprietary code in its binary)

Can you elaborate more on this? What is the proprietary code used by Signal?

They link several proprietary libraries into their APK, including GCM (which has its own internal analytics package)

Re: Signal Foundation

#237
post #142

Earlier quoted context omitted.

User want federation. See the adoption of email.

you mean that means of communication where spam problems effectively forced a centralized infrastructure provided by a few providers and that now is relegated to mostly being used as a poor man's notification service? running your own smtp server these days is painful.

Not that painful (speaking from experience of running one).

Re: Signal Foundation

#238
post #71

This is very very good news. As a heavy Signal user, from where I sit I personally see the following clear needs: -Better group support. Right now, to do a group in Signal you have to name the group, which makes it kind of a pain to create ad hoc quick groups. I'm forever naming them "John Sue Bill" or "Jane Roger Amanda". iMessage, by contrast, just automatically makes a group without a name. You get a thread for th…

Completely agreed on all of these (the lack of search, in particular) is just atrocious. I'd also like to see: - Improved export functionality on all platforms :: I should be able to export my chats in some readable format from any client. - More clients :: I should be able to read my Signal messages within emacs. - Support for non-phone-number identifiers :: I shouldn't need to purchase a new phone number in order t…

> There are ways to discover mutual contacts privately.

Such as? I don't have the URL handy but the Signal team did investigate the literature and known techniques for this a few years ago and found them to be nonviable.

Re: Signal Foundation

#239

Earlier quoted context omitted.

I've assimilated most friends and all family very easily by educating them about the why. Not to mention if you're a parent explicitly banning sharing of photos with relatives via social media. People accept any small inconvenience or lack of feature quickly. But at this point I'm not following on the "so behind" comment. Care to elaborate?

It's small things like gif/emoji support, @-ing people with their nickname/username sends them a dedicated notification on facebook messenger. As much as I hate fb, messenger is a pretty decent application.

Signal has both gif and emoji support.

Re: Signal Foundation

#240
post #230

I hate to be the one naysayer, but it seems to me like the benefits of this influx of funding and scope has very few tangible benefits, while predisposing them to a standard failure mode of large and well-funded tech activist organisations where the means (the organisation) are confused for and eventually put ahead of whatever goal they were founded for: see e.g. Mozilla support for EME, the continuing negative news…

It's easier to criticize than it is to build. Mozilla has been doing a lot of awesome stuff and people keep forgetting that their direct competition and threat are Google, Apple and Microsoft, the world's largest tech companies. Mozilla basically had no choice with EME, but to comply. When the majority of HN's userbase has been using Chrome for years, power users, nay, freaking developers which should know what EME m…

I understand the case in the case of Mozilla, because a browser is an intrinsically absurdly complex product. In the case of Signal, the benefits of having a foundation like that seem unclear to me. What exactly is it that they want to do but couldn't before they had a $50m foundation? The linked page seems very vague about this.
Post reply on HN