Live data from Hacker News

Signal Foundation

signal.org

261–270 of 298 posts

Re: Signal Foundation

#261
post #75

Earlier quoted context omitted.

This is 100% false. EVERYTHING that goes over the wire is encrypted, always, just like when you're on a TLS website such as your bank. Group chats aren't end-to-end encrypted, and 1 on 1 chats are only end-to-end encrypted if you make it a Secret Chat.

Did you really think they were talking about SSL in this context? Of course they meant E2E.

To say there's no encryption AT ALL when it's fully encrypted over the wire is still false. Not having E2E encryption is different than not having encryption AT ALL.

Re: Signal Foundation

#262
post #8

This is freakin' awesome: A non-profit foundation with $50 million in the bank dedicated to providing usable encryption to the general public, with no other agenda other than the public good. Go read the blog post by Moxie and Brian Acton (who is joining Signal). Very exciting!

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

> Signal is indeed an open protocol.

The Signal protocol is public, but not open. It is a proprietary protocol which is controlled entirely by the company behind Signal.

Re: Signal Foundation

#263
post #186

Earlier quoted context omitted.

https://news.ycombinator.com/item?id=11727870

Extract from that comment: > We haven't patented any of the concepts here, and we've done a lot to explain and popularize them. We're happy for people to use these concepts to build their own implementations of similar protocols, but we don't want people slapping things together and calling that Signal Protocol. That doesn't debunk anything in the blog post - it reinforces the point that moxie doesn't want any third-…

Did you read the license?

Re: Signal Foundation

#264
post #75
post #44

Earlier quoted context omitted.

Telegram isn't remotely similar to Signal. Telegram communications aren't encrypted by default, and Telegram group chat messages aren't encrypted at all .

This is 100% false. EVERYTHING that goes over the wire is encrypted, always, just like when you're on a TLS website such as your bank. Group chats aren't end-to-end encrypted, and 1 on 1 chats are only end-to-end encrypted if you make it a Secret Chat.

So, it's similar to Facebook Messenger rather than to Signal?

(Actually I think Messenger might support E2EE group chats, but I'm not sure.)

Re: Signal Foundation

#265
post #224

Earlier quoted context omitted.

It sounds like they'll defend the Signal trademark, but not the implementation concepts. I don't see how that's bad.

Especially with crypto, one small implementation error could ruin any security value. It's completely reasonable that they don't want their trademark used with code they aren't responsible for.

Yeah. "You can do whatever you want with our GPL'd code, so long as you follow the license, and we don't have any patents, just don't use our name/branding on stuff we don't control" is a reasonable way to ensure the reputation of your name. It's the same thing Firefox does with Linux distros who want to add their own patches.

Re: Signal Foundation

#266
post #100

Earlier quoted context omitted.

I think users would prefer federated systems. Who wouldn't? Even though most people have probably never heard the word before, they almost certainly use and appreciate federated systems like phones and email. Do people want federation enough to have to take a principled stance in order to force change? Heck no. And that's the problem: there's no reasonable way for their desire to impact the producer side of the marke…

> Now most people don't even use those kinds of consolidation apps either, and resign themselves to literally running many separate apps. IMO that is really one personal hell for me. I blame android and apple for this. I was happy with my N900 where you got one chat application that supported SMS, Skype, XMPP, AIM, ICQ, whatever. The world was so simple back then. Now everything has to be a separate "app", where prev…

Pidgin (formerly known as GAIM) and its subproject libpurple is the one to thank for. Telepathy [1] and Bitlbee [2] are based on that. I used all of these throughout the '00s. Before the Nokia N900, I used a Nokia E71 with Nimbuzz (basically proprietary but it runs something like Bitlbee under the hood on their servers).

Some of these protocols are open, some are reverse engineered. Problem with the current generation is that they're focussed much more on security features such as E2EE. Although before GAIM, we had other applications which did multiple protocols we also had loads of single purpose applications for all these protocols you mentioned and a whole lot more. Back in the end of '90s if you wanted to run MSN and ICQ and AIM on Windows, you had to use a client for each of these. Its basically a cat and mouse game. Look at the history of the Skype support for an example of that.

[1] https://telepathy.freedesktop.org/

[2] https://www.bitlbee.org

Re: Signal Foundation

#267

Earlier quoted context omitted.

I'd love to use Signal, but in order for me to do so there's a lot that has to be added. - Real multi device support. I want my messages on all my devices, without having to have my phone on. - An iPad app. - A desktop app. I'd pay for a native one, without Electron. These things are basically table stakes for competing with Facebook Messenger, Telegram, and iMessage. If Signal's goal is to bring encryption to the ma…

> - A desktop app. I'd pay for a native one, without Electron. I'm working on a native app that supports Signal, Slack, Twitter etc. It's only 90 KB (!). https://eul.im *edit Signal support is coming in early March.

Thank you so much for this, I can't wait to try out the Linux version. Are you using GTK+ for the UI on Linux? Your website does not specify.

I'm asking because high-dpi support on Linux/Wayland is constantly problematic for desktop applications that don't use GTK+ 3 or Qt.

Re: Signal Foundation

#268
post #267

Earlier quoted context omitted.

> - A desktop app. I'd pay for a native one, without Electron. I'm working on a native app that supports Signal, Slack, Twitter etc. It's only 90 KB (!). https://eul.im *edit Signal support is coming in early March.

Thank you so much for this, I can't wait to try out the Linux version. Are you using GTK+ for the UI on Linux? Your website does not specify. I'm asking because high-dpi support on Linux/Wayland is constantly problematic for desktop applications that don't use GTK+ 3 or Qt.

GTK+ 3, yes.

Re: Signal Foundation

#269
post #183

Earlier quoted context omitted.

> I think users would prefer federated systems. Who wouldn't? Even though most people have probably never heard the word before, they almost certainly use and appreciate federated systems like phones and email. Except that they don't; they mostly use Facebook Messenger, iMessage, and Whatsapp. Those that do use email use gmail, which barely federates (most gmail users never see messages from my personal email address…

What we've seen isn't users showing how they feel about federated systems, it's users being forced into walled gardens as closed systems added support for open systems, but open systems could not reciprocate, and the market adjusted. If your choice as a user is to buy an iPhone that can communicate with your Apple friends over imessage and Android friends over hangouts, or buy an android phone and not access anyone t…

" it's users being forced into walled gardens as closed systems added support for open systems, but open systems could not reciprocate, and the market adjusted."

We haven't seen users forced to do much of anything. In general, there's multiple ways of achieving their goals. They almost always pick either a proprietary company that likes lock-in or a free, ad-driven solution that sells them out. They neither take time to understand the consequences of that ahead of time nor cared enough to switch in the years I've explained it to hundreds (thousands?) of them. Very, very few would switch. And for social media, it's usually a network effect they're joining where stadiums worth of people would have to switch at once or close together to avoid chicken-and-egg problem. They could collectively use open standards to communicate like open-source IM and buddy lists but most don't given they'll sacrifice control of their data and privacy for convenience.

There is a market effect like you describe where the suppliers benefit from lock-in. That's been steady a long time with even the open standards often intended to catch new customers in lock-in in other ways. On the demand side, though, the masses haven't used open-source as a factor in their purchasing much at all. So, it's not even a differentiator on their end for most suppliers to target. The market didn't even adjust: it defaulted on lock-in strategies for owners' benefit with companies occasionally experimenting with other methods they sometimes reversed.

Re: Signal Foundation

#270

Earlier quoted context omitted.

And the only reason Bitcoin is interesting is because "we" have effectively communicated, correctly or otherwise, that there's value in cryptocurrencies.

The overwhelming majority of people use Bitcoin and other cryptocurrencies through exchanges, they have no interest or knowledge of technical details. So it's not like technical communication has won here, more like greed and ease of use.

I agree with this completely! Bitcoin evangelist Trace Mayer always harps on keeping your private keys and not using exchanges to hold large amounts of coins. And Mayer's an investor in Kraken, one of the big exchanges. I have taught my friends this and they all had interest in it, but some skeptical if they trusted in themself enough to hold onto their coins offline.
Post reply on HN