Live data from Hacker News

Signal Foundation

signal.org

291–298 of 298 posts

Re: Signal Foundation

#291
post #204

Earlier quoted context omitted.

Yes. We didn't have each others phone numbers in our contacts. Manually adding by phone number didn't work. At this point we just gave up. I use prepaids because I travel a lot so my mobile numbers are just throwaways. I'd rather not give _all_ of my contacts to an app anyway. So there really should be a way to manage contacts inside the Signal client and add people via screen names or email addresses.

Contact permission is only required to associate a name with a number. All you would need to do is type in a phone number and Signal would have worked. I agree that it would be nice to have another root artifact for using signal (screen name, email, etc). The one frustrating piece about Signal is not being able to use it across mobile devices. However it needs to be considered Signal was originally securing texts via…

Thank you for the explanation.

I'm curious though; what happens if someone takes over your phone number? Eg. If the operator re-assigns a prepaid number?

Re: Signal Foundation

#292
post #210

Earlier quoted context omitted.

Morally, how does one weigh the implications of this, in that it will be easier for general citizens to use strong encryption, but also be easier for terrorists/ne'er-do-wells as well?

Simple. There are more "good people" (people who care about others lives', even if only in small ways) in this world, than "bad people" (people who don't care about others' lives). By a large margin.

By that same logic I assume you don't believe in gun bans, right?

Re: Signal Foundation

#293

Earlier quoted context omitted.

As if reproducible builds hadn't been done before. If Debian can get to building 80% of their packages reproducibly[1], the communities around Android can get there too. Luckily, it's being worked on.[2] Now the question is: (when) will this be supported by F-Droid? [1] Scroll down for a big graph https://wiki.debian.org/ReproducibleBuilds [2] https://github.com/signalapp/Signal-Android/wiki/Reproducibl...

F-Droid has supported reproducible builds for years: https://f-droid.org/en/docs/Reproducible_Builds/ The real question is, when will Signal finally support it?

Nice, thanks for pointing that out!

Re: Signal Foundation

#294
post #183

Earlier quoted context omitted.

I think users would prefer federated systems. Who wouldn't? Even though most people have probably never heard the word before, they almost certainly use and appreciate federated systems like phones and email. Do people want federation enough to have to take a principled stance in order to force change? Heck no. And that's the problem: there's no reasonable way for their desire to impact the producer side of the marke…

> I think users would prefer federated systems. Who wouldn't? Even though most people have probably never heard the word before, they almost certainly use and appreciate federated systems like phones and email. Except that they don't; they mostly use Facebook Messenger, iMessage, and Whatsapp. Those that do use email use gmail, which barely federates (most gmail users never see messages from my personal email address…

> most gmail users never see messages from my personal email address, because google routes them to spam despite my IP never having spammed

This is off topic but very briefly: implement SPF and DKIM and get a number of Gmail users (I'm not sure what this number is, but it is order of magnitude 10) to mark your emails as "Not Spam". Eventually Gmail will come to accept emails from your self-hosted server.

Re: Signal Foundation

#295
post #265

Earlier quoted context omitted.

Especially with crypto, one small implementation error could ruin any security value. It's completely reasonable that they don't want their trademark used with code they aren't responsible for.

Yeah. "You can do whatever you want with our GPL'd code, so long as you follow the license, and we don't have any patents, just don't use our name/branding on stuff we don't control" is a reasonable way to ensure the reputation of your name. It's the same thing Firefox does with Linux distros who want to add their own patches.

> It's the same thing Firefox does with Linux distros who want to add their own patches.

"did", I think. I don't know which distros still run into this, but Debian now ships Firefox (RIP Iceweasel).

Re: Signal Foundation

#296
post #103
post #8

This is freakin' awesome: A non-profit foundation with $50 million in the bank dedicated to providing usable encryption to the general public, with no other agenda other than the public good. Go read the blog post by Moxie and Brian Acton (who is joining Signal). Very exciting!

When you sum it up like that it sounds like a blatant op run by a clandestine agency... Sigh, trust is hard after the crypto wars.

Indeed. You may want to read these pages:

http://secushare.org/comparison

http://secushare.org/anonymity

http://secushare.org/answers

Re: Signal Foundation

#297

Congratulations to moxie and the Signal folks from the Matrix.org team :) The world wouldn't have the increasingly pervasive E2E encryption we enjoy today if not for the double ratchet algorithm, and it's fantastic that they can continue that work as a 501(c)(3)!

>The world wouldn't have the increasingly pervasive E2E encryption we enjoy today if not for the double ratchet algorithm

Too bad the Signal Protocol doesn't actually implement the double ratchet algorithm but a derivative of it that fails to protect metadata making the Signal Protocol leak metadata. Granted, it only leaks metadata leaked by the transport layer anyway, but this makes it pointless to implement the Signal Protocol over something like Tor, i2p or GNUnet.

Post reply on HN