Live data from Hacker News

Technology preview: Sealed sender for Signal

signal.org

31–40 of 162 posts

Re: Technology preview: Sealed sender for Signal

#31
post #29

Earlier quoted context omitted.

No, it's not. By requiring a phone number, Signal does not defend privacy. This is a binary question, there's not a grey area here. It doesn't matter that they're building a social network, or anything else. What matters is that it's not private so long as they require a phone number.

I'm not sure what was unclear about my summary of what Signal is doing. Here, let me put it differently for you: Signal's goal is to make all the messaging in the world that currently uses phone numbers as identifiers --- which, by a long ways, is most messaging in the world --- cryptographically secure. Hope that helps. You are welcome to have and to advocate for different goals. Please don't pretend your goals are…

>Signal's goal is to make all the messaging in the world that currently uses phone numbers as identifiers --- which, by a long ways, is most messaging in the world --- cryptographically secure.

This is a better explanation. However, these goals do not protect privacy. If Signal's main goal is to protect privacy, then they need to change their secondary goals to accomodate it.

Re: Technology preview: Sealed sender for Signal

#32
post #24

Here's an idea, Signal, how about removing the requirement that everything be tied to phone numbers? BBM back in the day worked great with their unique "PINs", that could be shared by QR code, and I could reject an "add" request.

This is the "Go y u no generics" of secure messaging. The answer is always the same: Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging . The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for…

What? Why is sms considered "elite secure messaging", as you put it? They don't have to "solve every problem" but just not asking for a real-world identifier like a phone number. Just ask for an email. It isn't that hard. The whole phone number thing is a massive turn off. Everyone has literally been using email since the advent of the internet. No all of a sudden we have to get sms involved for a service that provides secure messaging? Replacing phone number with email doesn't suddenly make it "elite".

Re: Technology preview: Sealed sender for Signal

#33

How does signal do media messages? All the time i'll open signal and see someone sent a picture but I have to download it. If signal doesn't store anything on it's own servers but ip and timestamp, where is this media message stored after it's sent but before I received? Am I just downloading it from the device that sent it to me? That would explain why it's so unreliable.

"Unreliable" - It's not. I've been using it since the early RedPhone and TextSecure days. The only times it's been remotely unreliable is because of my connectivity. I can say I've never had either a lost picture or file sent to me that I can recall. My family and circle of friends (~40 people) use it daily. I just transferred my backup from my old phone to a new one (which by the way thank you for implementing real…

Sorry but you must see how that's obviously jumping to conclusions. Just because you haven't had issues with Signal doesn't mean it's reliable.

I have been using it for 3 years and struggle to recommend it to people because I constantly have reliability issues, including messages delayed for hours, bugs where contacts get in an unusable state and other little weird things.

Whatsapp doesn't have these issues, so even if it's due to not being online 100% of the time, Signal should deal with it.

Re: Technology preview: Sealed sender for Signal

#35
post #24

Earlier quoted context omitted.

This is the "Go y u no generics" of secure messaging. The answer is always the same: Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging . The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for…

What? Why is sms considered "elite secure messaging", as you put it? They don't have to "solve every problem" but just not asking for a real-world identifier like a phone number. Just ask for an email. It isn't that hard. The whole phone number thing is a massive turn off. Everyone has literally been using email since the advent of the internet. No all of a sudden we have to get sms involved for a service that provid…

He’s presumably talking about WhatsApp

Re: Technology preview: Sealed sender for Signal

#36

How does signal do media messages? All the time i'll open signal and see someone sent a picture but I have to download it. If signal doesn't store anything on it's own servers but ip and timestamp, where is this media message stored after it's sent but before I received? Am I just downloading it from the device that sent it to me? That would explain why it's so unreliable.

It stores encrypted messages server side until all of your devices have downloaded it or some time period has passed (not sure how long, based on my limited observations, maybe around a month?).

About having to click on images to download them: it should automatically download pictures unless you don't have the sender in your contacts. Auto downloading on cellualr networks might be disabled by default though.

Re: Technology preview: Sealed sender for Signal

#37
post #29

Earlier quoted context omitted.

I'm not sure what was unclear about my summary of what Signal is doing. Here, let me put it differently for you: Signal's goal is to make all the messaging in the world that currently uses phone numbers as identifiers --- which, by a long ways, is most messaging in the world --- cryptographically secure. Hope that helps. You are welcome to have and to advocate for different goals. Please don't pretend your goals are…

>Signal's goal is to make all the messaging in the world that currently uses phone numbers as identifiers --- which, by a long ways, is most messaging in the world --- cryptographically secure. This is a better explanation. However, these goals do not protect privacy. If Signal's main goal is to protect privacy, then they need to change their secondary goals to accomodate it.

What is your qualification for "protecting" privacy? Clearly Signal has improved privacy compared to other messaging platforms as has been proven by subpoenas by law enforcement. That, in my mind, qualifies as privacy protection over many other messaging solutions that have not been proven or failed in that arena.

Claiming Signal doesn't protect privacy because: phone numbers is an opinion given you haven't qualified your argument.

Finally their goal is not predicated on what you claim just because you claim it. You're effectively creating a false argument so you can justify your position.

Re: Technology preview: Sealed sender for Signal

#38

Earlier quoted context omitted.

>Signal's goal is to make all the messaging in the world that currently uses phone numbers as identifiers --- which, by a long ways, is most messaging in the world --- cryptographically secure. This is a better explanation. However, these goals do not protect privacy. If Signal's main goal is to protect privacy, then they need to change their secondary goals to accomodate it.

What is your qualification for "protecting" privacy? Clearly Signal has improved privacy compared to other messaging platforms as has been proven by subpoenas by law enforcement. That, in my mind, qualifies as privacy protection over many other messaging solutions that have not been proven or failed in that arena. Claiming Signal doesn't protect privacy because: phone numbers is an opinion given you haven't qualified…

>Clearly Signal has improved privacy compared to other messaging platforms as has been proven by subpoenas by law enforcement.

Secure systems are not built on trust. They're built with math and with facts.

Their goal isn't based on what tptacek said just because tptacek said it, either. If I'm wrong and privacy isn't their goal, well that speaks volumes on its own.

Re: Technology preview: Sealed sender for Signal

#39

Earlier quoted context omitted.

"Unreliable" - It's not. I've been using it since the early RedPhone and TextSecure days. The only times it's been remotely unreliable is because of my connectivity. I can say I've never had either a lost picture or file sent to me that I can recall. My family and circle of friends (~40 people) use it daily. I just transferred my backup from my old phone to a new one (which by the way thank you for implementing real…

Sorry but you must see how that's obviously jumping to conclusions. Just because you haven't had issues with Signal doesn't mean it's reliable. I have been using it for 3 years and struggle to recommend it to people because I constantly have reliability issues, including messages delayed for hours, bugs where contacts get in an unusable state and other little weird things. Whatsapp doesn't have these issues, so even…

I'm not jumping to conclusions. For a product to have millions of users and no long term, outstanding, unfixed issues in their repo I don't seem to see the validity in your claim. Claiming it's Signal because your WhatsApp works is, obviously, jumping to conclusions.

Can you provide any issue you've submitted from years ago that hasn't been addressed? Please post it, I'd like to see.

Re: Technology preview: Sealed sender for Signal

#40
post #21
post #4

Can the URL be changed to the Signal blog post at https://signal.org/blog/sealed-sender ?

Yes, I don’t understand why TechCrunch blogspam is exempt from the normal original source rules. They don’t add any value and reduce the amount of information.

is exempt from the normal original source rules.

It's not. But if you want something fixed/looked into, your best bet is emailing the admins. They're super-responsive.

Post reply on HN