Live data from Hacker News

Technology preview: Sealed sender for Signal

signal.org

51–60 of 162 posts

Re: Technology preview: Sealed sender for Signal

#51
post #24

Earlier quoted context omitted.

This is the "Go y u no generics" of secure messaging. The answer is always the same: Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging . The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for…

But... Wire has both! With generics, you introduce complexity into the language that everyone has to understand, but that's obviously not true when it comes to having accounts that aren't tied to phone numbers!

You do have to verify fingerprints individually for each device that a user has. You also have to do it individually for each device that you have.

Re: Technology preview: Sealed sender for Signal

#52
post #26
post #13

I'm not sure I understand the feature. It protects the sender's identity from their servers , or from the recipient ? What's the use case / threat model? I think it prevents their servers from correlating my identity and my IP address etc., but since I want replies and I'm asking the server about replies, doesn't that operation tell the server what my identity is anyway? (There are some comments here talking about an…

It prevents their servers from easily tracking (and, importantly, logging) who sent which messages to whom.

Oh, I see - it effectively hides the fact that a conversation occurred between two participants from their servers. They know that I'm at my IP, they know that you're at your IP, and they know that we're both sending messages, but this feature prevents them from knowing whether we're sending messages to each other.

Re: Technology preview: Sealed sender for Signal

#53

Earlier quoted context omitted.

What is your qualification for "protecting" privacy? Clearly Signal has improved privacy compared to other messaging platforms as has been proven by subpoenas by law enforcement. That, in my mind, qualifies as privacy protection over many other messaging solutions that have not been proven or failed in that arena. Claiming Signal doesn't protect privacy because: phone numbers is an opinion given you haven't qualified…

>Clearly Signal has improved privacy compared to other messaging platforms as has been proven by subpoenas by law enforcement. Secure systems are not built on trust. They're built with math and with facts. Their goal isn't based on what tptacek said just because tptacek said it, either. If I'm wrong and privacy isn't their goal, well that speaks volumes on its own.

Well, a lot of things seem to speak volumes to you. You're also someone who wants to sysadmin their phones (no judgement, perfectly valid lifestyle choice). When you determined that Signal was making it hard to run through F-Droid, you wrote a long blog post casting aspersions on Moxie Marlinspike's motives.

There are two groups of people (among others) Signal clearly doesn't aim to serve:

1. People that are very sensitive about, and only have access to, their one phone number.

2. People who want to sysadmin their phones.

I have perhaps more sympathy for people in group (1), but, unlike you, in neither case do I think the mismatch is a great moral dilemma. I do, however, believe that promoting inferior and untested cryptography is immoral.

https://news.ycombinator.com/item?id=17723973

The two of us are far apart on these issues and perhaps we should just agree not to engage on them.

Re: Technology preview: Sealed sender for Signal

#54
post #48

Earlier quoted context omitted.

Briar is leading the field on privacy issues today, unlike Signal. There is no metadata leaking who you are sending messages to or from, just a connection to the Tor Network. This problem is still unsolved in Signal, with only partial protection of some messages looking to be added in the future, while mitigation tactics like running your own server are unsupported & discouraged by Open Whisper Systems. The post abou…

I am willing to stipulate "short of running everything over Tor" for the sake of argument.

I'm not looking to argue with you, just pointing out the current state of affairs wrt why so many privacy minded, tech aware folks either won't use Signal or choose to move conversations off it as quickly as possible.

The reasons for avoiding Signal (metadata leakage, mandatory phone number usage, questionable 3rd party dependencies, etc) are valid, despite how I often argue to the contrary in favor of getting as many people on Signal as possible and using it for daily communication. Talking common sense to this demographic is hard though, in the context of basic security concerns persisting year after year.

On the flipside, the phone number as identifier issue has caused apps like Kik (super popular among the gay community, despite shit security), Wickr and Wire to become popular among the non-tech demographics, which is extremely disheartening.

Re: Technology preview: Sealed sender for Signal

#55
post #24

Earlier quoted context omitted.

This is the "Go y u no generics" of secure messaging. The answer is always the same: Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging . The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for…

What? Why is sms considered "elite secure messaging", as you put it? They don't have to "solve every problem" but just not asking for a real-world identifier like a phone number. Just ask for an email. It isn't that hard. The whole phone number thing is a massive turn off. Everyone has literally been using email since the advent of the internet. No all of a sudden we have to get sms involved for a service that provid…

Email is a generational thing. Older generations didn't have one. A lot of people getting on the internet today don't have one, either, especially in developing nations. But Android needs one, you say -- they'll get their tech friend or someone at the phone store to login once, so they can access the play store. But that's not secure, you say -- they don't necessarily care about that.

The nice thing about phone numbers is you put them into a non app specific address book, so your friends list is portable.

Re: Technology preview: Sealed sender for Signal

#56
post #49
post #24

Earlier quoted context omitted.

This is the "Go y u no generics" of secure messaging. The answer is always the same: Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging . The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for…

Why do you think there are no "ordinary users" who don't have phone numbers, or don't have them in a manner that Signal needs? For example, it's pretty common for older people (especially in less technologically developed countries) to not have smartphones. I personally know at least one person who can't use Signal because they don't have a smartphone to install it on (but could install it on the desktop, if the desk…

Again, what Signal is trying to do is to create a wholesale replacement for the (vast majority of) messaging traffic that exists now and is addressed by phone numbers.

It's weird to me to see people downplaying this; if they succeed, it will be a monumental achievement, surpassing SSL/TLS in impact to communications.

Re: Technology preview: Sealed sender for Signal

#57
post #53

Earlier quoted context omitted.

>Clearly Signal has improved privacy compared to other messaging platforms as has been proven by subpoenas by law enforcement. Secure systems are not built on trust. They're built with math and with facts. Their goal isn't based on what tptacek said just because tptacek said it, either. If I'm wrong and privacy isn't their goal, well that speaks volumes on its own.

Well, a lot of things seem to speak volumes to you. You're also someone who wants to sysadmin their phones (no judgement, perfectly valid lifestyle choice). When you determined that Signal was making it hard to run through F-Droid, you wrote a long blog post casting aspersions on Moxie Marlinspike's motives. There are two groups of people (among others) Signal clearly doesn't aim to serve: 1. People that are very sen…

>I do, however, believe that promoting inferior and untested cryptography is immoral.

So you're doubling down on the lie I called you out on the first time around, then?

Re: Technology preview: Sealed sender for Signal

#58
post #50

Earlier quoted context omitted.

#2 is part of the trade off for more privacy vs ease of use. this goes all the back to classic pgp

The PGP ecosystem is a pretty great example of what happens when you target unbounded interoperability.

and it’s adoption rate is a great example of what that does to user experience

Re: Technology preview: Sealed sender for Signal

#59
post #52
post #26

Earlier quoted context omitted.

It prevents their servers from easily tracking (and, importantly, logging) who sent which messages to whom.

Oh, I see - it effectively hides the fact that a conversation occurred between two participants from their servers. They know that I'm at my IP, they know that you're at your IP, and they know that we're both sending messages, but this feature prevents them from knowing whether we're sending messages to each other.

Yes. I think there's a subtext here about other messengers, some of which not only log this, but keep it live in a database in order to populate their equivalent of buddy lists.

Re: Technology preview: Sealed sender for Signal

#60
post #48

Earlier quoted context omitted.

I am willing to stipulate "short of running everything over Tor" for the sake of argument.

I'm not looking to argue with you, just pointing out the current state of affairs wrt why so many privacy minded, tech aware folks either won't use Signal or choose to move conversations off it as quickly as possible. The reasons for avoiding Signal (metadata leakage, mandatory phone number usage, questionable 3rd party dependencies, etc) are valid, despite how I often argue to the contrary in favor of getting as man…

Of those issues, I believe only mandatory phone numbers are valid, for what it's worth. And I'm fine with mandatory phone numbers; there are other options for people who have a problem with that.
Post reply on HN