Earlier quoted context omitted.
This is the "Go y u no generics" of secure messaging. The answer is always the same: Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging . The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for…
But... Wire has both! With generics, you introduce complexity into the language that everyone has to understand, but that's obviously not true when it comes to having accounts that aren't tied to phone numbers!
Technology preview: Sealed sender for Signal
51–60 of 162 posts
Re: Technology preview: Sealed sender for Signal
#52I'm not sure I understand the feature. It protects the sender's identity from their servers , or from the recipient ? What's the use case / threat model? I think it prevents their servers from correlating my identity and my IP address etc., but since I want replies and I'm asking the server about replies, doesn't that operation tell the server what my identity is anyway? (There are some comments here talking about an…
It prevents their servers from easily tracking (and, importantly, logging) who sent which messages to whom.
Re: Technology preview: Sealed sender for Signal
#53Earlier quoted context omitted.
What is your qualification for "protecting" privacy? Clearly Signal has improved privacy compared to other messaging platforms as has been proven by subpoenas by law enforcement. That, in my mind, qualifies as privacy protection over many other messaging solutions that have not been proven or failed in that arena. Claiming Signal doesn't protect privacy because: phone numbers is an opinion given you haven't qualified…
>Clearly Signal has improved privacy compared to other messaging platforms as has been proven by subpoenas by law enforcement. Secure systems are not built on trust. They're built with math and with facts. Their goal isn't based on what tptacek said just because tptacek said it, either. If I'm wrong and privacy isn't their goal, well that speaks volumes on its own.
There are two groups of people (among others) Signal clearly doesn't aim to serve:
1. People that are very sensitive about, and only have access to, their one phone number.
2. People who want to sysadmin their phones.
I have perhaps more sympathy for people in group (1), but, unlike you, in neither case do I think the mismatch is a great moral dilemma. I do, however, believe that promoting inferior and untested cryptography is immoral.
https://news.ycombinator.com/item?id=17723973
The two of us are far apart on these issues and perhaps we should just agree not to engage on them.
Re: Technology preview: Sealed sender for Signal
#54Earlier quoted context omitted.
Briar is leading the field on privacy issues today, unlike Signal. There is no metadata leaking who you are sending messages to or from, just a connection to the Tor Network. This problem is still unsolved in Signal, with only partial protection of some messages looking to be added in the future, while mitigation tactics like running your own server are unsupported & discouraged by Open Whisper Systems. The post abou…
I am willing to stipulate "short of running everything over Tor" for the sake of argument.
The reasons for avoiding Signal (metadata leakage, mandatory phone number usage, questionable 3rd party dependencies, etc) are valid, despite how I often argue to the contrary in favor of getting as many people on Signal as possible and using it for daily communication. Talking common sense to this demographic is hard though, in the context of basic security concerns persisting year after year.
On the flipside, the phone number as identifier issue has caused apps like Kik (super popular among the gay community, despite shit security), Wickr and Wire to become popular among the non-tech demographics, which is extremely disheartening.
Re: Technology preview: Sealed sender for Signal
#55Earlier quoted context omitted.
This is the "Go y u no generics" of secure messaging. The answer is always the same: Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging . The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for…
What? Why is sms considered "elite secure messaging", as you put it? They don't have to "solve every problem" but just not asking for a real-world identifier like a phone number. Just ask for an email. It isn't that hard. The whole phone number thing is a massive turn off. Everyone has literally been using email since the advent of the internet. No all of a sudden we have to get sms involved for a service that provid…
The nice thing about phone numbers is you put them into a non app specific address book, so your friends list is portable.
Re: Technology preview: Sealed sender for Signal
#56Earlier quoted context omitted.
This is the "Go y u no generics" of secure messaging. The answer is always the same: Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging . The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for…
Why do you think there are no "ordinary users" who don't have phone numbers, or don't have them in a manner that Signal needs? For example, it's pretty common for older people (especially in less technologically developed countries) to not have smartphones. I personally know at least one person who can't use Signal because they don't have a smartphone to install it on (but could install it on the desktop, if the desk…
It's weird to me to see people downplaying this; if they succeed, it will be a monumental achievement, surpassing SSL/TLS in impact to communications.
Re: Technology preview: Sealed sender for Signal
#57Earlier quoted context omitted.
>Clearly Signal has improved privacy compared to other messaging platforms as has been proven by subpoenas by law enforcement. Secure systems are not built on trust. They're built with math and with facts. Their goal isn't based on what tptacek said just because tptacek said it, either. If I'm wrong and privacy isn't their goal, well that speaks volumes on its own.
Well, a lot of things seem to speak volumes to you. You're also someone who wants to sysadmin their phones (no judgement, perfectly valid lifestyle choice). When you determined that Signal was making it hard to run through F-Droid, you wrote a long blog post casting aspersions on Moxie Marlinspike's motives. There are two groups of people (among others) Signal clearly doesn't aim to serve: 1. People that are very sen…
So you're doubling down on the lie I called you out on the first time around, then?
Re: Technology preview: Sealed sender for Signal
#58Earlier quoted context omitted.
#2 is part of the trade off for more privacy vs ease of use. this goes all the back to classic pgp
The PGP ecosystem is a pretty great example of what happens when you target unbounded interoperability.
Re: Technology preview: Sealed sender for Signal
#59Earlier quoted context omitted.
It prevents their servers from easily tracking (and, importantly, logging) who sent which messages to whom.
Oh, I see - it effectively hides the fact that a conversation occurred between two participants from their servers. They know that I'm at my IP, they know that you're at your IP, and they know that we're both sending messages, but this feature prevents them from knowing whether we're sending messages to each other.
Re: Technology preview: Sealed sender for Signal
#60Earlier quoted context omitted.
I am willing to stipulate "short of running everything over Tor" for the sake of argument.
I'm not looking to argue with you, just pointing out the current state of affairs wrt why so many privacy minded, tech aware folks either won't use Signal or choose to move conversations off it as quickly as possible. The reasons for avoiding Signal (metadata leakage, mandatory phone number usage, questionable 3rd party dependencies, etc) are valid, despite how I often argue to the contrary in favor of getting as man…