Live data from Hacker News

Technology preview: Sealed sender for Signal

signal.org

101–110 of 162 posts

Re: Technology preview: Sealed sender for Signal

#101
post #56
post #49

Earlier quoted context omitted.

Why do you think there are no "ordinary users" who don't have phone numbers, or don't have them in a manner that Signal needs? For example, it's pretty common for older people (especially in less technologically developed countries) to not have smartphones. I personally know at least one person who can't use Signal because they don't have a smartphone to install it on (but could install it on the desktop, if the desk…

Again, what Signal is trying to do is to create a wholesale replacement for the (vast majority of) messaging traffic that exists now and is addressed by phone numbers. It's weird to me to see people downplaying this; if they succeed, it will be a monumental achievement, surpassing SSL/TLS in impact to communications.

Interestingly, you're always in these threads arguing forcefully that some feature that might improve user anonymity is bad or dismissible for nearly any reason. You both have a lot of time to spend commenting, as well as a rapid-response opinion that's consistently about slowing the rate of anonymity. Why is that exactly?

Re: Technology preview: Sealed sender for Signal

#102
post #23

Two observations: 1. You should look into what other messengers do with sender/receiver pairs information. One very popular competing messenger logs pairs permanently, serverside, in order to make UI features work. 2. One of the least popular attributes of Signal (on Hacker News, at least) is its lack of federation and ability to interoperate with third-party clients. This feature is a pretty crystalline example of t…

>This feature is a pretty crystalline example of the kind of protocol change you can make when you control all the mainstream clients, and that would be an absolute nightmare for a protocol where you didn't.

If the feature is well-documented, and you announce it well-ahead of final release, why? Anyone who is actively maintaining their client can add the feature. Those who aren't will either be forked or die. Nobody said it was on the core product to update third party clients. See: AIM/ICQ and trillian.

Re: Technology preview: Sealed sender for Signal

#103
post #90
post #24

Earlier quoted context omitted.

This is the "Go y u no generics" of secure messaging. The answer is always the same: Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging . The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for…

> This is the "Go y u no generics" of secure messaging. Yes, it is – and it turns out that Go 2 will be adding generics. Before that, you could have said "If generics are super-important to you, use Rust." But it turns out you can have both Go and generics, and (if you prefer Go over Rust for other reasons) that's even better than having to pick one or the other. The designers made a choice to omit generics in the in…

Generics in Go, even as proposed, would not be without some trade-offs in readability and orthogonality with interfaces. These are things Go currently excels at.

Its easy to imagine that adding an alternative UX in Signal for non-phone based contacts might complicate user flows. Creating a user-flow for alternative contact discovery without hurting the user experience for existing users I think is not simple and easy to underestimate.

Go and Signal both choose a set of trade-offs that consider both technical and human elements. I think this irks people that don't understand these trade-offs since the human side of trade-offs is harder to define or evaluate the importance of. Ergonomics plays a huge role in the ultimate value of Go and Signal to society.

Re: Technology preview: Sealed sender for Signal

#104
post #24

Here's an idea, Signal, how about removing the requirement that everything be tied to phone numbers? BBM back in the day worked great with their unique "PINs", that could be shared by QR code, and I could reject an "add" request.

This is the "Go y u no generics" of secure messaging. The answer is always the same: Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging . The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for…

fuck off you disgusting shill for surveillance

I bet you work for Google or some other demonic company

burn in hell

Re: Technology preview: Sealed sender for Signal

#105

Earlier quoted context omitted.

What is your qualification for "protecting" privacy? Clearly Signal has improved privacy compared to other messaging platforms as has been proven by subpoenas by law enforcement. That, in my mind, qualifies as privacy protection over many other messaging solutions that have not been proven or failed in that arena. Claiming Signal doesn't protect privacy because: phone numbers is an opinion given you haven't qualified…

>Clearly Signal has improved privacy compared to other messaging platforms as has been proven by subpoenas by law enforcement. Secure systems are not built on trust. They're built with math and with facts. Their goal isn't based on what tptacek said just because tptacek said it, either. If I'm wrong and privacy isn't their goal, well that speaks volumes on its own.

toilet paper tacek is a shill for big brother, ignore his vomit

Re: Technology preview: Sealed sender for Signal

#106
post #90
post #24

Earlier quoted context omitted.

This is the "Go y u no generics" of secure messaging. The answer is always the same: Phone numbers bootstrap a workable social network for ordinary users. Signal's goal is to transform all ordinary messaging into secure messaging. Not elite secure messaging. All messaging . The most popular messaging application in the world uses phone numbers for identifiers (as, obviously, does SMS). That's the goal they've set for…

> This is the "Go y u no generics" of secure messaging. Yes, it is – and it turns out that Go 2 will be adding generics. Before that, you could have said "If generics are super-important to you, use Rust." But it turns out you can have both Go and generics, and (if you prefer Go over Rust for other reasons) that's even better than having to pick one or the other. The designers made a choice to omit generics in the in…

Something being adopted doesn’t equal it being of benefit or a good thing. Vocal minorities have ruined many a thing this way, the vocal minority rarely possess the level of knowledge and insight as say, in this case, the language designers.

Re: Technology preview: Sealed sender for Signal

#107
post #23

Two observations: 1. You should look into what other messengers do with sender/receiver pairs information. One very popular competing messenger logs pairs permanently, serverside, in order to make UI features work. 2. One of the least popular attributes of Signal (on Hacker News, at least) is its lack of federation and ability to interoperate with third-party clients. This feature is a pretty crystalline example of t…

>2. One of the least popular attributes of Signal (on Hacker News, at least) is its lack of federation and ability to interoperate with third-party clients. This feature is a pretty crystalline example of the kind of protocol change you can make when you control all the mainstream clients, and that would be an absolute nightmare for a protocol where you didn't.

Personally I would be fine if they were in control of the only implementation but provided libraries that could be used to create bindings and gateways for other clients and protocols. My main problem with Signal is that their desktop app manages to be slower and clunkier than the average electron app which is quite a feat on its own.

If they provided a basic shared library or maybe even a stand alone "headless" binary client you could interface through some socket protocol for instance it would let me write a gateway to use irssi or whatever not-completely-trash and actually configurable client instead of that glorified webview that manages to be worse than an actual webpage (still haven't figured out how to change the spellchecker settings in the edit box since right clicking doesn't have the option to change the dictionary like in a real web browser). Also I've just started it and it already uses 158M of resident memory but that's business as usual for this garbage fire that's electron.

As far as I can tell that wouldn't make it harder for them to develop and improve the protocol since they would still completely control that bit of the code.

Re: Technology preview: Sealed sender for Signal

#108
post #70
post #61

Earlier quoted context omitted.

As tptacek says - Signal isn't attempting to solve every problem or cover every edge case. If you don't have a smartphone you can install apps on - perhaps the company making a smartphone app which happens to integrate with a desktop app as well) isn't for you. Same for "tablet users". FWIW, you don't need to do _too_ much hoop jumping to get a non-phone device running Signal - I mainly use it on a dedicated iPod Tou…

This all has network effects. I have a smartphone, and I run Signal. But I run it much less, precisely because several people whom I want to interact with regularly are unable to, due to its limitation. This also means that I'm less likely to recommend it to others. And I don't think that tablets are an "edge case". I mean, seriously? We're talking about millions of devices on the market. They may not be as popular a…

Why don't you use it for SMS? At most 20% of my contacts use Signal, but for the rest of my non-Signal contacts I still use it to communicate using normal SMS/MMS without any hiccups, the only thing being the lack of encryption. I also personally prefer it to the IMO horrible default SMS apps provided by multiple vendors (including stock Android, at least up to V7).

Re: Technology preview: Sealed sender for Signal

#109
post #70
post #61

Earlier quoted context omitted.

As tptacek says - Signal isn't attempting to solve every problem or cover every edge case. If you don't have a smartphone you can install apps on - perhaps the company making a smartphone app which happens to integrate with a desktop app as well) isn't for you. Same for "tablet users". FWIW, you don't need to do _too_ much hoop jumping to get a non-phone device running Signal - I mainly use it on a dedicated iPod Tou…

This all has network effects. I have a smartphone, and I run Signal. But I run it much less, precisely because several people whom I want to interact with regularly are unable to, due to its limitation. This also means that I'm less likely to recommend it to others. And I don't think that tablets are an "edge case". I mean, seriously? We're talking about millions of devices on the market. They may not be as popular a…

It also seems to be the future. Phone numbers are how people receive phone calls, and more and more people are opting out of that in favor of instant messaging and video chat. More and more people have stopped answering their phones. Including our parents, who got sick of the scams and the robocalls. In my region, despite phone number portability, the numbers are fairly ephemeral with people switching to new ones all the time for all sorts of reasons. And nobody cares, because it is the IM system that is important.

Skype almost managed to replace the legacy phone network, but fell out of favor. If there was interoperability between clients like Signal, Whatsapp, Line, Wechat, it would take over a multi-billion dollar industry. Instead, my bank is trying to use some proprietary video conference system to schedule meetings with me.

Re: Technology preview: Sealed sender for Signal

#110
post #101
post #56

Earlier quoted context omitted.

Again, what Signal is trying to do is to create a wholesale replacement for the (vast majority of) messaging traffic that exists now and is addressed by phone numbers. It's weird to me to see people downplaying this; if they succeed, it will be a monumental achievement, surpassing SSL/TLS in impact to communications.

Interestingly, you're always in these threads arguing forcefully that some feature that might improve user anonymity is bad or dismissible for nearly any reason. You both have a lot of time to spend commenting, as well as a rapid-response opinion that's consistently about slowing the rate of anonymity. Why is that exactly?

Good questions
Post reply on HN