Does anyone have any advice for what platform might be best to migrate to? I'm not overly concerned with group E2E, but it is a nice-to-have. Telegram and Discord seem like two of the most practical options, Keybase and Matrix seem like two of the most ideal from a security standpoint. I wonder what offers the best cross-section of features and user experience.
Facebook, WhatsApp Will Have to Share Messages With U.K.?
301–310 of 591 posts
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#302Earlier quoted context omitted.
Unless your mom is planning to involve herself in illegal activities I don't see a problem. Most electronic communication channels are compromised anyway. If you don't want eavesdroppers, don't use electronics.
> Unless your mom is planning to involve herself in illegal activities I don't see a problem. I assume you'd be happy to post all your credit card receipts and emails for all of us to see then. You're not doing anything illegal, right? That would be the only reason you don't want those things to be visible.
That should be a much better analogy. Especially in the postmodern hypersensitive world.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#303Yes, this is something that literally everyone who reads HN will oppose. Meanwhile do you hear the deafening silence from the average Joe who thinks he has "nothing to hide"? Don't hate the politicians who keep pushing this. They're just trying not to get fired. And the surest way to get fired in a western country right now is to be seen doing nothing about the terrorism problem and then having terrorist acts committ…
I also have nothing to hide :-)
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#304We are venturing straight into a totalitarian nightmare, and are totally fine with it.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#305Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#306In other news: US, UK subjects agree to stop using WhatsApp in favor of Telegram and Signal: https://telegram.org/ https://www.signal.org/ These are free software, not controlled by a giant corporation (although both are limited liability companies; Telegram in London/Dubai, Signal in San Francisco IIANM); with the developer/company not having unencyrpyed access to your data.
Telegram group chats are not e2e encrypted, while Signal is notorious for being unreliable at actually delivering messages. Also, if you change your phone number the official Signal recommendation is to manually tell all your friends about the new number. WhatsApp just lets you do it. I use both apps regularly but neither of them is perfect.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#307Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#308Earlier quoted context omitted.
There is no other endgame in which this is pointful.
You're assuming the people making these rules actually understand encryption, which is doubtful at best.
And you can bet those people do understand encryption.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#309Earlier quoted context omitted.
> If the source code isn't available for audit by 3rd parties (or yourself), and you can't build it from source, then it was never really "secure" anyway. What lawmakers do or don't say is just noise. Careful - you're right that WhatsApp is untrustworthy, but laws that force them to add backdoors could well be applied to open-source code as well. Or make possession of non-backdoored software, open or not, illegal. Or…
If I can compile audited code from source myself, without any backdoors, then I can be reasonably assured there aren't any backdoors (excluding perhaps hardware level backdoors--but that's why we do the encryption in software). Implementing hardware backdoors that are opaque to end users is theoretically possible, but more difficult in practice. You could, for example, build a screen/monitor that just captures everyt…
You assume that you actually understand the code well enough to identify the backdoor - e.g. as some sort of function that will bypass authentication when some secret hardwired password is provided (to give a dumb example).
However, to give a real world example of backdoored crypto, it is nothing of the sort. For example, the issue with the potentially backdoored Dual_EC_DRBG pseudorandom number generator has been known since 2004 at least - but the algorithm has been standardized by ISO/NIST and used for years until the potential backdoor issue was widely publicized following the Snowden leaks and the standard was withdrawn.
Good luck finding something like that only by reading code unless you are expert in crypto and mathematics. If you were only auditing code whether or not it matches the published, supposedly correct, standard (or algorithm description), you would never find this. The backdoored code was working completely fine, exactly as intended. But the weak random number generator allowed an adversary with sufficient computing resources to break the encryption.
Re: Facebook, WhatsApp Will Have to Share Messages With U.K.?
#310Earlier quoted context omitted.
Still remember how one German Islamist terror group just used their web-email provider's draft feature. They never 'sent' anything. There are often quite simple ways to circumvent this kind of thing.
Yeah only a stupid person can think that backdooring whatsapp will actually prevent the next 9/11. And that's in my opinion the core issue with most politicians, stupidity/tech illiteracy. I'd love to hear about either a possible alternative government structure in which there are no politicians or a way to attract the smartest people in governments.