But what should I use if I am a politician and fundamentally believe that the government should be able to read my communications?
Dumb question: is your comment meant to be sarcastic? I initially read it as such but now I'm not sure, given all the other replies.
EU Commission to staff: Switch to Signal messaging app
271–280 of 289 posts
Re: EU Commission to staff: Switch to Signal messaging app
#272Earlier quoted context omitted.
It also very shadily holds that number hostage, meaning you are forced to wait seven days after uninstalling the app in order to be able to unregister your number from signal. If you don't you'll just not get messages from people on Signal. My opinion of them is quite low thanks to the iMessage-tier bullshit.
This certainly isn't the case with any version I've used. It's just Settings -> Delete Account, and its a large, red, very visible button.
Re: EU Commission to staff: Switch to Signal messaging app
#273I know Signal is secure and all — and I use it myself — but I can’t help but think how can we trusted that the central servers aren’t wiretapped? It would be the ultimate proof of security if one could transparently verify that the middle man is running the actual code it claims to be running.
The point of signal is that you do not need to trust the middleman due to e2ee about your actual communication (but this does not include your metadata where you do need to trust their servers - and there is no way to prove that they run the code that they claim to run) As for the actual client, see https://signal.org/blog/reproducible-android/ Right now signal is not fully reproducible so you can't trust that the bi…
Re: EU Commission to staff: Switch to Signal messaging app
#274I know Signal is secure and all — and I use it myself — but I can’t help but think how can we trusted that the central servers aren’t wiretapped? It would be the ultimate proof of security if one could transparently verify that the middle man is running the actual code it claims to be running.
Signal uses Intel SGX to give you some assurances about this, at least for parts of their serving stack. You can run the remote attestation tools and get a report back from Intel that says, in effect, "you connected to a genuine CPU and it's running software with this hash". Then you reproduce the build of the open source code and check the hashes match. I'd be surprised if anyone has ever actually done this. It's a…
Re: EU Commission to staff: Switch to Signal messaging app
#275Re: EU Commission to staff: Switch to Signal messaging app
#276Earlier quoted context omitted.
> good luck getting rid of that one without building your own hardware and drivers from scratch. For an individual that is obviously infeasible. For the continent of Europe as a whole, it obviously isn't. Why shouldn't they put some money into developing cellphone hardware with open source drivers?
The size of the supply chain required for such an endeavor is so huge and spread among various countries and companies worldwide this would be a big task even for the EU. I mean, competing with the like of Broadcom and ARM from scratch. Good luck with that. Even then, the NSA would just need to pay or blackmail a single entity in the supply chain to get their backdoor in there. The EU itself would probably implement…
Supply chain security is an independent problem. First you have to know exactly what the design is supposed to be, only then can you verify that it actually is.
Re: EU Commission to staff: Switch to Signal messaging app
#277Re: EU Commission to staff: Switch to Signal messaging app
#278Earlier quoted context omitted.
> some guy who literally said he got the job because he was friends with Obama There are two kinds of U.S. ambassadors: 1) Career foreign service people 2) Friends of the presidential administration at the time Examples of the latter aren't hard to find. Off the top of my head I'm familiar with William Timken, a US businessman who was appointed Ambassador to Germany by George W. Bush because he was a huge supporter […
All US ambassadorships are political appointment, therefore option 2 is the only answer. These positions are almost always ceremonial. They are there to execute the will of the president. The real work is done by the diplomats who are appointed through the US Foreign Service office. They do the actual work of the embassies.
Re: EU Commission to staff: Switch to Signal messaging app
#279Earlier quoted context omitted.
Yes, and the huge majority of people don't have that requirement. Signal's devs have been very clear for years and years that the are optimizing for getting as many people as possible to use functioning e2e encrypted messaging rather than to focus on features that a subset of techies in the west care about.
I don't know about you, but I as a 'techie in the east-west' have a bunch of people who ask me or follow my choices wrt tech stuff. I might recommend Signal to them if they specifically ask for something encrypted, but if they just follow what I use they'll see no Signal.
Heck, whatsapp has gotten several orders of magnitude more people to use encrypted messaging than any other software, and techies hate it.
Re: EU Commission to staff: Switch to Signal messaging app
#280In previous discussion here on HN, Wire was claimed to be more secure than Signal (something related to initial key sharing?) I don't understand why there's so much publicity behind Signal, and Wire is never mentioned. I've been using Wire for years, and it doesn't require a phone number to setup.
Wire is owned by a US company now: https://techcrunch.com/2019/11/13/messaging-app-wire-confirm...
I honestly don't see how privacy and security do not go hand-in-hand.
From Wikipedia[0]: "Wire stores unencrypted meta data for every user" ... "Wire changed its privacy policy from "sharing user data when required by law" to "sharing user data when necessary"." ... "Wire did not inform its users about this policy change, which makes it even more suspicious, considering that it is about a tool that promises privacy to its users."
I use to speak highly of Wire a few years ago but have not used their programs in a while. It's pretty clear that non-corporate users and their expectations of privacy are of little importance to them.