Earlier quoted context omitted.
Whenever key management is centralized, there is basically no security from the legal authority in the jurisdiction that the messaging vendor is located in. The vendor can always push you an MITM key. They can even show you the "correct" recipient key when you physically verify but use a different one for the actual message transfer and this would be a trivial easy to obfuscate switch in the program binary. E2E with…
The Signal Foundation is based in Mountain View and both Moxie Marlinspike and Brian Acton are US nationals... What’s stopping some US government agency from forcing them to insert code that causes the Signal app to a indicate it is behaving correctly but isn’t? And don’t say “laws”. If your threat model includes advanced persistent threats all bets are off.
Signal app downloads spike as US protesters seek message encryption
101–110 of 367 posts
Re: Signal app downloads spike as US protesters seek message encryption
#102Earlier quoted context omitted.
I would ditch WhatsApp in a heartbeat if Signal had a browser client.
In my opinion Desktop Clients > Browser Clients when it comes to messengers. If you have more than ten tabs open it is annoying to always have to switch tabs or break out a window. Having a desktop application that remembers where you want to save stuff people send you is a plus too.
Re: Signal app downloads spike as US protesters seek message encryption
#103Earlier quoted context omitted.
Is Telegram at all trustworthy? I feel like I’ve repeatedly seen on HN that they’re not a good choice for secure messaging (though I don’t remember the specifics around it). Signal and Matrix are the two options I’ve settled on. [Edit]: Looks like the main issues with Telegram are that it doesn't use end to end encryption by default and that they rolled their own encryption protocol that's likely not secure. They als…
Telegram's homegrown crypto has been dismissed by many people (including experts). But it offers privacy features that some other messengers do not. Is Signal trustworthy considering that it exposes your phone number to everyone else in groups? With Telegram it's possible to communicate with anyone without revealing your phone number or profile picture or anything else.
They're also making moves to make the phone number requirement unnecessary. What privacy features does Telegram have? It sounds like they don't even have encryption on by default and people have also dismissed their security? Why would anyone use them?
Re: Signal app downloads spike as US protesters seek message encryption
#104I hope one day apps like Signal will be the default for everyone , not just protesters in a time of crisis.
I don't think that's a great idea until Signal stops exposing the phone number of the user to everyone else (for all the bashing that Telegram gets on cryptography, it has mechanisms to hide one's phone number and even the fact that one has a Telegram account from others).
Phone numbers are NOT safe. I don't know why SMS MFA is even a thing, they're worse than passwords.
When you use phone numbers or SMS for security, you are putting the fate of your entire company's security on an underpaid customer service rep at Verizon.
Re: Signal app downloads spike as US protesters seek message encryption
#105Earlier quoted context omitted.
my encrypted chats saved across multiple devices
Wire has E2E synced across devices and platforms, though its client and features lag behind Telegram (it's still better than Signal on features).
Maybe this is an okay trade-off for you, but Signal's phone number as ID requirement means they can rely on the local contacts kept on your device and keep very little metadata about you on their servers.
Re: Signal app downloads spike as US protesters seek message encryption
#106I hope one day apps like Signal will be the default for everyone , not just protesters in a time of crisis.
The Signal app experience leaves a lot to be desired compared to Telegram or Matrix.
Signal, Wickr, WhatsApp and others do not have this experience. They all have drawbacks and do not feel Telegram fast.
Re: Signal app downloads spike as US protesters seek message encryption
#107Re: Signal app downloads spike as US protesters seek message encryption
#108The biggest drawback with Signal for protesters is that it exposes the user's phone number to everyone else in groups (just like WhatsApp does). There is no way to even hide the fact that you have an account on Signal. I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it. If the authorities don't use tactics like they did in Hong Kong, the protesters may be safe…
By using phone numbers as IDs signal can rely on your phone's local contacts (meaning they don't have to send your social graph to their servers). This way they can keep very little metadata on you.
There's pretty much nothing for them to turn over except the fact that your phone number has the signal app.
Most of the other secure apps could turn over your entire contact list (which could be damaging for people in a protest that are being targeted).
Confirming a single phone number has the app is not nearly as big of a deal (I'd argue it doesn't matter at all).
Re: Signal app downloads spike as US protesters seek message encryption
#109Earlier quoted context omitted.
The Signal app experience leaves a lot to be desired compared to Telegram or Matrix.
Does it tho? It changed a lot during the last years and for most stuff I do with my friends (videocalls, textmessages, recorded speechmessages, pictures, videos, groupstuff, desktop app) it just works fine.
Re: Signal app downloads spike as US protesters seek message encryption
#110Honest question for those in the know: If I wanted to run my own personal “analysis” to verify the security of Signal, where would I start? Is it even possible? Just curious if there was a way to “know” rather than “trust”.