Live data from Hacker News

Signal app downloads spike as US protesters seek message encryption

qz.com

101–110 of 367 posts

Re: Signal app downloads spike as US protesters seek message encryption

#101
post #30

Earlier quoted context omitted.

Whenever key management is centralized, there is basically no security from the legal authority in the jurisdiction that the messaging vendor is located in. The vendor can always push you an MITM key. They can even show you the "correct" recipient key when you physically verify but use a different one for the actual message transfer and this would be a trivial easy to obfuscate switch in the program binary. E2E with…

The Signal Foundation is based in Mountain View and both Moxie Marlinspike and Brian Acton are US nationals... What’s stopping some US government agency from forcing them to insert code that causes the Signal app to a indicate it is behaving correctly but isn’t? And don’t say “laws”. If your threat model includes advanced persistent threats all bets are off.

[deleted]

Re: Signal app downloads spike as US protesters seek message encryption

#102
post #50

Earlier quoted context omitted.

I would ditch WhatsApp in a heartbeat if Signal had a browser client.

In my opinion Desktop Clients > Browser Clients when it comes to messengers. If you have more than ten tabs open it is annoying to always have to switch tabs or break out a window. Having a desktop application that remembers where you want to save stuff people send you is a plus too.

My opinion is the opposite, because Electron is quite heavy (which is an issue for Signal Desktop at least), and because you can't use browser containers to use multiple accounts.

Re: Signal app downloads spike as US protesters seek message encryption

#103
post #97

Earlier quoted context omitted.

Is Telegram at all trustworthy? I feel like I’ve repeatedly seen on HN that they’re not a good choice for secure messaging (though I don’t remember the specifics around it). Signal and Matrix are the two options I’ve settled on. [Edit]: Looks like the main issues with Telegram are that it doesn't use end to end encryption by default and that they rolled their own encryption protocol that's likely not secure. They als…

Telegram's homegrown crypto has been dismissed by many people (including experts). But it offers privacy features that some other messengers do not. Is Signal trustworthy considering that it exposes your phone number to everyone else in groups? With Telegram it's possible to communicate with anyone without revealing your phone number or profile picture or anything else.

The phone number issue is pretty overblown since it's a clear and intentional tradeoff that allows signal to retain very little metadata (leveraging local phone contacts instead of sending your social graph to their servers like everyone else). Moxie Marlinspike is the founder/co-author of the protocol and Brian Acton put in massive funding after the FB/Whatsapp fallout - not sure you can get better than that?

They're also making moves to make the phone number requirement unnecessary. What privacy features does Telegram have? It sounds like they don't even have encryption on by default and people have also dismissed their security? Why would anyone use them?

Re: Signal app downloads spike as US protesters seek message encryption

#104
post #95

I hope one day apps like Signal will be the default for everyone , not just protesters in a time of crisis.

I don't think that's a great idea until Signal stops exposing the phone number of the user to everyone else (for all the bashing that Telegram gets on cryptography, it has mechanisms to hide one's phone number and even the fact that one has a Telegram account from others).

Absolutely agree. I really wish Telegram would get off the phone number system, especially after the embarrassing hack in Brazil. It's not explicitly Telegram's fault, but if your primary authentication method is insecure it's at least a little bit your fault.

Phone numbers are NOT safe. I don't know why SMS MFA is even a thing, they're worse than passwords.

When you use phone numbers or SMS for security, you are putting the fate of your entire company's security on an underpaid customer service rep at Verizon.

Re: Signal app downloads spike as US protesters seek message encryption

#105
post #98
post #72

Earlier quoted context omitted.

my encrypted chats saved across multiple devices

Wire has E2E synced across devices and platforms, though its client and features lag behind Telegram (it's still better than Signal on features).

Wire sends your social graph to the cloud.

Maybe this is an okay trade-off for you, but Signal's phone number as ID requirement means they can rely on the local contacts kept on your device and keep very little metadata about you on their servers.

Re: Signal app downloads spike as US protesters seek message encryption

#106

I hope one day apps like Signal will be the default for everyone , not just protesters in a time of crisis.

The Signal app experience leaves a lot to be desired compared to Telegram or Matrix.

Telegram is THE standard in messaging apps. It's basically flawless. It's extremely fast, and it works every single time. Notifications are rock solid on every platform, it doesn't hog your battery and it feels fluid to use.

Signal, Wickr, WhatsApp and others do not have this experience. They all have drawbacks and do not feel Telegram fast.

Re: Signal app downloads spike as US protesters seek message encryption

#107

I hope one day apps like Signal will be the default for everyone , not just protesters in a time of crisis.

I would ditch WhatsApp in a heartbeat if Signal had a browser client.

Will only ever happen once Signal ditches their dependency on mobile phone number.

Re: Signal app downloads spike as US protesters seek message encryption

#108
post #92

The biggest drawback with Signal for protesters is that it exposes the user's phone number to everyone else in groups (just like WhatsApp does). There is no way to even hide the fact that you have an account on Signal. I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it. If the authorities don't use tactics like they did in Hong Kong, the protesters may be safe…

This tradeoff is arguably a good thing.

By using phone numbers as IDs signal can rely on your phone's local contacts (meaning they don't have to send your social graph to their servers). This way they can keep very little metadata on you.

There's pretty much nothing for them to turn over except the fact that your phone number has the signal app.

Most of the other secure apps could turn over your entire contact list (which could be damaging for people in a protest that are being targeted).

Confirming a single phone number has the app is not nearly as big of a deal (I'd argue it doesn't matter at all).

Re: Signal app downloads spike as US protesters seek message encryption

#109
post #48

Earlier quoted context omitted.

The Signal app experience leaves a lot to be desired compared to Telegram or Matrix.

Does it tho? It changed a lot during the last years and for most stuff I do with my friends (videocalls, textmessages, recorded speechmessages, pictures, videos, groupstuff, desktop app) it just works fine.

It doesn't do Video calls for one thing.

Re: Signal app downloads spike as US protesters seek message encryption

#110

Honest question for those in the know: If I wanted to run my own personal “analysis” to verify the security of Signal, where would I start? Is it even possible? Just curious if there was a way to “know” rather than “trust”.

Related question, is there an endorsement from a recognised expert? I'd have to live with that since I won't be getting an advanced degree in cryptography.
Post reply on HN