I actually like Signal, and would use it a lot more, but don't because of one feature - link previews. I understand the technical reasoning why are they so slow to adopt it, but I (and a group of people I communicate on a daily basis) would probably accept even a half-baked solution like the one on WhatsApp.
Why do you find WhatsApp's solution half baked?
Signal app downloads spike as US protesters seek message encryption
321–330 of 367 posts
Re: Signal app downloads spike as US protesters seek message encryption
#322Earlier quoted context omitted.
I’ve heard this before but here’s my practical problem: I don’t know any lawyers. I have literally no idea who to call in such a situation. Do I have to go find and retain a lawyer beforehand just in case I might need one later?
It's not a bad idea to have a relationship with a lawyer. Talk to family/friends/co-workers. Somebody will have a name for you. We made a relationship with one I found through family via estate planning (not his specialty) and land deals (not his specialty). Now I have a name to say out loud when I interact with police. This has happened twice. The OP is right, they'll do everything they can to get you to talk, but u…
Are you sure you're not exaggerating? I've totally seen incidents where cops were only talking to see if they've even found the right person. They lose interest pretty damn quickly when they realize they're talking to the wrong person (even to the point of rejecting extra evidence you might offer yourself). Whereas I'm pretty damn sure in these cases you cause yourself a lot of (short-term maybe, but still) grief if you suddenly go on the defensive and plead the 5th. It unnecessarily makes you look guilty, whereas a couple minutes of talking can make it crystal clear to them you're totally clueless.
Re: Signal app downloads spike as US protesters seek message encryption
#323I actually like Signal, and would use it a lot more, but don't because of one feature - link previews. I understand the technical reasoning why are they so slow to adopt it, but I (and a group of people I communicate on a daily basis) would probably accept even a half-baked solution like the one on WhatsApp.
https://github.com/signalapp/Signal-Android/blob/0ef01cc620c...
If you opened a PR with the websites you're missing, I'm sure they'd be open to it.
I see sibling comments mentioning that they wouldn't want this feature (which is already there) because of its privacy implications, but I think that it basically works like gifs, with a proxy controlled by Signal.
Re: Signal app downloads spike as US protesters seek message encryption
#324Earlier quoted context omitted.
Telegram indeed have better UX and same level of e2e security. Why Signal is getting all the publicity?
Telegram has off-by-default E2E encryption with a less vetted algorithm that only works for 1:1 chats, and less focus on minimizing server knowledge. That's clearly not > same level of e2e security
Re: Signal app downloads spike as US protesters seek message encryption
#325Earlier quoted context omitted.
Telegram indeed have better UX and same level of e2e security. Why Signal is getting all the publicity?
Telegram is not opensource, Signal is...and yes you can setup your own server with Signal. Why trust a Closed-source-Software? Do you even know that it is encrypted?
Re: Signal app downloads spike as US protesters seek message encryption
#326Earlier quoted context omitted.
oof the pin nag is brutal, i hear that. as someone who doesn't back up or transfer their message is completely unnecessary to me to even have it.
Same. How hard is it to make it optional?
Re: Signal app downloads spike as US protesters seek message encryption
#327Earlier quoted context omitted.
Signal is not only used by protesters[0][1] so discovering that a phone number is connected to a Signal account by no means implies that the phone is used by a protester. [0]: https://www.militarytimes.com/flashpoints/2020/01/23/deploye... [1]: https://www.theguardian.com/politics/2019/dec/17/tories-swit...
Yeah, if you're ever asked why you're on Signal, just say you wanted to stay in touch with a programmer friend who's not on Facebook/WhatsApp, and they suggested Signal (that is now literally true as well - I suggest you try Signal, friend)
Re: Signal app downloads spike as US protesters seek message encryption
#328Earlier quoted context omitted.
It's my default and over a few years I've pretty much converted everyone in my life except my mom
Sadly, Signal neglects user experience, and as a result people around me all tend to migrate to WhatsApp. They don't care that they are uploading their entire contact list to Facebook — "death before inconvenience".
I applaud the direction they've taken. These are the kinds of features that will acquire and retain a broader user base.
Re: Signal app downloads spike as US protesters seek message encryption
#329The biggest drawback with Signal for protesters is that it exposes the user's phone number to everyone else in groups (just like WhatsApp does). There is no way to even hide the fact that you have an account on Signal. I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it. If the authorities don't use tactics like they did in Hong Kong, the protesters may be safe…
Re: Signal app downloads spike as US protesters seek message encryption
#330Earlier quoted context omitted.
SGX is for the servers not the clients. Their enclave is open source so you can theoretically audit it using RA. I say theoretically because these schemes all have a core problem when they're not federated - you have no idea what your client is really doing and it's the client performing remote attestation with the enclave. You have no control over it. It could update tomorrow and switch every last bit of encryption…
> That didn't stop [facebook] blocking people from forwarding links related to coronavirus. Source?
Pick any version of the story. Or read their blog post:
https://blog.whatsapp.com/Keeping-WhatsApp-Personal-and-Priv...
How do they know a message is forwarded? The encryption is meant to make identical plaintexts encrypt to different ciphertexts, so obviously they must be leaking the forwarding status in unencrypted parts of the message. And why is an encrypted service trying to combat misinformation to start with - isn't that a contradiction in terms? These things raise difficult questions. You'd hope that once a service decides to go fully encrypted, its staff would believe that what kind of information going over it or how accurate that is, isn't any longer their concern.