Live data from Hacker News

Signal app downloads spike as US protesters seek message encryption

qz.com

351–360 of 367 posts

Re: Signal app downloads spike as US protesters seek message encryption

#351
post #346

Earlier quoted context omitted.

https://github.com/DrKLO/Telegram https://github.com/telegramdesktop/tdesktop

THAT is not the server, its like saying Firefox is opensource so Facebook is too, thanks and no thanks for the link's.

The encryption takes place in the client though, which you can verify by looking at the client source code. I find your comparison with Facebook a bit lacking, a better one would have been by looking at the Firefox code to verify if https traffic is encrypted.

Re: Signal app downloads spike as US protesters seek message encryption

#352
post #164

Earlier quoted context omitted.

Sadly, Signal neglects user experience, and as a result people around me all tend to migrate to WhatsApp. They don't care that they are uploading their entire contact list to Facebook — "death before inconvenience".

Signal cares so much about UX that they're starting to agitate security/privacy diehards. They've implemented features like stickers and message reactions that the diehard community calls "useless". And they recently implemented PINs with the intention of storing your encrypted profile and settings for easy recovery on a new device. I applaud the direction they've taken. These are the kinds of features that will acqu…

I recently stopped using Signal over the PIN thing. I do not want them to store my data on their servers, but they won't let me opt out.

Re: Signal app downloads spike as US protesters seek message encryption

#353
post #132

Earlier quoted context omitted.

Telegram should maybe just use proper encryption first.

Can someone explain to me why MtProto is not considered proper encryption? Genuinely asking, not challenging. At least since version 2.0 it seems it's using AES encryption: https://core.telegram.org/mtproto/description

By default its not e2e encrypted and if you want to use e2e you lose lots of capability. That is simply not acceptable in a modern messenger.

Re: Signal app downloads spike as US protesters seek message encryption

#354

Earlier quoted context omitted.

For Signal desktop on Linux to not require that I validate my mobile device randomly to read my encrypted messages. If it used GPG then this wouldn't be a problem.

What does this dialog look like? I don’t recall having seen that in my Signal desktop on Linux or Mac.

It looks like a yellow notification that says you need to re-link your mobile device, and in order to do so you have to take a picture of a QR code from your mobile device.

Re: Signal app downloads spike as US protesters seek message encryption

#355
post #353

Earlier quoted context omitted.

Can someone explain to me why MtProto is not considered proper encryption? Genuinely asking, not challenging. At least since version 2.0 it seems it's using AES encryption: https://core.telegram.org/mtproto/description

By default its not e2e encrypted and if you want to use e2e you lose lots of capability. That is simply not acceptable in a modern messenger.

Speaking as someone who regularly uses private chats, what capability?

Re: Signal app downloads spike as US protesters seek message encryption

#356
post #104

Earlier quoted context omitted.

Absolutely agree. I really wish Telegram would get off the phone number system, especially after the embarrassing hack in Brazil. It's not explicitly Telegram's fault, but if your primary authentication method is insecure it's at least a little bit your fault. Phone numbers are NOT safe. I don't know why SMS MFA is even a thing, they're worse than passwords. When you use phone numbers or SMS for security, you are put…

> especially after the embarrassing hack in Brazil What happened?

Numerous Brazilian judges and politicians had their Telegrams hacked via SIM hijacking.

Re: Signal app downloads spike as US protesters seek message encryption

#357
post #92

The biggest drawback with Signal for protesters is that it exposes the user's phone number to everyone else in groups (just like WhatsApp does). There is no way to even hide the fact that you have an account on Signal. I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it. If the authorities don't use tactics like they did in Hong Kong, the protesters may be safe…

Late post, but I'm just wondering why nobody has mentioned Briar Project. I think it's designed to remedy some of the issues mentioned here: https://briarproject.org/

Re: Signal app downloads spike as US protesters seek message encryption

#358
post #350

Earlier quoted context omitted.

https://duckduckgo.com/?q=facebook+whatsapp+covid+forwarding... Pick any version of the story. Or read their blog post: https://blog.whatsapp.com/Keeping-WhatsApp-Personal-and-Priv... How do they know a message is forwarded? The encryption is meant to make identical plaintexts encrypt to different ciphertexts, so obviously they must be leaking the forwarding status in unencrypted parts of the message. And why is an e…

I see. Given this clarification, I would argue that your original claim was misleading.

OK. Where is the argument then? You've asserted, but not argued.

Today, Signal is claiming their encryption means the only data they have to give to government is date of install and last use. In the past they also claimed WhatsApp uses the same cryptography as them, at least for messages. These two claims cannot both be true. If there's some incredibly subtle detail that means deliberately exposing forwarding metadata in WhatsApp but not Signal they should really clarify that because it's not something I've ever seen a discussion of, and it doesn't follow from the cryptography they're using.

Re: Signal app downloads spike as US protesters seek message encryption

#359
post #183

Earlier quoted context omitted.

Telegram is a great alternative also, offers encrypted chat's also.

Not encrypted by default afaik.

They're all encrypted, but only specifically created Secret Chats are end-to-end encrypted.

Re: Signal app downloads spike as US protesters seek message encryption

#360
post #355
post #353

Earlier quoted context omitted.

By default its not e2e encrypted and if you want to use e2e you lose lots of capability. That is simply not acceptable in a modern messenger.

Speaking as someone who regularly uses private chats, what capability?

Secret chats are tied to one single device, which may be ok for some people. The bigger disadvantage is that you cannot have group chats that are end to end encrypted. Only person to person chats are allowed as secret chats.
Post reply on HN