Live data from Hacker News

Looking back at how Signal works

signal.org

101–110 of 301 posts

Re: Looking back at how Signal works

#101

What happens to Signal when the EARN It Act passes? I assume that eventually the Apple App Store and Google Play Store will just stop allowing it to be downloaded if they do not add the backdoor in? Is there a workaround that will allow people to use it still? I've heard people mention locating the servers in other countries, but wouldn't the various App stores be bound by US law and still not allow them?

> the Apple App Store and Google Play Store will just stop allowing it to be downloaded Time for a privacy focused app store!

There is one already for Android, the F-Droid store. Totally open source and lots of good apps there https://f-droid.org/

Re: Looking back at how Signal works

#102
post #41

Anyone have information about how/where they get their funding and/or income?

They are funded by the Signal Foundation: https://signal.org/blog/signal-foundation/ "...Today, we are launching the Signal Foundation, an emerging 501(c)(3) nonprofit created and made possible by Brian Acton, the co-founder of WhatsApp, to support, accelerate, and broaden Signal’s mission of making private communication accessible and ubiquitous. In case you missed it, Brian left WhatsApp and Facebook last year, and…

Yep, originally the Open Tech Fund was a big funder. They funded apps like our own Umbrella App and also lots of Guardian Project and Tor etc

Re: Looking back at how Signal works

#104
post #69

Earlier quoted context omitted.

Thanks for the link. There's a subtle threat in there, that they'll move out of the country if they have issues which I think a lot of tech companies would. This bill is so stupid in that tech companies can relatively easily move.

The legal entities can move to other jurisdictions, sure, but it doesn't matter because app distribution still occurs primarily through USA-based Google Play and USA-based Apple App Store—both of which can easily geofence apps as they please (or as they're required). This is one of the reasons I've started to appreciate Matrix a lot more lately. https://matrix.org/blog/2020/01/02/on-privacy-versus-freedom

The real solution is switching to open source mobile operating systems.

Re: Looking back at how Signal works

#105

Earlier quoted context omitted.

Well, there isn't. "All lives matter" and "pro-life" represent specific political views, but they don't represent any specific groups or organizations. Just like antifa.

I don't understand the point you're making, sorry. I agree with you that antifa is not a specific organization.

Well, then what is it besides a term for antifascism? And how was the "is there not a consensus on antifascism" question invalid?

Re: Looking back at how Signal works

#106
post #37

Earlier quoted context omitted.

Signal started open-source, it was TextSecure, I'm sure there'll be an open-source alternative if the commercial entity fails, though I hope they do not.

As far as I know, while the DevOps code is not open source, the server and app code are on GitHub; that is you’re able to roll your own version however it defined by the licensing; recent attack on Signal by security researcher used a self-compiled app as a proof of concept; Signal patched the issue.

Just to clarify, the bug you're talking about was in WebRTC. We submitted a patch upstream:

https://webrtc-review.googlesource.com/c/src/+/175960

Re: Looking back at how Signal works

#107
post #79

Earlier quoted context omitted.

There is no consensus on wether being against fascism is good or bad? Being against fascism is not a group or organisation. It’s like calling bird watching an organisation. Yes, there are bird watching organisations, as there are antifa organisations, but neither bird watching nor antifa is an organisation.

They purport they are against fascism. But if you look at what they do sometimes, it amounts to little more than looting, rioting and vandalism. Not always, but sometimes. They don’t seem to have a designated modus operandi.

You are being downvoted because the current understanding here, AFAIU, is that there is no good identifier of the "they" where you say "they purport" because there does not currently exist an organized group that identifies themselves as "ANTIFA".

If you are aware of sources that indicate otherwise, would you mind sharing them?

Re: Looking back at how Signal works

#108

Is it worth trying to move my friends from WhatsApp to Signal? As I understand it, they're both e2e encrypted. I'm also trying to move my chats from SMS and Gchat to something encrypted, but am torn between WhatsApp and Signal. The former has more of a buy-in with my contacts already. I realize WhatsApp is owned by Facebook, but isn't the whole point of e2e encryption that you don't have to trust the intermediate inf…

That is an impossible question to give one answer to. There are lots of considerations. For example:

1) Do you trust facebook with messaging metadata? For example, do you want them to know that you messaged your friend Jane a specific number of times on specific dates, knowing that they can coorelate this information to facebook profiles, and will give up this information for ad, and law enforcement purposes.

2) Do you trust Signal's infrastructure to be reliable when you need it?

3) What is you're threat model? For me, I want to be kept out of all ad-related data sets, and I want to have conversations with friends without having to think about a paper trail.

4) Do you care that you will have to convince people to install yet another messaging app?

5) Do you trust that Signal and WhatsApp have correctly integrated the underlying crypto protocol? I assume that you would, considering its history. Still, I would trust signal more in this regard.

6) Do you think that Facebook or Signal is more likely to cut a privacy corner in support of a ease-of-use feature? Do you care?

For my friends, the answer is that I use signal. Everyone who doesn't use signal falls back to getting SMS, or phone calls. The problem here is that SMS and phone calls are both huge privacy holes. For my threat model, I don't care, but you might.

Re: Looking back at how Signal works

#110

Earlier quoted context omitted.

This is such an uncharitable interpretation of what I was saying that it's basically a straw man. If you're required to use ID to get a SIM (as K2L8M11N2 stated in the parent comment I replied to), then what I was saying follows - that the person is already tied to the phone number anyway. In this context Signal revealing the only data they have (that a phone number signed up on X day) really doesn't matter or reveal…

I'm sorry but absolutely nothing about this is a straw man or uncharitable, and I'll explain why. >If you're required to use ID to get a SIM (as K2L8M11N2 stated in the parent comment I replied to), then what I was saying follows Yes, and this is what I was responding to. You want that "if" to be taken for granted as an unchallenged starting premise to your entire argument. And that amounts to a massive privacy conce…

> "You want that "if" to be taken for granted as an unchallenged starting premise to your entire argument."

I don't want that 'if' to be anything. It was the premise, because the parent comment I was responding to was stating it as a fact for where they live.

My point is that signal revealing your phone number and when you signed up doesn't reveal anything new about you. The issue is the case K2L8M11N2 mentioned when they have compromised a device (and can now tie content to IDs via the phone number).

> "That's going true in any context where your number can be revealed...under any conceivable hypothetical scenario."

This is just false? Without access to the content on a compromised device a phone number alone doesn't reveal much (that's the entire point of the e2ee), if it limits the ability for Signal to hand over the social graph or any other metadata (which does reveal a lot) that seems like a win.

Obviously revealing the phone number still reveals more than a username would, and if you can get all the benefits of not having to upload your social graph to their servers or share metadata without having to use phone numbers that would be better - I think they're working on that.

People using apps that upload their social graph and collect their metadata so they don't have to use their phone number are probably making the wrong choice when considering the trade-offs.

Post reply on HN