Live data from Hacker News

I don't trust Signal (2018)

drewdevault.com

91–100 of 115 posts

Re: I don't trust Signal (2018)

#91
post #83

Earlier quoted context omitted.

Until a couple years ago, Tox worked with sidecar services that existed solely to store this information serverside. That, and the fact that Tox is not a mainstream messenger, illustrates the point I'm trying to make --- which is about messengers, not about this post, which thankfully doesn't make this bogus but popular argument.

> Tox worked with sidecar services that existed solely to store this information serverside. So Tox is out. No contest. > That, and the fact that Tox is not a mainstream messenger, illustrates the point I'm trying to make --- which is about messengers This doesn't make sense to me. @ddevault stated that a messenger could store contacts client side. Jami clearly demonstrates this. What does it being mainstream or not…

You can do anything if you relax the constraint that people are willing to use your tool. By that logic, PGP is a perfectly cromulent secure messenger! That's the point of narrowing it down to mainstream messengers.

You misread my last sentence. DeVault's post does not make the bogus argument we're discussing. I'm trying to be explicit that I'm not criticizing his post for doing so. If it's an attack, it's an attack on an argument that he didn't make. (If it reads like a personalized attack on an argument that you believe in, I apologize, and will dial it back).

Re: I don't trust Signal (2018)

#92
post #91

Earlier quoted context omitted.

> Tox worked with sidecar services that existed solely to store this information serverside. So Tox is out. No contest. > That, and the fact that Tox is not a mainstream messenger, illustrates the point I'm trying to make --- which is about messengers This doesn't make sense to me. @ddevault stated that a messenger could store contacts client side. Jami clearly demonstrates this. What does it being mainstream or not…

You can do anything if you relax the constraint that people are willing to use your tool. By that logic, PGP is a perfectly cromulent secure messenger! That's the point of narrowing it down to mainstream messengers. You misread my last sentence. DeVault's post does not make the bogus argument we're discussing. I'm trying to be explicit that I'm not criticizing his post for doing so. If it's an attack, it's an attack…

> You can do anything if you relax the constraint that people are willing to use your tool.

I used Jami until I found Matrix. The only reason I shifted was Matrix was more interoperable with other protocols, and riot.im's interface was more like Discord, which is what my circle wanted to use but I refused.

Regardless, the threat model for this discussion is one where the targets have the option to use any messenger they want to communicate within themselves. I see no reason why they would be unwilling to use Jami.

> PGP is a perfectly cromulent secure messenger!

I recognize this is not what you are stating but...

PGP + Email + A nice client, yes I would agree, and it checks all of the security and privacy boxes.

Edit: Just saw

> (If it reads like a personalized attack on an argument that you believe in, I apologize, and will dial it back).

It's not that I believe in it per se, but that it reads more aggressively then seems appropriate for a board like HN. That said, I am still a bit of a noob here, so what do I know.

That said, I see no reason a messenger couldn't do this, I used one that did for a while.

Re: I don't trust Signal (2018)

#93
post #91

Earlier quoted context omitted.

You can do anything if you relax the constraint that people are willing to use your tool. By that logic, PGP is a perfectly cromulent secure messenger! That's the point of narrowing it down to mainstream messengers. You misread my last sentence. DeVault's post does not make the bogus argument we're discussing. I'm trying to be explicit that I'm not criticizing his post for doing so. If it's an attack, it's an attack…

> You can do anything if you relax the constraint that people are willing to use your tool. I used Jami until I found Matrix. The only reason I shifted was Matrix was more interoperable with other protocols, and riot.im's interface was more like Discord, which is what my circle wanted to use but I refused. Regardless, the threat model for this discussion is one where the targets have the option to use any messenger t…

If you'd like to know why PGP doesn't check those boxes, and why virtually everyone who works professionally in this space disagrees with you about its soundness, feel free to shoot me an email.

Re: I don't trust Signal (2018)

#94

Earlier quoted context omitted.

Yes, you are absolutely right. No, it does not invalidate what I am saying. If we keep expecting underfunded and under-resourced parties to come up with software ready and with absolute feature-parity over what is being pushed by the companies that have time, money and marketing teams, we are never going to make a dent on mindshare of the general public. If on the other hand are diligent in refusing for centralized a…

> absolute feature-parity over what is being pushed by the companies that have time, money and marketing teams Signal started as any other startup. And yet ;) > while willing to learn and emulate what they do right, then we will at the very least be in a state of steady progress In total agreement with you

> Signal started as any other startup. And yet

Not sure what you mean here. To me Signal is just another startup that wants to keep control over the market and uses excuses such as "federation leads to fragmentation and bad UX" in order to put its own interests ahead of the users. To me they are no different than FB or Google.

Re: I don't trust Signal (2018)

#95
post #93

Earlier quoted context omitted.

> You can do anything if you relax the constraint that people are willing to use your tool. I used Jami until I found Matrix. The only reason I shifted was Matrix was more interoperable with other protocols, and riot.im's interface was more like Discord, which is what my circle wanted to use but I refused. Regardless, the threat model for this discussion is one where the targets have the option to use any messenger t…

If you'd like to know why PGP doesn't check those boxes, and why virtually everyone who works professionally in this space disagrees with you about its soundness, feel free to shoot me an email.

I just sent one, thanks for the offer.

Re: I don't trust Signal (2018)

#96

Earlier quoted context omitted.

I would guess that a significant portion of Signal's users are non-technical people dragged there by their technical friends that couldn't get them onto Matrix. I would still guess that none is a bad assumption, however. Edit: Spelling

Practically none. I think it's safe to assume it's not even 1 in 1000 who have registered with a VLN, or even know what one is.

You raise a valid point. I would think that probably more than 1 in 1000 would know, but suspect you are right about how many actually would do it.

Re: I don't trust Signal (2018)

#97
post #47

Earlier quoted context omitted.

I don't buy it. I've been running my own Matrix homeserver and giving access to non-techy members of my family for years already. Setting up e2e is not automatic, but nothing that my mother couldn't do after 5 minutes of hand-holding. It is on us with tech skills to help others to get out of any centralized alternative. Ease of use will come with the less technical user base.

e2e, with pfs, is entirely automatic on Signal, and doesn’t require weird client configurations like self-hosted Matrix.

It doesn't change the fact that there is an alternative besides Signal that provides e2e. And it specially doesn't change the fact that it is almost trivial to self host Matrix and get to interoperate with other clients, while Signal does everything possible to avoid that and keep everyone under their control.

Re: I don't trust Signal (2018)

#98
post #88

Earlier quoted context omitted.

No experience in Wifi Calling but I use the 2ndLine app for (very rare) calls and SMS. It gives you a local number. Data-only is the most cost effective imo

Thanks for the response. One more question: when I look at those plans on Fido¹ they seem to suggest that I need to be an existing postpaid customer. The plan seems like an add-on to other plans. Is this accurate or did you sign up from scratch with no other commercial relationship with Fido? Make sure that you are an eligible Fido customer. You must be an existing, postpaid, mobile customer. 1. https://www.fido.ca/c…

I have a friend who's a Fido customer so I used their plan for signup.

I found out about the deal on a Redflagdeals post where some have successfully got the plan without being a Fido customer

https://forums.redflagdeals.com/fido-4gb-tablet-plan-cpo-tab...

Re: I don't trust Signal (2018)

#99

What's the alternative to Signal then? For iOS users?

Personally I use Matrix [0], specifically the Element client [1] which was previously known as Riot.

Among other features, it has end-to-end encryption, federation, comprehensive support for multiple devices and doesn't require a phone number. Basically, as far as I'm concerned, it has all of Signal's security but none of its flaws.

For the Android folks, it's available on F-Droid as well as the Play Store.

Surprisingly, despite the features and security, it's approachable enough that my mostly tech illiterate wife is able to handle it without issues.

[0]: https://matrix.org/

[1]: https://element.io/

Re: I don't trust Signal (2018)

#100
post #88

Earlier quoted context omitted.

Thanks for the response. One more question: when I look at those plans on Fido¹ they seem to suggest that I need to be an existing postpaid customer. The plan seems like an add-on to other plans. Is this accurate or did you sign up from scratch with no other commercial relationship with Fido? Make sure that you are an eligible Fido customer. You must be an existing, postpaid, mobile customer. 1. https://www.fido.ca/c…

I have a friend who's a Fido customer so I used their plan for signup. I found out about the deal on a Redflagdeals post where some have successfully got the plan without being a Fido customer https://forums.redflagdeals.com/fido-4gb-tablet-plan-cpo-tab...

Thanks. Guess I have to start making some new friends: "Heyyyy... you look like Fido kinda guy..."
Post reply on HN