Live data from Hacker News

I don't trust Signal (2018)

drewdevault.com

101–110 of 115 posts

Re: I don't trust Signal (2018)

#101

I'm so proud that a family member managed to get all of my extended family on Signal. My grandparents are even on Signal. I wouldn't trust such an app for anything actually secret due to the mentioned issues (and phone number req), but I think it's great that we're using high grade encryption to talk about what we had for dinner. Encrypted and private should be the default no matter what!

Plus cross-platform video chat and nice (large) multimedia attachments.

Re: I don't trust Signal (2018)

#102

Earlier quoted context omitted.

> absolute feature-parity over what is being pushed by the companies that have time, money and marketing teams Signal started as any other startup. And yet ;) > while willing to learn and emulate what they do right, then we will at the very least be in a state of steady progress In total agreement with you

> Signal started as any other startup. And yet Not sure what you mean here. To me Signal is just another startup that wants to keep control over the market and uses excuses such as "federation leads to fragmentation and bad UX" in order to put its own interests ahead of the users. To me they are no different than FB or Google.

They also started "with no money and recognition" and ended up defining what e2e means for consumers.

Re: I don't trust Signal (2018)

#103
post #13
post #9

Earlier quoted context omitted.

There is no alternative that provides the ease of use and privacy guarantees. I think the OWS/Moxie hate is misplaced. They’re competing with iMessage and WhatsApp and Instagram and Facebook, and Signal is a much better option than all of those. Let’s be honest: the alternative is that Facebook gets all of our chats in cleartext.

I sincerely appreciate this blog post and discussion, as it raises a lot of important and compelling points, but I wish it had had some discussion of alternatives and why. To me, messaging is a mess at the moment, somewhat like IoT because of lack of solid widely adopted standards (either de facto or de jure). It's extremely difficult to get friends and family to use something. Most decisions are driven by secondary…

My son has eight different IM things on his phone, counting Signal/SMS as just one. There is Element, Discord, and a bunch of others, that all warble and chime at him.

Re: I don't trust Signal (2018)

#104

Earlier quoted context omitted.

> Signal started as any other startup. And yet Not sure what you mean here. To me Signal is just another startup that wants to keep control over the market and uses excuses such as "federation leads to fragmentation and bad UX" in order to put its own interests ahead of the users. To me they are no different than FB or Google.

They also started "with no money and recognition" and ended up defining what e2e means for consumers.

Forgive me for being dense, but I still don't get the point you are trying to make. Do you think Signal is worthy of some praise that the alternatives are not? Was their software ready to compete with the status quo of the time in features?

Re: I don't trust Signal (2018)

#105
post #49

I trust Signal's end-to-end encryption promise, but I have a problem with the application not offering anonymity or privacy. By demanding users to provide a cell phone number to enable their accounts, they are connecting actual people to the Signal accounts and consequently also allowing them (or someone else) to visualize social networks; in intelligence gathering, data such as who speaks to whom, at what hours, wit…

The exact opposite privacy thing is happening with Signal. They use your phone number because your phone links it to your contacts, which Signal uses as its "buddy list". By repurposing your contacts as a buddy list, Signal avoids storing any of that information itself. Virtually every other competing service stores a plaintext buddy list serverside, where it can be subpoena'd and NSL'd. The data in that buddy list i…

> By repurposing your contacts as a buddy list

My contacts aren't all my buddies and conversely many of my buddies in WhatsApp or Snapchat or whatever aren't in my contact list.

Trying to repurpose one data silo that contains contacts such as my dentist and a taxi firm and reusing it as 'buddies' is clumsy and ill-considered.

Re: I don't trust Signal (2018)

#106
post #54

Earlier quoted context omitted.

Ah, yes, because it's impossible to store a contact list client-side. Or to encrypt arbitrary data like that to store server-side! Glad Moxie's looking out for us.

Please point to the mainstream secure messenger other than Signal that doesn't store a database of contacts serverside.

Take your SIM and install it in a clean phone. Install WhatsApp and verify the account.

Notice that when you open WhatsApp, only your group memberships are populated. Individual contacts are not, because they are held on the original device.

Re: I don't trust Signal (2018)

#107

Earlier quoted context omitted.

They also started "with no money and recognition" and ended up defining what e2e means for consumers.

Forgive me for being dense, but I still don't get the point you are trying to make. Do you think Signal is worthy of some praise that the alternatives are not? Was their software ready to compete with the status quo of the time in features?

What was the point of this statement: "If we keep expecting underfunded and under-resourced parties to come up with software ready and with absolute feature-parity over what is being pushed by the companies that have time, money and marketing teams"?

My counterpoint is: Signal started as any startup. Now it basically defines e2e encryption. Why can't other "underfunded and under-resourced parties" do similar things?

Re: I don't trust Signal (2018)

#108

Earlier quoted context omitted.

Forgive me for being dense, but I still don't get the point you are trying to make. Do you think Signal is worthy of some praise that the alternatives are not? Was their software ready to compete with the status quo of the time in features?

What was the point of this statement: "If we keep expecting underfunded and under-resourced parties to come up with software ready and with absolute feature-parity over what is being pushed by the companies that have time, money and marketing teams"? My counterpoint is: Signal started as any startup. Now it basically defines e2e encryption. Why can't other "underfunded and under-resourced parties" do similar things?

Because "defining e2e encryption" is the case of building a feature and not a product, and a startup creating a novel feature is a lot easier than bringing a whole product with feature-parity against the dominant market leader?

Re: I don't trust Signal (2018)

#109
post #99

What's the alternative to Signal then? For iOS users?

Personally I use Matrix [0], specifically the Element client [1] which was previously known as Riot. Among other features, it has end-to-end encryption, federation, comprehensive support for multiple devices and doesn't require a phone number. Basically, as far as I'm concerned, it has all of Signal's security but none of its flaws. For the Android folks, it's available on F-Droid as well as the Play Store. Surprisin…

> it has all of Signal's security but none of its flaws.

What about metadata protection? Whenever I hear people talk about how unsupportive Signal / Moxie is of federation and how federation would be better for everyone's privacy, my question is this: In case of Signal you only need to trust one provider (Signal) with your metadata (who's talking to whom) whereas with a federated network you have to trust your provider and all providers your friends use.

On top of that Signal has a track record of standing in for their users' privacy[0]. That probably can't be said about the administrator of some random Matrix server.

[0]: https://signal.org/bigbrother/eastern-virginia-grand-jury/

Re: I don't trust Signal (2018)

#110

Earlier quoted context omitted.

I'm sorry you're getting downvoted. Though I disagree with some of your stances on OWS and Mozilla, your articles are always thoughtful and there is never a doubt you're earnestly fighting for a better world w.r.t software.

I've been seeing him get downvoted frequently, often for well written and thought out comments. I suspect there is a non-negligible number of people who just vote based on username.

Do you have any examples of well-written and thoughtful comments by ddevault that were downvoted?

Many of the comments I see from him violate the guidelines at https://news.ycombinator.com/newsguidelines.html

Many of his blog posts (4 out of the last 5 submissions from drewdevault.com) are ill-informed and angry rants about a technology or company. These discussions generate a lot of heat but little light; it’s not surprising that they are downvoted.

Post reply on HN