Live data from Hacker News

Moxie Marlinspike has a plan to reclaim our privacy

newyorker.com

31–40 of 237 posts

Re: Moxie Marlinspike has a plan to reclaim our privacy

#31
post #25
post #11

Earlier quoted context omitted.

There is a reason why signal is relatively mainstream succesful (by crypto product standards) and PGP wasn't. Its because its willing to make tradeoffs in the name of usability (while still emphasizing security). A secure messenger product nobody uses helps nobody's security.

Many of the security design flaws in signal have had little to no direct impact on usability. For example, for years we asked for a simple mechanism which could be used to view a users key and mark it as identified, to prevent MITM -- even one buried in a menu for advanced users (who could at least act as canaries against widespread interception). Not only was the request turned down but usually responded to with vig…

Can the downvoters please respond to the post with the reasons why they are downvoting?

Re: Moxie Marlinspike has a plan to reclaim our privacy

#32
post #12

Earlier quoted context omitted.

A great deal of human communication is dedicated to signalling high rank/superiority, or demonstrating familiarity/intimacy.[1] In the case of HN, very few people know much about Moxie, so the only useful signal they can convey is expertise. Many people come here because of their technical or product development background/interests, and the way they show expertise is by second-guessing technical, user interface, and…

I think this is an uncharitable view, and while it might be true in some cases it is certainly not always the case. Many times the people who point out issues with Signal do it not because they think they want to show off, but because they honestly are frustrated that no product seems to meet their needs and Signal has specific issues that matter to them. I honestly believe “Signal is stupid for relying on phone numb…

I remember the outrage quite well when Facebook started spamming ads to the phone numbers of people who were forced to give Facebook phone numbers for "security" purposes and promised to never been shown ads on those numbers. Or when Jack Dorsey's Twitter account was hacked because of SMS 2fA.

Last, phone numbers are general identifiers used in the search boxes of various data collection tools. Maybe you can search by the Threema ID as well, but that requires the tool to be a tiny bit more sophisticated, and that means the people who like to invade privacy of are a bit more frustrated.

That isn't "smartness signalling" or whatever, that's a real concern.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#33

Other than matrix, what are some other alternatives or upcomers in the messaging field I should try. Matrix still has a high burden of me setting up my own server and maintaining it. Till their P2P solution doesnt release, they have their own metadata problem.

In addition to what the siblings said, Threema. Doesn't require phone numbers, is end to end encrypted like Signal.

https://threema.ch/

Also they announced that they will open source their client.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#34
post #30

It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…

> update agility makes Signal infinitely superior to every existing or proposed federated network. Translation: Signals ability to forcefully change the software and protocol out for users without any consent (much less informed consent) renders it functionally immune to any criticism or review because any aspect of the protocol could be changed ('improved') at a moments notice. I think signal is a fine insecure mess…

>Translation: Signals ability to forcefully change the software and protocol out for users without any consent (much less informed consent) renders it functionally immune to any criticism or review because any aspect of the protocol could be changed ('improved') at a moments notice.

What percentage of users, globally, do you suppose are qualified to make informed consent on arbitrary patches to $secure_messenger of your choosing?

Re: Moxie Marlinspike has a plan to reclaim our privacy

#35

It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…

> When tech nerds nit pick Signal's implementation, they ignore that the unfederated nature of Signal limits the damage these decisions can cause. It limits the damage that some decisions can cause, but exacerbates others. Signal only allows the first-party client to connect to its network; if the developers were legally compelled to add a backdoor into that client, users would have few options. Its security depends…

Signal is OSS and you can start your own fork & network if you want to.

App publishing platforms not having a good binary signature verification system is the orthogonal issue that you're bringing up, that would in many ways apply to matrix for most users too. Most will never bother to sideload it.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#36
post #9

Why is it, whenever Signal is brought up on Hacker News, we get inundated with the people who object to the core decisions of the Signal Project? Would Signal really be better if, instead of having a secure messenger available to the masses, it spent massive amounts of time implementing the things these people want? No. I would be comfortable recommending Signal (or WhatsApp) to a nontechnical friend and communicatin…

Signal only has any userbase due to advocacy; compared to the secure-enough-for-most WhatsApp which has literally billions of users and is the default choice, every user of Signal had to be convinced to install it. So I think it's unfair to bash people who criticise the project. The 'drag' they apply to wider adoption is still miniscule. Put it this way: why does Signal exist when WhatsApp is good enough? Wouldn't Mr…

> why does Signal exist when WhatsApp is good enough?

WhatsApp sends all your contacts to Facebook instead of the Signal Foundation, and unlike Signal, doesn't use SGX to keep Facebook from knowing what they are.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#37
post #25

Earlier quoted context omitted.

Many of the security design flaws in signal have had little to no direct impact on usability. For example, for years we asked for a simple mechanism which could be used to view a users key and mark it as identified, to prevent MITM -- even one buried in a menu for advanced users (who could at least act as canaries against widespread interception). Not only was the request turned down but usually responded to with vig…

Can the downvoters please respond to the post with the reasons why they are downvoting?

I assume it's a defensible question of priorities.

In spite of the many issues to complain about signal it's still a lot better than what $random_person would likely use otherwise.

Do we do the most good for the world by under-representing signal's weaknesses and overstating its security in order to maximize the people using it over choices that are worse and cheerlead its development, or do we do the most good by trying to be frank and being critical of its limitations (at least some of which are pretty nitpicky), potentially at the expense of the discussion causing people to continue using clearly worse alternatives?

Personally I answer this conflict like this: Outside of a techy venue I don't go into any details about signal's limitations-- I tell people they should use it, but don't assume it keeps them private from governments, google, or other powerful parties.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#38
post #35

Earlier quoted context omitted.

> When tech nerds nit pick Signal's implementation, they ignore that the unfederated nature of Signal limits the damage these decisions can cause. It limits the damage that some decisions can cause, but exacerbates others. Signal only allows the first-party client to connect to its network; if the developers were legally compelled to add a backdoor into that client, users would have few options. Its security depends…

Signal is OSS and you can start your own fork & network if you want to. App publishing platforms not having a good binary signature verification system is the orthogonal issue that you're bringing up, that would in many ways apply to matrix for most users too. Most will never bother to sideload it.

> Signal is OSS and you can start your own fork & network if you want to.

You can't though, what use is your own fork when nobody uses it?

Re: Moxie Marlinspike has a plan to reclaim our privacy

#39
post #34
post #30

Earlier quoted context omitted.

> update agility makes Signal infinitely superior to every existing or proposed federated network. Translation: Signals ability to forcefully change the software and protocol out for users without any consent (much less informed consent) renders it functionally immune to any criticism or review because any aspect of the protocol could be changed ('improved') at a moments notice. I think signal is a fine insecure mess…

>Translation: Signals ability to forcefully change the software and protocol out for users without any consent (much less informed consent) renders it functionally immune to any criticism or review because any aspect of the protocol could be changed ('improved') at a moments notice. What percentage of users, globally, do you suppose are qualified to make informed consent on arbitrary patches to $secure_messenger of y…

Informed consent for a drug doesn't mean that you personally understand molecular biology. It usually means that you've received and understand factual information about the tradeoffs from hopefully neutral parties who are acting in your best interest and can weigh those considerations based on your own priorities and preferences. And that you can make the choice you make free of coercion, or otherwise it isn't consent at all.

Signal's software management practices make the system largely opaque even to experts, and what review does happen comes at a significant lag. This is evidenced by the substantial number of times that signal has had to back-pedal on a change after substantial backlash. Even where it isn't opaque, there is no consent: the software stops running if you don't accept all changes, and seldom are changes introduced as optional features (default-on or otherwise).

Re: Moxie Marlinspike has a plan to reclaim our privacy

#40
post #23

Earlier quoted context omitted.

I’m not sure that that’s the only conclusion you can draw. Some systems choose to not handle that metadata, which often makes them a worse service but they make that choice by looking at the landscape and choosing to not use SGX. The other plausible argument is that Signal uses SGX, which is better than nothing, but in selling it as more secure than it is they do more harm than good.

What’s an example of a system in this space which chooses not to handle that metadata?

I don't need a phone number, nor do I need to upload my contacts' phone numbers[1], in order to use Matrix.

[1]: I work around this by running Signal in a work profile with no contacts. So it's... kinda sorta optional, but in practice there are many caveats and complications that make it effectively not. Certainly not when we're claiming it for average users, which is Signal's argument for using it.

Post reply on HN