Live data from Hacker News

Moxie Marlinspike has a plan to reclaim our privacy

newyorker.com

81–90 of 237 posts

Re: Moxie Marlinspike has a plan to reclaim our privacy

#81
post #76

Weird typos(?) in the article: coördinate, coöperate. Seemingly other sloppy typos like "Signal could only proffer the relevant". No critique against the substance of the article though, seems great so far, love Moxie. Edit: And the date in the URL is October 26.

The New Yorker's house style is to use a dieresis to indicate when adjacent vowels do not form a diphthong. There's a syllable-break in between the Os of "coöperate", as opposed to between the Os of "chicken coop", so it gets a special marker.

See https://en.wikipedia.org/wiki/Diaeresis_%28diacritic%29#Engl...

"proffer" is also a perfectly legitimate word: https://www.merriam-webster.com/dictionary/proffer

Re: Moxie Marlinspike has a plan to reclaim our privacy

#83
post #76

Weird typos(?) in the article: coördinate, coöperate. Seemingly other sloppy typos like "Signal could only proffer the relevant". No critique against the substance of the article though, seems great so far, love Moxie. Edit: And the date in the URL is October 26.

The diereses over the o (or any doubled letter) is an old-fashioned way of indicating a syllable break, rather than a longer vowel sound (as in “good”). It’s the New Yorker’s house style.

Also, I don’t see any spelling mistakes in the sentence you mention...

Re: Moxie Marlinspike has a plan to reclaim our privacy

#84

Earlier quoted context omitted.

> When tech nerds nit pick Signal's implementation, they ignore that the unfederated nature of Signal limits the damage these decisions can cause. It limits the damage that some decisions can cause, but exacerbates others. Signal only allows the first-party client to connect to its network; if the developers were legally compelled to add a backdoor into that client, users would have few options. Its security depends…

Compile your own client binary and use that?

The binaries are not obfuscated. You can analyze the official versions from the app stores for backdoors.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#85
post #67
post #61

Earlier quoted context omitted.

I've also heard that Signal on android leaks message text because of google's keyboard auto-prediction feature. They should implement their own keyboard or find a way to disable text prediction - and educate their users.

In general I would not expect much privacy from a stock Android device on any chat tool considering they shamelessly ship lots of third party blobs carriers demand be included, some of which like OMA-DM toolkits have sweeping permissions on your device. On Apple this is less true, but it is also a centralized black box that grants you no freedom, and apps can be banned at any time with little recourse. You could use…

> some of which like OMA-DM toolkits have sweeping permissions on your device.

Fortunately this seems to be going away.

For those not aware as to what you're talking about, this is the proprietary 'rootkit' providers like Sprint had to use to activate CDMA modems on their carriers on many of their devices that did not come with a CSIM. As it's doing a lot with the phone's modem, it needs tons of permissions on the device. Verizon Wireless and Google Fi also had similar apk's that were required to provision phones and update PRL (prority roaming list) information.

In the US all modern devices on Verizon are CDMA-less and new Sprint customers are usually activated on T-Mobile network (with fallback to GSM/WCDMA not CDMA).

Re: Moxie Marlinspike has a plan to reclaim our privacy

#87
post #72

Earlier quoted context omitted.

>Like the key agility that makes the Axolotl Ratchet so superior to GPG, I am not sure how you can usefully compare a thing originally intended to secure email to a thing intended to secure IM. The ratchet only provides forward secrecy anyway. My take on that is that it is a pointless thing for something like email and pointless in practice for most IM applications. Most IM users keep their old messages and practical…

It provides forward secrecy and deniability. Your chat database doesn't prove that I said what your database says I said.

Both Signal and OTR provide deniability in a narrow cryptographic sense with no real practical benefit. Cool idea though...

Re: Moxie Marlinspike has a plan to reclaim our privacy

#88
post #20

Earlier quoted context omitted.

Signal only has any userbase due to advocacy; compared to the secure-enough-for-most WhatsApp which has literally billions of users and is the default choice, every user of Signal had to be convinced to install it. So I think it's unfair to bash people who criticise the project. The 'drag' they apply to wider adoption is still miniscule. Put it this way: why does Signal exist when WhatsApp is good enough? Wouldn't Mr…

WhatsApp... uses the Signal Protocol. I don't understand this line of thinking at all.

Well at least they used to. Who knows these days.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#89

Other than matrix, what are some other alternatives or upcomers in the messaging field I should try. Matrix still has a high burden of me setting up my own server and maintaining it. Till their P2P solution doesnt release, they have their own metadata problem.

Wire: open source (AGPL server/clients), can self-host, available as a public cloud service (free for user-to-user comms, paid for orga comms).

Disclosure: worked for them.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#90

It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…

Centralized solutions vs federated solutions is like monarchy vs republic.

Under monarchy, the power of the monarch is greatly amplifed. A great monarch can accomplish beneficial reforms at scope and speed not achievable by any republic. A bad monarch can inflict damage at scope and speed unprecedented in any republic.

Equally, a centralized network can achieve colossal heights of UX, security, speed, architectural cleanliness, etc; moxie wrote a lot about that. Or it can fall into bottomless chasms of poor UX, poor functioning, and insecurity (examples are many, take maybe ICQ by the early 2000s). By construction, three's no way for a part of the network to avoid the common fate, try and find a recourse, etc.

A republic (and a democracy) severely limits the power of officials it elects, more, it intentionally pitches different branches against each other in a system of checks and balances. This prevents it from achieving grandiose visions in short time, most of the time, even when the best officials are elected. It also prevents it from turning into hell, most of the time, even if some egregiously bad officials are elected to the highest offices.

Same with federated networks: they offer a much less coherent UX, are more complex, less powerful, more slow, harder to upgrade — but they are also resilient against a bad actor that grabs power, for they lack a SPOF, and have a healthy nonzero amount of distrust between parts. If one part rots, others remain, and new can be made.

So yes, bet on the centralized system, a brilliant benevolent dictator if you think the dictator outlives your need to use a system. Bet on moxie, Steve Jobs, or king Arthur to live effectively forever.

Or bet on an open standard with a half-dozen implementations of varying quality if you think that things will inevitably go sour in some of them during your lifetime, or whatever is the time scope for your use of the system.

There is no single right answer, no Goldilocks solution. Choose your poison.

Post reply on HN