Live data from Hacker News

Moxie Marlinspike has a plan to reclaim our privacy

newyorker.com

121–130 of 237 posts

Re: Moxie Marlinspike has a plan to reclaim our privacy

#121

It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…

> When tech nerds nit pick Signal's implementation, they ignore that the unfederated nature of Signal limits the damage these decisions can cause. It limits the damage that some decisions can cause, but exacerbates others. Signal only allows the first-party client to connect to its network; if the developers were legally compelled to add a backdoor into that client, users would have few options. Its security depends…

> It limits the damage that some decisions can cause, but exacerbates others. Signal only allows the first-party client to connect to its network; if the developers were legally compelled to add a backdoor into that client, users would have few options.

Huh? I send messages to my friends daily using the API via https://gitlab.com/thefinn93/signald which is definitely third party.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#122
post #101
post #65

Earlier quoted context omitted.

I have run my own identity servers for private deployments without issue. This is, granted, not as easy as it should be, but it is an issue the matrix team is working on improving. You also don't need to use the identity service at all. It is totally optional for user discovery. Third party implementations of the identity server already exist too. Someone could even write their own replacement that uses SGX if they r…

Optional security isn't security. Especially with the sort of metadata that is in _someone else's phone_. Basically, everybody who has my phone number probably has it in their iOS/Android contacts. I can't opt out of _them_ using a bad identity server.

But you already can't opt out of them sharing their entire address book with the latest sketchy app they downloaded. What's the difference?

They either have your phone number and other contact details in their phone or they don't. They either make good decisions or they don't. You choose how much to trust them and what with. Federation and third party implementations of identity servers for one particular app changes absolutely none of that.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#123
post #121

Earlier quoted context omitted.

> When tech nerds nit pick Signal's implementation, they ignore that the unfederated nature of Signal limits the damage these decisions can cause. It limits the damage that some decisions can cause, but exacerbates others. Signal only allows the first-party client to connect to its network; if the developers were legally compelled to add a backdoor into that client, users would have few options. Its security depends…

> It limits the damage that some decisions can cause, but exacerbates others. Signal only allows the first-party client to connect to its network; if the developers were legally compelled to add a backdoor into that client, users would have few options. Huh? I send messages to my friends daily using the API via https://gitlab.com/thefinn93/signald which is definitely third party.

Moxie has explicitly said several times that third-party clients connecting to the main Signal servers are actively not supported and has threatened to start blocking them or enforcing the Signal trademark if they get big enough. (I tried to find a link to the exact comments he's made, but the threads involved have hundreds of comments and I'm on my phone -- he said this in one of the huge Google Play issues.)

Re: Moxie Marlinspike has a plan to reclaim our privacy

#124
post #39
post #34

Earlier quoted context omitted.

>Translation: Signals ability to forcefully change the software and protocol out for users without any consent (much less informed consent) renders it functionally immune to any criticism or review because any aspect of the protocol could be changed ('improved') at a moments notice. What percentage of users, globally, do you suppose are qualified to make informed consent on arbitrary patches to $secure_messenger of y…

Informed consent for a drug doesn't mean that you personally understand molecular biology. It usually means that you've received and understand factual information about the tradeoffs from hopefully neutral parties who are acting in your best interest and can weigh those considerations based on your own priorities and preferences. And that you can make the choice you make free of coercion, or otherwise it isn't conse…

To your point:

https://github.com/signalapp/Signal-Desktop/issues/4578

Re: Moxie Marlinspike has a plan to reclaim our privacy

#125
post #62
post #51

Earlier quoted context omitted.

You can optionally add your public identifiers to Matrix (phone, email, etc), which lets people search for you via identity providers. What Signal does is 1) require your phone number, 2) automatically upload every phone number in your contacts, and 3) send a push notification to people on Signal that have uploaded your number in the past that you have joined. It's a world of difference. And a huge breach of implied…

As noted above, I’m pretty sure that Signal’s current state allows a user to choose whether their contacts are uploaded. But again, the point I made originally, and which you replied to, isn’t about what users may or may not do. It’s whether any messaging platforms have resolved to not store metadata, rather than attempting (as Signal has) to only store it securely. We can debate whether people agree with Signal’s ap…

You're really missing the point here. The core Matrix protocol doesn't handle contact discovery at all.

An entirely separate system exists to facilitate contact discovery. You have to explicitly choose to publish an identifier to it. You choose the server you want to publish to. You choose if, which, and when to query such servers. You choose what to query them with.

A server implementation can (in theory) support whatever arbitrary thing it wants to for an identifier. The fact that email addresses are commonly supported is already _significantly_ better than being forced to use a phone number.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#126

Other than matrix, what are some other alternatives or upcomers in the messaging field I should try. Matrix still has a high burden of me setting up my own server and maintaining it. Till their P2P solution doesnt release, they have their own metadata problem.

Briar has good traction, it's p2p https://briarproject.org/

Re: Moxie Marlinspike has a plan to reclaim our privacy

#127
post #91

Earlier quoted context omitted.

The New Yorker's house style is to use a dieresis to indicate when adjacent vowels do not form a diphthong. There's a syllable-break in between the Os of "coöperate", as opposed to between the Os of "chicken coop", so it gets a special marker. See https://en.wikipedia.org/wiki/Diaeresis_%28diacritic%29#Engl... "proffer" is also a perfectly legitimate word: https://www.merriam-webster.com/dictionary/proffer

While being a non-native speaker I still consider myself to have a high grade of English knowledge and I knew about neither of these. Thank you!

Just to complete the trifecta, the URL date is presumably that of the print issue in which this article will appear. This "cover date" is usually a week or so ahead of the actual printing date: https://en.wikipedia.org/wiki/Cover_date

Re: Moxie Marlinspike has a plan to reclaim our privacy

#128
post #64

Earlier quoted context omitted.

Signal disallows federation from forks (it has been attempted). "Using signal" requires using the official build, and that requires closed-source libraries and services (e.g. Google Play Services).

Signal doesn't require Google Play Services. It will use Play Services if installed for notifications, but works fine without them, and it can be installed on LineageOS etc.

In fairness to GP, this only became true a few years ago and Signal has not advertised this (nor the fact that you can now download the Signal APK from their website and it auto-updates outside of the play store[1]). Folks who opted to not use Signal some time ago likely had no way of finding this out, and Moxie's comments on this in ~2014 gave the impression that it would never happen.

[1]: https://signal.org/android/apk/

Re: Moxie Marlinspike has a plan to reclaim our privacy

#129
post #62
post #51

Earlier quoted context omitted.

You can optionally add your public identifiers to Matrix (phone, email, etc), which lets people search for you via identity providers. What Signal does is 1) require your phone number, 2) automatically upload every phone number in your contacts, and 3) send a push notification to people on Signal that have uploaded your number in the past that you have joined. It's a world of difference. And a huge breach of implied…

As noted above, I’m pretty sure that Signal’s current state allows a user to choose whether their contacts are uploaded. But again, the point I made originally, and which you replied to, isn’t about what users may or may not do. It’s whether any messaging platforms have resolved to not store metadata, rather than attempting (as Signal has) to only store it securely. We can debate whether people agree with Signal’s ap…

Also note that with Matrix, you have the option of running your own home server (or use one provided by someone you personally trust) and communicate seamlessly with people on other home servers. The dynamic is completely different.

Oh, and any/every device/client is a first-class citizen which means you can run it on more then one phone at the same time, or use it without a phone at all.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#130
post #119
post #28

Earlier quoted context omitted.

Who, though? Matrix has contact discovery, doesn't it?

If and only if you opt in to it. It's difficult to understate how important that is.

You also have the option of using alternative identity servers, and still have no problem communicating with those on others.
Post reply on HN