Live data from Hacker News

Moxie Marlinspike has a plan to reclaim our privacy

newyorker.com

151–160 of 237 posts

Re: Moxie Marlinspike has a plan to reclaim our privacy

#151
Is this a form of personality cult?

> Marlinspike is the C.E.O. of Signal, the end-to-end encrypted messaging service, which he launched in 2014; he is also a cryptographer, a hacker, a shipwright, and a licensed mariner.

What's all the hype about Signal? It's a bad application.

Let's see. Install it. Oh, it starts with a screen about Terms and confidentiality. But... why does Signal get me to agree to things if it's so much about privacy? Are they... reading our chats?

OK, next. Oh, it needs access to Contacts and Media to improve communications. Right -- because nothing like that sweet social graph. But I can skip this one.

Oh, now it wants my phone number!

Experiment complete. Let's uninstall this app.

I fail to see how this is any better than Whatsapp.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#152

It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…

I imagine it was even more frustrating for the eavesdroppers when they could no longer listen in on the top secret discussions with your grandparents. The eavesdroppers will not give up easily though; grandparents everywhere must stay vigilant.

You're revealing your own lack of aspiration while condescending toward older people.

Some people have prominent positions or intend to do important things in their life and they don't want to see personal conversations being leaked under the threat of blackmail.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#153
post #123
post #121

Earlier quoted context omitted.

> It limits the damage that some decisions can cause, but exacerbates others. Signal only allows the first-party client to connect to its network; if the developers were legally compelled to add a backdoor into that client, users would have few options. Huh? I send messages to my friends daily using the API via https://gitlab.com/thefinn93/signald which is definitely third party.

Moxie has explicitly said several times that third-party clients connecting to the main Signal servers are actively not supported and has threatened to start blocking them or enforcing the Signal trademark if they get big enough. (I tried to find a link to the exact comments he's made, but the threads involved have hundreds of comments and I'm on my phone -- he said this in one of the huge Google Play issues.)

Yup - you're probably thinking of this one and the other similar comments in the (mess of a) thread: https://github.com/LibreSignal/LibreSignal/issues/37#issueco...

Makes it pretty clear that OWS does not want people using third-party clients with the official Signal servers.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#155
post #96
post #88

Earlier quoted context omitted.

Well at least they used to. Who knows these days.

...anyone with a packet sniffer?

WhatsApp encourages people to back up their messages to either Apple Cloud or Google Drive which breaks the E2E encryption. There is no way to tell whether the other party is doing this and just one person in a group chat can accidentally / on purpose back up the chat at any time.

Signal allows chat backups but it's not the default option and the UX deliberately discourages this behaviour. They are also encrypted with a password which offers more security.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#156
post #152

Earlier quoted context omitted.

I imagine it was even more frustrating for the eavesdroppers when they could no longer listen in on the top secret discussions with your grandparents. The eavesdroppers will not give up easily though; grandparents everywhere must stay vigilant.

You're revealing your own lack of aspiration while condescending toward older people. Some people have prominent positions or intend to do important things in their life and they don't want to see personal conversations being leaked under the threat of blackmail.

And some people have nothing better to say, over and over again, than "That software you like is [...] because my Grandmother does not use it."

This is a tired trope and it's time we put it to rest. There is nothing wrong with software not intended for a "mass market".

Re: Moxie Marlinspike has a plan to reclaim our privacy

#157

I applaud the man for trying really, really, hard to make a difference, and succeeding. I look forward to the day when Signal doesn't require a phone number. Telegram, while requiring a phone number doesn't require you to disclose it to receive messages. Others having your phone number opens you to all kind of other attacks, which are quite bad. Sim swapping, and SS7 attacks. SS7 vulns can disclose your real time loc…

OTOH, Telegram's crypto is... suspect. https://security.stackexchange.com/a/49802

Sigh. That Stack Exchange answer is incredibly old and points to the flaws everyone knew in MTProto 1, which has been superseded by MTProto 2 for years. MTProto 2 is based on standard crypto primitives that not a single human being has found fault in.

Please do your research before putting this stuff out there in the future: it spreads unnecessary fear, uncertainty and doubt.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#158
post #134

Earlier quoted context omitted.

Even the server-side software is not feature complete yet. Give it time. Another client that I think is aiming to fill that gap (and also has a provider with bridges to eg Messenger et al) is Novachat: https://nova.chat/ Matrix is not an IM app, it’s a protocol. Anyone is encouraged to make an app for it. It’s a long game. I’d give it another year or two before I think it’s grandma-ready.

Indeed it's a protocol. A horrendous, reinvent-everything, excessively complex mess of a protocol, that the developers of the reference server have gone on record saying that they don't expect anyone else to be able to successfully implement.

> the developers of the reference server have gone on record saying that they don't expect anyone else to be able to successfully implement.

Despite this, there are multiple alternative server implementations. Dendrite is the next gen server from the same core team, though Construct and Conduit are fledgling servers from different groups.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#159
post #9

Why is it, whenever Signal is brought up on Hacker News, we get inundated with the people who object to the core decisions of the Signal Project? Would Signal really be better if, instead of having a secure messenger available to the masses, it spent massive amounts of time implementing the things these people want? No. I would be comfortable recommending Signal (or WhatsApp) to a nontechnical friend and communicatin…

> No. I would be comfortable recommending Signal (or WhatsApp) to a nontechnical friend and communicating with them on it

I kind of like Signal. It seems like an honest effort for a really great goal and the dedication as well as some of the things they have achieved seems seriously impressive!

As for WhatsApp, you realize that they upload all your chats to the cloud, unencrypted, easily retrievable by you and whoever you chat with, and that getting rid of them will take effort on both sides?

You are aware that Facebook probably use your metadata to feed their algorithms?

Edit: my point is that as engineers and technologists it is so easy to be blinded by tbe technical rick solid technical implementation if an (important) part and forget that security depends on all parts of the puzzle.

- End-to-end doesn't matter if the endpoints by default upload everything to cloud storage unencrypted. If it is going to end up unencrypted in Googles cloud you can just as well use gmail. That way you won't make your metadata accessible to Facebook at the same time.

- End-to-end only means so much when an adversary is running the routing: they cannot know the contents of your messages as they fly through their networks but if you don't trust Facebook, do you really want them to know who you talk to and when?

Re: Moxie Marlinspike has a plan to reclaim our privacy

#160

It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…

In general, I agree. However, their decision to force PINs broke Signal for one of my non-technical contacts, to this day (despite them supposedly offering an opt-out now). This person opens Signal, gets some weird confusing modal dialog, and is now stuck. There is supposed to be a way to opt out without having to set and remember a PIN now, but I was unable to guide this person to find it, and I can't exactly travel…

OK, this is shit. I was not under the impression that this PIN was used to encrypt user data for storage somewhere else. That was not made clear to me.
Post reply on HN