Earlier quoted context omitted.
Signal has open clients with reproducible builds. We know that they are keeping their promises wrt what information is communicated with the backends. That's a step above the other options in common use, and in fact does make Signal special.
> Signal has open clients with reproducible builds. Not really. First of all, there is only one Signal client allowed to connect to Signal’s servers. And in the real world, the vast majority of Signal uses are getting their APK for that app from the Google Play store (the Signal team has said that they prefer you to use the Play store as well, instead of direct-downloading an APK from their website which they offer o…
Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
161–170 of 243 posts
Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
#162Earlier quoted context omitted.
Signal has open clients with reproducible builds. We know that they are keeping their promises wrt what information is communicated with the backends. That's a step above the other options in common use, and in fact does make Signal special.
Are you running an open client? Is anyone? That's all a smoke screen. Nobody is running an open client with a reproducible build, everybody is running whatever version is downloaded from their app store of choice. It's not special, and I don't trust it a bit.
Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
#163Earlier quoted context omitted.
I wish people would emphasize this more. Bitcoin isn't anonymous, and with the legal requirements for reporting transactions, much of what happens on there can be corellated to real-world identities. Far as privacy goes, it's probably a step backwards even from bank accounts and credit cards since there's no warrant needed to access it.
Bitcoin is old and stagnant, the future is full anonymity in the form of zk-snarks, used by millions.
Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
#164Earlier quoted context omitted.
What's better, Signal or Telegram?
In contrast to Signal, Telegram doesn't end-to-end-encrypt messages by default (they get stored in plaintext on their servers), it also doesn't protect the social graph and even stores your contact list on their servers. Even WhatsApp is more secure than Telegram.
Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
#165Earlier quoted context omitted.
The people who visit this website are the people who are paid to create and administer all of this technology. They're not only the last people you would be able to convince of something that would affect their livelihoods, but even the ones who do understand feel like it is part of their duty to deceive the less technically adept about the capabilities and dangers of the technology that they're surrounded with. The…
I work in a factory doing factory stuff
Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
#166Earlier quoted context omitted.
The people who visit this website are the people who are paid to create and administer all of this technology. They're not only the last people you would be able to convince of something that would affect their livelihoods, but even the ones who do understand feel like it is part of their duty to deceive the less technically adept about the capabilities and dangers of the technology that they're surrounded with. The…
> upper middle-class are the most conservative elements of any society This very clearly is not the case in the US.
> But among the 64% of American voters who earn more than $50,000 a year, 49% chose Trump, and 47% Clinton.
[1] https://www.theguardian.com/us-news/2016/nov/09/white-voters...
Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
#167Earlier quoted context omitted.
It honestly worries me that this is the top comment on hacker news. Not because it is wrong (it isn't) but because of all places that website filled with tech workers and experts in the full software stack, full of people that work on and exploit meta data, it still needs to be discussed how important metadata is. If we can't convince people with their ear to the ground, how does one convince the general public. Espe…
An analogy I like is that they know you called a suicide hotline from a tall bridge in the middle of the night, but they don't know what you discussed.
Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
#168Earlier quoted context omitted.
> Signal has open clients with reproducible builds. Not really. First of all, there is only one Signal client allowed to connect to Signal’s servers. And in the real world, the vast majority of Signal uses are getting their APK for that app from the Google Play store (the Signal team has said that they prefer you to use the Play store as well, instead of direct-downloading an APK from their website which they offer o…
> That means that a state-level actor could possibly carry out a targeted attack to replace the Signal app on a given person's phone with a malicious build. No, they couldn't. They would need the Signal developers' key. Android requires app updates to be signed with the same key as the original app.
That isn't to say "all crypto is hopeless", simply that you shouldn't consider Signal to be state-level actor proof.
Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
#169Earlier quoted context omitted.
The people who visit this website are the people who are paid to create and administer all of this technology. They're not only the last people you would be able to convince of something that would affect their livelihoods, but even the ones who do understand feel like it is part of their duty to deceive the less technically adept about the capabilities and dangers of the technology that they're surrounded with. The…
Care to enlighten us what some of the "dangers" of metadata are?
Goal of metadata investigation isn't to directly target you, most of the time. It's to put you in the bucket of interesting people, that government will pay attention to.
It's exactly the same as ads on the internet - they maybe classifying you as a person potentially interested in computer security because you're visiting tech crunch. Are all people visiting it interested in computer security? Of course not. But you're many orders of magnitude more likely to be interested in it, than a random person from the internet.
Re: Danish military intelligence uses XKEYSCORE to tap cables in co-op with the NSA
#170Earlier quoted context omitted.
> upper middle-class are the most conservative elements of any society This very clearly is not the case in the US.
What? It's absolutely true in the US > But among the 64% of American voters who earn more than $50,000 a year, 49% chose Trump, and 47% Clinton. [1] https://www.theguardian.com/us-news/2016/nov/09/white-voters...