Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

61–70 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#61
post #28
post #25

Earlier quoted context omitted.

> Sometimes I really wonder the motives and identities behind the people causing such massive and unnecessary drama In this case, it's pretty boring. They are just a group of "your average power users" or "wannabe programmers" in their highschool or junior years who happened to be born in China so had some exposure to anti-censorship. Being in their overconfident period of life, they pass by various myth they don't r…

I've seen a growing number of anti-Signal posts and activism lately, mostly surrounding the (well-documented) design tradeoffs that Signal makes for usability and privacy (such as opting to use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers), or their famous decision not to federate/interoperate. Perhaps it's just criticism growing in lockstep with Signal's overall…

>use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers

Why can't the user just be expected to deal with their contact list? The phone company doesn't store your address book either.

This is a terrible excuse. They require the phone number as an anti-spam/moderation measure and hide behind privacy.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#62
post #21
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…

> So what should we use instead of signal?

Threema is one alternative.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#63
post #28

Earlier quoted context omitted.

I've seen a growing number of anti-Signal posts and activism lately, mostly surrounding the (well-documented) design tradeoffs that Signal makes for usability and privacy (such as opting to use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers), or their famous decision not to federate/interoperate. Perhaps it's just criticism growing in lockstep with Signal's overall…

One major reason for the push back against Signal promotion is that it does not represent any sort of federated protocol. It is a complete silo. So if it did become popular it would eventually be a serious problem and would need to be fought against.

> It is a complete silo. So if it did become popular it would eventually be a serious problem and would need to be fought against.

This is an explicit design decision. It used to federate, and they found that to be terrible, so they stopped, and now it's better.

Maybe you should find something else to fight against.

https://signal.org/blog/the-ecosystem-is-moving/

Worth noting: Google Talk used to federate, via XMPP. They found that almost nobody actually used the federation functionality, and something like 99%+ of the federation traffic was inbound spam.

Federated protocols aren't very good, and don't evolve.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#64
post #48

Signal seems to get a lot of unfair criticism. I think this is at least partly because they made something a lot of people actually do use. This would otherwise be quite a rarity in cryptography. This ‘statement’ is quite weird. Is it normal to declare oneself an oppressed minority over a github issue? I feel like we should be a bit more charitable to people who make things. Otherwise nobody will make anything anymor…

I agree. If you don't like it, create a fork? It is open source.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#65
post #21

Earlier quoted context omitted.

It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…

I think we are both talking about tone. While you are saying that expressing emotions and the drama is important in a discussion over Signals' future, I believe that such conduct only drives a wedge into it. These issues are emotional and affect important freedoms, but while expressing them is important doing it in such a high-profile, damaging way can only bruise egos and create even more tension. Instead, both part…

How exactly do both parties sit down to discuss their grievances when the incumbent party is clearly banning the party with a different perspective?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#66
post #61
post #28

Earlier quoted context omitted.

I've seen a growing number of anti-Signal posts and activism lately, mostly surrounding the (well-documented) design tradeoffs that Signal makes for usability and privacy (such as opting to use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers), or their famous decision not to federate/interoperate. Perhaps it's just criticism growing in lockstep with Signal's overall…

>use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers Why can't the user just be expected to deal with their contact list? The phone company doesn't store your address book either. This is a terrible excuse. They require the phone number as an anti-spam/moderation measure and hide behind privacy.

> Why can't the user just be expected to deal with their contact list?

They are; they let the user maintain their own list of phone numbers for their contacts, precisely like the phone company in your example.

> They require the phone number as an anti-spam/moderation measure and hide behind privacy.

This is (inaccurate) speculation from ignorance. Signal, unlike almost every other phone-number-using-service on the planet, does not block burner/disposable/voip numbers from being used with the service.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#67
post #66
post #61

Earlier quoted context omitted.

>use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers Why can't the user just be expected to deal with their contact list? The phone company doesn't store your address book either. This is a terrible excuse. They require the phone number as an anti-spam/moderation measure and hide behind privacy.

> Why can't the user just be expected to deal with their contact list? They are; they let the user maintain their own list of phone numbers for their contacts, precisely like the phone company in your example. > They require the phone number as an anti-spam/moderation measure and hide behind privacy. This is (inaccurate) speculation from ignorance. Signal, unlike almost every other phone-number-using-service on the p…

Then why not let users sign up with a random unique ID number that they can share with their contacts?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#70
Even if I agree with the principles of the anti-censorship people, to be an activist to apply pressure on Signal for features instead of forking and building solutions is suspicious to me. Signal does a great job of frustrating mass interception, which I think was its original point.

Inventing new criteria and re-framing their product as inadequate for this scope change as an activism play seems insincere. We can expect this kind of pressure to be applied to all BDFL-run software projects, as I think there is an emerging organized play to insert new governance over foundational internet software.

Post reply on HN