Live data from Hacker News

Signal Adds Cryptocurrency Support

schneier.com

71–80 of 263 posts

Re: Signal Adds Cryptocurrency Support

#71
post #44

Earlier quoted context omitted.

This obsession with crypto killed Keybase for many of it's users and honestly this could be a bad news for Signal.

The problem with Keybase is that its UI should be a lot more polished. Other than that, how does using cryptocurrencies interfere with chat?

Keybase was a passion project that always had very limited development time. They churned out a lot of proof-of-concept grade features, but never really polished any of them. And then some of the features only would be really useful if they either were backed by a proper commitment or had a selfhostable plan B.

The wallet is just one of many parts of keybases focus thrashing.

Re: Signal Adds Cryptocurrency Support

#73
post #49

I convinced quite a lot of my friends to switch to Threema. No phone number required, and really open source ( https://threema.ch/en/faq/source_code )

Except the server it seems? I only see the various clients on github.

Like signal, their server code on github is not what they are running.

Re: Signal Adds Cryptocurrency Support

#74
post #35

I think there are 3 attitudes towards Signal: 1. Anger from purists who care about the fact it's not decentralised, and that Moxie runs the show, and that it uses phone numbers etc etc... 2. Indifference from those who have never heard of it 3. Joy from those who are extremely happy a decent, private, alternative to Facebook/Whatsapp exists My worry is that group 1) try and ruin it for the rest of us. Signal is liter…

> and prevents mass surveillance

A chain is only as strong as its weakest link. What if you somehow got malware on your device? That's all your Signal privacy out the window. Some phones are stuck on older versions and can't update to mitigate against so called 'zero click' attacks or attacks that require user action like clicking on a link sent via SMS which then spawns a malicious payload that's executed in the default browser. Malware on phones is rampant. It's not just 'spouseware' being installed behind your back or high-profile people being targeted. Millions of devices (billions even?) en masse are getting compromised with malware.

Re: Signal Adds Cryptocurrency Support

#76
post #68

Earlier quoted context omitted.

That seems wrong, is like if Mozilla forces crypto in Firefox. there will be many Firefox users that will not like it, it is not only the haters or Chrome users that will complain, hopefully maybe you can see the missing 4th perspective.

I don't believe the main competitors to Firefox (Chrome, Edge, Safari) offer a payment mechanism? So this wouldn't be required for core feature parity. However the two main competitors to Signal (Telegram and Whatsapp imo) do have a payment mechanism.

Chrome has the Payments API and the most recent betas have the Digital Goods API which allows Play Store billing.

Re: Signal Adds Cryptocurrency Support

#77
post #31

Earlier quoted context omitted.

The act of "sending" a cryptocurrency payment is actually the publication of a cryptographic signature.

And the act of 'sending' a conventional fiat payment today is actually the publication of a transaction record in one or more databases. That doesn't mean it's 'speech'.

[deleted]

Re: Signal Adds Cryptocurrency Support

#78
post #23

Earlier quoted context omitted.

iMessage is backdoored? Evidence please?

iCloud Backup backs up plaintext of all iMessages from the device to Apple, with Apple keys (non-e2e). It also includes all SMS. This is documented plainly on Apple's iCloud security overview page. The list of things that are end-to-end encrypted is listed. iCloud Backup is not in it. It's on by default on all iOS devices. Apple was to fix this by end to end encrypting iCloud device backups, and (I understand) even h…

iCloud Backup being insecure does NOT mean iMessage is "backdoored": if you don't use iCloud Backup--and there is no reason to do so, as Apple (notably unlike anything Android) has a really good local way to do highly-secure backups using iTunes--my (rather firm) understanding is that, even if you turn on the iCloud iMessage sync (which is also optional: I do not have it on, for example), iMessage actually is pretty damned secure (with no key escrow).

I appreciate that a lot of people--maybe most or even "almost all" people!--use iCloud Backup, but semantics matter as you present it as if iMessage is insecure, when not only the "real" but the only issue is iCloud Backups (which we should be making sure people don't use, with targeted education campaigns, as it isn't like using Signal could ever solve this issue for all of the other personal data the user had).

If you want to make this kind of argument, you need to be doing it from a place of being more informed; like, you could be trying to poke at how the protocol had a weakness--found by pod2g's team--with respect to Apple's ability to inject new keys for existing chat participants, an issue I am not sure they fixed (or even could fix, as it is arguably a UI security problem... but maybe they did, as I don't always follow the blow-by-blow); but this indirect argument you make is FUD.

Re: Signal Adds Cryptocurrency Support

#79
post #12

I find this incredibly offensive. Has there been any deliberation in the Signal community on whether or not this is something that Signal should have?

Mirroring the sibling comment here, moxie has been very open that this is his project, top down. He moves as fast as he wants and he steers wherever he thinks is appropriate. This is one of the main reasons Signal doesn't federate - he thought it'd bring iteration speed to a halt.

(And let's be honest, if XMPP and the A3-sized spreadsheet you need for to pick a client based on XEP support is anything to go by, this is not undue concern.)

Post reply on HN