Live data from Hacker News

Signal Adds Cryptocurrency Support

schneier.com

121–130 of 263 posts

Re: Signal Adds Cryptocurrency Support

#121
post #107
post #97

Earlier quoted context omitted.

Signal doesn't--and can't--somehow magically prevent people from backing up their messages insecurely. That they don't support being backed up by normal backup methods on iOS--including highly-secure ones--is a missing feature (and a devastating one at that: people expect to have access to their old messages) more than a security measure. Consider this: the existence of a popular tool that helps people back up their…

If that tool shipped as part of iOS, were on by default, and silently sent the full message history plaintext to Apple (such as if Apple iCloud Backup stopped respecting the storage class of apps and just backed up EVERY FILE), I think it would be fair to call that a backdoor (in iOS). What if iCloud Backup started including in the backup a snapshot of device RAM? I think we are splitting hairs here. The desire of us…

Call a spade a spade: if iCloud Backup is insecure (and it is), then say iCloud Backup is insecure, not iMessage. Your stance on this is FUD because you don't respect the semantic boundaries of the systems you are discussing, and so anyone who decides to truly listen to you and internalize the things you say leaves with a broken mental model rather than an educated stance :/. Every single person who reads what you say "iMessage, now backdoored for the FBI" who decides to stop using iMessage (which wasn't even insecure to begin with) and does NOT decide to stop using iCloud Backup (which will be insecure even if the user is using Signal, along with Signal's iOS product flaw that attempts to circular file your messages, as messaging is but one of myriad things a user does on their phone) is someone you have failed by teaching them the wrong lesson.

Re: Signal Adds Cryptocurrency Support

#123
post #35

I think there are 3 attitudes towards Signal: 1. Anger from purists who care about the fact it's not decentralised, and that Moxie runs the show, and that it uses phone numbers etc etc... 2. Indifference from those who have never heard of it 3. Joy from those who are extremely happy a decent, private, alternative to Facebook/Whatsapp exists My worry is that group 1) try and ruin it for the rest of us. Signal is liter…

I have another attitude, which is suspicion that it is a honey trap. If the FBI can read messages ( https://www.forbes.com/sites/thomasbrewster/2021/02/08/can-t... ), it would seem like the perfect setup for them. Why does everyone have so much faith in Signal? What if that faith is being misplaced?

Gov agencies can hack devices to read the contents - this is not specific to Signal or any weakness of Signal.

However Signal does provide secure e2e encryption which prevents mass surveillance.

Re: Signal Adds Cryptocurrency Support

#124
post #35

I think there are 3 attitudes towards Signal: 1. Anger from purists who care about the fact it's not decentralised, and that Moxie runs the show, and that it uses phone numbers etc etc... 2. Indifference from those who have never heard of it 3. Joy from those who are extremely happy a decent, private, alternative to Facebook/Whatsapp exists My worry is that group 1) try and ruin it for the rest of us. Signal is liter…

So... Looks like the people on group #1 were right all the time. And you are posting this as an answer to somebody telling you that his pet idea will kill the platform and bring law enforcement all over the world into its users.

(What in my impression is the best case scenario, because when I've read about it I could only think about it bringing fraud and extortion into the users.)

Re: Signal Adds Cryptocurrency Support

#125

Earlier quoted context omitted.

You can both think cryptocurrencies are a stupid idea and believe that introducing payments into Signal is a bad idea for other reasons. Your assumption that one belief is simply a fig-leaf for the other is not justified. Based on my personal experience, people who are serious about cryptography from a public-policy perspective are likely to have both of those opinions.

My point is completely justified when you read the article attached (and much of the comments here).

I'm sure you think that; would you be prepared to explain why? I have read the article.

Re: Signal Adds Cryptocurrency Support

#126

Earlier quoted context omitted.

I have another attitude, which is suspicion that it is a honey trap. If the FBI can read messages ( https://www.forbes.com/sites/thomasbrewster/2021/02/08/can-t... ), it would seem like the perfect setup for them. Why does everyone have so much faith in Signal? What if that faith is being misplaced?

Come on. The article you linked just shows that if the FBI can unlock an iPhone, they can read Signal messages. This is not exactly a surprising revelation.

[deleted]

Re: Signal Adds Cryptocurrency Support

#127
post #54

Earlier quoted context omitted.

With regards to the first, you see, it's an > uncluttered messaging app that just works. Cryptocurrency turns it into a cluttered messaging app, one that gives hackers extra financial incentives to compromise it.

Perhaps there will be a tab for your wallet, and an extra button to pay. Apart from that - you don't need to use the cryptocurrency parts.

I don't need to use any cluttered features, yet they are still clutter.

Re: Signal Adds Cryptocurrency Support

#130
post #35

I think there are 3 attitudes towards Signal: 1. Anger from purists who care about the fact it's not decentralised, and that Moxie runs the show, and that it uses phone numbers etc etc... 2. Indifference from those who have never heard of it 3. Joy from those who are extremely happy a decent, private, alternative to Facebook/Whatsapp exists My worry is that group 1) try and ruin it for the rest of us. Signal is liter…

What the world needs, though, is a decent, private alternative to Snapchat--which a lot of very normal non-technical people use specifically with the goal of "privacy" as they don't want to give their phone number to random people they meet at parties or while doing online dating or on services such as TikTok--not WhatsApp, which is already end-to-end encrypted (with the same protocol!). Signal needs to remain a viable alternative to WhatsApp to "keep them honest", but doesn't need to fight them and should move on to their next challenge (as the goal shouldn't be "get everyone to use Signal", but instead should be "get everyone to use an end-to-end secure messaging app"). This all happens to firmly fall into the first camp, which you incorrectly label as "purists" :(. Even the people I talk to who want to organize protests and the such are harmed by everyone pushing Signal as their main threat is a cop getting a list of all of the phone numbers in a chat off of someone's phone, something Signal doesn't solve... but, ironically, Snapchat and Telegram do, for all of their other faults: we need an end-to-end encrypted Snapchat/Telegram _stat_.
Post reply on HN