Live data from Hacker News

Signal Server code on GitHub is up to date again

github.com

111–120 of 206 posts

Re: Signal Server code on GitHub is up to date again

#111
post #40

Earlier quoted context omitted.

Oh wow. That’s incredibly suspicious...

It could just be an arguably-legitimate desire to keep the hot new feature secret until the big announcement; this particular bit is... sub-optimal... but it doesn't seem like it needs to be nefarious.

Open source trust is a big selling point. Arguably more so than a new payment feature. Hard to understand the desire to hide it all...

Re: Signal Server code on GitHub is up to date again

#112
post #38
post #35

Earlier quoted context omitted.

It's obviously related. The implication is that they pushed code to Github just to gain public trust that can be leveraged to market their cryptocurrency.

I think you’re part correct. I suspect they didn’t want to go public with the shitcoin until it was done.

Obviously. Otherwise Signal employees would not be able to do shitcoin insider trading.

Re: Signal Server code on GitHub is up to date again

#113
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

> - Whether or not Signal's server is open source has nothing to do with security. [...] having the server code open source adds absolutely nothing to this security model, [...] The security rests only upon the open source client code. The server is completely orthogonal to security. The issue a lot of people have with Signal is that your definition here of where security comes from is an extremely narrow & technical…

But now the server code is there, so we now have this mobility, no?

Re: Signal Server code on GitHub is up to date again

#114

The crapcoin thing is REDICULOUS! THIS is what we setup nonprofits to support - some private entity and their crapcoin? How is this legal? How is this not a conflict of interest? How is this not private inurment? The crapcoin is totally opaque to. With premined coins.

It probably isn't legal but people use non-profits all the time for personal gain and get away with it almost always.

Re: Signal Server code on GitHub is up to date again

#115
I am disappointed they are supporting mobilecoin yet it's not available for use in the US. I understand it has important privacy and security features, but there seems little point to it if it can't be used in most of the world (the us isn't that big, but it's important financially). There were some confusing comments that it could be supported one day, easily. I guessed that it wasn't supported because they somehow want to avoid us financial regulation. So what is the reason for no us capable currencies here?

Re: Signal Server code on GitHub is up to date again

#116
post #113

Earlier quoted context omitted.

> - Whether or not Signal's server is open source has nothing to do with security. [...] having the server code open source adds absolutely nothing to this security model, [...] The security rests only upon the open source client code. The server is completely orthogonal to security. The issue a lot of people have with Signal is that your definition here of where security comes from is an extremely narrow & technical…

But now the server code is there, so we now have this mobility, no?

Until they decide to go silent for another 11 months

Re: Signal Server code on GitHub is up to date again

#117
post #113

Earlier quoted context omitted.

> - Whether or not Signal's server is open source has nothing to do with security. [...] having the server code open source adds absolutely nothing to this security model, [...] The security rests only upon the open source client code. The server is completely orthogonal to security. The issue a lot of people have with Signal is that your definition here of where security comes from is an extremely narrow & technical…

But now the server code is there, so we now have this mobility, no?

Yes and no.

Signal is not actually designed with mobility in mind (in fact I would argue, based on Moxie's 36C3 talks, it was designed to be and continues to be persistently kept anti-mobility). That fact is independent of it being open- or closed-source.

However, if the server is open-source, it opens the door for future mobility in the event of org change. If it's closed-source, you get what's currently happening with WhatsApp.

In actuality, if we had something federated, with mobility pre-baked in, having a closed-source server would be less of a security-risk (the gp's comments on only needing to trust the client would apply more strongly since mobility removes the power to change from server maintainers)

Basically:

- with multi-server clients (e.g. Matrix/OMEMO), you have no dependency on any orgs' server, so their being open-source is less relevant (provided the protocol remains open—this can still go wrong, e.g. with GChat/FBMessenger's use of XMPP).

- with single-server clients (Telegram/WhatsApp/Signal), you are dependent on a single server, so that server being open-source is important to ensure the community can make changes in the event of org change.

Re: Signal Server code on GitHub is up to date again

#120

So it just took close to a year to dump thousands of private commits into the public repo! Is there an official response as to why they stopped sharing the code for so long and more importantly, why they started sharing it publicly again? Who gains what with the publication now? And seriously, why is it even relevant anymore?

remove plain text passwords and China's message redirects
Post reply on HN