Live data from Hacker News

Signal Server code on GitHub is up to date again

github.com

151–160 of 206 posts

Re: Signal Server code on GitHub is up to date again

#151
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

>kneejerk HN "crypto bad" reflex

You make it sound as if that's a bad thing. Reflexes are beneficial when the treats are real. And the crypto“currency” multi-level marketing pyramid schemes are very real. They do nothing but induce greed, gambling, spam, and all-around toxic behavior. It's a digital cancer that needs to end.

Re: Signal Server code on GitHub is up to date again

#152
post #129
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

> A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Nope. It's a reaction to "who the f* asked for this in a messaging app?!".

Text isn't the only thing I want to be able to send to people. I wish there were a universal "send thing" api that could be implemented for text, images, money, whatever.

Re: Signal Server code on GitHub is up to date again

#153
post #146

Earlier quoted context omitted.

Until they decide to go silent for another 11 months

Most of the popular chat-app space is not open source. What is it with Signal that people feel entitled to condemn it for not having the latest commits on github?

What is it with chat apps that people don't condemn them for being closed source? Imagine if GCC hid their changes for a year.

Re: Signal Server code on GitHub is up to date again

#154
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

>kneejerk HN "crypto bad" reflex You make it sound as if that's a bad thing. Reflexes are beneficial when the treats are real. And the crypto“currency” multi-level marketing pyramid schemes are very real. They do nothing but induce greed, gambling, spam, and all-around toxic behavior. It's a digital cancer that needs to end.

So you want us to stick with the usual paper money, im sorry -- fiat currency, pyramid scheme? no thanks

Re: Signal Server code on GitHub is up to date again

#155

Earlier quoted context omitted.

Wait, how would end-to-end encryption help this problem at all? I agree that it is impossible (currently), but not sure how E2E helps anything? E2E encryption only helps you verify WHO you are connecting to, not what they are doing with your connection once it is established.

Because the other end in E2E is your friend's phone, not a server. We call end-to-server encryption "in-flight" encryption.

Ah, ok I misunderstood

Re: Signal Server code on GitHub is up to date again

#156
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

> Whether or not Signal's server is open source has nothing to do with security This true only when you are exclusively concerned about your messages' content but not about the metadata. As we all know, though, the metadata is the valuable stuff. There is a second reason it is wrong, though: These days, lots of actual user data (i.e. != metadata) gets uploaded to the Signal servers[0] and encrypted with the user's Si…

SGX is just the processor pinky swearing (signed with Intel keys) that everything is totally legit. Nation State Adversaries can and will take Intel's keys and lie.

Re: Signal Server code on GitHub is up to date again

#157
post #156

Earlier quoted context omitted.

> Whether or not Signal's server is open source has nothing to do with security This true only when you are exclusively concerned about your messages' content but not about the metadata. As we all know, though, the metadata is the valuable stuff. There is a second reason it is wrong, though: These days, lots of actual user data (i.e. != metadata) gets uploaded to the Signal servers[0] and encrypted with the user's Si…

SGX is just the processor pinky swearing (signed with Intel keys) that everything is totally legit. Nation State Adversaries can and will take Intel's keys and lie.

SGX is also supposed to protect against Signal as a potential adversary, though, as well as against hackers. Or at least that's how I understood the blog article.

Re: Signal Server code on GitHub is up to date again

#158
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

Focussing on whether the changes directly make things insecure is missing the point. Fundamentally this sort of security is about trust. While it's nice to try to have Signal be resilient to attacks by the core team, there just aren't enough community-minded independent volunteer code reviewers to reliably catch them up. I doubt the signal foundation gets any significant volunteer efforts, even by programmers who are…

> Shilling sketchy cryptocurrencies is indicative of loose morals, which makes me think I was wrong to trust them in the past.

Who decided it was sketchy?

The "I don't like change so I'm going to piss all over you" attitude is what sinks a lot good things.

How does Signal benefit from being a shill for this coin? Are they being paid by MOB or do they get a % of the cut?

So far all I've read are people screaming their heads off that MOB eats babies and how dare Signal stoop so low as to even fart in their general direction, but I have yet to see anyone explain why MOB is bad or how Signal is bad for giving MOB a platform.

Re: Signal Server code on GitHub is up to date again

#159
post #129
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

> A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Nope. It's a reaction to "who the f* asked for this in a messaging app?!".

Unless you have your head thoroughly buried in the sand, you'd understand that all the major players allow people to send money AND people are using those platforms to send money.

When people evaluate a new messaging client, the minimum feature set required to be considered viable now includes sending money for a lot of the population.

* removed insult

Re: Signal Server code on GitHub is up to date again

#160
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

> The security rests only upon the open source client code. The server is completely orthogonal to security. For Android at least, builds are reproducible https://signal.org/blog/reproducible-android/ (would be neat if there was one or more third party CI's that also checked that the CI-built app reproduces the one on Google Play Store – or maybe there already are?)

That's pretty neat, I wasn't aware that was possible.
Post reply on HN