Live data from Hacker News

Signal Server code on GitHub is up to date again

github.com

161–170 of 206 posts

Re: Signal Server code on GitHub is up to date again

#161

Earlier quoted context omitted.

Focussing on whether the changes directly make things insecure is missing the point. Fundamentally this sort of security is about trust. While it's nice to try to have Signal be resilient to attacks by the core team, there just aren't enough community-minded independent volunteer code reviewers to reliably catch them up. I doubt the signal foundation gets any significant volunteer efforts, even by programmers who are…

> Shilling sketchy cryptocurrencies is indicative of loose morals, which makes me think I was wrong to trust them in the past. Who decided it was sketchy? The "I don't like change so I'm going to piss all over you" attitude is what sinks a lot good things. How does Signal benefit from being a shill for this coin? Are they being paid by MOB or do they get a % of the cut? So far all I've read are people screaming their…

Yea, I'm bearish on cryptocurrencies, but I think moxie and his team have built up an incredible amount of goodwill in my book. Enough for me to hear out their solution before making a decision. I'm assuming they didn't write dogecoin2 or even a bitcoin clone. It will be interesting to learn about it.

Re: Signal Server code on GitHub is up to date again

#162

Earlier quoted context omitted.

Focussing on whether the changes directly make things insecure is missing the point. Fundamentally this sort of security is about trust. While it's nice to try to have Signal be resilient to attacks by the core team, there just aren't enough community-minded independent volunteer code reviewers to reliably catch them up. I doubt the signal foundation gets any significant volunteer efforts, even by programmers who are…

> Shilling sketchy cryptocurrencies is indicative of loose morals, which makes me think I was wrong to trust them in the past. Who decided it was sketchy? The "I don't like change so I'm going to piss all over you" attitude is what sinks a lot good things. How does Signal benefit from being a shill for this coin? Are they being paid by MOB or do they get a % of the cut? So far all I've read are people screaming their…

> How does Signal benefit from being a shill for this coin? Are they being paid by MOB or do they get a % of the cut?

The CEO of signal messenger LLC was/is the CTO of MOB.

See https://www.reddit.com/r/signal/comments/mm6nad/bought_mobil... and https://www.wired.com/story/signal-mobilecoin-payments-messa...

Re: Signal Server code on GitHub is up to date again

#163
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

> A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex

The contrarian dynamic strikes again: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&sor...

Re: Signal Server code on GitHub is up to date again

#164
post #153
post #146

Earlier quoted context omitted.

Most of the popular chat-app space is not open source. What is it with Signal that people feel entitled to condemn it for not having the latest commits on github?

What is it with chat apps that people don't condemn them for being closed source? Imagine if GCC hid their changes for a year.

Sure, it would be nice if any software were open source, but that you are entitled for it? Funny attitude.

Re: Signal Server code on GitHub is up to date again

#165
post #144

Earlier quoted context omitted.

There's no concern about metadata leakage?

Even if you have access to an up-to-date source code it doesn't guarantee at all they'd be running a completely different version if so they wish. I mean this have just happened yet this question kind of implies you'd still trust such entity to run the server from the source code you have access to. I hope this collective illusion dies already.

True, neither the absence of an identified vuln in published source code, nor the absence of published source code can guarantee that you don't have vulns. And sure, a bad-faith operator can always back-door the server and run different code.

But, a good-faith operator can find and fix bugs faster if they operate in the open and in collaboration with the community. "Given enough eyeballs, all bugs are shallow" etc.

Re: Signal Server code on GitHub is up to date again

#166
post #164
post #153

Earlier quoted context omitted.

What is it with chat apps that people don't condemn them for being closed source? Imagine if GCC hid their changes for a year.

Sure, it would be nice if any software were open source, but that you are entitled for it? Funny attitude.

There's plenty of writing on that issue [1]. It makes a lot of sense to think of people being actually entitled to certain rights, especially in domains with network effects.

Btw, the Signal Foundation is a non-profit organization that benefits from community goodwill based on an open-source ethos. So people are critical when its software is closed source.

[1] https://www.gnu.org/philosophy/free-sw.en.html

Re: Signal Server code on GitHub is up to date again

#167
post #142

Thank Fefe for that: https://blog.fefe.de/?ts=9e9221ad (second update in posting, completely in german) Coincidence or bad press covfefe? ;)

For updating the source? Fwiw I skimmed it and it doesn't say anything of the sort. But thanks for making me look at this, now I know which of my friends keep up with their blog to the minute. I've heard these arguments word for word a couple hours ago...

Re: Signal Server code on GitHub is up to date again

#168

Earlier quoted context omitted.

Focussing on whether the changes directly make things insecure is missing the point. Fundamentally this sort of security is about trust. While it's nice to try to have Signal be resilient to attacks by the core team, there just aren't enough community-minded independent volunteer code reviewers to reliably catch them up. I doubt the signal foundation gets any significant volunteer efforts, even by programmers who are…

> Shilling sketchy cryptocurrencies is indicative of loose morals, which makes me think I was wrong to trust them in the past. Who decided it was sketchy? The "I don't like change so I'm going to piss all over you" attitude is what sinks a lot good things. How does Signal benefit from being a shill for this coin? Are they being paid by MOB or do they get a % of the cut? So far all I've read are people screaming their…

Part of the problem is that at the moment any government trying to force Signal to break the e2e security model is clearly interfering with speech.

By incorporating cryptocurrency/payments, governments are being handed a massive lever to force Signal to comply with the financial monitoring requirements that governments have in place.

This has a negative impact on those of us who just wanted a secure communications platform.

Re: Signal Server code on GitHub is up to date again

#169
post #166
post #164

Earlier quoted context omitted.

Sure, it would be nice if any software were open source, but that you are entitled for it? Funny attitude.

There's plenty of writing on that issue [1]. It makes a lot of sense to think of people being actually entitled to certain rights, especially in domains with network effects. Btw, the Signal Foundation is a non-profit organization that benefits from community goodwill based on an open-source ethos. So people are critical when its software is closed source. [1] https://www.gnu.org/philosophy/free-sw.en.html

...it's software is open source.

Re: Signal Server code on GitHub is up to date again

#170
post #169
post #166

Earlier quoted context omitted.

There's plenty of writing on that issue [1]. It makes a lot of sense to think of people being actually entitled to certain rights, especially in domains with network effects. Btw, the Signal Foundation is a non-profit organization that benefits from community goodwill based on an open-source ethos. So people are critical when its software is closed source. [1] https://www.gnu.org/philosophy/free-sw.en.html

...it's software is open source.

The reason is that this story is on HN is that the source was previously missing.
Post reply on HN