Earlier quoted context omitted.
So in principle we do have this mobility because you can run your own servers. Perhaps it is not all that unlikely that they will do a bridge to matrix.
You cannot currently run your own Signal server, no. That's what prevents mobility. You are free to examine the source of theirs ( if they choose to continue releasing it), but you cannot self-host.
Signal Server code on GitHub is up to date again
181–190 of 206 posts
Re: Signal Server code on GitHub is up to date again
#182Earlier quoted context omitted.
You cannot currently run your own Signal server, no. That's what prevents mobility. You are free to examine the source of theirs ( if they choose to continue releasing it), but you cannot self-host.
If both the code and the server are open source then how come you can't run it?
So you would have to then follow the above steps for any contacts you want to communicate with, distributing your own client to them. Signal devs have generally been extremely hostile toward anyone wishing to do this however.
The only way out of this situation would be if the Signal project itself was forked and people moved to that forked open-source multi-server client.
Re: Signal Server code on GitHub is up to date again
#183Earlier quoted context omitted.
Unless you have your head thoroughly buried in the sand, you'd understand that all the major players allow people to send money AND people are using those platforms to send money. When people evaluate a new messaging client, the minimum feature set required to be considered viable now includes sending money for a lot of the population. * removed insult
> all the major players allow people to send money AND people are using those platforms to send money. So if major players jump off a cliff, everyone should always follow? > the minimum feature set required to be considered viable now includes sending money for a lot of the population. ? No, thank you. Not where the actual banking system is working.
Re: Signal Server code on GitHub is up to date again
#184Earlier quoted context omitted.
> Shilling sketchy cryptocurrencies is indicative of loose morals, which makes me think I was wrong to trust them in the past. Who decided it was sketchy? The "I don't like change so I'm going to piss all over you" attitude is what sinks a lot good things. How does Signal benefit from being a shill for this coin? Are they being paid by MOB or do they get a % of the cut? So far all I've read are people screaming their…
> How does Signal benefit from being a shill for this coin? Are they being paid by MOB or do they get a % of the cut? The CEO of signal messenger LLC was/is the CTO of MOB. See https://www.reddit.com/r/signal/comments/mm6nad/bought_mobil... and https://www.wired.com/story/signal-mobilecoin-payments-messa...
But in Edit 4 of the Reddit post it says
> Also, the extended whitepaper wrongly cites Moxie as chief technology officer, while he is the technical advisor.
On top of that, this whitepaper that's being passed around is a forgery with 1.5 pages of factually incorrect information.
The Wired article you link isn't even really critical, it just matter-of-factly explains the feature and it's back story.
> Signal's choice of MobileCoin is no surprise for anyone watching the cryptocurrency's development since it launched in late 2017. Marlinspike has served as a paid technical adviser for the project since its inception, and he's worked with Goldbard to design MobileCoin's mechanics with a possible future integration into apps like Signal in mind. (Marlinspike notes, however, that neither he nor Signal own any MobileCoins.)
It seems like you're trying conclusions based on lies you read 2nd or 3rd hand and didn't bother to verify. The reddit post you linked to would be received very differently depending on when you read it since it's been edited numerous times with addendums refuting earlier claims. Only by reading from beginning to end with all edits can you start to see a clear picture. Even then the picture I see is someone backpedaling a lot of false claims they made.
Re: Signal Server code on GitHub is up to date again
#185Earlier quoted context omitted.
> Shilling sketchy cryptocurrencies is indicative of loose morals, which makes me think I was wrong to trust them in the past. Who decided it was sketchy? The "I don't like change so I'm going to piss all over you" attitude is what sinks a lot good things. How does Signal benefit from being a shill for this coin? Are they being paid by MOB or do they get a % of the cut? So far all I've read are people screaming their…
Part of the problem is that at the moment any government trying to force Signal to break the e2e security model is clearly interfering with speech. By incorporating cryptocurrency/payments, governments are being handed a massive lever to force Signal to comply with the financial monitoring requirements that governments have in place. This has a negative impact on those of us who just wanted a secure communications pl…
Everyone else is trying to pass off false information, doctored white papers, and all sort of conspiracy theories to support their dislike for the feature.
Re: Signal Server code on GitHub is up to date again
#186Earlier quoted context omitted.
I said willfully for a reason, as opposed to just reluctantly. I agree about the sorry state of non-Google notifications on Android. I wish someone would make a common notification framework for the Free world that would be installed alongside system-level F-Droid. Although F-Droid Conversations and Element notifications do work fine for me, regardless of purportedly less battery life, I can understand not everyone w…
> Signal where they touted the benefits of fully opting into the Google ecosystem - the gist was that Google has expended all of this effort on security and they wanted to take advantage of it to bring security to the masses What exactly do they rely on google for? They use them for their push notifications and they use some google servers on the back end. They do offer the app on the app store as 99% of android user…
Re: Signal Server code on GitHub is up to date again
#187Earlier quoted context omitted.
There's plenty of writing on that issue [1]. It makes a lot of sense to think of people being actually entitled to certain rights, especially in domains with network effects. Btw, the Signal Foundation is a non-profit organization that benefits from community goodwill based on an open-source ethos. So people are critical when its software is closed source. [1] https://www.gnu.org/philosophy/free-sw.en.html
I don't think a piece on gnu.org qualifies as "plenty of writing" and for sure doesn't count as basis for what you are entitled for :).
There are some links there to other pieces if you want to read more about it.
> for sure doesn't count as basis for what you are entitled for
I'm not claiming that moral authority flows from the Gnu brand; rather, they provide some information and reasoning which people can use to come to their own conclusions.
Re: Signal Server code on GitHub is up to date again
#188Given that you have said... "the bulk of users is either too stupid or unwilling to invest even the tiniest amount of effort into their privacy." I don't feel the need to pull my punches. This is the most deluded, idiotic response I've seen on hacker news in a long time. It seems unlikely that the average person (or even a non-techie person of above average intelligence - e.g. a doctor) will be able to set up matrix…
If you don't want to be banned, you're welcome to email hn@ycombinator.com and give us reason to believe that you'll follow the rules in the future. They're here: https://news.ycombinator.com/newsguidelines.html.
We detached this subthread from https://news.ycombinator.com/item?id=26727160.
Re: Signal Server code on GitHub is up to date again
#189Earlier quoted context omitted.
That's basically the same problem as DRM, so no, you can't verify that someone is running only code you want them to run against data you gave them, on hardware they own.
Yet DRM does exist. (Yes, these schemes usually end up getting broken at some point, but so does other software.) The problem is more generally called trusted computing, with Intel SGX being an implementation (albeit one with a pretty bad track record).
SGX running on centralized servers turns that calculus on it's head by concentrating the benefits of the hack all in one place.
Re: Signal Server code on GitHub is up to date again
#190Earlier quoted context omitted.
> Whether or not Signal's server is open source has nothing to do with security This true only when you are exclusively concerned about your messages' content but not about the metadata. As we all know, though, the metadata is the valuable stuff. There is a second reason it is wrong, though: These days, lots of actual user data (i.e. != metadata) gets uploaded to the Signal servers[0] and encrypted with the user's Si…
Addendum: Out of pure interest I just went into a deep dive into the Signal-Android repository and tried to figure out where exactly the SGX remote attestation happens. I figured that somewhere in the app there should be hash or something of the code running on the servers. Unfortunately, `rg -i SGX` only yielded the following two pieces of code: https://github.com/signalapp/Signal-Android/blob/master/libs... https:/…
During remote attestation, the prover (here, Signal's server) create a "quote" that proves it is running a genuine enclave. The quote also includes the MRENCLAVE value.
It sends the quote to the verifier (here, Signal-Andriod), which in turn sends it to Intel Attestation Service (IAS). IAS verifies the quote, then signs the content of the quote, thus signing the MRENCLAVE value. The digital signature is sent back to the verifier.
Assuming that the verifier trusts IAS's public key (e.g., through a certificate), it can verify the digital signature, thus trust the MRENCLAVE value is valid.
The code where the verifier is verifying the IAS signature is here: https://github.com/signalapp/Signal-Android/blob/6ddfbcb9451...
The code where the MRENCLAVE value is checked is here: https://github.com/signalapp/Signal-Android/blob/6ddfbcb9451...
Hope this helps!