Earlier quoted context omitted.
Can't imagine a negative second order affect of moving all government discussions to the public /s
Where did I say public - I meant available to the courts if required...
Hence why Lord whatever is in trouble.
51–60 of 187 posts
Earlier quoted context omitted.
The default, if I'm reading the article correctly, is to not disappear messages. What's new is the ability to disappear messages by default for all conversations, instead of having to remember to set it for each conversation. For some people (e.g. journalists) this is exactly what they need, because forgetting to set disappearing before sending a message could be problematic, and I'm glad they added this feature for…
> The default, if I'm reading the article correctly, is to not disappear messages. But that is exactly what the default should be and what's needed to thwart large-scale blanket surveillance of the whole population. If the mere fact that ephemeral messages are enabled raises a flag, that kind of defeats (part of) the purpose.
Earlier quoted context omitted.
> In all seriousness though, my messages are part of my memory. They're shared experience with my partner and a record of decisions. Thanks for saying this, I moved to Telegram[1] before I had a chance to learn about/suffer from Whatsapp take on backups, but it would have been devastating to lose years of messages with people over a bricked phone. [1] I know Telegram has a bad rep due to their home cooked crypto and…
> [1] I know Telegram has a bad rep due to their home cooked crypto and maybe other stuff, but I like the app, I vaguely trust the author, and it works fine for me. Is that because you assume the NSA aren't reading all your messages or you don't mind if they are? Because the whole problem with dodgy crypto is that it still seems to "work fine for me" even when it isn't.
I keep that in mind when discussing things.
If I want to start doing something shady, I can pick up something else than Signal, since I don't want my phone number ending up on random people's phones.
Earlier quoted context omitted.
This is one of the biggest things that stops me from using Signal. I don't have a phone number really any more (I'm a digital nomad, and pick up regional sims) I'm not really interested in the disappearing message either if I wanted that I could just use Slack Free edition :troll:. In all seriousness though, my messages are part of my memory. They're shared experience with my partner and a record of decisions. I unde…
If you don't mind me asking, how do you handle 2FA and companies that require a phone number(eg. my bank)? Do you have to constantly cycle through numbers, do you have a VOIP number?
I'm note vertis, but I wont give out my cell phone number, so: Companies that require 2FA via phone just don't get my business and about all banks in germany offer chipTAN. The chipTAN devices are all made by shady companies and are less than open but I still trust them more than any smartphone or the mobile network.
Persistent messages seem like the obvious better default. 99.9% of my conversations have no obscene secrets, but a solid 1% have information that might be search-worthy. Hangouts / gChat seemed to get this right - extremely fast search and an "off the record" function for when you can't switch to an ephemeral alternative (usually a phone call). I know HN has a higher proportion of the reasonably-paranoid EFF-loving p…
Earlier quoted context omitted.
> [1] I know Telegram has a bad rep due to their home cooked crypto and maybe other stuff, but I like the app, I vaguely trust the author, and it works fine for me. Is that because you assume the NSA aren't reading all your messages or you don't mind if they are? Because the whole problem with dodgy crypto is that it still seems to "work fine for me" even when it isn't.
My main chat platforms are IRC, Telegram and Discord. None of them are E2E encrypted and don't sell themselves as such. I keep that in mind when discussing things. If I want to start doing something shady, I can pick up something else than Signal, since I don't want my phone number ending up on random people's phones.
Telegram's initial marketing heavily emphasised privacy. If I search for Telegram then the very first search result blurb starts "Telegram messages are heavily encrypted". Maybe they don't explicitly claim to be E2E, but they absolutely are selling themselves as an encrypted, privacy-friendly messenger.
> If I want to start doing something shady, I can pick up something else than Signal, since I don't want my phone number ending up on random people's phones.
Completely agreed, I dislike the Signal hype as much as anyone. But I trust Telegram even less.
Earlier quoted context omitted.
> In all seriousness though, my messages are part of my memory. They're shared experience with my partner and a record of decisions. Thanks for saying this, I moved to Telegram[1] before I had a chance to learn about/suffer from Whatsapp take on backups, but it would have been devastating to lose years of messages with people over a bricked phone. [1] I know Telegram has a bad rep due to their home cooked crypto and…
> [1] I know Telegram has a bad rep due to their home cooked crypto and maybe other stuff, but I like the app, I vaguely trust the author, and it works fine for me. Is that because you assume the NSA aren't reading all your messages or you don't mind if they are? Because the whole problem with dodgy crypto is that it still seems to "work fine for me" even when it isn't.
Disappearing messages are to prevent my kids reading the messages between me and their mother ;-)
If NSA actually read my messages that would be kind of funny.
If they have such a hack I'm sure they won't spend it on me or any other Joe Sixpack.
Maybe ФСБ reads it but I have a hard time believing that too.
My threat model consists of (not in any particular order):
- my kids,
- random internet strangers,
- Facebook (who'll sell you to whoever pays),
- Google or a Google-like entity with runaway "AI" and arrogant customer support[1] (who can lock out from my accounts for no reason)
Besides, despite all the talk about E2E-encryption being so important, Signal (which I cheer for) IIRC has had a nasty XSS-exploit in their desktop allowing remote control of the pc, their phone client has been sending pictures to others than the recipient and probably a couple more.
Ad I and others have pointed out repeatedly:
There is more to security than encryption. It doesn't matter if it is E2E-encrypted if it is delivered to the wrong contact. And it doesn't matter if it is E2E-encrypted if whoever knows the secret can send you a specially crafted message and take control over your machine.
[1]: I originally wrote employees but I don't think the average Google employee is more arrogant than others, they just come across that way because of policies created far above them.
Earlier quoted context omitted.
Where did I say public - I meant available to the courts if required...
Isn't that already the requirement? Hence why Lord whatever is in trouble.
It seems to be extremely common in govt now. To the point where actively requiring surveillance of personal devices of government officials seems pretty reasonable.
Earlier quoted context omitted.
The default, if I'm reading the article correctly, is to not disappear messages. What's new is the ability to disappear messages by default for all conversations, instead of having to remember to set it for each conversation. For some people (e.g. journalists) this is exactly what they need, because forgetting to set disappearing before sending a message could be problematic, and I'm glad they added this feature for…
> The default, if I'm reading the article correctly, is to not disappear messages. But that is exactly what the default should be and what's needed to thwart large-scale blanket surveillance of the whole population. If the mere fact that ephemeral messages are enabled raises a flag, that kind of defeats (part of) the purpose.
The max timer is too short. 6 months would be a convenient value - enough time to reference the messages while they might be relevant, but also not floating around forever
> We’ve also added the ability to set custom timer durations on your conversations, so that some content can be gone in 60 seconds and others can exist for 18 minutes or 4 weeks.