Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

41–50 of 336 posts

Re: Signal says it won’t compromise on encryption

#41
post #33
post #7

Earlier quoted context omitted.

This is incorrect. iMessage is encrypted, the encryption is end-to-end, there are no backdoors. The unencrypted backup is a clear and annoying hole in the apple privacy story, but the non-e2ee iCloud backup does not include any messages (SMS, MMS, or iMessage), Contacts, Calendars, Notes, iCloud Photos, or health data. A local backup is local, and is protected by filesystem encryption on your local storage. So no, iM…

iCloud Backup is effectively unencrypted and on by default, and sends the end device keys to Apple. Apple knows this, and went about encrypting iCloud Backups (like Google does on Android) but then stopped to preserve this vulnerability to avoid antagonizing the FBI, leaving Apple in possession of cleartext endpoint keys of all of their customers. Approximately nobody uses local iOS backups because iCloud Backup is e…

[deleted]

Re: Signal says it won’t compromise on encryption

#43
post #11

Requiring handing over encryption keys as a requirement to do business there sounds like a good way to sanction yourself from the modern world.

As much as I agree with you according to my own principles, I would not underestimate the sacrifice-anything-for-profits side of the cost-benefit analysis that many businesses will perform.

Re: Signal says it won’t compromise on encryption

#46

Tech companies will make all sort of noise when India, China, Turkey ask to have access and control over the data of their own people. However when NSA comes around with their secret laws and courts, they all bend the knee ...

That's because the NSA doesn't make big public statements. They just install a little black box in your servers and you don't say anything.

That's because when the NSA comes knocking to your door you are also prevented from disclaiming the fact that the NSA came to visit. Unless you like the hospitality of prison, that is.

Re: Signal says it won’t compromise on encryption

#47

Is there anything more secure than signal that is widely used? Maybe something that doesn’t leak metadata or require a phone number?

Uhh, Jitsi? Jitsi Meet? Free and open source of course.

Jitsi has ZRTP encryption. Jitsi Meet uses WebRTC and its encryption isn't the same, but from the academic research papers I've read such as "Stegozoa: Enhancing WebRTC Covert Channels with Video Steganography for Internet Censorship Circumvention" from June 2022, it's convincing enough for me to have set up my own Jitsi Meet server on a Debian Linux Virtualbox machine.

From the paper:

"Given that the peer-to-peer connections carrying the video streams are encrypted end-to-end, not even a state-level adversary with unrestricted access to the network infrastructure will be able to observe the raw video content of the WebRTC streams. "

Re: Signal says it won’t compromise on encryption

#50

> Some things are a bit Boolean, as Whittaker states above, but some things are simply binary. Eh, what's the difference? It's better to read the original article: https://www.theverge.com/23409716/signal-encryption-messagin...

Ok, we changed to that from https://www.techdirt.com/2022/10/26/signal-says-it-will-exit.... Thanks!
Post reply on HN