Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

71–80 of 336 posts

Re: Signal says it won’t compromise on encryption

#71

Earlier quoted context omitted.

Its was a proposed law (to solicit feedback). Signal is not exiting but would exit if such law comes to India. https://www.hindustantimes.com/india-news/govt-proposes-law-... But Telecom Authority of India rules out any immediate intervention. https://tech.hindustantimes.com/tech/news/trai-rules-out-reg... I couldn't quote from the article here but looks like they are going to wait till clarity emerges from Internati…

Proposed law draft (I hate that news outlets do not link to the law they discuss) https://dot.gov.in/sites/default/files/Draft%20Indian%20Tele...

Thanks. This bill seems to be about telecom infrastructure. Does not talk about metadata, or encryption. As far as I can find does not seem to touch on messaging apps as well. Was anyone able to find anything related to which provision in the bill would impact Signal.

Re: Signal says it won’t compromise on encryption

#72
> WhatsApp does not protect metadata the way that Signal does. Signal knows nothing about who you are.

This isn't strictly true though, no? Signal knows your mobile phone number.

I appreciate that this is for facilitating usability, but its still a piece of metadata that can specifically be used to identify you - and signal knows it. You cant even use signal without verifying a mobile phone number AFAIK.

They really shouldnt be making false statements like this. It undermines their (otherwise admirable) position.

Re: Signal says it won’t compromise on encryption

#73

Big govt vs big tech, a battle that is being played out all over the world. Any country that value sovereignty and sees itself as an independent actor rather than a vassal state, must take the position India is taking, or else be susceptible to foreign owned apps influencing its citizenry. The only alternative would be to insist Signal hire its security agents into product / moderator roles, so that oversight can be…

> be susceptible to foreign owned apps influencing its citizenry

Are they banning all of the internet, books, movies and everything else too? Your position is that a state needs to control what the citizens can consume otherwise it's a vassal state?

My country lived under dictatorship with hard censorship before, and reading your comment that was the vibes I got.

Re: Signal says it won’t compromise on encryption

#75

> WhatsApp does not protect metadata the way that Signal does. Signal knows nothing about who you are. This isn't strictly true though, no? Signal knows your mobile phone number. I appreciate that this is for facilitating usability, but its still a piece of metadata that can specifically be used to identify you - and signal knows it. You cant even use signal without verifying a mobile phone number AFAIK. They really…

[deleted]

Re: Signal says it won’t compromise on encryption

#78

Is there anything more secure than signal that is widely used? Maybe something that doesn’t leak metadata or require a phone number?

Widely used? No. I've found Session to be a decent alternative however it's still early development which entails some scuff and details as to how they intend for it to be financially supported long term aren't clear.

https://getsession.org/

TLDR on Session is that it's a fork of Signal (effectively same front end, key scheme, encryption scheme, etc) with a modified transport/delivery and notification system and without the phone-number-as-an-identifier caveat that signal has.

Note: Sorry for the wall of text below.

As for what that modified transport layer is, it's routing all the messaging and data hosting over Oxen (https://oxen.io/) which is a cryptocurrency that serves as a decentralised short term / small size addressable data store and an onion router for those messages/data. As much as cryptocurrency=bad in a lot of cases, here it kinda makes sense as it's just an automated digital marketplace for data hosting and bandwidth with tooling wrapped around it to support privacy and anonymity preserving tools without relying on some hopefully benevolent dictator to run it.

As for who's backing it, same group that develops the Oxen, an Australian non-profit focused on privacy tech and bearing the same name (Oxen Privacy Tech Foundation). While Oxen is pay for use (messaging and all that has an on chain cost), it looks like the foundation is covering the costs of running Session for the foreseeable future. Given the nature of the project, it should eventually be possible for users to pay their own infra costs however that doesn't seem to be implemented yet.

It's pretty easy to use.

1. Install via F-droid or download from the web.

2. Basic cryptocurrency wallet style setup where your account is based on a randomly generated "recovery seed" phrase (string of words with equal bits of randomness as the private key which can be used to rebuild the private key on a new device).

3. Then you can share your "Session ID" which is basically just your public key or you can pay for a custom username which is addressed to your public key (you can set names for contacts after adding them so the username is mostly for ease of discoverability).

4. After that it's basically just Signal but where you can make and throw away accounts at the drop of a hat.

My main complaints are

1. that it's a bit slow on delivery

2. The onion routing half of decentralised storage + routing is still being implemented for Session as the project is very much WIP at this stage.

----

My takeaway is that provided it can stick around, Session has potential to shore up where Signal falls short. Give it a year or two in the oven and I might recommend it as a daily driver for messaging.

Likewise for the OPTF and their goals in general. It looks like once Session is "fully implemented" they are looking at trying to expand the approach to a discord/slack/matrix competitor as well which could be interesting. As far as I can tell they are just a bunch of privacy nerds with a little bit of a cryptocurrency lean to them but they are doing good work.

Re: Signal says it won’t compromise on encryption

#79

Big govt vs big tech, a battle that is being played out all over the world. Any country that value sovereignty and sees itself as an independent actor rather than a vassal state, must take the position India is taking, or else be susceptible to foreign owned apps influencing its citizenry. The only alternative would be to insist Signal hire its security agents into product / moderator roles, so that oversight can be…

Signal does not have the keys either, so how could they accept moderators? Moderators of what, encrypted data streams?

Re: Signal says it won’t compromise on encryption

#80

Is there anything more secure than signal that is widely used? Maybe something that doesn’t leak metadata or require a phone number?

There's Briar, its peer to peer and pretty great. XMPP/Jabber with OMEMO encryption, it runs on federating servers. Session is a fork of signal that doesn't require phone numbers, there's some cryptocurrency something or other in there I don't quite get, but I don't believe you need it to send messages. There's Tox, another p2p sort of thing. Then there's threema, wire, and a bunch of others im not all that familiar…

> Session is a fork of signal that doesn't require phone numbers, there's some cryptocurrency something or other in there I don't quite get, but I don't believe you need it to send messages.

This is not a fork of Signal. It was originally designed to use Signal protocol under the hood for encryption and key management but does not anymore[1]. They appear to be going a different direction now with the service using cryptocurrency nodes to route the service[2]

[1] https://getsession.org/blog/session-protocol-technical-infor...

[2] https://oxen.io/session-lokinet

Post reply on HN