Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

101–110 of 336 posts

Re: Signal says it won’t compromise on encryption

#101
>“A big part of our model is telling people not to take our word for it.”

That's rich, coming from a company that wasn't (and probably still isn't) running the code they made public.

>So if I want to fork Signal and make my own, I can just take the code and do it today?

>People do it. There are many of those. We don’t endorse them because we can’t guarantee or validate them — we don’t have the time or the resources for that. But yes, there are many out there.

Sure, but you can't use them with the same server cluster everyone else in the world is using, making it about as useful as a chocolate teapot.

Re: Signal says it won’t compromise on encryption

#102
Whenever India and its authoritarian stances are mentioned, a number of folks (I presume Indians, both on HN and elsewhere) come out of the woodwork to sing praises of "national security" while saying nothing about how such power can be abused.

It is truly sad to see that an entire populace can't see the perils of a government with broad-reaching powers, when government institutions jailing the opposition, censoring the press, and supressing minorities is rather commonplace there[1][2].

[1] https://en.wikipedia.org/wiki/The_Emergency_(India)

[2] https://en.wikipedia.org/wiki/Violence_against_Muslims_in_In...

Re: Signal says it won’t compromise on encryption

#103
post #99

Earlier quoted context omitted.

How do you know that there is not a back door in WhatsApp?

Presumption of innocence, or do you have seen any evidence to prove it exist, besides Durov's shit from time to time?

In the context of privacy, you can pretty much assume every black box is compromised. With Telegram this black box is the server (the client is open source); with WhatsApp, it's the client. I suppose there's threat models where WA still wins, but knowing it's owned by Meta, I have a hard time imagining what such a threat model would look like.

Re: Signal says it won’t compromise on encryption

#104
post #77

A noob question, how does signal know/prevent use of its app for illegal/criminal activities? Larger question here would be - Do governments and security agencies need to keep a tab on social media to check for illegal activities

This is answered in the article.

Re: Signal says it won’t compromise on encryption

#105

Is there anything more secure than signal that is widely used? Maybe something that doesn’t leak metadata or require a phone number?

There are a few secure alternatives but as stated in the article, their goal is privacy as well as security. For instance they don’t even know who’s in which groups or that a group exists and they keep as little metadata as possible. The remaining metadata that is required for the service to work, they encrypt and don’t even have the keys.

Re: Signal says it won’t compromise on encryption

#106

> WhatsApp does not protect metadata the way that Signal does. Signal knows nothing about who you are. This isn't strictly true though, no? Signal knows your mobile phone number. I appreciate that this is for facilitating usability, but its still a piece of metadata that can specifically be used to identify you - and signal knows it. You cant even use signal without verifying a mobile phone number AFAIK. They really…

I think this means, assuming it’s not a burner SIM bought with cash, that someone could “only” identify you were a signal user. They wouldn’t be able to see your social graph , who you contacted and when, from where, what was said, what groups you were in.

I also thought I’d read on HN recently that they were looking at making this optional in the future but don’t quote me on that !

Re: Signal says it won’t compromise on encryption

#107

I do want to hear more about how signal and other companies are working to prevent their apps being used by bad actors, terrorists.

Next we would like to hear more about what owners of open spaces are doing allowing bad humans to use them to communicate sounding words over air.

Re: Signal says it won’t compromise on encryption

#108

Signal is too small a player and is therefore more likely to be bullied by governments. India is taking pot shots at it to see if it can get away with forcing them into intercepting communications. If they leave as a result, they'll simply shrug and move on. Also, I'm convinced that if Signal were to become popular they'd probably sell it to some commercial provider, since the cost of maintaining a service used by hu…

How do you know that there is not a back door in WhatsApp?

[deleted]

Re: Signal says it won’t compromise on encryption

#109
post #11

Requiring handing over encryption keys as a requirement to do business there sounds like a good way to sanction yourself from the modern world.

Especially when companies are looking to move their manufacturing from China...

India just shot itself in the foot

Re: Signal says it won’t compromise on encryption

#110
Meredith Whittaker was always an activist, and her being in charge of a big product doesn't change that, it just increases the risk. I don't believe for one second that if push comes to shove and she thinks it's an important cause she won't wield her power to cut through the supposed security of Signal and expose "undesirables" to the light of day and leak all their private info.

I would not trust this product anymore, especially if you are not a hard leftist like her.

Post reply on HN