Earlier quoted context omitted.
In the context of privacy, you can pretty much assume every black box is compromised. With Telegram this black box is the server (the client is open source); with WhatsApp, it's the client. I suppose there's threat models where WA still wins, but knowing it's owned by Meta, I have a hard time imagining what such a threat model would look like.
Is the Whatsapp client really a black box? APKs are fairly straightforward to decompile back to Smali or a reasonable approximation of Java, or people on rooted devices can hook it with Frida. Of course source code would be better, but it would be pretty brazen to stick a backdoor in an app store release. App versions for popular apps get archived by numerous third-party sites, so even a temporary backdoor in one spe…
Signal says it won’t compromise on encryption
151–160 of 336 posts
Re: Signal says it won’t compromise on encryption
#152Requiring handing over encryption keys as a requirement to do business there sounds like a good way to sanction yourself from the modern world.
As much as I agree with you according to my own principles, I would not underestimate the sacrifice-anything-for-profits side of the cost-benefit analysis that many businesses will perform.
Re: Signal says it won’t compromise on encryption
#153Big govt vs big tech, a battle that is being played out all over the world. Any country that value sovereignty and sees itself as an independent actor rather than a vassal state, must take the position India is taking, or else be susceptible to foreign owned apps influencing its citizenry. The only alternative would be to insist Signal hire its security agents into product / moderator roles, so that oversight can be…
> Big govt vs big tech Signal has 40 employees.
Re: Signal says it won’t compromise on encryption
#154Neither Signal, WhatsApp, or Telegram are particularly secure. On Signal for example, your private key is protected only by a verification text message and short PIN. That's very low entropy compared to a full ED25519 keypair. It's better than SMS but don't be fooled into thinking you have Snowden-level opsec because you use one of these apps. Use PGP and email.
Can you explain what you mean by this? In practice, I can see the argument that the only verified identity (phone number) for most users is the one protected by a flimsy SMS verification message, but I don't believe that that implies your private key is terribly vulnerable to e.g. SIM swap attacks. Or perhaps I'm misunderstanding you.
Put another way: if you rigidly adhere to out-of-band-verified pubkeys for contacts, you should be fairly safe. True that Signal's UI makes this hard to do, but that's a different conversation than "your keys are only protected by SMS verification".
Re: Signal says it won’t compromise on encryption
#155Earlier quoted context omitted.
As much as I agree with you according to my own principles, I would not underestimate the sacrifice-anything-for-profits side of the cost-benefit analysis that many businesses will perform.
Signal is a nonprofit though. They shouldn't be under pressure to create business.
Re: Signal says it won’t compromise on encryption
#156Earlier quoted context omitted.
Smart people don’t dictate things, majority does.
Who is "smarter", the people that manipulate both their philosophy and the majority's opinion to suit their goals, or the people who's smart philosophies are uncompromised but unimplemented?
I read it as smart=intellectually smart and virtuous.
Re: Signal says it won’t compromise on encryption
#157Earlier quoted context omitted.
Signal certeinly can store it, because they have access to it. They have access to that data alone through the fact that they are in control of their servers and, thus, can see who sends and receives messages.
But they can't. That's the thing. https://signal.org/blog/sealed-sender/
Even on a theoretical level their sealed sender technique doesn't work: https://www.ndss-symposium.org/ndss-paper/improving-signals-...
Now, include lower level technical Details such as the IP layer.
1. Imagine you connect to a server to send a message. Now, you send a message to someone else. The server can't see who you are, right? Because the letter misses your name. Imagine someone else sends a message to you.
2. Imagine you to connect to the same server to receive messages that the server stored for delivery with your name on it. The server gives you the messages.
Do you notice something?
Re: Signal says it won’t compromise on encryption
#158Decentralized protocols are the only viable alternatives to 'normie' chat apps like Telegram & Signal.
Speek! is a new app that looks promising: https://speek.network/
Re: Signal says it won’t compromise on encryption
#159Earlier quoted context omitted.
I'm not an Indian, but I can understand why a country that was oppressed by the Great Britain for such a long time, and endured such atrocities, can opt to support the party that stands on the opposite side of Britain. That alone could explain why not only India, but big parts of the worlds, especially the ones that suffered from the British and American imperialism, would rather see an arch-enemy of their usurper wi…
I understand this. I'm simply asserting that if one believes in this political drivel, ignoring the onslaught happening in Ukraine, then you've not progressed as a human much beyond the middle ages.
When we plunder the other village, take their crop and their wives, it's to bring justice to the world. When they come to us, take our crop and our wives, they are evil aggressors.
Nothing has changed, and probably will not change anytime soon. Thousands of years of evolution are still stronger than whatever thin layer of civilization we try to put on top.
Re: Signal says it won’t compromise on encryption
#160Earlier quoted context omitted.
Well that's what we call power of propaganda, I say that as an Indian(still living in India). I honestly couldn't do anything even after writing letters, talking to friends who can talk to people who make shitty decisions, just cause there is no larger sentiment against these decisions, things just go by. And now I have to say I am not sure when will the general public understand this issue, or will they ever. Are we…
Btw if anyone here is from Australia, you guys had a similar bill a few years ago correct? what happened after that? I am curious any hope of overturning this stuff from the sheer corporate backlash? Or, maybe I am too optimistic about people who sold their souls for money, making a stand.
Probably only 1 out of 10 Aussies would have even heard of it. The mainstream media here are about half a dozen ideologically aligned corporations who are not the type to ask hard questions, and the average Australian is focused only on their wealth, their family or their recreation.