Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

161–170 of 336 posts

Re: Signal says it won’t compromise on encryption

#161
post #56
post #44

Is it me or India is becoming the next China?

People really have warped perceptions of different Asian nations. As someone that has been a resident of most of them they are mostly all like China... which shouldn't be surprising there is a lot of shared cultural history in the region and by and large they are more collectivist societies. Some are obviously worse (looking at you Myanmar) but most are various shades of authoritarian (Singapore, Thailand, Vietnam, e…

This talk by professor Jeffrey Sachs at the Athens Democracy Forum couldn't be more timely. https://youtu.be/Ec2E4k1K52E

Different countries have long, deep-rooted political cultures that go back centuries. "Democracy vs authoritarianism" is the wrong lens: different systems are complex and cannot be ranked on an easy scale like we want them to.

Re: Signal says it won’t compromise on encryption

#162
post #150

Earlier quoted context omitted.

But they can't. That's the thing. https://signal.org/blog/sealed-sender/

They can. Even on a theoretical level their sealed sender technique doesn't work: https://www.ndss-symposium.org/ndss-paper/improving-signals-... Now, include lower level technical Details such as the IP layer. 1. Imagine you connect to a server to send a message. Now, you send a message to someone else. The server can't see who you are, right? Because the letter misses your name. Imagine someone else sends a message…

Okay, maybe Signal has access to this information with sufficient investigation then.

Re: Signal says it won’t compromise on encryption

#165
post #162

Earlier quoted context omitted.

They can. Even on a theoretical level their sealed sender technique doesn't work: https://www.ndss-symposium.org/ndss-paper/improving-signals-... Now, include lower level technical Details such as the IP layer. 1. Imagine you connect to a server to send a message. Now, you send a message to someone else. The server can't see who you are, right? Because the letter misses your name. Imagine someone else sends a message…

Okay, maybe Signal has access to this information with sufficient investigation then.

No investigation necessary.

The information can be obtained in an automated way.

Re: Signal says it won’t compromise on encryption

#166
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

The solutions for the most of the issues you are describing comes with great usability costs. It is already hard to make non-tech people to switch from WhatsApp.

Re: Signal says it won’t compromise on encryption

#167
post #152

Earlier quoted context omitted.

Signal is a nonprofit though. They shouldn't be under pressure to create business.

Non profit but still against federation or anyone running an alternative client. Why?

It's a non profit so it can receive donations, but the developer is a LLC that's run for profit. It's a similar story in almost all software companies that market themselves as non-profit foundations (Mozilla too btw)

https://en.m.wikipedia.org/wiki/Signal_Foundation#Signal_Mes...

Re: Signal says it won’t compromise on encryption

#168
post #100

Earlier quoted context omitted.

If you and everyone you talk to are hosted on servers you trust, down to the physical provider, yes. EDIT: if the person you're talking to is hosted on Google, Google has all the metadata. Even if one person is hosted on Google and is part of a room you're in, Google has all the metadata in that room. In 2022 e2ee is the standard for messages but not metadata, and unfortunately Matrix doesn't tackle it, so no, you ca…

Signal is hosted on Amazon

But the backend of Signal doesn't store who talks to who, so Amazon can't have that information. It also doesn't store what groups exist and who is part of it.

Re: Signal says it won’t compromise on encryption

#169
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

> ...your account will be associated with this phone number anyways.

Messages exchanged in Signal are repudiable. That said, in a recent blog post Signal indicated that arbitrary usernames is something they're working on.

> ...unlike XMPP you cannot spin up your own server and have full control over it.

Signal is a better alternative for the likes of PGP because it is centralized [0]. Spam notwithstanding, Matrix has made good of the federation model, however. So that's there too.

> And I am sure you cannot run an end-to-end audit of the whole Signal platform to verify that what they actually run...

Valid but shallow. Case in point: Public CAs, though held to accountability by browsers, are no where near as transparent as Signal is, and yet they form the backbone of almost all sensitive communication on the Interwebs.

> Signal is prone to censorship in those countries that decide to fight it.

This is the only major concern, but glad that Matrix exists, and so do other solutions. May be it isn't Signal's battle to fight. May be it is, and they'll figure something else out aside from building naive TLS proxies.

[0] https://signal.org/blog/the-ecosystem-is-moving/

Re: Signal says it won’t compromise on encryption

#170
post #166
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

The solutions for the most of the issues you are describing comes with great usability costs. It is already hard to make non-tech people to switch from WhatsApp.

> The solutions for the most of the issues you are describing comes with great usability costs.

What costs? Element (a popular Matrix client) has recently improved their onboarding greatly!

https://element.io/blog/all-aboard-better-ftue-for-less-wtf/

It really is just as easy to onboard to Element as Signal these days, the UX has come a long way. And you'll never have the move them again, because you can choose any client you like.

Post reply on HN