Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

181–190 of 336 posts

Re: Signal says it won’t compromise on encryption

#182
post #175

Earlier quoted context omitted.

> The solutions for the most of the issues you are describing comes with great usability costs. What costs? Element (a popular Matrix client) has recently improved their onboarding greatly! https://element.io/blog/all-aboard-better-ftue-for-less-wtf/ It really is just as easy to onboard to Element as Signal these days, the UX has come a long way. And you'll never have the move them again, because you can choose any c…

> What costs? Element (a popular Matrix client) has recently improved their onboarding greatly! Matrix is a great example where you need that one tech guy to create home server. Otherwise nobody of your friend group can use it as intended to.

It's easy to use the free server at matrix.org. For $5/month you can get a hosted server from EMS with optional bridges to Signal/Telegram/WhatsApp.

Or another paid provider: https://matrix.org/hosting/

Re: Signal says it won’t compromise on encryption

#183
post #172

Earlier quoted context omitted.

Non profit but still against federation or anyone running an alternative client. Why?

The good answer: They can't verify the integrity of alternative clients and that they don't leak info The other answer: They've got somewhat of a "we know best" vibe going for them which also comes in play when you see their response to feature requests - e.g. for usernames instead of phone numbers or for "edit message" functionality like Telegram has.

I don't know what response to username feature requests you're talking about, but AFAIK they've been saying for a long time already that they're working on that ­— but it's a significant rework of their architecture, so it understandably is taking a long time, especially to also do so in a privacy preserving way.

Re: Signal says it won’t compromise on encryption

#184

Earlier quoted context omitted.

Non profit but still against federation or anyone running an alternative client. Why?

It's a non profit so it can receive donations, but the developer is a LLC that's run for profit. It's a similar story in almost all software companies that market themselves as non-profit foundations (Mozilla too btw) https://en.m.wikipedia.org/wiki/Signal_Foundation#Signal_Mes...

The effect is the same as it is for "regular" non-profits: there are no shareholders (other than the non-profit), and so no incentives to maximise profits.

(Of course employees and board members can still receive handsome compensation, but the same holds true for regular non-profits.)

Re: Signal says it won’t compromise on encryption

#185
post #152

Earlier quoted context omitted.

Signal is a nonprofit though. They shouldn't be under pressure to create business.

Non profit but still against federation or anyone running an alternative client. Why?

That's described here: https://signal.org/blog/the-ecosystem-is-moving/

(And also extensively discussed elsewhere on HN already, if you want to dive into it some more.)

Re: Signal says it won’t compromise on encryption

#186

Earlier quoted context omitted.

In the context of privacy, you can pretty much assume every black box is compromised. With Telegram this black box is the server (the client is open source); with WhatsApp, it's the client. I suppose there's threat models where WA still wins, but knowing it's owned by Meta, I have a hard time imagining what such a threat model would look like.

Is the Whatsapp client really a black box? APKs are fairly straightforward to decompile back to Smali or a reasonable approximation of Java, or people on rooted devices can hook it with Frida. Of course source code would be better, but it would be pretty brazen to stick a backdoor in an app store release. App versions for popular apps get archived by numerous third-party sites, so even a temporary backdoor in one spe…

It is very difficult to find a backdoor even in the open source code, in megabytes of closed source code it is nearly impossible.

> That would be putting their reputation

Does Facebook have any reputation left?

Re: Signal says it won’t compromise on encryption

#188
post #166

Earlier quoted context omitted.

The solutions for the most of the issues you are describing comes with great usability costs. It is already hard to make non-tech people to switch from WhatsApp.

> The solutions for the most of the issues you are describing comes with great usability costs. What costs? Element (a popular Matrix client) has recently improved their onboarding greatly! https://element.io/blog/all-aboard-better-ftue-for-less-wtf/ It really is just as easy to onboard to Element as Signal these days, the UX has come a long way. And you'll never have the move them again, because you can choose any c…

That's very good to hear. I use Element a lot, but I found it very difficult to get non-technical friends and family to use it. A better onboarding experience is a real step in the right direction.

Another constant stumbling block is this whole "verify session" business. No one understands what it means. I understand technically what it does but I can't explain why it is so important that it keeps popping up all the time. It creates a constant sense of "something isn't right here but I don't know what to do".

I hope this was fixed as well.

Re: Signal says it won’t compromise on encryption

#190
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

Also:

- There is no way to back up your message history (with photos, etc). This could be done using their (annoyingly pushed to users) "PIN", but isn't.

Few people realize that if your phone dies today, your history is GONE. From what I saw, once people do realize this, it's game over for Signal. WhatsApp is just easier, "everybody is there", and it does back up your history.

EDIT: Yes, it's on iOS. Yes, I realize this might not matter to you, but it matters to a lot of people. And if Signal tries to "bring privacy to the masses", this needs to be fixed. I've seen multiple people stop using Signal after losing all their data.

Post reply on HN