Requiring handing over encryption keys as a requirement to do business there sounds like a good way to sanction yourself from the modern world.
Signal says it won’t compromise on encryption
181–190 of 336 posts
Re: Signal says it won’t compromise on encryption
#182Earlier quoted context omitted.
> The solutions for the most of the issues you are describing comes with great usability costs. What costs? Element (a popular Matrix client) has recently improved their onboarding greatly! https://element.io/blog/all-aboard-better-ftue-for-less-wtf/ It really is just as easy to onboard to Element as Signal these days, the UX has come a long way. And you'll never have the move them again, because you can choose any c…
> What costs? Element (a popular Matrix client) has recently improved their onboarding greatly! Matrix is a great example where you need that one tech guy to create home server. Otherwise nobody of your friend group can use it as intended to.
Or another paid provider: https://matrix.org/hosting/
Re: Signal says it won’t compromise on encryption
#183Earlier quoted context omitted.
Non profit but still against federation or anyone running an alternative client. Why?
The good answer: They can't verify the integrity of alternative clients and that they don't leak info The other answer: They've got somewhat of a "we know best" vibe going for them which also comes in play when you see their response to feature requests - e.g. for usernames instead of phone numbers or for "edit message" functionality like Telegram has.
Re: Signal says it won’t compromise on encryption
#184Earlier quoted context omitted.
Non profit but still against federation or anyone running an alternative client. Why?
It's a non profit so it can receive donations, but the developer is a LLC that's run for profit. It's a similar story in almost all software companies that market themselves as non-profit foundations (Mozilla too btw) https://en.m.wikipedia.org/wiki/Signal_Foundation#Signal_Mes...
(Of course employees and board members can still receive handsome compensation, but the same holds true for regular non-profits.)
Re: Signal says it won’t compromise on encryption
#185Earlier quoted context omitted.
Signal is a nonprofit though. They shouldn't be under pressure to create business.
Non profit but still against federation or anyone running an alternative client. Why?
(And also extensively discussed elsewhere on HN already, if you want to dive into it some more.)
Re: Signal says it won’t compromise on encryption
#186Earlier quoted context omitted.
In the context of privacy, you can pretty much assume every black box is compromised. With Telegram this black box is the server (the client is open source); with WhatsApp, it's the client. I suppose there's threat models where WA still wins, but knowing it's owned by Meta, I have a hard time imagining what such a threat model would look like.
Is the Whatsapp client really a black box? APKs are fairly straightforward to decompile back to Smali or a reasonable approximation of Java, or people on rooted devices can hook it with Frida. Of course source code would be better, but it would be pretty brazen to stick a backdoor in an app store release. App versions for popular apps get archived by numerous third-party sites, so even a temporary backdoor in one spe…
> That would be putting their reputation
Does Facebook have any reputation left?
Re: Signal says it won’t compromise on encryption
#187I do want to hear more about how signal and other companies are working to prevent their apps being used by bad actors, terrorists.
Re: Signal says it won’t compromise on encryption
#188Earlier quoted context omitted.
The solutions for the most of the issues you are describing comes with great usability costs. It is already hard to make non-tech people to switch from WhatsApp.
> The solutions for the most of the issues you are describing comes with great usability costs. What costs? Element (a popular Matrix client) has recently improved their onboarding greatly! https://element.io/blog/all-aboard-better-ftue-for-less-wtf/ It really is just as easy to onboard to Element as Signal these days, the UX has come a long way. And you'll never have the move them again, because you can choose any c…
Another constant stumbling block is this whole "verify session" business. No one understands what it means. I understand technically what it does but I can't explain why it is so important that it keeps popping up all the time. It creates a constant sense of "something isn't right here but I don't know what to do".
I hope this was fixed as well.
Re: Signal says it won’t compromise on encryption
#189Re: Signal says it won’t compromise on encryption
#190Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…
- There is no way to back up your message history (with photos, etc). This could be done using their (annoyingly pushed to users) "PIN", but isn't.
Few people realize that if your phone dies today, your history is GONE. From what I saw, once people do realize this, it's game over for Signal. WhatsApp is just easier, "everybody is there", and it does back up your history.
EDIT: Yes, it's on iOS. Yes, I realize this might not matter to you, but it matters to a lot of people. And if Signal tries to "bring privacy to the masses", this needs to be fixed. I've seen multiple people stop using Signal after losing all their data.