Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

191–200 of 336 posts

Re: Signal says it won’t compromise on encryption

#191

India wants to read everything? Why don't they just forbid the use of https. So that everyone can read everything on the internet

Kazakstan mandated government issue man-in-the-middle TLS certificates:

https://www.zdnet.com/article/kazakhstan-government-is-inter...

The EU is following this govennment friendly move:

https://www.bleepingcomputer.com/news/security/experts-urge-...

It would not be difficult for India as well. I see itlikely Modi and BJP will make this move as part of some anti-terrorist legislation.

Re: Signal says it won’t compromise on encryption

#192
post #179

Earlier quoted context omitted.

Saying that people who disagree with you do so because of propaganda isn't a helpful way of looking at the world. EDIT: Just saw the company I am keeping. This is not a pro-war comment.

It really feels like a pro-war comment. You seem to be missing a lot of context, at best.

We're going a bit off topic here but I'll expand a bit.

If we both (presumably) start from the premise of "this invasion is a bad thing", then following this up with "anyone who supports it is just a moron duped my propaganda" and/or "the Russian administration are simply crazy" isn't helpful. This did not happen in isolation, it happened against a backdrop of decades of western failures in diplomacy & deterrence.

That's worth examining if we wish to prevent future wars.

Re: Signal says it won’t compromise on encryption

#193
post #11

Requiring handing over encryption keys as a requirement to do business there sounds like a good way to sanction yourself from the modern world.

I mean, this is how the USA works. It is widely speculated that the USG will retaliate against Apple for shipping true end-to-end encryption software that does not enable surveillance unless they (Apple) do some sort of clientside scanning. This seems to indicate that Apple's 1A rights to publish software are being infringed.

Presently all large/webscale messengers in the USA (iMessage, WhatsApp, etc) all have backdoors in the e2ee that allow the FBI et al to access message content at will (often without a warrant or probable cause).

Re: Signal says it won’t compromise on encryption

#194
post #175

Earlier quoted context omitted.

> What costs? Element (a popular Matrix client) has recently improved their onboarding greatly! Matrix is a great example where you need that one tech guy to create home server. Otherwise nobody of your friend group can use it as intended to.

It's easy to use the free server at matrix.org. For $5/month you can get a hosted server from EMS with optional bridges to Signal/Telegram/WhatsApp. Or another paid provider: https://matrix.org/hosting/

Try to convince non-technial users to pay for something they already use for free… They don’t understand the benefits.

Re: Signal says it won’t compromise on encryption

#195
post #190
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

Also: - There is no way to back up your message history (with photos, etc). This could be done using their (annoyingly pushed to users) "PIN", but isn't. Few people realize that if your phone dies today, your history is GONE. From what I saw, once people do realize this, it's game over for Signal. WhatsApp is just easier, "everybody is there", and it does back up your history. EDIT: Yes, it's on iOS. Yes, I realize t…

I do off-device Signal backups all the time, and have successfully restored.

Re: Signal says it won’t compromise on encryption

#197
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

I've never had a spam message on Signal in all the years I've been using it.

Neither did I until a few months ago, had like 1 spam per week for about 2 months. Then it stopped ¯\_(ツ)_/¯

Re: Signal says it won’t compromise on encryption

#198
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

> ...your account will be associated with this phone number anyways. Messages exchanged in Signal are repudiable. That said, in a recent blog post Signal indicated that arbitrary usernames is something they're working on. > ...unlike XMPP you cannot spin up your own server and have full control over it. Signal is a better alternative for the likes of PGP because it is centralized [0]. Spam notwithstanding, Matrix has…

> Signal indicated that arbitrary usernames is something they're working on.

no offense but they've been saying this for years, the feature may eventually come but I'm not holding my breath

Re: Signal says it won’t compromise on encryption

#199

Earlier quoted context omitted.

Btw if anyone here is from Australia, you guys had a similar bill a few years ago correct? what happened after that? I am curious any hope of overturning this stuff from the sheer corporate backlash? Or, maybe I am too optimistic about people who sold their souls for money, making a stand.

Yeah, the Assistance and Access Act (2018) passed and is still the law of the land. It gave law enforcement, intelligence and the government the ability to compel Australian providers to backdoor their services. Can't tell you how often it's been invoked since it also allows for gag orders. Probably only 1 out of 10 Aussies would have even heard of it. The mainstream media here are about half a dozen ideologically al…

I guess now we share that plight.

Re: Signal says it won’t compromise on encryption

#200
post #190
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

Also: - There is no way to back up your message history (with photos, etc). This could be done using their (annoyingly pushed to users) "PIN", but isn't. Few people realize that if your phone dies today, your history is GONE. From what I saw, once people do realize this, it's game over for Signal. WhatsApp is just easier, "everybody is there", and it does back up your history. EDIT: Yes, it's on iOS. Yes, I realize t…

I see no reason to back-up my history ever. I don't use signal for anything that needs to be archived. Nor do any of my friends. One of the selling points of signal is the feature that it doesn't automatically save photos, this is a good feature. You manually save the photos you want to save.

And I thought people regularly backed up everything worth saving from phones to non phone archive anyway.

Post reply on HN