Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

201–210 of 336 posts

Re: Signal says it won’t compromise on encryption

#201
post #166
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

The solutions for the most of the issues you are describing comes with great usability costs. It is already hard to make non-tech people to switch from WhatsApp.

How come, signal works exactly the same as whatsapp. I forced my friends and (older) relatives to change to signal and there has been no problems and everyone is happy.

Re: Signal says it won’t compromise on encryption

#202

Earlier quoted context omitted.

> The solutions for the most of the issues you are describing comes with great usability costs. What costs? Element (a popular Matrix client) has recently improved their onboarding greatly! https://element.io/blog/all-aboard-better-ftue-for-less-wtf/ It really is just as easy to onboard to Element as Signal these days, the UX has come a long way. And you'll never have the move them again, because you can choose any c…

That's very good to hear. I use Element a lot, but I found it very difficult to get non-technical friends and family to use it. A better onboarding experience is a real step in the right direction. Another constant stumbling block is this whole "verify session" business. No one understands what it means. I understand technically what it does but I can't explain why it is so important that it keeps popping up all the…

Yep, it's definitely been frustrating in the past. The number of iOS Element bugs was overwhelming at times too. It's a lot more stable now, but the bubble layout still isn't the default - I think that's what most people expect from a personal messenger. I'm looking forward to seeing what the Rust rewrite [1] brings for performance/stability.

FluffyChat also has quite nice UX and a bubble layout by default, but threads are still a while off [2]. On iOS it worked flawlessly through the iOS 16 betas while Element had some show stopping bugs, a couple of my friends moved over if they were on the beta.

I haven't had any friends ask me about the verify session buttons. I don't see any prompts on latest iOS Element but it's still too prominent on Element desktop for my liking.

SchildiChat [3] is my daily driver and feels more friendly than Element on desktop (unified DMs & group chats, no verify UX, chat bubbles), but it doesn't have any update mechanism built in, so I'm wary to recommend it to non-technical friends. It was also my goto recommendation on Android before the Element redesign.

I'm confident the ecosystem is moving in the right direction though, and so thankful for the amount of choice.

[1]: https://github.com/vector-im/element-x-ios [2]: https://gitlab.com/famedly/fluffychat/-/issues/881 [3]: https://schildi.chat/

Re: Signal says it won’t compromise on encryption

#203
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

>it is a product that is run by other people[...]Since it is centralized

so are federated instances in reality because the vast majority of people are going to be on some popular node by virtue of how communication networks organize.

And I'd rather trust Signal than having to trust some server in a guy's basement who I can only pray has a reasonable security setup, and is going to fold ten times more quickly to a court order than a foundation with a 50 million dollar check and nice lawyers.

Re: Signal says it won’t compromise on encryption

#204
post #190
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

Also: - There is no way to back up your message history (with photos, etc). This could be done using their (annoyingly pushed to users) "PIN", but isn't. Few people realize that if your phone dies today, your history is GONE. From what I saw, once people do realize this, it's game over for Signal. WhatsApp is just easier, "everybody is there", and it does back up your history. EDIT: Yes, it's on iOS. Yes, I realize t…

Signal has backup on Android, and fairly fast image management, but it's lacking on iOS. That points to a lack of developer resources.

What you call WhatsApp history is other people being able to read your messages.

WhatsApp is violently agressive in demanding you use your phone and give access to your contacts. You can't use it without feeling violated.

Re: Signal says it won’t compromise on encryption

#205
post #115

India wants to read everything? Why don't they just forbid the use of https. So that everyone can read everything on the internet

I'm trying to imagine a ban on https for better understanfing and I remember that Australia implemented anti-encryption laws some 3-4 years ago. Can someone comment on how Australian anti-encryption laws work in a case of https? Is it illegal to use encryption (like https to send data to server in a browser) without a backdoor now in Australia?

Australia law doesn't require you to do anything until explicitly asked by the intelligence agencies. The first stage is a gentle "Request for Technical Assistence" with no penalties for no saying no. But then they can then ask again and demand you provide assistance with jail time/fines for non-compliance. The orders also come secrecy notices so you can't inform anyone (except your lawyers) that you've received the notice. The request have to target specific users so they can't be "Collect messages on everyone with a Muslim name" or something.

The chilling effect of it is. What if they demand you give them information you do not have a way of accessing. (Eg Signal). How would you comply? Do you have to pre-empt whatever requests you MIGHT get and ensure you could back-door a user if it were required. The law also seems to imply that ASIO could demand a single employee at a company backdoors something and they wouldn't be able to tell their co-workers.

Re: Signal says it won’t compromise on encryption

#206
post #190

Earlier quoted context omitted.

Also: - There is no way to back up your message history (with photos, etc). This could be done using their (annoyingly pushed to users) "PIN", but isn't. Few people realize that if your phone dies today, your history is GONE. From what I saw, once people do realize this, it's game over for Signal. WhatsApp is just easier, "everybody is there", and it does back up your history. EDIT: Yes, it's on iOS. Yes, I realize t…

I do off-device Signal backups all the time, and have successfully restored.

You have on Android, but not iOS.

Re: Signal says it won’t compromise on encryption

#207

Is there anything more secure than signal that is widely used? Maybe something that doesn’t leak metadata or require a phone number?

Maybe these? https://olvid.io/en/ https://berty.tech

https://threema.ch/en

https://wickr.com/

Re: Signal says it won’t compromise on encryption

#208
post #180

Earlier quoted context omitted.

90% world the world (i.e. nearly everybody outside the west) has a similar position on the Russia-Ukraine issue as India though. Is 90% of the world propagandized? Or can they have a legit different perspective on things?

This is inaccurate at best. Most Asian countries have shown support for Ukraine. Most African countries as well, with a few notable exceptions. There's no "different perspective" when it comes to slaughtering innocent civilians and other war crimes.

The UN vote on not recognising the annexation was a crushing defeat for Moscow, they only got votes from Syria, NK, Nicaragua and Belarus.

https://news.un.org/en/story/2022/10/1129492

Re: Signal says it won’t compromise on encryption

#209
post #198

Earlier quoted context omitted.

> ...your account will be associated with this phone number anyways. Messages exchanged in Signal are repudiable. That said, in a recent blog post Signal indicated that arbitrary usernames is something they're working on. > ...unlike XMPP you cannot spin up your own server and have full control over it. Signal is a better alternative for the likes of PGP because it is centralized [0]. Spam notwithstanding, Matrix has…

> Signal indicated that arbitrary usernames is something they're working on. no offense but they've been saying this for years, the feature may eventually come but I'm not holding my breath

[deleted]

Re: Signal says it won’t compromise on encryption

#210

Neither Signal, WhatsApp, or Telegram are particularly secure. On Signal for example, your private key is protected only by a verification text message and short PIN. That's very low entropy compared to a full ED25519 keypair. It's better than SMS but don't be fooled into thinking you have Snowden-level opsec because you use one of these apps. Use PGP and email.

This is completely wrong? Do you really think the first text message they send is some crypto negotiation?

PGP and email is extremely error prone and has zero forward secrecy, and web of trust is completely broken as a practical matter.

Post reply on HN