Signal says it won’t compromise on encryption
221–230 of 336 posts
Re: Signal says it won’t compromise on encryption
#222Couldn’t one just do PGP over WhatsApp, over Telegram or whatever? Instead of sending a plaintext message you’d send the PGP message but using existing infrastructure. Then there’d only be metadata to harvest but content should definitely be secure.
And nowadays, every popular IM network wants 3rd-party clients off their net at all costs. Signal is on the better side of the spectrum here. While they explicitly say they don't support non-official clients connecting to the official network, this isn't rigorously enforced. WA, on the other hand, would permaban your whole account if you even so much as try to use 3rd-party client.
Re: Signal says it won’t compromise on encryption
#223India wants to read everything? Why don't they just forbid the use of https. So that everyone can read everything on the internet
Kazakstan mandated government issue man-in-the-middle TLS certificates: https://www.zdnet.com/article/kazakhstan-government-is-inter... The EU is following this govennment friendly move: https://www.bleepingcomputer.com/news/security/experts-urge-... It would not be difficult for India as well. I see itlikely Modi and BJP will make this move as part of some anti-terrorist legislation.
Re: Signal says it won’t compromise on encryption
#224Earlier quoted context omitted.
The solutions for the most of the issues you are describing comes with great usability costs. It is already hard to make non-tech people to switch from WhatsApp.
How come, signal works exactly the same as whatsapp. I forced my friends and (older) relatives to change to signal and there has been no problems and everyone is happy.
Re: Signal says it won’t compromise on encryption
#225Big govt vs big tech, a battle that is being played out all over the world. Any country that value sovereignty and sees itself as an independent actor rather than a vassal state, must take the position India is taking, or else be susceptible to foreign owned apps influencing its citizenry. The only alternative would be to insist Signal hire its security agents into product / moderator roles, so that oversight can be…
Two mathematicians could literraly communicate encrypted on a piece of paper, and there would be no way to stop them other than scaring them put of doing it with threats of violence, jail or similar. There is an aspect ro this we have to acknowledge: we live in a world where everybody who knows how can create encrypted communications that are impossible or at least very costly to break. You cannot stop them from doin…
Publishing is a more difficult matter though. Wouldn't you say that governments should be able to demand transparency when someone distributes information to entire populations?
If someone was calling on millions of followers to kill members of some minority, would you still take the position that the distribution channel must remain off limits to governments trying to enforce encitement laws?
Re: Signal says it won’t compromise on encryption
#226I do want to hear more about how signal and other companies are working to prevent their apps being used by bad actors, terrorists.
I do want to hear more about how toll road management companies are working to prevent their roads being used by bad actors, terrorists. Food manufacturers should also ensure that they are not contributing to feeding bad actors... People like you being so easily manipulated by governments are extremely dangerous to democracy.
Re: Signal says it won’t compromise on encryption
#227Earlier quoted context omitted.
> ...your account will be associated with this phone number anyways. Messages exchanged in Signal are repudiable. That said, in a recent blog post Signal indicated that arbitrary usernames is something they're working on. > ...unlike XMPP you cannot spin up your own server and have full control over it. Signal is a better alternative for the likes of PGP because it is centralized [0]. Spam notwithstanding, Matrix has…
> Signal indicated that arbitrary usernames is something they're working on. no offense but they've been saying this for years, the feature may eventually come but I'm not holding my breath
Re: Signal says it won’t compromise on encryption
#228>> Signal knows nothing about who you are.
This is based on trust, not systematic proofs, Signal knows this, yet never tells its users. For example, Signal uses Intel’s Software Guard Extensions (SGX) - which is know to have multiple attacks, any of which Signal might be forced to run using national security letter. They have also had multiple data breaches, which I am guessing average user is not aware of. Moxie is still on the board, and he personally refused multiple times to remove the requirement for a phone number. Lastly, Signals three board members have all been the leader of Signal in last year and I have been unable to find their most recent 990 non-profit disclosure.
Re: Signal says it won’t compromise on encryption
#229Earlier quoted context omitted.
> Signal indicated that arbitrary usernames is something they're working on. no offense but they've been saying this for years, the feature may eventually come but I'm not holding my breath
I hate having to come up with a username. A better (IMHO) solution would be GUIDs or similar, generated on-device.
Re: Signal says it won’t compromise on encryption
#230I have nothing against Signal, Moxie, etc — but it attracts high-value targets. As such, Signal is an extremely high-value target. >> Signal knows nothing about who you are. This is based on trust, not systematic proofs, Signal knows this, yet never tells its users. For example, Signal uses Intel’s Software Guard Extensions (SGX) - which is know to have multiple attacks, any of which Signal might be forced to run usi…
NSLs can demand information but cannot compel action. The govt cannot use an NSL to force you into military service, for example, or force you to hack someone else’s computer (which is essentially what you are suggesting).