Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

261–270 of 336 posts

Re: Signal says it won’t compromise on encryption

#261
post #218

Earlier quoted context omitted.

i think SMS support was part of the reason they could not do it before, since usernames would break that feature. removing SMS makes this a non-issue. the phone number is now just an arbitrary ID string which can be replaced by any other

There's no reason they couldn't have done both. Signal never used SMS as a transport. It only provided a UI to have unencrypted SMS messages alongside Signal chats. As far as Signal messenges themselves go, phone numbers always were an arbitrary ID string. Having a username that isn't a phone number would have only more clearly segregated the SMS feature from Signal chat; and the desire for that segregation is one of…

> Signal never used SMS as a transport.

Signal is a merge of the TextSecure and RedPhone applications; back when it was still called TextSecure, it did use SMS as a transport for encrypted messages.

Re: Signal says it won’t compromise on encryption

#263

I have nothing against Signal, Moxie, etc — but it attracts high-value targets. As such, Signal is an extremely high-value target. >> Signal knows nothing about who you are. This is based on trust, not systematic proofs, Signal knows this, yet never tells its users. For example, Signal uses Intel’s Software Guard Extensions (SGX) - which is know to have multiple attacks, any of which Signal might be forced to run usi…

> Signal is rapid on its way to a billion users

The last number I could find is 40 million in 2021

Re: Signal says it won’t compromise on encryption

#264

I have nothing against Signal, Moxie, etc — but it attracts high-value targets. As such, Signal is an extremely high-value target. >> Signal knows nothing about who you are. This is based on trust, not systematic proofs, Signal knows this, yet never tells its users. For example, Signal uses Intel’s Software Guard Extensions (SGX) - which is know to have multiple attacks, any of which Signal might be forced to run usi…

That's not how NSLs work.

Re: Signal says it won’t compromise on encryption

#265

Earlier quoted context omitted.

Kazakstan mandated government issue man-in-the-middle TLS certificates: https://www.zdnet.com/article/kazakhstan-government-is-inter... The EU is following this govennment friendly move: https://www.bleepingcomputer.com/news/security/experts-urge-... It would not be difficult for India as well. I see itlikely Modi and BJP will make this move as part of some anti-terrorist legislation.

Personally I find it unbelievable that major governments are not already in possession of the private key for at least one of the 150+ root certificates pre-installed on my device.

Having the private key for a root CA does not allow them to decrypt your traffic. They'd have to sign an impostor certificate for the hostnames to which you connect, and actively tamper with (MITM) your traffic using that new key/certificate. This would be trivially detectable (indeed that's what certificate transparency does).

Re: Signal says it won’t compromise on encryption

#266

I have nothing against Signal, Moxie, etc — but it attracts high-value targets. As such, Signal is an extremely high-value target. >> Signal knows nothing about who you are. This is based on trust, not systematic proofs, Signal knows this, yet never tells its users. For example, Signal uses Intel’s Software Guard Extensions (SGX) - which is know to have multiple attacks, any of which Signal might be forced to run usi…

> Signal is rapid on its way to a billion users The last number I could find is 40 million in 2021

You’re correct; removed that from comment, not sure where I got that from, but was unable to find anything quickly that would be anywhere near billion.

Re: Signal says it won’t compromise on encryption

#267

I have nothing against Signal, Moxie, etc — but it attracts high-value targets. As such, Signal is an extremely high-value target. >> Signal knows nothing about who you are. This is based on trust, not systematic proofs, Signal knows this, yet never tells its users. For example, Signal uses Intel’s Software Guard Extensions (SGX) - which is know to have multiple attacks, any of which Signal might be forced to run usi…

Signal does marketing by omission: "Intel’s SGX protects against introspection", "we depend on donations from our community", etc.

Would it be possible for you to expand on Signal not being dependent on donations?

Re: Signal says it won’t compromise on encryption

#268
post #129

fucking lying is what they do! how come, if they do not share data with third parties, that a "breakin" at TWILIO would have any consequence on signal? the app store claims data is not shared with 3rd parties, yet they use twilio to "verify phonenumbers" how about verifing them yourself? to expensive...? so twilio does it for free for you? what the fishy fuck is going on here? sure they do mention verifying the numbe…

https://twilio.com/verify

Re: Signal says it won’t compromise on encryption

#269

Earlier quoted context omitted.

Signal does marketing by omission: "Intel’s SGX protects against introspection", "we depend on donations from our community", etc.

Would it be possible for you to expand on Signal not being dependent on donations?

They also received a very large amount of funding from some successful tech founders, Brian Acton and Pavel Durov

Re: Signal says it won’t compromise on encryption

#270
post #269

Earlier quoted context omitted.

Would it be possible for you to expand on Signal not being dependent on donations?

They also received a very large amount of funding from some successful tech founders, Brian Acton and Pavel Durov

My understanding was that the funds from Brian Acton were a loan to be repaid, though might be wrong. I was unable to quickly locate any information relate to Pavel Durov having any financial relationship with Signal.
Post reply on HN