Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

271–280 of 336 posts

Re: Signal says it won’t compromise on encryption

#271
post #190

Earlier quoted context omitted.

Also: - There is no way to back up your message history (with photos, etc). This could be done using their (annoyingly pushed to users) "PIN", but isn't. Few people realize that if your phone dies today, your history is GONE. From what I saw, once people do realize this, it's game over for Signal. WhatsApp is just easier, "everybody is there", and it does back up your history. EDIT: Yes, it's on iOS. Yes, I realize t…

I see no reason to back-up my history ever. I don't use signal for anything that needs to be archived. Nor do any of my friends. One of the selling points of signal is the feature that it doesn't automatically save photos, this is a good feature. You manually save the photos you want to save. And I thought people regularly backed up everything worth saving from phones to non phone archive anyway.

Some people want their complete messaging history, but encrypted so that only they can see it. And backed up so that... well... they don't lose it.

Re: Signal says it won’t compromise on encryption

#272
post #53

Earlier quoted context omitted.

Isn't this what Bill Barr and the Trump administration wanted, too? https://www.justice.gov/opa/pr/statement-attorney-general-wi...

What is it about that guy, that makes people unable to stop talking about him? Was it not enough for him to be the top story in the news every day for 4 years?

He was our president, every former president is newsworthy. Even when they just speak out. January 6th and the theft of top secret documents including nuclear secrets guarantees that he's not leaving the news cycle anytime soon. If he's not charged with a crime that is disqualifying for president, most expect him to run and deny any loss, ensuring our republic is overthrown by a banana republic as well. Many folks are keeping eyes on him.

There's really no other political figure with as much unrestricted aggression as he has. I certainly don't have his nerve, I have far too much respect for the founders and institutions of our government to so willfully rage against it. I guess our greatest leaders, Washington, Lincoln, Roosevelt and everything we've built till now humbles me.

But unlike Mr. Trump, I also was working as a paperboy at 12 years old, worked night shifts during college, and never got a break being unemployed all the way into my 40s now. There's a bigger difference between someone like me and Trump, and people of other racial and ethnic backgrounds. That's why I never saw eye to eye with him. But he is pretty fascinating.

The audacity and outright disregard for our institutions is absolutely astonishing. I do hope the media spotlight remains on him for the rest of his life, I don't want that guy flying under the radar. He's a reminder of what America's worst inclinations can produce. Never worked a job (other than President of the United States of America), was born at the finish line, and a soul full of man's worst inclinations. And believe me, I agree with at least 75%+ of "his" policies. I remain an independent. If I had to describe my leanings it would be a "pre-MAGA Republican, who supports unions". These parties have to work for my vote and cannot count on my vote.. In case, you think someone saying the things I have is somehow anti-Trump. If I am, it's only because it makes sense to be so.

Re: Signal says it won’t compromise on encryption

#273

I have nothing against Signal, Moxie, etc — but it attracts high-value targets. As such, Signal is an extremely high-value target. >> Signal knows nothing about who you are. This is based on trust, not systematic proofs, Signal knows this, yet never tells its users. For example, Signal uses Intel’s Software Guard Extensions (SGX) - which is know to have multiple attacks, any of which Signal might be forced to run usi…

[deleted]

Re: Signal says it won’t compromise on encryption

#275

Signal is too small a player and is therefore more likely to be bullied by governments. India is taking pot shots at it to see if it can get away with forcing them into intercepting communications. If they leave as a result, they'll simply shrug and move on. Also, I'm convinced that if Signal were to become popular they'd probably sell it to some commercial provider, since the cost of maintaining a service used by hu…

bullied how? it's easier to get bullied when you have an office space, they harass your employees. it's easier to get bullied when you sell products/service, they stop your money flow. what/how do you envision them bullying Signal?

Re: Signal says it won’t compromise on encryption

#276

Earlier quoted context omitted.

> any of which Signal might be forced to run using national security letter. NSLs can demand information but cannot compel action. The govt cannot use an NSL to force you into military service, for example, or force you to hack someone else’s computer (which is essentially what you are suggesting).

Regardless if they were “compeled” - nation security letter related activities have included actions. For example, this included a room and split: - https://wikipedia.org/wiki/33_Thomas_Street My understanding is that vendors that execute national security letters offer system integration technology to be locally installed to ingest the related data. Signal has the data, it just requires them collecting it — hence my…

Those actions were not the result of a national security letter. NSLs can only require the production of existing records. They cannot require the release of the content of communications nor the collection of records which don't already exist. They must also specify the time period the records request covers which can only include up to the date the NSL was received.

Re: Signal says it won’t compromise on encryption

#277
post #11

Requiring handing over encryption keys as a requirement to do business there sounds like a good way to sanction yourself from the modern world.

Many countries tried this, even the ones we consider the "modern world" (like france, more than once). Some even prohibited export of encryption, so they could more easily decrypt foreign traffic (usa). Some protocols were even designed with "alternative" encryption, intentionally weakened (GSM).

Re: Signal says it won’t compromise on encryption

#279

Signal is too small a player and is therefore more likely to be bullied by governments. India is taking pot shots at it to see if it can get away with forcing them into intercepting communications. If they leave as a result, they'll simply shrug and move on. Also, I'm convinced that if Signal were to become popular they'd probably sell it to some commercial provider, since the cost of maintaining a service used by hu…

bullied how? it's easier to get bullied when you have an office space, they harass your employees. it's easier to get bullied when you sell products/service, they stop your money flow. what/how do you envision them bullying Signal?

> ... what/how do you envision them bullying Signal?

I guess, by outlawing them. Think of the collateral damage. For ex, unavailability of Signal means MobileCoins in wallets of its Indian users become inaccessible (theoretically, since Signal is a non-custodial wallet) if they don't get it out in time before the ban, so there's something for Signal to think about.

Re: Signal says it won’t compromise on encryption

#280
I suppose people should decide for themselves if they take the word of a centralized service. Convenience is a factor after all.

For those that have small circles of friends they wish to chat with and minimize the number of ISP's their traffic traverses, I would suggest tinkering around with uMurmur [1] a lightweight version of Murmur. There are pre-built packages in several operating systems package managers. The configuration is dirt simple [2] and the daemon is very light weight, designed to run on home routers. Use Certbot to generate LE certs or just use self-signed. One TCP and one UDP port must be opened to the daemon or forwarded if on a different device with the default port being 64738. One can set a server-wide password to keep strangers off of it, or set passwords per-channel. It took me about 2 minutes to install and configure uMurmur on Alpine Linux and most of that time was deciding how I wanted to nest channels.

The mobile client is Mumla. Just put in the IP or hostname of the uMurmur instance. uMurmur is not E2EE but if it is running on your own router or VM and you are talking with your friends that you know and trust then maybe that is less of an issue given the server is on your hardware.

The voice quality is incredible. It uses the OPUS codec and does not require much bandwidth. The client also supports text chat, but that can be disabled in the server if one so wishes.

[1] - https://github.com/umurmur/umurmur

[2] - https://github.com/umurmur/umurmur/wiki/Configuration

Post reply on HN