Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

291–300 of 336 posts

Re: Signal says it won’t compromise on encryption

#291
post #172

Earlier quoted context omitted.

Non profit but still against federation or anyone running an alternative client. Why?

The good answer: They can't verify the integrity of alternative clients and that they don't leak info The other answer: They've got somewhat of a "we know best" vibe going for them which also comes in play when you see their response to feature requests - e.g. for usernames instead of phone numbers or for "edit message" functionality like Telegram has.

>The good answer: They can't verify the integrity of alternative clients and that they don't leak info

The good answer isn't even a good argument.

The client is open source. People have forked it and used the Signal network. Signal asked them to stop and they did, but there is nothing stopping people from ignoring Signal's request in the future.

This has nothing to do with federation. Signal could federate their network and still request everybody use the official client.

Re: Signal says it won’t compromise on encryption

#292

Signal is already compromised. I don't understand why people still keep fooling themselves it's private and secure. It requires a mobile number, and thus your identity is known and your device is uniquely identifiable anyway, and it's also developed in the US where three-letter agencies have infinite reach and control.

Yes, your signal identity is tied to a phone number. But attackers can't tell who you are talking to, or what groups you are in. So why does it matter?

Re: Signal says it won’t compromise on encryption

#293
post #77

A noob question, how does signal know/prevent use of its app for illegal/criminal activities? Larger question here would be - Do governments and security agencies need to keep a tab on social media to check for illegal activities

How do roads prevent speeding, drug trafficing, human trafficing, fraud, etc?

Re: Signal says it won’t compromise on encryption

#294
post #172

Earlier quoted context omitted.

The good answer: They can't verify the integrity of alternative clients and that they don't leak info The other answer: They've got somewhat of a "we know best" vibe going for them which also comes in play when you see their response to feature requests - e.g. for usernames instead of phone numbers or for "edit message" functionality like Telegram has.

>The good answer: They can't verify the integrity of alternative clients and that they don't leak info The good answer isn't even a good argument. The client is open source. People have forked it and used the Signal network. Signal asked them to stop and they did, but there is nothing stopping people from ignoring Signal's request in the future. This has nothing to do with federation. Signal could federate their netw…

Your point in no way explains why the argument from Signal is bad, and arguably completely misses the point.

Re: Signal says it won’t compromise on encryption

#295

Earlier quoted context omitted.

Because federation is seriously difficult — look at all the effort the Matrix team has put in, and it’s still not quite 100%. Plus yes Signal has a bit of an NIH complex.

Matrix federation is hard because they want to support large IRV style rooms with consistent history and strong controls to prevent room takeovers. Signal is more focused on 1:1 or small group chats. Federation there can be much simpler, more like email/xmpp than IRC. It does still add friction and slows down youe development as upgrading is difficult.

Signal also has a grand total of 40 employees. Keeping the application running on the various platforms takes a decent chunk of their time. Difficult development to add something like federation cannot be expected to happen quickly.

Re: Signal says it won’t compromise on encryption

#296

Earlier quoted context omitted.

>The good answer: They can't verify the integrity of alternative clients and that they don't leak info The good answer isn't even a good argument. The client is open source. People have forked it and used the Signal network. Signal asked them to stop and they did, but there is nothing stopping people from ignoring Signal's request in the future. This has nothing to do with federation. Signal could federate their netw…

Your point in no way explains why the argument from Signal is bad, and arguably completely misses the point.

My point is client integrity and federation of servers are not related.

Re: Signal says it won’t compromise on encryption

#297

They might not compromise on encryption, but they have no intentions of open sourcing their censorship module either: https://github.com/signalapp/Signal-Server/blob/90490c9c8485...

There are legitimate reasons for not open sourcing it. It would become effortless to circumvent.

Re: Signal says it won’t compromise on encryption

#298

Earlier quoted context omitted.

He was our president, every former president is newsworthy. Even when they just speak out. January 6th and the theft of top secret documents including nuclear secrets guarantees that he's not leaving the news cycle anytime soon. If he's not charged with a crime that is disqualifying for president, most expect him to run and deny any loss, ensuring our republic is overthrown by a banana republic as well. Many folks ar…

The FBI desires that you are referencing through Trump have been policy goals since the 80s when source code had to be exported as pages on a book. So it rings false when you claim he's just another president. You do get into your real reasons at least, but the soapbox betrays the real nugget of the question. Why cant we have a policy discussion because someone must derail it with their absolute need to tell us how b…

I said I agree with 75% of his policies or more. I'm not sure where you read that I "badly disagree with him". That's a disingenuous take on what I said. I disagree with his methods and disapprove of his lack of character and integrity. It's not worth the win.

That said, for an example of the 25%, while I agree with low taxes, I do not agree with tax cuts when already at historical lows as President Trump enacted. Deficit spending should not be supporting any tax cuts. To share just one example outside of that 75% of agreement I have with Trump policies. I would hardly characterize that disagreement as proof that I "badly disagree" with "his" policies.

Scarequotes around him because I'm not convinced many of his administration's actions were his ideas. I would characterize him as more of a puppet that dominated the room and was willing to disregard any form of humility or tradition, but did not dominate any intellectual matters such as policy decisions. Any positive change that occurred could only accurately be ascribed to his administration. His criminal actions have nullified, or should nullify all of his support. We're long past the stage of it qualifying as a cult.

Re: Signal says it won’t compromise on encryption

#299

Earlier quoted context omitted.

Kazakstan mandated government issue man-in-the-middle TLS certificates: https://www.zdnet.com/article/kazakhstan-government-is-inter... The EU is following this govennment friendly move: https://www.bleepingcomputer.com/news/security/experts-urge-... It would not be difficult for India as well. I see itlikely Modi and BJP will make this move as part of some anti-terrorist legislation.

Personally I find it unbelievable that major governments are not already in possession of the private key for at least one of the 150+ root certificates pre-installed on my device.

All of this has happened already, see this: https://en.wikipedia.org/wiki/DigiNotar

"Cryptographer Bruce Schneier says the attack may have been "either the work of the NSA, or exploited by the NSA."[6] However, this has been disputed, with others saying the NSA had only detected a foreign intelligence service using the fake certificates.[7]"

Re: Signal says it won’t compromise on encryption

#300
post #85

Earlier quoted context omitted.

Two mathematicians could literraly communicate encrypted on a piece of paper, and there would be no way to stop them other than scaring them put of doing it with threats of violence, jail or similar. There is an aspect ro this we have to acknowledge: we live in a world where everybody who knows how can create encrypted communications that are impossible or at least very costly to break. You cannot stop them from doin…

I agree with you when it comes to regular crime, and I'm not finding it difficult to defend my right to privately communicate with other individuals and small groups. We have always been able to do that, one way or another. Publishing is a more difficult matter though. Wouldn't you say that governments should be able to demand transparency when someone distributes information to entire populations? If someone was cal…

I also agree that publishing is a different thing, it is very much the difference between private and public communication.

Where a private group becomws of the size that posting there constitutes an act of publication is a matter of discussion, but I'd argue below a certain size any group chat can still be seen as private communications.

This means Signal groups with their lower size are in less jeopardy than a one-to-many telegram group.

Post reply on HN