Live data from Hacker News

Privacy is priceless, but Signal is expensive

signal.org

551–560 of 965 posts

Re: Privacy is priceless, but Signal is expensive

#551
post #335

Earlier quoted context omitted.

Telecoms don't even want to roll out all of the infrastructure they get paid by the government to, I don't know that their willingness to do anything is a point I'd try to stand firmly on.

Exactly, so how on earth does Google think that it is a good idea to put them in charge of running the infrastructure powering the future of instant messaging? Any chance at all it has something to do with the fact that they've acquired an RCS infrastructure provider that they can sell to telcos? https://jibe.google.com/

Someone has to run it. Logically, the obvious party to do so the carrier providing network access to the device, which also has a recurring billing relationship with the user from which to recoup its costs, and that the user knows to contact when they have issues. As a standard ostensibly replacing SMS, and coming out of the GSMA, it's also pretty obvious it'd be biased toward a carrier-centric solution.

There are a couple other options of course, but I am not sure they are better:

* Fully federate this, a la Matrix or XMPP. I really wish this was a practical option, but without legislation I doubt any company wants to go willingly in this direction. Even if they did, it'd be difficult to contain spam at scale. It also creates 'first contact' issues; love it or hate it, the general public seem attached to the idea of phone numbers and it seems to work relatively well and unambiguously. It is also the most technically complicated and most brittle and unpredictable for users.

* Phone / OS maker operates it for their devices. You don't seem to want Google running things, so this seems markedly worse than what they have actually done which is give you options (most people can at least choose a carrier, and carriers can choose implementations). It's unclear how operating costs are recouped here, especially for low-end devices. Does this lead to feature stratification? I hope not, but probably. It's a global single point of failure, both from a technical point of view as well as a policy/jurisdiction one (can $country LE subpoena my records because the company operating the service is ${country}an - or perhaps merely operates in $country, for example?). Also unclear how users are 'found', but maybe it's a bit easier than in a fully federated system.

* Phone / OS maker partners operate the service, giving users a few choices. Not really sure why anyone would go in for this, but it's basically the same as if the phone maker operates it.

None of these are great options, but I think the carrier is probably the least-bad one. You have an agreement with them. You have the legal protections offered in your home jurisdiction, with clear jurisdiction over the whole thing. They already have a ton of data on you and access to your traffic. You have a neck to wring if the service doesn't work properly.

They really should have standardized E2EE though, not including it is ridiculous.

Re: Privacy is priceless, but Signal is expensive

#552

Earlier quoted context omitted.

> open it up to let other people run their own servers instead of trying to control everything. If you know of a good open architecture that solves the problems of spam and impersonation while maintaining the convenience and ease of use necessary for mass adoption, please share it.

I could get my parents who are nearing their 70s to use Element (Matrix) and it took them less than 10 minutes, even with me asking them to register to a non-default homeserver. Screw "convenience". It's a poison pill. "Convenience" should never be put above "resilience" (not to mention "freedom") in a value scale. The American obsession with "convenience" is turning us all into cattle and it's getting harder and har…

With all due respect, it seems that you have conceded that a convenient, spam free, open option not only doesn’t exist in practice, but can’t in principle.

That’s more than even I believe. I just think nobody in the OSS space has put the work in to figure it out yet.

> I could get my parents who are nearing their 70s to use Element (Matrix) and it took them less than 10 minutes, even with me asking them to register to a non-default homeserver.

Well in that case Element would be the solution we’re looking for, except that not everyone’s parents have someone like you to help them.

And as for the desire for convenience, it’s hard to imagine you seriously believe that only Americans value convenience over resilience. If that were true, the rest of the world would be using Element rather than WhatsApp.

Simply railing against people’s needs doesn’t change them.

Re: Privacy is priceless, but Signal is expensive

#553

Personally, I refuse to financially support Signal so long as they're still holding my chat logs hostage on my old iPhone and seem not at all concerned about solving this problem, which has existed for years. There was (and still is, so far as I know) no upfront warning to users that if they don't first sync with a desktop client, and their phone gets lost or stolen, their iTunes backups do not (unlike most iPhone ap…

Interesting, I always saw this as a deliberate feature aligned with what I first came across Signal for (sensitive communications between trusted parties that may need wiping at a moment's notice). If a journo reporting in a less than hospitable regime had their phone confiscated then they need not worry about their chat logs compromising them.

Re: Privacy is priceless, but Signal is expensive

#554

Support for Signal development supports all privacy-oriented software and systems, because Signal is open source. The Signal Protocol already is an industry standard. What other Signal development - either the components, the code, or the concepts - are used by others?

The only issue I'm aware of is that The Signal Protocol is only really defined in Signal's GPL'd code. So it's almost impossible to write a clean room implementation (e.g. Wire tried and ultimately failed. they ended up also GPL-ing their library).

It's used by many major services, such as WhatsApp. How could it be that hard to define and implement?

Re: Privacy is priceless, but Signal is expensive

#555

Earlier quoted context omitted.

Not completely ? Their server seems to be open source too now (with the exception of the spam filter) ?

Can I operate my own Signal server and talk with people on the "main" one?

Federation can only make security worse and I do not want it. You can have something else.

Re: Privacy is priceless, but Signal is expensive

#556
post #523

$6 million per year on outgoing SMS? Do not send SMS to users, make users send SMS to you instead to confirm their numbers! I have this solution for years and it works >90% of the time. The rest 10% is calling a verification number which drops calls with busy signal (no fees for the caller) but sees who is calling and is able to verify their number.

Significantly less secure. Faking the sending number is much easier than hacking SS7 and getting SMS routed to you which are not destined to you (which is also doable but require an order of magnitude more skills and ressources in my view).

This is correct; anyone with relatively basic knowledge of VOIP can spoof any number (and CID name) they want.

Re: Privacy is priceless, but Signal is expensive

#557

I'm seeing all the comments about the $6m Twilio expense, but nothing commenting on how their cost per employee is $380,000 totaling $19m. I think they could optimize this easier if the will was there. I know HN is very SV/tech centric, and that number makes sense there given the run up of VC money, etc. but I'm willing to bet they could source talent from cheaper places and slash this in half; if they wanted to. Jus…

I interviewed at Signal for a senior developer. They do not pay well. I didn't even get past the phone interview because they were nowhere near my range. No idea where the $380k comes from, executives maybe?

Re: Privacy is priceless, but Signal is expensive

#558
post #553

Personally, I refuse to financially support Signal so long as they're still holding my chat logs hostage on my old iPhone and seem not at all concerned about solving this problem, which has existed for years. There was (and still is, so far as I know) no upfront warning to users that if they don't first sync with a desktop client, and their phone gets lost or stolen, their iTunes backups do not (unlike most iPhone ap…

Interesting, I always saw this as a deliberate feature aligned with what I first came across Signal for (sensitive communications between trusted parties that may need wiping at a moment's notice). If a journo reporting in a less than hospitable regime had their phone confiscated then they need not worry about their chat logs compromising them.

Sorry, how is this any safer for the journalist? If their phone is compromised in a way such that someone can login and control their Signal app, their chat logs are already compromised. I’m just saying there should be the ability to export those logs once you’ve logged in.

But if they don’t want to provide that, then:

1) Why does the Android app support this?

2) They should warn users of this BEFORE holding their data hostage, and not market Signal like it’s the right solution for everyone.

Re: Privacy is priceless, but Signal is expensive

#559
post #464

Earlier quoted context omitted.

Removing essential features like voice/video calling for non-paying users would be a terrible choice IMHO. This is a communication app, which means it is only useful if others use it too. And how are you going to convince others to pay for Signal when there are many free alternatives, including WhatsApp, which most people already have and while not as privacy focused as Signal, does have end-to-end encryption. If Sig…

Valid but if there is no model that is sustainable then who cares if its successful? Some trade offs will have to be made. How can they keep going if the vast majority of people don't pay? They don't have the model of "ok we are going to flip and monetize after we get to X mass". Its like a growth startup but with no end game plan.

Call to donations, ads, pre-mined cryptocurrencies, selling cosmetics, premium features no free service offers, partnering with other organizations, etc...

They already do some of these, and some are less popular than others, but the key is to keep the essential features free and easy.

On Discord for instance, a free account is enough to cover all of most people needs, but you get a little extra by paying a subscription, and it is enough for Discord to be worth billions. Maybe not the perfect example since Discord has a critical mass, but no one wants to leave just because they don't have premium features (larger uploads, higher resolution streaming, flashy emoji) for free.

For Signal, it seems like just calling for donations is enough. They have a good image, so they can do that. It can actually be a solid business plan, look at Wikipedia, they get more than $100M a year doing that despite the controversy.

Re: Privacy is priceless, but Signal is expensive

#560
Maybe I'm the only one here but this so-called "transparency" in the form of a single blog post doesn't instill much trust in me. I have been an avid Signal user since the TextSecure days and still recommend Signal over any other messenger. However:

- There were times (e.g. during the introduction of MobileCoin) when the Github repositories hadn't seen any update for months, while they were still releasing new app versions on a regular basis. Heck, last time I checked there were not even public changelogs for any of the apps. Calling Signal "open-source" is a stretch at best.

- The Signal team time and again has failed to react to criticism of the usage of Intel SGX, or of how they completely messed up the introduction of the Signal PIN. And let's not talk about MobileCoin. Yes, being "open-source" or "nonprofit" doesn't imply they need to ask their users for permission or respond to every complaint. However, a minimum amount of openness and debating critical features in public would go a long way here.

- I would like to see some transparency regarding the overall foundation and corporate structure, beyond just silently filing form 990 years with significant delay. For instance, it seems Brian Acton can elect and dissolve the entire board just by himself[0, 1]?

Long story short, before donating to Signal I'd like to see a proper and continuous commitment to transparency, not just a once-in-time blog post.

[0]: (German) https://www.spektrum.de/news/mythos-signal-licht-und-schatte...

[1]: https://projects.propublica.org/nonprofits/organizations/824...

Post reply on HN