Live data from Hacker News

Confer – End to end encrypted AI chat

confer.to

121–130 of 180 posts

Re: Confer – End to end encrypted AI chat

#121
post #120

It’s exciting to hear that Moxie and colleagues are working on something like this. They definitely have the skills to pull it off. Few in this world have done as much for privacy as the people who built Signal. Yes, it’s not perfect, but building security systems with good UX is hard. There are all sorts of tradeoffs and sacrifices one needs to make. For those interested in the underlying technology, they’re basical…

I don't know, I'd say Signal is perfect, as it maximizes "privacy times spread". A solution that's more private wouldn't be as widespread, and thus wouldn't benefit as many people.

Signal's achievement is that it's very private while being extremely usable (it just works). Under that lens, I don't think it could be improved much.

Re: Confer – End to end encrypted AI chat

#122

Earlier quoted context omitted.

Looks like using Google for login. You can also "Continue with Email." Logging in with Google is pretty standard.

It is not privacy oriented if you are sharing login, profile information with Google and Confer. It wouldn't be long until Google and Gemini can read this information and Google knows you are using Confer. Wouldn't trust it regardless if Email is available. The fact that confer allows Google login shows that Confer doesn't care about users privacy.

Most people don't care about Google knowing whether they're using a particular app. If they do, they have the option not to use it. The main concern is that the chats themselves are E2E encrypted, which we have every reason to believe.

This is a perfect example of purism vs. pragmatism. Moxie is a pragmatist who builds things that the average person can actually use. If it means that millions of people who would otherwise have used ChatGPT will migrate because of the reduced friction and get better privacy as a result, that's a win even if at the margin they're still leaking one insignificant piece of metadata to Google.

Re: Confer – End to end encrypted AI chat

#124
post #99

Earlier quoted context omitted.

Not sure why you're gettimg downvoted. This is exactly what he did to instant messaging; extremely damaging to everyone and without solid arguments for such design.

Or, he took a barely niché messaging app plugin (OTR), improved it to provide forward secrecy for non-round trips, and deployed the current state-of-the art end-to-end encryption to over 3,000,000,000 users, as Signal isn't the only tool to use double-ratchet E2EE. >broken SGX metadata protections Citation needed. Also, SGX is just there to try to verify what the server is doing, including that the server isn't colle…

Exactly. These arguments are so weak that they read more like a smear campaign than an actual technical discussion.

"You have to agree to Apple's terms to use it"? What's Signal meant to do, jailbreak your phone before installing itself on it?

Re: Confer – End to end encrypted AI chat

#125
post #107

what did he do for messaging? Signal is hardly more private than goddamn Whatsapp. in fact, given that Whatsapp had not been heavily shilled as the "totally private messenger for journalists and whistleblowers :^)" by the establishment media, I distrust it less. edit @ -4 points: please go ahead and explain why does Signal need your phone number and reject third party clients.

> Signal is hardly more private than goddamn Whatsapp Kind of because Whatsapp adopted Signal's E2EE... And not even that long ago!

If by "not even that long ago" you mean "a few months short of a decade ago", sure.

Re: Confer – End to end encrypted AI chat

#126
post #99

Earlier quoted context omitted.

Not sure why you're gettimg downvoted. This is exactly what he did to instant messaging; extremely damaging to everyone and without solid arguments for such design.

Or, he took a barely niché messaging app plugin (OTR), improved it to provide forward secrecy for non-round trips, and deployed the current state-of-the art end-to-end encryption to over 3,000,000,000 users, as Signal isn't the only tool to use double-ratchet E2EE. >broken SGX metadata protections Citation needed. Also, SGX is just there to try to verify what the server is doing, including that the server isn't colle…

>> and agree to Apple or Google terms of service to use it?

> Yeah that's what happens when you create a phone app for the masses.

No, that's what happens when you actively forbid alternative clients and servers, prevent (secure) alternative methods of delivery for your app and force people to rely on the American megacorps known for helping governmental spying on users, https://news.ycombinator.com/item?id=38555810

Re: Confer – End to end encrypted AI chat

#127
post #120

It’s exciting to hear that Moxie and colleagues are working on something like this. They definitely have the skills to pull it off. Few in this world have done as much for privacy as the people who built Signal. Yes, it’s not perfect, but building security systems with good UX is hard. There are all sorts of tradeoffs and sacrifices one needs to make. For those interested in the underlying technology, they’re basical…

I don't know, I'd say Signal is perfect, as it maximizes "privacy times spread". A solution that's more private wouldn't be as widespread, and thus wouldn't benefit as many people. Signal's achievement is that it's very private while being extremely usable (it just works). Under that lens, I don't think it could be improved much.

>Signal's achievement is that it's very private while being extremely usable (it just works).

Exactly. Plus it basically pioneered the multi-device E2EE. E.g., Telegram claimed defaulting to E2EE would kill multi-client support:

"Unlike WhatsApp, we can allow our users to access their Telegram message history from several devices at once thanks to our built-in instant cloud sync"

https://web.archive.org/web/20200226124508/https://tgraph.io...

Signal just did it, and in a fantastic way given that there's no cross device key verification hassle or anything. And Telegram never caught up.

Re: Confer – End to end encrypted AI chat

#128
post #99

Earlier quoted context omitted.

Or, he took a barely niché messaging app plugin (OTR), improved it to provide forward secrecy for non-round trips, and deployed the current state-of-the art end-to-end encryption to over 3,000,000,000 users, as Signal isn't the only tool to use double-ratchet E2EE. >broken SGX metadata protections Citation needed. Also, SGX is just there to try to verify what the server is doing, including that the server isn't colle…

Exactly. These arguments are so weak that they read more like a smear campaign than an actual technical discussion. "You have to agree to Apple's terms to use it"? What's Signal meant to do, jailbreak your phone before installing itself on it?

Moxie Marlinspike sounds like some 90s intelligence guy’s understanding of what an appealing name to hacker groups would sound like. Put a guy like that as so-called creator of some encryption protocol for messaging and promote the app like it’s for secret conversations and you think people won’t be suspicious? It screams honeypot like nothing else.

Re: Confer – End to end encrypted AI chat

#129

I’m missing something, won’t the input to the llm necessarily be plaintext? And the output too? Then, as long as the llm has logs, the real input by users will be available somewhere in their servers

According to the article:

>Data and conversations originating from users and the resulting responses from the LLMs are encrypted in a trusted execution environment (TEE) that prevents even server administrators from peeking at or tampering with them.

I think what they meant to say is that data is decrypted only in a trusted execution environment, and otherwise is stored/transmitted in an encrypted format.

Re: Confer – End to end encrypted AI chat

#130

Earlier quoted context omitted.

Exactly. These arguments are so weak that they read more like a smear campaign than an actual technical discussion. "You have to agree to Apple's terms to use it"? What's Signal meant to do, jailbreak your phone before installing itself on it?

Moxie Marlinspike sounds like some 90s intelligence guy’s understanding of what an appealing name to hacker groups would sound like. Put a guy like that as so-called creator of some encryption protocol for messaging and promote the app like it’s for secret conversations and you think people won’t be suspicious? It screams honeypot like nothing else.

So the argument against Signal is now "the creator's nickname sounds odd"? I mean, OK? Keep using WhatsApp, Telegram or Instagram if you think those are more private than Signal.
Post reply on HN