Live data from Hacker News

Confer – End to end encrypted AI chat

confer.to

131–140 of 180 posts

Re: Confer – End to end encrypted AI chat

#131
post #99

Earlier quoted context omitted.

Not sure why you're gettimg downvoted. This is exactly what he did to instant messaging; extremely damaging to everyone and without solid arguments for such design.

Or, he took a barely niché messaging app plugin (OTR), improved it to provide forward secrecy for non-round trips, and deployed the current state-of-the art end-to-end encryption to over 3,000,000,000 users, as Signal isn't the only tool to use double-ratchet E2EE. >broken SGX metadata protections Citation needed. Also, SGX is just there to try to verify what the server is doing, including that the server isn't colle…

>>broken SGX metadata protections

>Citation needed.

https://sgx.fail

https://en.wikipedia.org/wiki/Software_Guard_Extensions#List...

Re: Confer – End to end encrypted AI chat

#132

Earlier quoted context omitted.

Exactly. These arguments are so weak that they read more like a smear campaign than an actual technical discussion. "You have to agree to Apple's terms to use it"? What's Signal meant to do, jailbreak your phone before installing itself on it?

Moxie Marlinspike sounds like some 90s intelligence guy’s understanding of what an appealing name to hacker groups would sound like. Put a guy like that as so-called creator of some encryption protocol for messaging and promote the app like it’s for secret conversations and you think people won’t be suspicious? It screams honeypot like nothing else.

>Moxie Marlinspike sounds like some 90s intelligence guy’s understanding of what an appealing name to hacker groups would sound like. Put a guy like that as so-called creator of some encryption protocol for messaging and promote the app like it’s for secret conversations and you think people won’t be suspicious? It screams honeypot like nothing else.

This criticism has absolutely zero substance and honestly just reads like paranoid rambling. The Signal protocol has been independently formally analyzed [1] and has no known security issues.

[1] https://eprint.iacr.org/2016/1013

Re: Confer – End to end encrypted AI chat

#133

Earlier quoted context omitted.

Moxie Marlinspike sounds like some 90s intelligence guy’s understanding of what an appealing name to hacker groups would sound like. Put a guy like that as so-called creator of some encryption protocol for messaging and promote the app like it’s for secret conversations and you think people won’t be suspicious? It screams honeypot like nothing else.

>Moxie Marlinspike sounds like some 90s intelligence guy’s understanding of what an appealing name to hacker groups would sound like. Put a guy like that as so-called creator of some encryption protocol for messaging and promote the app like it’s for secret conversations and you think people won’t be suspicious? It screams honeypot like nothing else. This criticism has absolutely zero substance and honestly just read…

It's not about the protocol but other sides of the design. Example: https://news.ycombinator.com/item?id=38555810

Re: Confer – End to end encrypted AI chat

#134

Earlier quoted context omitted.

>Moxie Marlinspike sounds like some 90s intelligence guy’s understanding of what an appealing name to hacker groups would sound like. Put a guy like that as so-called creator of some encryption protocol for messaging and promote the app like it’s for secret conversations and you think people won’t be suspicious? It screams honeypot like nothing else. This criticism has absolutely zero substance and honestly just read…

It's not about the protocol but other sides of the design. Example: https://news.ycombinator.com/item?id=38555810

The example you linked is about push notifications in general, nothing specific to the Signal app. If the concern is that your OS is compromised or spying on you, that's not something E2E encryption can protect against, whether it's Signal or any other app.

Re: Confer – End to end encrypted AI chat

#135
post #86

What he did with messaging... So he will centralize all of it with known broken SGX metadata protections, weak supply chain integrity, and a mandate everyone supply their phone numbers and agree to Apple or Google terms of service to use it?

By default, the mobile app continually tries to connect to "updates2.signal.org"

Perhaps manual, user-controlled updates is not part of the design

If the source code is available^1 then surely someone has modified it to remove the phone number requirement, not to mention other improvements

1. https://github.com/signalapp/Signal-Server

It seems like Signal may be another example of "read-only" open source, where there is no expectation anyone will actually try to _use_ the source code. Instead, there is an expectation that everyone will use binaries distributed by a third party and allow remote code installation and RCE of software on their computers _at the third party's discretion_. In other words, all users will cede control to a third party

NB. This comment is not referring to the "Signal protocol". It pertains to _control_ over the software that implements it

Re: Confer – End to end encrypted AI chat

#136

Get a fun error message on debian 13 with firefox v140: "This application requires passkey with PRF extension support for secure encryption key storage. Your browser or device doesn't support these advanced features.Please use Chrome 116+, Firefox 139+, or Edge 141+ on a device with platform authentication (Face ID, Touch ID, Windows Hello, etc.)."

In KeePassXC:

> Your authenticator doesn't support encryption keys. Please try again using 1Password — some password managers like Bitwarden don't work yet.

Re: Confer – End to end encrypted AI chat

#137
post #108

Earlier quoted context omitted.

Yeah, it seems kind of funny how Signal is marketed as a somewhat paranoid solution, but most people run it on an iPhone out of the app store with no way to verify the source. All it takes is one villain to infiltrate one of a few offices and Signal falls apart. Same goes for Whatsapp, but the marketing is different there.

Ok so which iPhone app can be verified from source? Or is your problem that your peer might run the app on an insecure device? How would you exclude decade old Android devices with unpatched holes? I don't want to argue nirvana fallacy here but what is the solution you'd like to propose?

I don't think there is a solution -- Signal advertises itself as having a sort of security that isn't really possible with any commercially available device. You have to trust more people then just the person you're communicating with; if that's unacceptable then you need to give up a bunch of convenience and find another method of communicating.

Fortunately, the parties that you have to trust when you use signal haven't been malicious in any way, but that doesn't mean that they can't.

Re: Confer – End to end encrypted AI chat

#138

Earlier quoted context omitted.

Moxie Marlinspike sounds like some 90s intelligence guy’s understanding of what an appealing name to hacker groups would sound like. Put a guy like that as so-called creator of some encryption protocol for messaging and promote the app like it’s for secret conversations and you think people won’t be suspicious? It screams honeypot like nothing else.

So the argument against Signal is now "the creator's nickname sounds odd"? I mean, OK? Keep using WhatsApp, Telegram or Instagram if you think those are more private than Signal.

Does anyone actually think that’s his real name?

Re: Confer – End to end encrypted AI chat

#139

Earlier quoted context omitted.

So the argument against Signal is now "the creator's nickname sounds odd"? I mean, OK? Keep using WhatsApp, Telegram or Instagram if you think those are more private than Signal.

Does anyone actually think that’s his real name?

I'm sure some people who don't realise it's a pseudonym do? Sounds like you're one of them.

Re: Confer – End to end encrypted AI chat

#140

Earlier quoted context omitted.

Moxie Marlinspike sounds like some 90s intelligence guy’s understanding of what an appealing name to hacker groups would sound like. Put a guy like that as so-called creator of some encryption protocol for messaging and promote the app like it’s for secret conversations and you think people won’t be suspicious? It screams honeypot like nothing else.

So the argument against Signal is now "the creator's nickname sounds odd"? I mean, OK? Keep using WhatsApp, Telegram or Instagram if you think those are more private than Signal.

It's totally comments of people using Telegram.
Post reply on HN