Live data from Hacker News

Confer – End to end encrypted AI chat

confer.to

141–150 of 180 posts

Re: Confer – End to end encrypted AI chat

#141
Collecting the email doesn't inspire much confidence. An account-number model like Mullvad's would seem preferable, or you could go all-in on syncable passkeys as the only user identifier.

The web app itself feels poorly made—almost vibe-coded in places: nonsensical gradients, UI elements rendering in flashes of white, and subtly off margins and padding.

The model itself is unknown, but speaks with the cadence reminiscent of GPT-4o.

I'm no expert, but calling this "end-to-end encrypted" is only accurate if one end is your client and the other is a very much interposable GPU (assuming vendor’s TEE actually works—something that, in light of tee.fail, feels rather optimistic).

Re: Confer – End to end encrypted AI chat

#142

Earlier quoted context omitted.

Exactly. These arguments are so weak that they read more like a smear campaign than an actual technical discussion. "You have to agree to Apple's terms to use it"? What's Signal meant to do, jailbreak your phone before installing itself on it?

Moxie Marlinspike sounds like some 90s intelligence guy’s understanding of what an appealing name to hacker groups would sound like. Put a guy like that as so-called creator of some encryption protocol for messaging and promote the app like it’s for secret conversations and you think people won’t be suspicious? It screams honeypot like nothing else.

He IS a hacker from the 90s. It’s an assumed name. Plenty of hackers from the 90s have pseudonyms.

> so-called creator of some encryption protocol

All evidence points to him being one of the protocol’s designers, along with Trevor Perrin.

I’ve met both of them. The first time I met Moxie and talked about axolotl (as it was called back then) was in 2014. Moxie and Trevor strike me as having more integrity and conviction than most. There is no doubt in my mind that they are real and genuine.

Interestingly enough, some of the work Trevor did related to Signal’s cryptography was later used by Jason Donenfeld in the design of WireGuard.

> It screams honeypot like nothing else.

As you can see there is plenty of evidence suggesting otherwise.

Re: Confer – End to end encrypted AI chat

#143

Earlier quoted context omitted.

It's not about the protocol but other sides of the design. Example: https://news.ycombinator.com/item?id=38555810

The example you linked is about push notifications in general, nothing specific to the Signal app. If the concern is that your OS is compromised or spying on you, that's not something E2E encryption can protect against, whether it's Signal or any other app.

> nothing specific to the Signal app

The specific part is that Signal forces Google and Apple on its users, and forces the specific kind of push notifications, too.

Re: Confer – End to end encrypted AI chat

#144

Earlier quoted context omitted.

This is what F-droid does (well, I suspect most apps don't have reproducable builds that would allow 3rd-party verification), but Signal does not want 3rd-party builds of their client anyhow.

They could still figure out a way to attest their builds against source.

This is much harder when Signal actively goes against that.

Re: Confer – End to end encrypted AI chat

#146
post #141

Collecting the email doesn't inspire much confidence. An account-number model like Mullvad's would seem preferable, or you could go all-in on syncable passkeys as the only user identifier. The web app itself feels poorly made—almost vibe-coded in places: nonsensical gradients, UI elements rendering in flashes of white, and subtly off margins and padding. The model itself is unknown, but speaks with the cadence remini…

> An account-number model like Mullvad's would seem preferable

Thank you! :)

> .. assuming vendor’s TEE actually works

For sure TEEs have a rich history of vulnerabilities and nuanced limitations in their threat models. As a concept however, it is really powerful, and implementers will likely get things more and more right.

As for GPUs, some of Nvidia’s hardware does support remote attestation.

https://docs.nvidia.com/attestation/index.html

Re: Confer – End to end encrypted AI chat

#147
post #120

It’s exciting to hear that Moxie and colleagues are working on something like this. They definitely have the skills to pull it off. Few in this world have done as much for privacy as the people who built Signal. Yes, it’s not perfect, but building security systems with good UX is hard. There are all sorts of tradeoffs and sacrifices one needs to make. For those interested in the underlying technology, they’re basical…

I don't know, I'd say Signal is perfect, as it maximizes "privacy times spread". A solution that's more private wouldn't be as widespread, and thus wouldn't benefit as many people. Signal's achievement is that it's very private while being extremely usable (it just works). Under that lens, I don't think it could be improved much.

It's not perfect simply because it's a mobile-first app. That's Signal's main problem.

Re: Confer – End to end encrypted AI chat

#148

Earlier quoted context omitted.

I don't know, I'd say Signal is perfect, as it maximizes "privacy times spread". A solution that's more private wouldn't be as widespread, and thus wouldn't benefit as many people. Signal's achievement is that it's very private while being extremely usable (it just works). Under that lens, I don't think it could be improved much.

It's not perfect simply because it's a mobile-first app. That's Signal's main problem.

Yeah, most people don't even have a phone, let alone use it as their main method of communication...

Re: Confer – End to end encrypted AI chat

#149

Earlier quoted context omitted.

So the argument against Signal is now "the creator's nickname sounds odd"? I mean, OK? Keep using WhatsApp, Telegram or Instagram if you think those are more private than Signal.

It's totally comments of people using Telegram.

It's just people having zero product sense, or an idea of what it means to target more than 0.01% of the market. The last comment said that Signal's problem is that it's mobile-first, which, how does someone even think that a messaging app should be anything other than mobile-first?

Re: Confer – End to end encrypted AI chat

#150
post #86

What he did with messaging... So he will centralize all of it with known broken SGX metadata protections, weak supply chain integrity, and a mandate everyone supply their phone numbers and agree to Apple or Google terms of service to use it?

The issue being there's not really a credible better option. Matrix is the next best, because they do avoid the tie-in to phone numbers and such, but their cryptographic design is not so great (or rather, makes more tradeoffs for usability and decentralisation), and it's a lot buggier and harder to use.

Full time matrix user and all my family and businesses use Matrix too. It works just fine, and with self hosting, I control the metadata on the servers I host for my orgs.

It actually is the least bad option available, and decentralization is always worth it even if development is slower and more complex as a consequence.

Post reply on HN