Live data from Hacker News

Signal 2.0 released with private messaging support

whispersystems.org

21–30 of 174 posts

Re: Signal 2.0 released with private messaging support

#21
post #18
post #2

Still asks for a phone number. Useless.

You want to read this conversation between Matt Blaze and The Grugq before making your mind up on that: https://twitter.com/thegrugq/status/572472282028744704

I agree with 13.

There needs to be a way to have an account that is not tied to a SIM card or any kind of phone number.

I'm frankly astonished there's even a debate about that.

Re: Signal 2.0 released with private messaging support

#22
post #5

Awesome. Is there a rough timeline for Signal on Android? What about the desktop version - will there still be one? (at least a Whatsapp Web/Pushbullet style "desktop app")

For desktop- https://github.com/WhisperSystems/TextSecure-Browser

For those who might clone, build, and use without actually reading the readme, take note of this warning by the project maintainers:

"warning: This project is still in the prototype phase. It contains many bugs and lacks many features."

Re: Signal 2.0 released with private messaging support

#23
post #4

One question I always have with secure systems distributed by app stores, even the open source ones, is how to you verify the source you're reading is the app you're using?

Google Play Store requires the developer to sign the program with their private key, and only the developer can provide future versions of the program. Moxie from whisper systems seems to trust this system (decentralized signing of binaries) more than the f-droid one (centralized signing of binaries). There is a very interesting discussion about this on the TextSecure issue queue: https://github.com/WhisperSystems/Te…

If I understand correctly, the iPhone only cares that the chain of trust for an app key is validated up to their CA.

In other words, if the bad guys with guns coerce Apple to mint them a cert, they could simply replace your known good binary with a crocked one signed with the new key, and your phone will happily run it. Getting that binary onto your phone is an exercise left to the reader, but there are many means, legal and otherwise, that could be employed to make that happen.

If your privacy means your life is on the line, you probably shouldn't be running stock Android or iOS. (And depending on how you feel about basebands, any modern smartphone, period.)

Re: Signal 2.0 released with private messaging support

#24
post #4

One question I always have with secure systems distributed by app stores, even the open source ones, is how to you verify the source you're reading is the app you're using?

Is there no option in the store for developers to "sign" the apps in some way and for phones to detect when the app doesn't use the developer's signature?

If such a feature doesn't exist in the app stores, it should.

Re: Signal 2.0 released with private messaging support

#25
post #21
post #18

Earlier quoted context omitted.

You want to read this conversation between Matt Blaze and The Grugq before making your mind up on that: https://twitter.com/thegrugq/status/572472282028744704

I agree with 13. There needs to be a way to have an account that is not tied to a SIM card or any kind of phone number. I'm frankly astonished there's even a debate about that.

I'm just astonished that there's even justification for it not being an option. Bang on about easy discovery all you want, there's lots of people who don't want to give out their phone number for no good reason to some strangers.

Re: Signal 2.0 released with private messaging support

#26

Earlier quoted context omitted.

Google Play Store requires the developer to sign the program with their private key, and only the developer can provide future versions of the program. Moxie from whisper systems seems to trust this system (decentralized signing of binaries) more than the f-droid one (centralized signing of binaries). There is a very interesting discussion about this on the TextSecure issue queue: https://github.com/WhisperSystems/Te…

If I understand correctly, the iPhone only cares that the chain of trust for an app key is validated up to their CA. In other words, if the bad guys with guns coerce Apple to mint them a cert, they could simply replace your known good binary with a crocked one signed with the new key, and your phone will happily run it. Getting that binary onto your phone is an exercise left to the reader, but there are many means, l…

I submitted this the other day:

http://www.oss.net/dynamaster/file_archive/100102/0a947a77d7...

In one part, it says:

The greatest material curse to the profession, despite all its advantages, is undoubtably the telephone. It is a constant source of temptation to slackness. And even if you do not use it carelessly yourself, the other fellow, very often will, so in any case, warn him. Always act on the principle that every conversation is listened to, that a call may always give the enemy a line. Naturally, always unplug during confidential conversations. Even better is it to have no phone in your room, or else have it in a box or cupboard.

That's talking about the plane old telephone in the 1960s.

The message I get from it? If your life is on the line, consider not using any electronic communication at all.

Re: Signal 2.0 released with private messaging support

#28

How is it working out? Is the messaging solid between Android and iOS? How is the group messaging working? Sorry, I just downloaded it, but I have no friends on the list yet. I'm impatient. I really want it to work.

same here. also, what is the blue button for?

Re: Signal 2.0 released with private messaging support

#29
post #9
post #7

I see it's open source, but is there a good third-party security evaluation of this anywhere?

Ha — found one: > You need to have Signal on your iPhone. Full stop. https://twitter.com/tqbf/status/572469319554088960

That's an endorsement, not security evaluation. Not exactly the same thing.

Re: Signal 2.0 released with private messaging support

#30
post #25
post #21

Earlier quoted context omitted.

I agree with 13. There needs to be a way to have an account that is not tied to a SIM card or any kind of phone number. I'm frankly astonished there's even a debate about that.

I'm just astonished that there's even justification for it not being an option. Bang on about easy discovery all you want, there's lots of people who don't want to give out their phone number for no good reason to some strangers.

Get a Google Voice number (Free. Use throw away account) and use that. There are instructions out there on how to connect a Google Voice number to Signal.
Post reply on HN