Live data from Hacker News

Signal 2.0 released with private messaging support

whispersystems.org

91–100 of 174 posts

Re: Signal 2.0 released with private messaging support

#91
post #31
post #25

Earlier quoted context omitted.

I'm just astonished that there's even justification for it not being an option. Bang on about easy discovery all you want, there's lots of people who don't want to give out their phone number for no good reason to some strangers.

This is nowhere nearly as simple as "you just published your phone number to TextSecure": https://whispersystems.org/blog/contact-discovery/ It is a very real security issue, too. What Matt Blaze is talking about with "extra namespaces" is a giant piece of attack surface TextSecure is avoiding.

We're getting back to the issue of 'usability' though.

My desktop has no phone number, my tablet has no phone number and .. I have multiple phones, which have different phone numbers. I would like to use a single IM account (hey, like with mail. Or xmpp).

TextSecure doesn't allow that. TextSecure is not usable in these scenarios. It's not about "Could TextSecure leak my number", it's more about "The current architecture of TextSecure makes no sense for these use cases and seems to be quite close to WhatsApp et al - even before their agreement".

A telephone number is not an identifier, it's not stable and it's not something you can expect as 'given'. This is a broken system. As 13, the thread starter, mentioned.

Re: Signal 2.0 released with private messaging support

#92
Maybe a stupid question

What good is open source, when the developer can still add a backdoor later and put the backdoored version on iOS store?

I still need to trust the developer.

(And Apple, too, but once I can't trust Apple I can no longer the OS itself and just throw the phone away)

Re: Signal 2.0 released with private messaging support

#93

Why is the iPhone app called Signal whereas the Android app is called RedPhone? (as an aside, I love the screenshots for RedPhone https://play.google.com/store/apps/details?id=org.thoughtcri... )

On Android, they first started with TextSecure years ago, then built the voice app, RedPhone. Signal is a rebranding that began with the first app on the iOS platform, which happened to be the voice app. However, Signal is intended to be a fully "integrated" app, that will include text, voice, photo/video attachments, and hopefully video-chatting eventually, too, to take on Skype. The Android version of Signal will p…

[deleted]

Re: Signal 2.0 released with private messaging support

#94
I was waiting for this, even donated some time ago. Went to install it but it requires iOS8 so my perfectly functioning iPhone 4 can't run it.

Is very hard to keep older iOS support?

Side rant: I hate Apple is leaving my hardware off the grid. It is well cared, like new, battery is ok, no reason to think about replacing other than iOS8, and that sucks.

Re: Signal 2.0 released with private messaging support

#95
post #51
post #37

What's the difference between this and Telegram? I'm starting to feel a bit overwhelmed with what messaging app I'm supposed to use. Also, why is ios8 required?

I'm a Signal/TextSecure contributor. There's been a lot of controversy over the Telegram encryption protocol, and any cryptographer that looks at it cringes. Beyond doubts with the protocol itself, I think the more important consideration is that most people never use it. Telegram is not encrypted by default. Users have to create a special "secret chat" with contacts that is ephemeral, and some Telegram clients don't…

Awesome, thanks for taking a moment to explain that for me!

Re: Signal 2.0 released with private messaging support

#96
post #92

Maybe a stupid question What good is open source, when the developer can still add a backdoor later and put the backdoored version on iOS store? I still need to trust the developer. (And Apple, too, but once I can't trust Apple I can no longer the OS itself and just throw the phone away)

I think the premise of that sort of thing is that in theory, you could build your own copy and install that, or at least check it against the pre-compiled version.

Re: Signal 2.0 released with private messaging support

#97
post #96
post #92

Maybe a stupid question What good is open source, when the developer can still add a backdoor later and put the backdoored version on iOS store? I still need to trust the developer. (And Apple, too, but once I can't trust Apple I can no longer the OS itself and just throw the phone away)

I think the premise of that sort of thing is that in theory, you could build your own copy and install that, or at least check it against the pre-compiled version.

Yes, but I cannot do that with Apple's iOS (well, I can, but I have to buy certificate for 99 dollars)

Re: Signal 2.0 released with private messaging support

#98
post #94

I was waiting for this, even donated some time ago. Went to install it but it requires iOS8 so my perfectly functioning iPhone 4 can't run it. Is very hard to keep older iOS support? Side rant: I hate Apple is leaving my hardware off the grid. It is well cared, like new, battery is ok, no reason to think about replacing other than iOS8, and that sucks.

They addressed it in this github issue: https://github.com/WhisperSystems/Signal-iOS/issues/614

I'm also disappointed in this. The people I most want to use this with are also the people who have an iphone4.

I don't get the impression it'd be impossible to backport it from that post, so some enterprising individual could maybe do just that...

Re: Signal 2.0 released with private messaging support

#99
post #31

Earlier quoted context omitted.

This is nowhere nearly as simple as "you just published your phone number to TextSecure": https://whispersystems.org/blog/contact-discovery/ It is a very real security issue, too. What Matt Blaze is talking about with "extra namespaces" is a giant piece of attack surface TextSecure is avoiding.

We're getting back to the issue of 'usability' though. My desktop has no phone number, my tablet has no phone number and .. I have multiple phones, which have different phone numbers. I would like to use a single IM account (hey, like with mail. Or xmpp). TextSecure doesn't allow that. TextSecure is not usable in these scenarios. It's not about "Could TextSecure leak my number", it's more about "The current architect…

It's not a "broken system". It's one that doesn't work for your particular use case. As Matt Blaze pointed out in his Twitter message and I did here: simplifying "identity" down a phone number sidesteps a complicated security problem that has created flaws in other applications and will continue to do so.

I'm sorry you can't use TextSecure right now; it's the only encrypted messaging system I actually like (though I think you can get by with OTR [but not group OTR!] and GPG). They have to start somewhere, though. And it's far better than they get a simple case right than an ambitious case wrong.

Re: Signal 2.0 released with private messaging support

#100
post #90
post #67

Can anyone explain what's the difference between using Signal and using WhatsApp (assuming TextSecure is the default protocol being used - is it?)?

Signal is open-source while WhatsApp is proprietary. WhatsApp also uses the 2-part ratcheting developed in Aoxotle my understanding is, but they are not mutually compatable on-the-wire transport.

Only the Android version of WhatsApp has encryption, as far as I can tell.

Also WhatsApp (i.e. Facebook) get the metadata still - who messaged who, and when.

Post reply on HN