Live data from Hacker News

Encrypted messengers: Riot, not Signal, is the future

titus-stahl.de

1–10 of 178 posts

Re: Encrypted messengers: Riot, not Signal, is the future

#5
> If OpenWhisperSystems adopts any policy that goes against users’ interests in the future, users cannot switch providers without losing all their contacts.

Is this correct? I've never bothered looking it up, but Signal was connecting me with people in my phone's address-book.

Re: Encrypted messengers: Riot, not Signal, is the future

#6

I have the impression that Signal by now has such a great brand name that mere technical objections won't affect its growth for a very long time.

I wonder if the name of Riot will be a hindrance for widespread adoption. Most people don't like riots.

Re: Encrypted messengers: Riot, not Signal, is the future

#7
post #6

I have the impression that Signal by now has such a great brand name that mere technical objections won't affect its growth for a very long time.

I wonder if the name of Riot will be a hindrance for widespread adoption. Most people don't like riots.

You might have a point there. "Signal" feels much smoother than "Riot".

Re: Encrypted messengers: Riot, not Signal, is the future

#8
post #2

Are there any plans to do a security audit on Riot? The useful report by NCC [1] looks at libolm (which implements the end-to-end encryption) but of course that's only part of the whole product. [1] https://matrix.org/blog/2016/11/21/matrixs-olm-end-to-end-en...

Note that that report explains that the Double Ratchet E2E algorithm is used in Matrix, in large part because of the Open Whisper Systems implementation in Signal and subsequent licensing. So we're looking at an apples-to-apples comparison, at least with respect to this one piece.

Re: Encrypted messengers: Riot, not Signal, is the future

#9
This topic has been beaten to death on HN over the last year (other people can provide links to discussions, with Moxie participating).

I think something worth keeping in mind is that almost everyone who works in secure messaging agrees on one thing: that electronic mail is not the future of secure communication.

There's no fundamental reason why that should be the case. The store-and-forward model used by SMTP could be made to work for asynchronous secure group messaging. You can get forward and future security with it. It can interoperate with existing email addresses. All of that can be made to work.

But it is the case. Email won't be a secure group communication system. The reason for that is that email is federated and thus permanently mired in the lowest common denominator of mainstream email clients.

I think reasonable people can disagree about whether it's tractable to create a federated secure group messaging system with what we know right now. But I do not think it's reasonable to suggest that the concern (federation = lowest common denominator security) is invalid. And that's what this piece does.

Re: Encrypted messengers: Riot, not Signal, is the future

#10
A question I've had about Signal is what is stopping Apple from modifying and rebuilding the source with a backdoor in it? Is this technically possible (seems like it would be since they control distribution of the binary to devices)? The article is correct in stating that web based chat is inherently insecure but it seems all iOS apps are also inherently insecure. I'm by no means an expert though so would love to hear from someone with more knowledge.

EDIT: Thank you for the responses! It pretty much confirms what I thought; Apple _could_ access your communication (either through keylogging at the OS level or backdooring Signal) but this solution is better than everyone use plain text communication. I personally would not trust Apple with my life if I needed that level of protection but maybe that's not the main use case for Signal.

Post reply on HN