Live data from Hacker News

Et Tu, Signal?

stephendiehl.com

111–120 of 459 posts

Re: Et Tu, Signal?

#111

Earlier quoted context omitted.

Proper message sync is hardly possible with end-to-end encryption everyone so excited about (without fully understanding the implications of true secrecy). If you have e2ee and then sync messages via google drive (looking at you, Viber), you are kinda missing the point.

I remember that Skype, before it was bought and ruined by Microsoft, had P2P chat history sync that worked the following way: once two of your devices were online at the same time, they synchronized chat history among the two running instances flawlessly. It was super reliable and predictable. I am sure that Signal could implement the same peer-to-peer sync scheme with full end-to-end encryption without any secrecy c…

This is actually working very bad in most practical situations. The way to go is Telegrams way, where you store all data on the server and happily sync ut easily between devices. Just do it on your own server using xmpp. E2ee helps mostly against server owner, and you eliminate this risk by being your own server owner.

Re: Et Tu, Signal?

#112
post #82

Earlier quoted context omitted.

Try transferring from an iOS phone to Android. Try transferring messages to a new desktop (you can't). It's 2021, I don't want to be platform locked and none of the other popular messaging apps have that issue.

Last I checked (about a year ago I think) Whatsapp backups were platform-locked as well.

They are working on it https://9to5mac.com/2021/04/05/whatsapp-chat-history-migrati...

Re: Et Tu, Signal?

#113
post #20

I definitely agree with the article that it felt a bit like a betrayal. I've pushed some friends and family to use it over Telegram despite significant usability issue, and now I see that instead of implementing some IMO basic features like proper message sync and easy backup when you get a new phone, they prefer to implement a... micropayment system? Based on some niche altcoin which doesn't even exist on mainstream…

Proper message sync is hardly possible with end-to-end encryption everyone so excited about (without fully understanding the implications of true secrecy). If you have e2ee and then sync messages via google drive (looking at you, Viber), you are kinda missing the point.

e2ee is a technical term, not a social term. It only means that 2 devices exchange bytes and no third-party can read them. Nowhere is there any obligation that the 2 devices belong to different people: it is perfectly possible to exchange history between your laptop and your smartphone with e2ee.

Re: Et Tu, Signal?

#114
It could be nothing, but it seems like it should have been disclosed and the article author neatly avoided it. They're the CTO of something very financ-ey/crypto-ey oriented in the B2B payments space, although the site (adjoint.io) explains little. Going by their GitHub most of their work somehow relates to cryptography.

Re: Et Tu, Signal?

#115

I see Keybase mentioned a lot in this discussions (both in the linked article, and in HN comments). Does anyone have a good summary to read up on what happened with Keybase?

Using the HN search bar at the bottom of the page with keywords "stellar keybase" will return a bunch of different threads.[1][2][3]

[1] https://news.ycombinator.com/item?id=21758671

[2] https://news.ycombinator.com/item?id=19913496

[3] https://news.ycombinator.com/item?id=20919927

Re: Et Tu, Signal?

#116
post #61

I'm a little surprised that nobody is mentioning that any kind of blockchain payment system creates a permanent, public ledger. One US Attorney called Bitcoin's blockchain "prosecution futures" as it's only a matter of time before the sender/receiver addresses for transactions are correlated with unique individuals. This permanent, public record of a transaction between a Signal account and another user or a service…

MobileCoin uses a combination of two other private coins, Monero and Zcash. There are no addresses on the MobileCoins's blockchain to be correlated. Didn't it cross your mind that a private messenger would probably use a private cryptocurrency?

Re: Et Tu, Signal?

#117

This article mirrors my feelings toward this announcement well. I spent a significant amount of time trying out different messaging apps and convincing my friends and family to move over from Telegram and WhatsApp. I used my reputation and their trust in my expertise. The whole blockchain industry is just too mixed with scams that I feel comfortable to have my non-tech relatives dealing with it. It's enough that I ha…

What would you say are the cons of Telegram?

I've been highly impressed with the UX for quite some time, but have refrained from pushing it (and the likes) onto friends. My family and friends seems to have slowly drifted towards signal, and I haven't bothered affecting that, but if I would go from a pure UX, I'd suggest telegram. So, I'm genuinely curious to know others' thoughts on it. I have only limited knowledge, just vague recollections of Russian developers (?), which might or might not have distanced themselves from political pressure (?), as well as the app itself being somewhat open sourced (?), based on the same protocol as signal (?).

Re: Et Tu, Signal?

#118
post #53
post #33

I'm baffled how tech-savvy people like the author are surprised when a seemingly free product suddenly introduce ways to monetize its service. There is no free lunch or to put it in another way, if you're not paying for the product, you are the product.

I'm baffled how people assume this is monetization. Signal has been a nonprofit for years and has no money issues: https://signalfoundation.org . The organization has no formal ties to the alt-coin, although Moxie does. It doesn't monetize the Signal foundation. I'm very unhappy with this, but it's not a monetization scheme.

So, signal is all about privacy, but when they chose a cryptocurrency, they didn't chose based on privacy. If privacy was the point, why not choose Monero, a mainstream coin which already has a reputation for privacy? So, if privacy wasn't their main concern in choosing a cryptocurrency, it's perfectly reasonable to wonder what was their main concern. And given that MOB's only unique characteristic (as far as I can tell) is the deep pockets of their foundation (because they allegedly own ~85% of MOB tokens, worth Billions), it's not much of a stretch to assume that those deep pockets are the reason that MOB was selected.

For a crass comparison, let's say you've got a friend named Bob. Bob likes blondes. He loves 'em. He's always talking about how he loves the blondes and could never be with a brunette or a redhead. One day you bump into Bob, and he tells you that he has just married a bald chick, who just happens to be very wealthy. How strange, that this guy, who always harped on this one feature, suddenly made a decision that was not based on that feature at all! Clearly, some other feature was the driver of his decision. Now, that doesn't necessarily mean that Bob is a gold digger. But wouldn't you wonder?

Re: Et Tu, Signal?

#120
post #61

I'm a little surprised that nobody is mentioning that any kind of blockchain payment system creates a permanent, public ledger. One US Attorney called Bitcoin's blockchain "prosecution futures" as it's only a matter of time before the sender/receiver addresses for transactions are correlated with unique individuals. This permanent, public record of a transaction between a Signal account and another user or a service…

A very good point.

Signal's tying encrypted messages and phone numbers to a publicly available ledge of transactions?

Post reply on HN