Live data from Hacker News

Session is shutting down in 90 days

getsession.org

121–130 of 196 posts

Re: Session is shutting down in 90 days

#121
post #48
post #29

Earlier quoted context omitted.

Signal's code quality is not conducive to security. They had an extremely bad state management bug that resulted in photos being sent to random contacts in your list (potentially life ruining implications if you're sending private photos). For this reason, it's hard to trust them. The encryption quality is irrelevant if the slop coded client is blasting random photos to random contacts.

Source?

It would've taken you less time to Google, but sure: https://www.bleepingcomputer.com/news/security/signal-fixes-...

Send a GIF to Contact A, Contact B receives random private images? Absolutely inexcusable slop code project. This class of state management bugs should not be possible with a well-architected client, period.

Signal's E2E encryption is more like End 2 Random End.

Re: Session is shutting down in 90 days

#123
post #14

I feel like a crazy person for having to write this, but: if you are starting a business (yes, non-profits are businesses), then you need to have a business plan. If you launch a business and you have not done the work to have a business plan, then in 99.999% of situations, your business will fail. A business plan includes market & competitive research, a revenue plan based on that research that includes realistic pr…

https://cdn.sanity.io/files/btop3zhg/production/6cdd8502a5fd...

Closest thing I could find poking around.

Here is an example of one of their core growth plan items from the strategy above:

"Social Media Campaigns, Organic and Paid Driving key messages around digital hygiene, decentralisation, and security on social media platforms to raise awareness."

The whole pdf is basically a collection of the remedial "go-to" SaaS growth blog posts everyone thinking about startups read: make content, build a community, turn your community into advocates, write about things people care about etc etc.

Given I've done this stuff for some 20+ years now, here is what is missing and frankly what most folks miss/don't want to admit:

This document basically has no ICP, who is the ideal customer? What is their persona? Who specifically are they, like, super specifically! You can't start with "oh anyone who wants anon-privacy first msg'ing!" That would have been like me at digitalocean saying "oh it's for anyone who needs a VM" - you can't execute a series of steps with that, you can't boil the ocean so to speak, we had to work through communities one at a time, we did: rails, node, php, devops/config management, in that order, split up over quarters and years, maybe it looked like we just...did developers, but we didn't, we slowly worked our way through all the developer communities slightly tailoring towards them while keeping things general enough.

The biggest problem here tho is the classic vitamin vs. aspirin problem. They're selling "better privacy" and "decentralization" - these are vitamins for the vast majority of people - they're things people say they care about in surveys but don't actually switch apps for. The 85% of adults who "want to do more to protect their privacy" aren't switching off WhatsApp. Are they the most secure messenger, or are they a token ecosystem with staking? Those attract fundamentally different people with different motivations...so just bolting them together creates confusion.

Folks need to stop thinking "we're going to do marketing" = "we're going to build a business" marketing, go to market, growth.. these are tiny components of overall business strategy.

Re: Session is shutting down in 90 days

#124

That’s not really a big deal since the session encryption was insecure anyway. It feels almost like a honeypot after they've removed forward secrecy. If you’re looking for a decentralized alternative SimpleX Chat is a more secure option.

Or the mature and robust XMPP + OMEMO.

The problem with XMPP is that most clients use an outdated and insecure implementation of OMEMO. This includes popular clients such as Conversations and Gajim. Currently only Profanity and Kaidan use the latest version and you must always assume that the encryption has been secretly downgraded because the other person is using an insecure client. I highly recommend Soatek's blog post on this topic. https://soatok.blog/2024/08/04/against-xmppomemo/

Re: Session is shutting down in 90 days

#125
It's sad but I'll forever remember them for having the best tagline ever on their frontpage:

    "Send messages, not metadata"
We all know who this is directed at: the project(s) pretending to offer privacy but that need to collect your cellphone and that'll happily be able to know who you exchanges messages with.

Project(s) whom, moreover, have often weird shills that, if you squint your eyes just a little bit, suddenly look like xxxINT moles.

So if only for that tagline, thanks a huge lot: metadata are more important than the content of the messages themselves and you have no privacy if your phone number and contacts are known.

Re: Session is shutting down in 90 days

#126
post #74

Session was Australian based which means they would have to do all sorts of horrible things when asked by the government, such as even letting police impersonate users... I just checked and they claim to have moved their infra to Switzerland. There are many other issues, some I've forgotten about since I would never trust it in the first place. They also require a phone number even! Seeing them go, I feel neutral. It…

> They also require a phone number even!

No? Where did you get this from? I have used the app and was never asked anything. I was given an id I could share with others and that's it. Very simple. I wish more apps had this easy onboarding process.

Re: Session is shutting down in 90 days

#127
post #49

Earlier quoted context omitted.

Claude (or any other chatbot) can do it for 1/100th of the cost and faster than anyone. So $150k+ is overpriced.

this is true, Claude and other LLMs are highly skilled at producing secure code

Name checks out.

Re: Session is shutting down in 90 days

#129

My advice: If you want people to give you money so that you don’t have to shut down, and you’re writing a ten paragraph plea for donations, consider using one of those paragraphs to tell people what your thing is. If we knew what it was, we might want to help.

It's in the footer but yeah
Post reply on HN