Earlier quoted context omitted.
While this is true, they also, through TextSecure, support many android phones that are probably in much worse shape on that front. It's also not like web browsers refuse to use TLS because your computer's running a compromiseable version of Windows.
That analogy sure stopped and made me think. What a sticky issue. SHOULD browsers do that? What if your bank website refused to allow you to sign in from a machine running unpatched XP? I think right now there might not be enough exploits targeting banking on XP machines to justify that inconvenience, but it seems like a responsable argument could be made for both cases.
Signal 2.0 released with private messaging support
131–140 of 174 posts
Re: Signal 2.0 released with private messaging support
#132Question: how and where message is stored when my phone is off and somebody will send me a message? How it is encrypted and then decrypted on my device once turned on?
It will either be on the remote device, or os Signal's servers, depending on how the implementation works. Either way doesn't really matter; the whole point of encryption like this is to prevent third-party access to your communications. It could be stored at NSA central for all it matters, and you'd still be the only one able to read the message (using the keys on your device).
Re: Signal 2.0 released with private messaging support
#133Great app - but I fail to see how that's going to replace GnuPG.
Re: Signal 2.0 released with private messaging support
#134Earlier quoted context omitted.
Yeah, I'm aware of that, but doesn't that require a smartphone with TextSecure installed? I don't own a smartphone. (I accept that I'm a weirdo.)
No, just requires a phone number. It's still under development, but if you're curious you can check out install instructions here: https://github.com/WhisperSystems/TextSecure-Browser/blob/ma...
Re: Signal 2.0 released with private messaging support
#135Awesome. Is there a rough timeline for Signal on Android? What about the desktop version - will there still be one? (at least a Whatsapp Web/Pushbullet style "desktop app")
Signal for Android is already available, kinda... It's split into TextSecure for the messaging portion and RedPhone for the call portion[0]. [0] https://whispersystems.org/
Re: Signal 2.0 released with private messaging support
#136Re: Signal 2.0 released with private messaging support
#137Earlier quoted context omitted.
They addressed it in this github issue: https://github.com/WhisperSystems/Signal-iOS/issues/614 I'm also disappointed in this. The people I most want to use this with are also the people who have an iphone4. I don't get the impression it'd be impossible to backport it from that post, so some enterprising individual could maybe do just that...
I'm surprised they didn't mention how amazingly insecure it is to be running a phone that old. If you're running a private messenger like Signal, you might not want to install it on a device vulnerable to bootrom exploits that negate all the advantages of disk encryption.
For that scenario, it doesn't matter if you're also vulnerable to direct hacks. You can still help normalise encryption.
Re: Signal 2.0 released with private messaging support
#138I was waiting for this, even donated some time ago. Went to install it but it requires iOS8 so my perfectly functioning iPhone 4 can't run it. Is very hard to keep older iOS support? Side rant: I hate Apple is leaving my hardware off the grid. It is well cared, like new, battery is ok, no reason to think about replacing other than iOS8, and that sucks.
They addressed it in this github issue: https://github.com/WhisperSystems/Signal-iOS/issues/614 I'm also disappointed in this. The people I most want to use this with are also the people who have an iphone4. I don't get the impression it'd be impossible to backport it from that post, so some enterprising individual could maybe do just that...
Re: Signal 2.0 released with private messaging support
#139Presumably there are still multiple ways for messages to be intercepted from the user's iPhone: - Physical access or confiscation of the device - Possible backdoor in iOS or the physical iPhone hardware? - Compromise or physical access to a host machine where the user backs up their device. Although, I'm not sure what can be done to stop this.
[0] https://www.usenix.org/conference/usenixsecurity13/technical...