Live data from Hacker News

We can do better than Signal

icyphox.sh

151–160 of 290 posts

Re: We can do better than Signal

#151

I feel like Signal is held to a ridiculously high bar when it comes to anything. Is it perfect? No. But come on now; I see other threads on HN where people are debating/bashing their use of Intel SGX, really? Assuming you trust the client builds (or use a verified build) and verify the public key, all of these arguments go out the window with the exception of exposing your phone number. This situation seems like a pr…

Messages arriving out of order when you switch devices and missed notifications isn't supposed to be a high bar for a messenger.

Telegram and WhatsApp get these things right, Signal is just lacking at the moment.

Re: We can do better than Signal

#152
post #68

As I wrote in https://news.ycombinator.com/item?id=25795575 - WhatsApp: Oh wait, SMS etc. is completely insecure - Signal: Oh wait, WhatsApp is structurally unable to be a force for privacy - Matrix: Oh wait, even benevolent centralization is an unnecessary risk It's not that worse is better, but the general public's imagination can only grow so fast. We need to coax people along. As such, I do think all 3 serve a pu…

Matrix is merely federated, right? Why is it unlikely that a situation like email or the Internet will emerge, where the network still ends up massively centralized because that's just more convenient ?

While e-mail usercount is not evenly distributed across many servers, the fact that it's open an interoperable gives you several things:

- you can use whatever client/server you want (or host your own)

- you can still communicate with your friends if they're on another server

- servers are run by separate entities in politically distinct regions

None of these things depend on there being a uniform spread of users across servers.

Re: We can do better than Signal

#153

I feel like Signal is held to a ridiculously high bar when it comes to anything. Is it perfect? No. But come on now; I see other threads on HN where people are debating/bashing their use of Intel SGX, really? Assuming you trust the client builds (or use a verified build) and verify the public key, all of these arguments go out the window with the exception of exposing your phone number. This situation seems like a pr…

Why is not wanting vendor lock-in a high bar? After dealing with Messenger, WhatsApp, Face time, etc all my life I'm tired of it.

It doesn't matter if the code is open source, I'm still going to be locked in when all my friends move to Signal.

Re: We can do better than Signal

#154
post #57

Earlier quoted context omitted.

I had a similar experience with Matrix/Element. I was using the desktop app to chat with a friend, and while we were able to get some end-to-end encryption working, it was a huge pain the butt, and if two software engineers struggled this much to get the damn thing working, there's no way in hell that I'm convincing my parents to use it. To me, we have to accept the incremental wins where we can get them; getting my…

Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…

> If anyone in the "I tried Matrix and it was awful" camp could give detailed feedback (either here, or on github.com/vector-im/element-{web,ios,android}/issues) then it would be genuinely useful for prioritising our work. At the moment the vast majority of negative feedback on HN has been "it sucked" without giving a hint of what actually went wrong.

Your two modes of suggested contact (HN, GitHub) ensure only a certain type of user will contact (both require tech skills and a login). If there really are UX issues, you might want to encourage different types of users to give feedback (and if the fear is that the feedback won't be detailed/useful, maybe a guided form can help).

Re: We can do better than Signal

#155

Earlier quoted context omitted.

Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…

> At the moment the vast majority of negative feedback on HN has been "it sucked" without giving a hint of what actually went wrong. That's the nature of the HN beast: getting all the "it sucked" comments without STR and/or use-case descriptions is certainly demoralizing (reading HN comments about your own work is not for the unprepared) but asking folks who've had a bad time with your product to spend more time, for…

I couldn’t emphasise this more. Stick to the YC mantra: always talk to users. Ask them what they want or have problems with, quantitatively (questionnaire style) and qualitatively (talk to them in person, real user testing).

Added a new feature? Don’t assume it’s well designed. Assume something is wrong with it and that it can and should be further optimised and sweat the details. Details matter.

Unless you sweat the details, users will notice.

Re: We can do better than Signal

#156

I disagree. A decentralized version of Signal might not be necessarily more reliable. What do you do when your Matrix home server is down? Will you still be able to log in? Receive messages? Is this overall system more stable if only 90% of the network work all the time? Apart from that, most non-technical users won't care about it, and a decentralized solution might not be as convenient for them. It also might open…

I'd argue that vendor lock-in is a far more important issue.

You're right that non-technical people won't care about why decentralization matters. It's up to technical people to nudge the boat in the right direction.

That's why it's so disappointing to see HN embrace another silo.

Re: We can do better than Signal

#157

As I wrote in https://news.ycombinator.com/item?id=25795575 - WhatsApp: Oh wait, SMS etc. is completely insecure - Signal: Oh wait, WhatsApp is structurally unable to be a force for privacy - Matrix: Oh wait, even benevolent centralization is an unnecessary risk It's not that worse is better, but the general public's imagination can only grow so fast. We need to coax people along. As such, I do think all 3 serve a pu…

This is the worst thing about Matrix fans gloating over the outage: do you really think the outage helps Matrix become widespread? No, it will make people think twice before potentially taking that next step. And rightly so, because the same problem can happen in Matrix as well. A sudden surge in popularity can make matrix.org go down, and federation or not, that's not going to be a good look.

But alas, growing pains are part of the game. Let's hope they're not fatal for either.

Re: We can do better than Signal

#158
post #57

Earlier quoted context omitted.

I had a similar experience with Matrix/Element. I was using the desktop app to chat with a friend, and while we were able to get some end-to-end encryption working, it was a huge pain the butt, and if two software engineers struggled this much to get the damn thing working, there's no way in hell that I'm convincing my parents to use it. To me, we have to accept the incremental wins where we can get them; getting my…

Speaking as project lead for Matrix (and Element), I'm trying to understand the mixed feedback we've had this week, and somehow channel all the negativity into improving things. While some folks are clearly using it successfully and seem to like it, another bunch of people say "it was a huge pain in the butt to get E2EE working, and if it two software engineers struggled this much..." etc. When did this E2EE failure…

I have used Element on n off. The UX around encryption and passphrase still needs some work. I cant imagine moving my family and less tech oriented friends on it.

I logged on to it yesterday and got a prompt to enter the passphrase. I have it all in bitwarden, so easy to get around but for the average joe that would be the end of the journey. Even the verify session, when in fact Ive verified them in the past.

Minor thing, I echo the sentiment to get some average joes and non-tech oriented using the product and get some feedback.

Re: We can do better than Signal

#159
post #68

As I wrote in https://news.ycombinator.com/item?id=25795575 - WhatsApp: Oh wait, SMS etc. is completely insecure - Signal: Oh wait, WhatsApp is structurally unable to be a force for privacy - Matrix: Oh wait, even benevolent centralization is an unnecessary risk It's not that worse is better, but the general public's imagination can only grow so fast. We need to coax people along. As such, I do think all 3 serve a pu…

Matrix is merely federated, right? Why is it unlikely that a situation like email or the Internet will emerge, where the network still ends up massively centralized because that's just more convenient ?

As I recently said in another thread, an email sort of scenario is exactly what I'd like, or at least it would be many times better than what we currently have for im systems. The most important thing to me (and I suspect many other people in favor of decentralization/federation) is the ability to host my own service. I couldn't care less if 90% of email users are on gmail as long as I can run own email server or pay someone else to run one for me while still communicating with everyone.

I'm sure some people would disagree with my priorities above but for my experience as a user, that is what makes the most difference to me - not being boxed into what someone else thinks my client should look/act like or being locked into their server. Naturally I think more decentralization is better, but that's more a philosophical preference whereas wanting to run my own server or pick my own client is more about usability and control.

Re: We can do better than Signal

#160
post #42

Earlier quoted context omitted.

How do you prevent bots giving each other reputation?

By punishing their connections when they misbehave. Or at least, that's how you make it not matter. If spam-bot hands out reputation to spim-bot and then you get a bunch of garbage from spim-bot, derate everything coming from anyone that has given either of them reputation (and perhaps ignore their attestations also).

Now what happens when spam is done through a compromised user, or when the user acts human and has real interactions before spamming?
Post reply on HN