Live data from Hacker News

Signal Foundation

signal.org

161–170 of 298 posts

Re: Signal Foundation

#161

Earlier quoted context omitted.

I find it odd that someone would say an iPhone is “very insecure” after the USG, of all players, very publicly couldn’t get into a model from right before the security design hardened , not to mention the also very public panic in the IC about losing access to intelligence due to mobile phone developments. That’s a strange position to tout with the underlying implication that PC platforms are better. Are you broadeni…

I thought that ended with the government getting into the phone using an exploit, just without forcing Apple's cooperation.

Only after they paid an Israeli security company for a 0-day vulnerability, which allegedly cost north of $1m.

Interested to know how that amount compares to other OSes, I really don't know what the going rate is on Windows/Linux.

Re: Signal Foundation

#162
post #128

Earlier quoted context omitted.

is it known how many of those 50 were devs?

"When WhatsApp was acquired by Facebook for $19 billion, the popular messaging app had about 35 engineers and 450 million users." http://www.businessinsider.com/facebook-f8-whatsapp-engineer...

35 still seems high to me

Re: Signal Foundation

#163
This is great news. Now maybe they'll have the resources to ditch your phone number as your identity. Traveling overseas is really frustrating when you get a new sim card and your Signal identity changes.

Re: Signal Foundation

#164

Maybe they can use their $50,000,000 to make it possible to sign up for their service without a phone number. The hype around Signal is insane to me considering this lack of basic functionality.

Also considering questions like "why does this app want all my contacts?" or "how do I know I can trust the implementation? or, critically, "how much does it even matter when the OS itself might be compromised?"

Re: Signal Foundation

#165
post #65

Pretty amazing and absolutely deserved. After the failures of systems like PGP, which aren't really suitable for the masses, the Signal protocol did a great job at spreading end-to-end encryption. I'm happy to hear that they got some philanthropic funding, even though I don't doubt that Moxie and the others did the work out of principle anyway and might have continued to do so even without the money.

IMO, saying PGP has failed is like saying cryptocurrencies have failed.

Considering the diversity of opinions on cryptocurrencies, this post leaves me with no idea what you think about PGP.

Re: Signal Foundation

#167

Earlier quoted context omitted.

And yet even the best of the best cryptographic protocols provide little to no value on very insecure systems like iphone and android. It's like bike shedding of security, where Moxi focuses on the things he can do but for the systems where it doesn't matter.

I find it odd that someone would say an iPhone is “very insecure” after the USG, of all players, very publicly couldn’t get into a model from right before the security design hardened , not to mention the also very public panic in the IC about losing access to intelligence due to mobile phone developments. That’s a strange position to tout with the underlying implication that PC platforms are better. Are you broadeni…

Very secure means high-assurance for both hardware and software, very insecure means no assurance for neither hardware, nor software, with control over system belonging to multiple third parties and what not, basically consumer stuff. And threat model for this consumer stuff just doesn't include an adversary capable of intercepting all of your communication and cracking less secure protocols, this is just silly. Because with such level of capabilities an adversary can just target a whole bunch of third parties that have control over your system, penetrate one of them and push a fake update to your system with screen grabbing malware or whatever. By the way, this is an example of a real world attack.

Re: Signal Foundation

#168

I'm hoping they can use some of this cash to make a better desktop client: 1. That can be minimized to the system tray. 2. That can be used when behind an http proxy server. 3. Doesn't require a phone to use. 4. Doesn't take 200MB ram to run.

You seem pretty passionate - wanna help us test proxy and system tray support?

Tray support behind command-line argument: https://github.com/signalapp/Signal-Desktop/pull/1676

Proxy support behind command-line argument: https://github.com/signalapp/Signal-Desktop/pull/1878

Re: Signal Foundation

#170
post #144
post #42

Earlier quoted context omitted.

Signal Protocol is one of the best documented cryptographic message protocols on the planet, and is accompanied by multiple GPL'd implementations. https://signal.org/docs/

Unfortunately, it looks like the signal people are possibly not friendly to third-party devs and have levied seemingly spurious IP threats against third-party implementations: https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 Obviously this is just one side of the story, but it sounds rather alarming.

I believed this was debunked by moxie somewhere on HN
Post reply on HN