> Signal Desktop is a Chrome app That surprises me. I don't trust Chrome for confidentiality; I assume it collects data for Google and I don't know that it protects my data from others. If Chrome isn't trustworthy for confidentiality, it would seem to fatally cripple the security of Signal Desktop. However, I believe the people at Whisper Systems would see that obvious flaw so I suspect that I'm misunderstanding some…
Can't you run it under Chromium then?
Signal Desktop
171–180 of 288 posts
Re: Signal Desktop
#172Earlier quoted context omitted.
That's a pretty big holiday wishlist. =) This is the world we live in: people do most of their communication on mobile devices running iOS or Android, use Chrome on the desktop, and expect contact discovery to be automatic in their social apps. The browser has won the desktop, iOS and Android have won mobile, and the velocity of the ecosystem is unlikely to make "distributed" communication mechanisms possible for som…
The problem of course being that those users that use the closed source Google browser and iOS won't care much about what Signal is offering either. They're already using Hangouts, iMessage and Signal is pretty much a downgrade from those.
Re: Signal Desktop
#173Earlier quoted context omitted.
If we ever meet I'll buy you a beer for the year of the Linux desktop line. But honestly: I understand mobile support for iOS/Android only. I don't understand Chrome as a platform (FF isn't dead. And the biggest reason for that is that I fail to understand why that client needs to be 'web based' and then again not. A web app in a silo) Mobile numbers.. Why? I mean, if 90% of the population WANT mum to see that they u…
Perhaps Signal just isn't for you. No one who I've introduced signal to has ever had a problem with it. Now if you add a randomly generated 128 bit account identifier, then people WILL have problems with it. Not with you, but with your mum/grandma. I really think Signal might not be for you. Signal is not about building the most secure or private system, it's about building the first mass-market encrypted that that's…
Making it a de facto requirement that users on your network be personally identified via a phone number ("get a burner number"? really?) and that you have a copy of their contact list and phone calls, all within US jurisdiction, means mass metadata surveillance a single judicial order away (as it is now with the telecoms).
Unlike POTS, Signal prevents phone taps, yes, but it does not hide your social network, and so does little to provide you with the ability to associate with someone anonymously.
Re: Signal Desktop
#174Earlier quoted context omitted.
Oh I see. That is indeed annoying. So I guess this bit from the desktop announcement is a stretch: "....all incoming and outgoing messages are displayed consistently on all your devices." I mean I guess if you ONLY have one phone and a desktop that would be true? And I guess if Signal only allows you to register those two things, it is TECHNICALLY true, in the sense that "all" <= 2
And all = Android + Chrome (at least for now). Since I'm not an Android user, I'm unable to confirm all > 2 scenarios. Someone should try and report back.
It's all very fast and working quite well.
Re: Signal Desktop
#175Earlier quoted context omitted.
Enh. Signal's UX is still not effortless. For example: * Does not make it clear it's a point to point mapping (on iOS) right now. I discovered this the hard way. * Unclear failure modes (see above). It's entirely possible to have messages be silently dropped. * Texting vs. call methods unclear. I.e. there's a phone icon but no text icon (select name instead). * Contacts list has some text only, some phone only, some…
I do have an "invite" prompt on my SMS contacts that don't yet have Signal: "Invite to Signal: Take your conversation with %s to the next level.". Perhaps it's a function in the beta version that isn't in the live version yet? I haven't seen a message with a double-tick that's been dropped yet , at least not on a recent version. It can sometimes behave poorly with Android battery-saving mode - however, so does plain…
Re: Signal Desktop
#176Earlier quoted context omitted.
For now! We're hiring, if you know anyone that wants to help us speed up iOS development: https://whispersystems.org/workworkwork/
Why tie it to a phone at all? Why not have this Chrome app work standalone? Apple's messaging app uses end-to-end encryption and it can be routed to multiple devices. I would expect Signal to strive to attain parity with Apple's offerings. Also, the naming of this app is pretty disingenuous. This app should be called "Signal Remote", since it's not running the actual Signal comms on my desktop, it's remotely controll…
Re: Signal Desktop
#177Earlier quoted context omitted.
last time I checked Google Analytics doesn't record anything like that kind of data.
It records where you click, and when. "Accidentally" logging keys is possible, as Google can modify the content of the JS on request – for example, in case of being served an NSL, Google can be forced to modify the JS to log that.
Re: Signal Desktop
#178Call it what it really is: "Signal Phone Remote". This is not Signal Desktop if you need a non-desktop to use it.
Re: Signal Desktop
#179I'm feeling dirty, because I don't like to be that negative, especially if we're talking open-source software. And I feel that I kinda hold this project to higher standards: If I compare this to WhatsApp/Telegram/Threema/Whatever, I inheritently, somewhat subconciously expect more from Signal. And I'm disappointed. I tend to repeat the 'central server' and 'a phone number is not an address and not public information,…
The central server in Signal does not have the same role as the Telegram's. If you care first and foremost about UX, use Telegram. If you care first and foremost about the security of your communications, use Signal; go out of your way to use Signal.
Re: Signal Desktop
#180Earlier quoted context omitted.
Is it? It is also what Edward Snowden said.
In fact, he may have even said it on Cryptocat; Poitras and Greenwald used it to collaborate with him. Snowden also used Lavabit to send email. Why? Because Lavabit had superior UX to his other options --- because Lavabit handled all the crypto serverside. NSA has presumably read everything he sent on both of those systems. Despite the extreme ease of use both systems boasted, they were both so badly designed that th…