Live data from Hacker News

Signal Foundation

signal.org

171–180 of 298 posts

Re: Signal Foundation

#171
post #83

Earlier quoted context omitted.

And Moxie disallows people from building third-party clients for the server where 99% of Signal users are on, and without that, group chats aren’t useful.

Since when? You by default use the main servers when you install Noise or signal-cli, despite how Moxie may dislike this fracturing of the Signal client ecosystem.

Moxie still disallows their use of his servers, they just disregard his demands.

Re: Signal Foundation

#172
post #144
post #42

Earlier quoted context omitted.

Signal Protocol is one of the best documented cryptographic message protocols on the planet, and is accompanied by multiple GPL'd implementations. https://signal.org/docs/

Unfortunately, it looks like the signal people are possibly not friendly to third-party devs and have levied seemingly spurious IP threats against third-party implementations: https://medium.com/@wireapp/axolotl-and-proteus-788519b186a7 Obviously this is just one side of the story, but it sounds rather alarming.

It’s just one side of the story, but after Moxies comments regarding LibreSignal, third-party clients, etc, it’s hard not to believe it.

Re: Signal Foundation

#173
post #23

Since you are in the US how do you keep the US government from interfering with your mission because Signal uses strong encryption? How do you address the EARs (Export Administration Regulations) and ITARs (International Traffic in Arms Regulations)? These regulations look like a tar pit to me.

Why do you think strong encryption will have an export problem now when it hasn't for decades? Keep in mind that Signal is already open source and the algorithm is already widely distributed. Any restriction on export at this time would be closing the barn doors after the horses have all escaped.

If it's illegal and in a surveillance state, they can selectively prosecute or just coerce people any time they want. I tried to dig into the export regulations one night at this link:

https://www.schneier.com/blog/archives/2014/11/the_return_of...

My research suggested they did not change the status of encryption products in general: it was a narrow set of them like mass-market, downloadable stuff that got that designation. They kept high-assurance security, tools for building secure systems, customized secure software, and so on classified as munitions needing a license.

What I can't tell you is anything about that process since I never asked for an export license for any software. Maybe it's easy as some people told me with no restrictions. They weren't doing high-security stuff that irritates surveillance states, though. There could be pressure on big companies or providers of strong stuff. There could be nothing for now but something down the road. It's kind of a black box for me from this vantage point except the parts where it straight-up says specific things have old classification.

I'm really curious what experiences any of you have had that made strong security products on hardened OS's you requested permission to export.

Re: Signal Foundation

#174
post #82

Earlier quoted context omitted.

Theoretically, but when you throw in things like build systems often not being deterministic, minor versions of dependencies changing, different OS or slightly different OS version with different libraries; there's a multitude of places to throw the final binary off by a few bytes or more and end up with a different checksum. Signal wants to distribute a binary with a checksum. Once the checksum is different all bets…

As if reproducible builds hadn't been done before. If Debian can get to building 80% of their packages reproducibly[1], the communities around Android can get there too. Luckily, it's being worked on.[2] Now the question is: (when) will this be supported by F-Droid? [1] Scroll down for a big graph https://wiki.debian.org/ReproducibleBuilds [2] https://github.com/signalapp/Signal-Android/wiki/Reproducibl...

F-Droid has supported reproducible builds for years: https://f-droid.org/en/docs/Reproducible_Builds/

The real question is, when will Signal finally support it?

Re: Signal Foundation

#175

Earlier quoted context omitted.

I'd love to use Signal, but in order for me to do so there's a lot that has to be added. - Real multi device support. I want my messages on all my devices, without having to have my phone on. - An iPad app. - A desktop app. I'd pay for a native one, without Electron. These things are basically table stakes for competing with Facebook Messenger, Telegram, and iMessage. If Signal's goal is to bring encryption to the ma…

> - A desktop app. I'd pay for a native one, without Electron. I'm working on a native app that supports Signal, Slack, Twitter etc. It's only 90 KB (!). https://eul.im *edit Signal support is coming in early March.

[deleted]

Re: Signal Foundation

#176
Kudos to Signal! I derive great inspiration from projects such as Signal but as an average developer I just don't know how to take that inspiration, make a plan and become good programmer.

Re: Signal Foundation

#177

Earlier quoted context omitted.

I've assimilated most friends and all family very easily by educating them about the why. Not to mention if you're a parent explicitly banning sharing of photos with relatives via social media. People accept any small inconvenience or lack of feature quickly. But at this point I'm not following on the "so behind" comment. Care to elaborate?

On top of the myriad of missing features that for example Telegram has, the UI/UX for Signal (at least on the iOS app) is far behind. The app feels laggy and slow in comparison to Telegram or Messages (only other apps I use). It has giant text bubbles with large padding which IMO looks terribly ugly. Also, Telegram now has dark mode which I find very useful. And as mentioned, as silly as gif support is, it's a nice f…

On Android... Slow and laggy: not in the least, maybe this is IOS specific. Giant text bubbles: again on Android this is not a problem. Dark mode: Signal has had this for well over a year at this point. GIF support on Android has been there for almost a year as well.

The downside to Telegram? I don't trust it - so even if any of the above we're true they're all subjective and in my mind not worth compromise.

Re: Signal Foundation

#178
post #135

Earlier quoted context omitted.

I've assimilated most friends and all family very easily by educating them about the why. Not to mention if you're a parent explicitly banning sharing of photos with relatives via social media. People accept any small inconvenience or lack of feature quickly. But at this point I'm not following on the "so behind" comment. Care to elaborate?

Their Android app at least is way too difficult to use. I tried it with my friend some time ago and we just couldn't figure out in a reasonable amount of time how to add each other etc. I consider both of us tech savvy and we have absolutely no trouble with other IM clients or more archaic stuff like IRC.

Difficult to use? I'm even more confused as there is literally nothing to do to "add" someone.

As I stated our entire family uses Signal across Android, IOS and desktop. That age range in our entire family group is 20s to 70s and I happen to be the only user who would be considered tech savvy.

Re: Signal Foundation

#179

Earlier quoted context omitted.

I'd love to use Signal, but in order for me to do so there's a lot that has to be added. - Real multi device support. I want my messages on all my devices, without having to have my phone on. - An iPad app. - A desktop app. I'd pay for a native one, without Electron. These things are basically table stakes for competing with Facebook Messenger, Telegram, and iMessage. If Signal's goal is to bring encryption to the ma…

> - A desktop app. I'd pay for a native one, without Electron. I'm working on a native app that supports Signal, Slack, Twitter etc. It's only 90 KB (!). https://eul.im *edit Signal support is coming in early March.

Although you claim Wireshark, etc. can be used to verify the lack of external communication, the fact of the matter is that it only verifies you aren't sending data to third-parties all the time. It does not mean that it won't do so occasionally, or that (say, if triggered via a message in an existing platform) it won't suddenly send your credentials to someone else and then erase its tracks, or do anything more sophisticated than the naive approach you illustrated. The reality is that open-source really is necessary to prove that nothing nefarious is going on, as unfortunate as that is. I hope you can open-source it in the future so that it enjoys full adoption.

Re: Signal Foundation

#180

I'm hoping they can use some of this cash to make a better desktop client: 1. That can be minimized to the system tray. 2. That can be used when behind an http proxy server. 3. Doesn't require a phone to use. 4. Doesn't take 200MB ram to run.

So, what are you using the 15,800 MB of RAM for?

Running 4 instances of IDEA, 2 Android emulators, gradle to build an app, and a browser?
Post reply on HN