Live data from Hacker News

Signal Desktop

whispersystems.org

181–190 of 288 posts

Re: Signal Desktop

#181
post #93

Earlier quoted context omitted.

Approximately zero is the number of software security experts that would agree with that assessment of Android's security versus that of iOS. There are a lot of totally fine reasons (shakes fist) that OWS would start with Android; they might all have Android phones, they might have ideological problems with app store review, it might have just been an easier platform to build for. But yours isn't one of the valid rea…

Huh? Apple and MS have a record of communicating in sharing data with US government - plus as companies providing closed source software they are likely to introduce backdoors ... also something you might have heard of since Snowden.

And the Android build shipped with your phone is provided by your telecom provider, which presumably cooperates with your favorite Three Letter Agency.

So, you flash the phone with your own build? Most phones on the market rely on proprietary drivers only available as binary blobs. Even if you find a phone that has all Free drivers, can you replace the bootloader with your own trusted binary? Even the bootloader isn't nearly as dangerous as the baseband processor, and I don't know of a single phone with a Free baseband OS.

Sorry, as much of a fan as FOSS as I am, with your threat model, every phone on the market is equally bad. This might change once we're able to eliminate baseband processors from smart phones, but even then I wouldn't hold my breath.

Re: Signal Desktop

#182
post #179
post #61

Earlier quoted context omitted.

The central server in Signal does not have the same role as the Telegram's. If you care first and foremost about UX, use Telegram. If you care first and foremost about the security of your communications, use Signal; go out of your way to use Signal.

What if you care about control over the system and not being tied to a single vendor?

Then you definitely don't want to be using Telegram.

Re: Signal Desktop

#183

Earlier quoted context omitted.

In fact, he may have even said it on Cryptocat; Poitras and Greenwald used it to collaborate with him. Snowden also used Lavabit to send email. Why? Because Lavabit had superior UX to his other options --- because Lavabit handled all the crypto serverside. NSA has presumably read everything he sent on both of those systems. Despite the extreme ease of use both systems boasted, they were both so badly designed that th…

So they used bad products because their UX was good. That seems to be grandparent's point?

Secure messaging products with good UX and bad security should wait to launch until they can have good security; the alternative puts people at risk, as it did to Snowden.

Re: Signal Desktop

#184
post #98

Earlier quoted context omitted.

I'm making an engineering point, and you're making a conspiracy-theoretic point.

Engineering and corporate behavior aren't really orthogonal topics, are they, when the actual engineering you want to inspect is unavailable (closed source) and you have to rely on observed behavior and trust? If Apple actually did have a history of, say, pushing customized "iOS update" binary blobs at USG targets that undermined all the security features they describe in their white papers and in their (other) marke…

Closed source it may be but what's stopping you from reverse assembly? After all even in 'open source' you still don't know what you run unless you built it yourself. And even then you have to trust your toolchain.

Re: Signal Desktop

#185

Earlier quoted context omitted.

Yes, because it happens on recent hardware (a 6s) and other messaging systems don't seem to have this issue at all under the same conditions. Most of the time it would work fine, but quite frequently messages would be sent (have left my device) but not appear on the receiving device for ages, so i can only assume that sometimes the infra couldn't keep up.

Is there no acknowledgement of received messages? That seems somewhat of an oversight over unreliable third-party transports.

Yes, there is.

Re: Signal Desktop

#186
post #104

>Don't leave your friends behind, invite them to signup with this unique link. The more friends that join, the further you will advance in line for the beta. That's annoying.

with "34 clicks and 0 signups" I'm not even in the top 10%

Of course no human ever had clicked my link, but I'm surprised how many clicks other people generate (given they don't cheat as well, hehe).

Re: Signal Desktop

#187
post #55

Earlier quoted context omitted.

What about using something like http://electron.atom.io instead. This would likely be the best of both worlds - native, but not browser-dependent.

I really wish this was an Electron / nw.js app instead of a Chrome plugin.

I've experimented with this and with a little tweaking it works fine under NW.js's alpha support for running Chrome Apps.

Re: Signal Desktop

#188
post #163

This isn't working for me, the code I'm supposed to scan won't show up, just Connecting.... (I installed from github)

EDIT: I apologise, I'm wrong. It appears github has been updated to remove this warning.

and as it pretty says on github, the github repo is confiugred to connect to the development server.

So yea, trying to jump the queue by installing the dev blob from github won't work.

Re: Signal Desktop

#189
I agree with some of the folks here. I have the utmost respect for Signal and Marlinspike but this seems like a weird direction for this to go in. A Chrome app? Tying it to the Chrome App Store? Requiring a Google email for the beta group? Just seems out of place for Signal.

Re: Signal Desktop

#190
post #93

Earlier quoted context omitted.

> I tend to repeat the 'central server' and 'a phone number is not an address and not public information, it certainly is no identity' criticism. Your phone number is not your identity in Signal. If you change SIM cards then your friends won't notice and the app works as before. Signal is based on asym encryption - your private key effectively encodes your identity in combination with your public key. > And only if t…

Approximately zero is the number of software security experts that would agree with that assessment of Android's security versus that of iOS. There are a lot of totally fine reasons (shakes fist) that OWS would start with Android; they might all have Android phones, they might have ideological problems with app store review, it might have just been an easier platform to build for. But yours isn't one of the valid rea…

Do you happen to have a reference to any kind of freely available technical publication (blog post, etc) that goes through some core points to reach this conclusion? I read many things around for years and I agree with the general statement, but I failed to find a recap that can be used to explain the core points of differences to people not familiar with the matter.
Post reply on HN