Live data from Hacker News

Et Tu, Signal?

stephendiehl.com

181–190 of 459 posts

Re: Et Tu, Signal?

#181
post #104
post #20

I definitely agree with the article that it felt a bit like a betrayal. I've pushed some friends and family to use it over Telegram despite significant usability issue, and now I see that instead of implementing some IMO basic features like proper message sync and easy backup when you get a new phone, they prefer to implement a... micropayment system? Based on some niche altcoin which doesn't even exist on mainstream…

Telegram is just so much more usable than Signal. The perceived advantage of Signal over Telegram is LITERALLY not having an option for a cloud-synced chat and ONLY having end to end encrypted chats. That's all. You give up of usability to get that advantage. Explain to your mom why she has to give up Telegram to get basically the same functionality as Telegram secret chats. Signals crypto is used by Facebook and was…

There are no known attacks against Telegram.

The problem is entirely that its cryptography was sketchy and just plain weird to begin with. It wasn't wrong, per se, but raised some eyebrows. And then some of the questionable choices were silently fixed removing the ability to MITM, etc, but with no real notice.

It's not FUD.

Re: Et Tu, Signal?

#182
post #104
post #20

I definitely agree with the article that it felt a bit like a betrayal. I've pushed some friends and family to use it over Telegram despite significant usability issue, and now I see that instead of implementing some IMO basic features like proper message sync and easy backup when you get a new phone, they prefer to implement a... micropayment system? Based on some niche altcoin which doesn't even exist on mainstream…

Telegram is just so much more usable than Signal. The perceived advantage of Signal over Telegram is LITERALLY not having an option for a cloud-synced chat and ONLY having end to end encrypted chats. That's all. You give up of usability to get that advantage. Explain to your mom why she has to give up Telegram to get basically the same functionality as Telegram secret chats. Signals crypto is used by Facebook and was…

[deleted]

Re: Et Tu, Signal?

#183
post #104
post #20

I definitely agree with the article that it felt a bit like a betrayal. I've pushed some friends and family to use it over Telegram despite significant usability issue, and now I see that instead of implementing some IMO basic features like proper message sync and easy backup when you get a new phone, they prefer to implement a... micropayment system? Based on some niche altcoin which doesn't even exist on mainstream…

Telegram is just so much more usable than Signal. The perceived advantage of Signal over Telegram is LITERALLY not having an option for a cloud-synced chat and ONLY having end to end encrypted chats. That's all. You give up of usability to get that advantage. Explain to your mom why she has to give up Telegram to get basically the same functionality as Telegram secret chats. Signals crypto is used by Facebook and was…

That's a big advantage, and a very important one. But definitely, that and the superior crypto is what keeps me on the app. Telegram is in a whole different level when it comes to usability and refinement.

>Signals crypto is used by Facebook and was sponsored by the US Govt

Funny that you're talking about FUD.

Re: Et Tu, Signal?

#184

Earlier quoted context omitted.

> I feel like Element works better as a competitor to Slack or IRC than as a competitor to Signal or Whatsapp. To me it's a competitor to Keybase. "I want to send my co-worker/client an API key that I don't want exposed to the public" is about the only use for Keybase I've had. I have like 5 contacts on there for this reason. Slack/IRC is much more usable for getting shit done, but not being E2E I wouldn't send anyth…

Yep yep, totally think that's reasonable. I know very little about the intricacies of cryptography, but part of me wonders if there's some way of doing a federated "key synchronization" service similar to keybase.

So Keybase is just a UI for PGP/GPG (well that was what it was before it became a Borg). The problem with GPG:

1. You need to keep your private key very private, which is incompatible with the idea that you might have several devices you normally use. GPG itself does not provide you with a mechanism to sync your private keys between devices because this is a super insecure thing to do without some serious work.

2. GPG requires that you and another person verify each others' public keys out of band. I need to meet you in a parking lot to validate your key fingerprint while you validate mine.

3. GPG's web of trust relies on attaching public keys to real world identities. You are asked to validate government documents when verifying public keys. That's incompatible with how a lot of us want to work. Note that this isn't a built-in requirement, but GPG itself provides no guidance on how to validate user123 on GitHub, just User Onetwothree Jr in real life.

4. GPG's UI is almost as arcane as tar :)

Keybase solved this by:

1. Providing a secure way to manage private keys across devices.

2. Outsourcing proof of identity to other providers. Its use case is validating the identity of user123 on GitHub, which happens to also work fairly well for CelebrityName on Twitter, or FriendName on Facebook.

3. See #2: social proof means you can attach that proof to any kind of identity.

4. GUI + nice TUI works better.

Where Keybase fell short was that a non-techie will not understand much about "social proof" and the only kind of social proof they have access to is limited to Twitter, Facebook, and Instagram.

Signal's solution to this was simpler: you have a QR code/set of numbers that represent your fingerprint right in the app. You show me yours, I'll show you mine. We get connected by phone number or email. That's it. If Signal was built on a federated platform it'd be perfect and nothing about it from what I understand prevents that.

Re: Et Tu, Signal?

#185

Earlier quoted context omitted.

> easy backup when you get a new phone I just recently got a new phone, and used the new feature to do this (uses wi-fi direct) and I have to say it seemed like it would be easy enough for non-techy users to use.

Yeah, but consider the use case where you lose your phone in an accident or someone steals it. You can recover your sim card, you know your recovery password. But you'll be SoL and you won't be able to recover the history of all of your group and individual chats. This sucks.

There's a backup function. Maybe they should add some cloud drive integration to that feature.

Re: Et Tu, Signal?

#186
post #33

I'm baffled how tech-savvy people like the author are surprised when a seemingly free product suddenly introduce ways to monetize its service. There is no free lunch or to put it in another way, if you're not paying for the product, you are the product.

Let me try to de-baffle you -- it is the shitcoin-oh-god-yet-another-ICO aspect, not the monetize-aspect which is causing friction. If Signal switched to a 'Lite' vs 'Pro' model, or other incremental features, or had more donation related nagging, I doubt it would raise the slightest bother. Many people switched from other messaging apps on princple, much of that signalled (pun intended) by actions of the founders. T…

Yup. Before WhatsApp was bought by facebook they just charged people. This was fine and seemed fair. Same with 'pro features' or such.

The crypto scheme however does not seem like a fair deal. It looks like monetizing through a backdoor under false pretenses. Exploiting the unsavvy rather than dealing in good faith.

This is especially bad as signal was 'the app we trust' for many of us.

Re: Et Tu, Signal?

#187
post #53

Earlier quoted context omitted.

I'm baffled how people assume this is monetization. Signal has been a nonprofit for years and has no money issues: https://signalfoundation.org . The organization has no formal ties to the alt-coin, although Moxie does. It doesn't monetize the Signal foundation. I'm very unhappy with this, but it's not a monetization scheme.

So, signal is all about privacy, but when they chose a cryptocurrency, they didn't chose based on privacy. If privacy was the point, why not choose Monero, a mainstream coin which already has a reputation for privacy? So, if privacy wasn't their main concern in choosing a cryptocurrency, it's perfectly reasonable to wonder what was their main concern. And given that MOB's only unique characteristic (as far as I can t…

What makes you think MobileCoin is not based on privacy? It uses tech from both Monero and Zcash, two privacy cryptocurrencies.

Re: Et Tu, Signal?

#188
post #18

Earlier quoted context omitted.

You can, it's just that having the cryptocurrency in the first place leaves a bad taste in some people's mouths.

don't lick your phone then, seriously, if you don't like a feature, do use it. Done.

The problem is that these features need to be worked on, they require attention and the implementation sends a (strong) message.

It's not just the fact that it exists that leaves the bad taste, it's the fact the decision was made, what that implies about the mentality/goals of the people making such a decision and that it will from that point on hog resources. And those aspects won't go away by not using it.

Re: Et Tu, Signal?

#189
We used to say if developers did not have the idea what to add to the application, they were adding ability to chose skins.

Nowadays it seems adding cryptocurrencies took place of fancy skins management.

Re: Et Tu, Signal?

#190
Super sad. I played a major part in getting a lot of people I know onto Signal and felt vindicated by the masses switching recently, and now this.

So how do I adjust my filter for who I trust now? Are all American organisations corrupt, not just big tech? Why would I ever support any app again if even Signal is corrupt?

Post reply on HN