Earlier quoted context omitted.
Can't you use a phone-only google account which you otherwise don't use for anything else? I haven't used Android, but would you be able to use your real email account in K9, while using a dummy account for the device itself?
> Can't you use a phone-only google account which you otherwise don't use for anything else? Yes, good point! > I haven't used Android, but would you be able to use your real email account in K9, while using a dummy account for the device itself? The problem is that would prevent me from utilizing my android's contact list when emailing. When someone texts me, I like to easily click the name and then click on that co…
Facebook Messenger begins testing end-to-end encryption using Signal Protocol
191–200 of 312 posts
Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol
#192Earlier quoted context omitted.
Can you elaborate on the "anti-federation" stance of Signal's creator? I'm not familiar with this.
You can't run your own signal server. All accounts use phone numbers in the same namespace as ID, and all messages go from the phone to opensystems.org, further on to google, and from google to the destination phone (with lots of encryption being added and removed at various points). This has advantages (it's difficult for the Man distinguish a received signal message from other android notifications) but also disadv…
What you won't be able to do is federate with the official servers.
Oh, and there's also a WebSocket transport (used by the Desktop client) that doesn't involve Google. That just doesn't provide a pleasant experience on mobile.
Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol
#193Earlier quoted context omitted.
> The same reason Gmail can't work with end-to-end encryption--they want to advertise at you based on message content. I wonder how they'd do if they were more open about it. "You're getting Gmail for free because we read your email and advertise to you. However, if you want to pay for a premium account (or Google Apps for Work) then we won't advertise to you, won't read your email and we'll even make end-to-end encr…
It would be a (financially) bad choice for corpo. And answer why, is the same in many similar questions 'why can't corpo do this-and-that'. Here it is (google as an example only, simplified) the answer: * Put two googles side by side. competing. * one is a current one, earning money from ads on you being product, and keeping it under the radar (although in fine print etc etc) * second is the one devised: premium acco…
Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol
#194Earlier quoted context omitted.
I honestly find this centralization as worrying as mass surveillance itself. I'm as afraid of the Facebooks of this world as I am of any government, and I don't want all my communication locked in with one company. This is why I will not use or recommend Signal. Moxie's anti-federation stance is unacceptable to me. It's replacing one problem with another.
Can you elaborate on the "anti-federation" stance of Signal's creator? I'm not familiar with this.
Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol
#195Cute.
Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol
#196Earlier quoted context omitted.
The wording "we read your email" isn't quite accurate. There is nobody at google who goes through davb's emails one by one.
But they can. I doubt they do, because it's just not practical, but they do have the ability to
Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol
#197Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol
#198Is this some sort of elborate trolling? Can an exact match for a FB-provided binary be recreated from the open source code? If it's a No, then it's back to trusting FB to do the right thing and it doesn't make a slightest difference what exact protocol it's running or if the source was peer-reviewed behind closed doors.
As moxie has stated elsehwere in the comments here, they have confirmed that Messenger is using their open-source libs and I am sure that other people will do a bit of disassembly on the on-device binaries to confirm this fact.
Facebook may have an offshore account set up for moxie, they may simply be showing alternative source, they may have a rigged build system that builds from the patched source, etc. Seeing the source is the first necessary step to establishing any sort of real trust in a compiled binary.
You are also gravely mistaken in thinking that other people will take apart the binaries. It took several years for someone to try and verify a TrueCrypt build, which has a far more technical and privacy-minded following than the Facebook app. And even if some altruistic soul will do a binary audit of Messenger, it's all for naught as it's not a sustainable process. Every build needs to be verifiable and the source needs to be routinely peer reviewed for the binaries to be trustworthy. Doubly so in the Facebook's case given the very nature of their business.
Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol
#199Earlier quoted context omitted.
>but please feel free to continue risking other people's lives for the sake of feeling smug in your ignorant dismissal of this effort OK, I'll bite. How does this commenter's opinion (which is, to be clear, that the feature does not make him/her happy) risk the actual lives of other conscious, living humans?
I replied above, but there are few communication tools with such a wide userbase that have forward-secrecy and similar strong E2E crypto built in and available. People die because of what they post to Facebook or what they send in Messenger, I know this for a fact. With E2E security locked to devices it means that in the few seconds it takes me to wipe my phone while someone is knocking on the door with a gun then th…
I'll admit, too, that my reaction to your statements is colored by my other comment in this thread, which consists of being shirty about a dude who pontificated about PGP being unnecessary because of FB's new feature, which of course is ridiculous. Lives wouldn't be being lost, I reasoned, because only the foolhardy and unprepared dissident uses a surveillance network to organize dissent.
Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol
#200Earlier quoted context omitted.
"Walled garden" is more appropriate than "digital prison". No one is being sentenced involuntarily to these enclosures, they are voluntarily choosing to accept them because of what is inside them.
"Cult compound" is probably how I would describe it. Sure, you can leave, but there is immense social pressure to continue in what has become the norm, despite there clearly being something not okay with what is going on. And good luck convincing others to leave when you do.