Live data from Hacker News

Signal Server code on GitHub is up to date again

github.com

201–206 of 206 posts

Re: Signal Server code on GitHub is up to date again

#201
post #193
post #187

Earlier quoted context omitted.

> I don't think a piece on gnu.org qualifies as "plenty of writing" There are some links there to other pieces if you want to read more about it. > for sure doesn't count as basis for what you are entitled for I'm not claiming that moral authority flows from the Gnu brand; rather, they provide some information and reasoning which people can use to come to their own conclusions.

Most if not all of the links point to themselves.. It's ok to think that in an ideal world it would be like that, but argumenting as if you were entitled to the source because of it doesn't seem that it will persuade others. After all, if you aren't empathetic to the reality, how would you expect others be empathetic to you?

The reality is pretty diverse. Plenty of people use mostly or only free software. I certainly do.

Re: Signal Server code on GitHub is up to date again

#202
post #124
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

Signal Foundation has legitimate self-serving strategic reasons to prefer such secrecy, sure. But users also have legitimate reasons to want more transparency into both source-code & strategy. Whether such secrecy best serves the users & the cause of private messaging is an open question.

Exactly!

It isn't about cryptocurrency at all. It's about trust.

The relationship between mobilecoin and signal isn't even clear as far as I can tell. You're just asked to look at an obvious cash grab and be willing to accept it as normal operating procedure, and then expected to trust your most private communications to the same individuals that won't reveal their true intentions.

Re: Signal Server code on GitHub is up to date again

#203
post #191

Earlier quoted context omitted.

> - Whether or not Signal's server is open source has nothing to do with security. [...] having the server code open source adds absolutely nothing to this security model, [...] The security rests only upon the open source client code. The server is completely orthogonal to security. The issue a lot of people have with Signal is that your definition here of where security comes from is an extremely narrow & technical…

You're redefining the word "security" here to an incredibly expansive definition which includes all kinds of details about the ability for someone else to set up an interoperable service.

Yup. Security is hard.

Re: Signal Server code on GitHub is up to date again

#204
post #192

Earlier quoted context omitted.

If you checkout the client source, compile it, and install it on your own mobile device, you can then connect it to your own self-hosted server instance. However Signal's own server instance will then block your client (and there's no way to connect the client binaries they distribute to anything but their own server). So you would have to then follow the above steps for any contacts you want to communicate with, dis…

Ok, but they should be forced then to do the things they don't want to do? What I mean is: if Signal is not Elment.io/matrix, and that the latter is better for freedom and openness, then one can agree with with that. But what I don't understand is the demand from people that Signal somehow owes them the ability to be like matrix, be federated, etc. and also be so judgemental about it, is what rubs me the wrong way.

I've tried to approach this thread in good faith, as your earlier replies seemed genuinely curious/discussion oriented, but the "ok, but" tone is making them seem increasingly shill-like.

I don't think anyone's "demanding" or "forcing" anything here. We're simply describing a definition of what we consider desirable as a sustainable secure messaging option, and pointing out the specific reasons that Signal isn't currently living up to that definition.

It's maintainers are free to continue on their way ignoring said definition.

Personally, my own comments are not targeted at Signal devs but rather at others who might consider using Signal thinking it provides certain guarantees when it doesn't.

Re: Signal Server code on GitHub is up to date again

#205
post #152
post #129

Earlier quoted context omitted.

> A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Nope. It's a reaction to "who the f* asked for this in a messaging app?!".

Text isn't the only thing I want to be able to send to people. I wish there were a universal "send thing" api that could be implemented for text, images, money, whatever.

Like Matrix?

Re: Signal Server code on GitHub is up to date again

#206
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

You're apologizing for a project that has repeatedly damaged user trust with excuses. These are "valid" reasons for keeping the source code private for a year? By whose book? Yours? Certainly not by mine. I wouldn't let any other business abscond from its promise to keep open source open source in spirit and practice, why would I let Signal? This is some underhanded, sneaky maneuvering I'm more used to seeing from th…

Thanks for linking this, I had no idea this occurred.
Post reply on HN