Live data from Hacker News

Et Tu, Signal?

stephendiehl.com

261–270 of 459 posts

Re: Et Tu, Signal?

#261
If Signal can be as successful with private payments as they have been with private communications, then that would be a big win for everyone. I don't see why people are complaining about this.

What's the fundamental difference between private payments and private communication. Why support the latter but not the former?

Re: Et Tu, Signal?

#262

Did anyone ever consider that this is actually on purpose to deter people from using Signal by it's authors? Lets imagine, theoretically, some three letter agency in the US has forced signal to backdoor their platform somehow, and so signal stops posting source code to the clients, and everyone just keeps on using it for a year even though the authors thought that maybe this would be a big red "DANGER" signal to the…

Never ascribe to malice what can be ascribed to incompetence.

Re: Et Tu, Signal?

#263

I see Keybase mentioned a lot in this discussions (both in the linked article, and in HN comments). Does anyone have a good summary to read up on what happened with Keybase?

Got bought out by Zoom, and given their reputation for security/privacy, many users ditched Keybase quicker than rats from a sinking ship. It's almost like Zoom forgot that Keybase users are more likely from the more technical end of the spectrum and thus more security conscious.

I don't think Zoom cared about Keybase users; it seemed more like an acquihire.

Re: Et Tu, Signal?

#264

It sounds like they are trying to increase their revenue/profits and think this is the best way. I get that it is hard, because when everyone is anonymous then it is hard to collect money from people. Perhaps make some way to donate/subscription for signal a la pay what you want? I love Signal and would pay for it if I could.

1. It's not a company but an NGO. Therefore, in theory, as long as they can cover the operational cost, they should be good. Of course, there's plenty of NGOs that don't do that.

2. https://signal.org/donate/ wasn't that difficult to find.

3. Brian Acton (WhatsApp co-founder) "donated" a hundred million to it. In theory, that alone should keep them running for at least a decade, but the "donation" was more of a loan with 0% interest, meaning that Signal will have to re-pay it back at some point. Also, just to make it shadier, he happens to be the chairman of the Signal Foundation. So he loaned the money to the org he's in charge of.

Re: Et Tu, Signal?

#265
post #65

Earlier quoted context omitted.

I think you hit the nail on the head with "Element is much more like a chat program than a phone messenger". Me and a friend experimented chatting with Element (Riot at the time), and while it certainly "worked", the process of getting everything working was not something I would expect a non-programmer to be able to figure out. We had to finagle different keys across different computers and phones and it was fairly…

> I feel like Element works better as a competitor to Slack or IRC than as a competitor to Signal or Whatsapp. To me it's a competitor to Keybase. "I want to send my co-worker/client an API key that I don't want exposed to the public" is about the only use for Keybase I've had. I have like 5 contacts on there for this reason. Slack/IRC is much more usable for getting shit done, but not being E2E I wouldn't send anyth…

This is why I use https://keys.pub and/or Magic Wormhole.

Re: Et Tu, Signal?

#266
post #206
post #93

Earlier quoted context omitted.

It's anonymous with some caveats. The transaction graph is still there, it's just that there are decoy inputs/outputs which provides plausible deniability. However, over repeated transactions the plausible deniability weakens. ie. having an output to a darknet market in one of your transaction is easily explainable by bad luck, but it's present in several transactions it becomes suspicious enough that the police can…

This might be true of the particular decoy approach used with Monero, but I don’t think it’s true in general; e.g. with mixer/tumbler services. If every transaction that everyone does has some outputs to darknet markets (because they’re popular and high-volume), and some outputs to legitimate businesses (because they’re also popular and high-volume) then that really is reasonable doubt that any particular individual…

>If every transaction that everyone does has some outputs to darknet markets (because they’re popular and high-volume), and some outputs to legitimate businesses (because they’re also popular and high-volume) then that really is reasonable doubt that any particular individual did anything bad.

The problem is that transacting with a darknet market will still bring your illicit output % above average. Right now monero has 10 decoy outputs per transaction. If the proportion of illicit addresses to legitimate addresses were 50%-50%, then a legitimate transaction would have an average of 5 illicit outputs but a illicit transaction would have an average of 6 illicit outputs. The same applies to inputs. The difference between 5 and 6 might be small enough to be indistinguishable from background noise, but that result is heavily dependent on the proportion of illicit vs legitimate address. If the proportion is something like 95%-5%, then the difference would be 0.5 vs 1.5, which is significant. I won't bother to do the probability calculations for this, but I'm going to estimate you can get to 95% certainty within 10 transactions.

>It’s like how you can’t charge someone with possession of cocaine because there’s cocaine on the US dollar bills in their pocket: there’s actually trace amounts of cocaine on every US dollar bill.

The interesting bit is that they don't have to charge you based on that alone. If they're 80% sure you bought illegal drugs, they'll either get a warrant to search your house or perform surveillance on you and wait for you to slip up.

Re: Et Tu, Signal?

#267
post #82

Earlier quoted context omitted.

Try transferring from an iOS phone to Android. Try transferring messages to a new desktop (you can't). It's 2021, I don't want to be platform locked and none of the other popular messaging apps have that issue.

Whatsapp does, so it's probably not that critical of a feature.

Most people don't switch platforms very often so it's not a big deal to them and just a corner case. Also most people don't care that much about old messages so again a corner case.

Re: Et Tu, Signal?

#268
Throwaway for obvious reasons.

I interviewed at signal a while back, and none of their recent mishaps surprise me. At first, they had me talk to Brian Acton on the phone for about an hour, who seemed to think I was already getting an offer, and he was there to sell me on it. He was cool to talk to, so I didn't mind, but I was surprised at this level of confusion for a company that small.

Next, I was given a lengthy take home project (which I was warned not to do in a language other than Java, because Moxie would reject candidates if they didn't pick a language he liked). After I finished it, they disappeared for a month.

Apparently I passed. They said I was basically the only one out of 200 people they sent it to that did pass. I assumed this meant I would be getting an offer, but they then wanted me to do a full onsite. The "onsite" weirdly consisted of another take home, but shorter, and a live interview. After not hearing back again for a while, I got an email titled: "Hello from Signal!". Great! I opened it, excited: it was a rejection.

I tried to get feedback on why I was rejected but never heard back. The best thing I can come up with: in the system design interview, as a solution to a postgres node being overloaded, I didn't come up with the solution of having a SPOF redis node with a full key scan every 10 minutes acting as an intermediate data store before transferring to postgres. I was told this is how they actually do things.

Take this with a grain of salt, since I'm obviously still irked by the experience, but it's all true.

Re: Et Tu, Signal?

#269

Earlier quoted context omitted.

I remember that Skype, before it was bought and ruined by Microsoft, had P2P chat history sync that worked the following way: once two of your devices were online at the same time, they synchronized chat history among the two running instances flawlessly. It was super reliable and predictable. I am sure that Signal could implement the same peer-to-peer sync scheme with full end-to-end encryption without any secrecy c…

This is actually working very bad in most practical situations. The way to go is Telegrams way, where you store all data on the server and happily sync ut easily between devices. Just do it on your own server using xmpp. E2ee helps mostly against server owner, and you eliminate this risk by being your own server owner.

You run your own datacenter?

Re: Et Tu, Signal?

#270

Earlier quoted context omitted.

Hey, advisor for a non-signal E2EE chat service here that also benefited from the Open Technology Fund. I recognize that you'd basically just be taking my word for it, but literally all they did was take an application from us, approve it after doing their diligence, and paying Cure53 for an assessment. There was no other involvement or, as you're implying, interference. Just my experience, but I'm publishing this be…

In my experience, most people who project nefarious intentions on the government have no experience working with or within the government. The government, after all, is a big thing with no unified goals or intentions. But for some reason, for some people, 'government' always means 'bad'.

To be fair it usually is bad when it comes to matters of privacy and being open and honest about said privacy.
Post reply on HN