Live data from Hacker News

Et Tu, Signal?

stephendiehl.com

271–280 of 459 posts

Re: Et Tu, Signal?

#271
post #20

I definitely agree with the article that it felt a bit like a betrayal. I've pushed some friends and family to use it over Telegram despite significant usability issue, and now I see that instead of implementing some IMO basic features like proper message sync and easy backup when you get a new phone, they prefer to implement a... micropayment system? Based on some niche altcoin which doesn't even exist on mainstream…

As someone who has been defending Telegram against certain claims here from time to time this is still a sad day for me.

I'd appreciate however if everyone who has been saying ugly things about the alternatives would take a step back now and consider if there is more to security than E2E-encryption.

E2E-encryption is a seriously nice and useful property of a messaging system, but in the long run it is only one of many important details, and while E2E-encryption is always a good thing for end users as far as I can see other useful properties are often directly at odds with each other:

- incentives and funding. Free to give everyone the ability to use it or paid to align incentives?

- anonymity or verified identies? Both have significant advantages.

- repudiation or non repudiation? Depends on if you agreed on a contract or discussed something that the new regime doesn't approve of.

- backups? or ephemeral? Again, depends on if you are sharing family photos in a group or or sharing something that should stay between you and the recipient

Edit to add: As for solutions I think healthy competition is one of the best ways to ensure every messaging system tries to be tje best they can be.

Re: Et Tu, Signal?

#272

Did anyone ever consider that this is actually on purpose to deter people from using Signal by it's authors? Lets imagine, theoretically, some three letter agency in the US has forced signal to backdoor their platform somehow, and so signal stops posting source code to the clients, and everyone just keeps on using it for a year even though the authors thought that maybe this would be a big red "DANGER" signal to the…

I think it's just a bad call. I don't think there's anything nefarius to it. I'm unsure why they didn't use a real cryptocurrency that is somewhat popular like ethereum or monero. I would prefer none of that and to add more convenient messaging features.

Re: Et Tu, Signal?

#273
post #20

I definitely agree with the article that it felt a bit like a betrayal. I've pushed some friends and family to use it over Telegram despite significant usability issue, and now I see that instead of implementing some IMO basic features like proper message sync and easy backup when you get a new phone, they prefer to implement a... micropayment system? Based on some niche altcoin which doesn't even exist on mainstream…

[deleted]

Re: Et Tu, Signal?

#274
post #266
post #206

Earlier quoted context omitted.

This might be true of the particular decoy approach used with Monero, but I don’t think it’s true in general; e.g. with mixer/tumbler services. If every transaction that everyone does has some outputs to darknet markets (because they’re popular and high-volume), and some outputs to legitimate businesses (because they’re also popular and high-volume) then that really is reasonable doubt that any particular individual…

>If every transaction that everyone does has some outputs to darknet markets (because they’re popular and high-volume), and some outputs to legitimate businesses (because they’re also popular and high-volume) then that really is reasonable doubt that any particular individual did anything bad. The problem is that transacting with a darknet market will still bring your illicit output % above average. Right now monero…

I get what you mean, I think — you’re talking about traffic fingerprinting. But you can use the same anti-traffic-analysis techiques used elsewhere in systems like Tox. For example, the darknet market itself could use some of its revenue to pay for “noise transactions” (wash transfers through the mixer, then intentionally “black-laundered” in the market) to keep the number of darknet-market-spent outputs constant per mixer step, by asking for advance notice from buyers for when transfers targeted at their sellers will happen, and then running N fewer “noise transactions” during the appropriate mixer steps.

Though also, you’re assuming a constant “your account” in the above. If you mix 100% of your holdings every time you transact, setting it so that a set amount goes to a darknet market, and the rest goes back to a newly-created public-key-hash that you just generated the keypair for — and then when you want to use money from that address, you fully consume it to mix it again — then nobody ever gets the opportunity to fingerprint “your” traffic. There’s no stable “you.”

(I have a theory that this is the goal Satoshi was aiming at with Bitcoin UXTOs, but never finished that element of the design, and launched it half-baked.)

This also means that the mixer gets to eat a percentage fee off of your complete holdings every transaction, so it kind of sucks, but what can you do.

Re: Et Tu, Signal?

#275
Good Morning,

I am the CEO of MobileCoin.

A few points:

1) I started MobileCoin to fund Signal. That’s it. I believe that a world with a well-funded signal is a better place. In order for signal to compete in the 21st century with messaging apps around the world they need a payment story. MobileCoin is the only thing ever built that is both privacy protecting and fast that meets the standards of data retention signal requires.

2) MobileCoin Inc. intends to maintain an extreme minority of the coins once the dust settles.

3) This is designed to be used as a payment rail, which requires us getting coins in the hands of users. As you might imagine, navigating the regulatory waters of how to do that with compliance to how governments want us to behave is non-trivial. It’s important for us to move with correctness over speed.

4) this project is 4 years of my life building real technology. This is not a pump and dump scam. We have been very careful in the design, operation, and development of this system to give it the best chance at surviving in the world of cryptocurrency projects. It is non-trivial to deliver a coin that is useful for payments (the requirements are speed, privacy, low-energy footprint, and operation in resource-constrained mobile environments).

Let me put it simply, I love signal and we intentionally designed this currency to be as oblivious as possible with respect to user data so that signal could maintain their relationship with their users, one of retaining as little information as possible without compromising on the user experience. Nothing else in cryptocurrency, or payments, comes close to the level of privacy and performance that MobileCoin has achieved.

I welcome any questions I am able to answer. Note that some questions revolve around tightly regulated areas of concern and may take longer to answer as I must check with outside counsel before replying.

Re: Et Tu, Signal?

#276

Earlier quoted context omitted.

That's a big advantage, and a very important one. But definitely, that and the superior crypto is what keeps me on the app. Telegram is in a whole different level when it comes to usability and refinement. >Signals crypto is used by Facebook and was sponsored by the US Govt Funny that you're talking about FUD.

It is not FUD. OWS was financed by Open Technology Fund, to the tune of almost $3M, during the years 2013-2016. See here: https://www.opentech.fund/results/supported-projects/open-wh... What is Open Technology Fund? It is a program of Radio Free Asia, which run by US Agency for Global Media, funded by US Congress.

That is not the point. The point is what does the funding get them? A backdoor? The algorithm as well as the client source are open for audit and have been audited multiple times.

Re: Et Tu, Signal?

#277
post #61

I'm a little surprised that nobody is mentioning that any kind of blockchain payment system creates a permanent, public ledger. One US Attorney called Bitcoin's blockchain "prosecution futures" as it's only a matter of time before the sender/receiver addresses for transactions are correlated with unique individuals. This permanent, public record of a transaction between a Signal account and another user or a service…

A very good point. Signal's tying encrypted messages and phone numbers to a publicly available ledge of transactions?

Only if they get hold of your phone and you give them your password.

Re: Et Tu, Signal?

#278

Earlier quoted context omitted.

Hey, advisor for a non-signal E2EE chat service here that also benefited from the Open Technology Fund. I recognize that you'd basically just be taking my word for it, but literally all they did was take an application from us, approve it after doing their diligence, and paying Cure53 for an assessment. There was no other involvement or, as you're implying, interference. Just my experience, but I'm publishing this be…

It could be, I believe what you say is very much the truth. But that doesn't really matter. Even by doing that. these two are associated. Imagine, if there was a non-profit, that took money from some Kremlin or Fobidden City development program, using exactly the same procedure. Would be that non-profit trustworthy going forward, given their association? So this one is the same, just with red and white stripes. Defin…

>Would be that non-profit trustworthy going forward, given their association?

As long as the product is proprietary, no.

Re: Et Tu, Signal?

#279
post #216

"The ecosystem is moving"... to pump and dump pre-mined shitcoins.

The irony is that the coin would be excusable if it was used as a utility token to power a decentralized network of incentivized nodes (like Status or Session).

But Signal is still centralized. So there’s no reason for the sh*tcoin other than to make some people rich.

Re: Et Tu, Signal?

#280
post #61

I'm a little surprised that nobody is mentioning that any kind of blockchain payment system creates a permanent, public ledger. One US Attorney called Bitcoin's blockchain "prosecution futures" as it's only a matter of time before the sender/receiver addresses for transactions are correlated with unique individuals. This permanent, public record of a transaction between a Signal account and another user or a service…

That’s true for a lot of crypto but not for something like monero which has an anonymous blockchain.

Monero has been shown to not be completely anonymous on more than one occasion despite the claims. It's not as safe as people say. It's better than bitcoin in that respect though.
Post reply on HN