Live data from Hacker News

Et Tu, Signal?

stephendiehl.com

301–310 of 459 posts

Re: Et Tu, Signal?

#301

Good Morning, I am the CEO of MobileCoin. A few points: 1) I started MobileCoin to fund Signal. That’s it. I believe that a world with a well-funded signal is a better place. In order for signal to compete in the 21st century with messaging apps around the world they need a payment story. MobileCoin is the only thing ever built that is both privacy protecting and fast that meets the standards of data retention signal…

2) MobileCoin Inc. intends to maintain an extreme minority of the coins once the dust settles.

a.k.a. we intend to sell all of our vast stacks of pre-mined coins onto gullible users. This is exactly how a pump and dump scam works.

Re: Et Tu, Signal?

#302
post #140

But I thought moving from the walled garden owned by Facebook to another walled garden owned by a Non Profit Organisation whose main maintainer controls the entirety of the platform and discourages any forks/federation would solve all our problems. Surely they would never dare to push shady shit in their application since they are the good guys™. I am shocked.

I criticized both WhatsApp and Signal in an article linked here previously, and made the same points in a bit more detail: "WhatsApp and the domestication of users". Discussion: https://news.ycombinator.com/item?id=25982860

A sequel [0] describes how an open platform/protocol isn't a silver bullet, since open platforms can become (or act) closed if we're not careful. It goes over XMPP, email, and Matrix; I described Matrix in a generally negative light but I think it still shows promise.

[0]: https://seirdy.one/2021/02/23/keeping-platforms-open.html

TLDR of [0]: the key is to combine open platforms/protocols with simplicity and diversity.

Re: Et Tu, Signal?

#303

Earlier quoted context omitted.

There are no known attacks against Telegram. The problem is entirely that its cryptography was sketchy and just plain weird to begin with. It wasn't wrong , per se, but raised some eyebrows. And then some of the questionable choices were silently fixed removing the ability to MITM, etc, but with no real notice. It's not FUD.

Interestingly, if you say that Signal's funding is sketchy and it raised some eyebrows, that would be FUD (see sibling comment). But saying the same about Telegram encryption is for some reason perfectly fine and definitely not FUD. Shouldn't we have the same standard for all claims?

So you're saying we should have the same standard while literally giving two different types of allegations that are thrown at Signal and Telegram respectively?

We either consider the funding of both and decide how the funding COULD ultimately impact the product, or we could look at the source code of the applications and the cryptographic theory supporting them and talk about that. If crypto experts aren't finding holes in Signal's protocols [1], I don't think random people on the internet yelling "bUt It WaS fUnDeD bY ..." will make it less secure.

[1] https://eprint.iacr.org/2016/1013

Re: Et Tu, Signal?

#304
post #133

I'm afraid we'll always be jumping to new apps. If we jump ship from Signal to Matrix, as some people suggest, then I fear that in 2-5 years, Matrix will morph into something unacceptable, just as Signal has.

Matrix is an open, federated protocol so something like this can't happen. Worst that could happen is bad stuff happens to Element (the flagship client) at which point people can either fork it or simply use another client.

Jabber was an open Federated protocol, before Matrix.

I am absolutely in favor of open protocols, but they are not a guarantee against needing to change ecosystems in the future.

Re: Et Tu, Signal?

#305

Just make an in-app purchase button that allows me to buy a year of usage for myself as well as gift for others. I'd happily pay a couple of bucks per month for myself and my family.

Scooping the cream off every monetary transaction between some friends is a more appealing proposition than hoping some people will pay for your software.

Apple Pay, Google Pay, Visa, Signal - there is a lot of companies basing their business model on Office Space.

Hackers had the same theme, right? And Operation Swordfish, which was trash.

Re: Et Tu, Signal?

#306

Good Morning, I am the CEO of MobileCoin. A few points: 1) I started MobileCoin to fund Signal. That’s it. I believe that a world with a well-funded signal is a better place. In order for signal to compete in the 21st century with messaging apps around the world they need a payment story. MobileCoin is the only thing ever built that is both privacy protecting and fast that meets the standards of data retention signal…

2) MobileCoin Inc. intends to maintain an extreme minority of the coins once the dust settles. a.k.a. we intend to sell all of our vast stacks of pre-mined coins onto gullible users. This is exactly how a pump and dump scam works.

To be clear, we want to get the coins into the hands of users so they can buy things with them. Doing so in a legally compliant fashion is non-trivial. Looking at what happened with key base and stellar, a simple airdrop to users of the system doesn’t necessarily result in utilization or economic development.

There are multiple different things to consider here: 1) regulatory, 2) economic system design, 3) usability, and 4) user-first commerce.

In short, it’s much more important for us to be correct than it is to move quickly. When all is said and done, users of MobileCoin will have obtained coins many ways: through giveaways, sales, and commerce activities. Making sure we do these things correctly is the only way the ecosystem will be able to operate long term.

Re: Et Tu, Signal?

#307

Earlier quoted context omitted.

There are no known attacks against Telegram. The problem is entirely that its cryptography was sketchy and just plain weird to begin with. It wasn't wrong , per se, but raised some eyebrows. And then some of the questionable choices were silently fixed removing the ability to MITM, etc, but with no real notice. It's not FUD.

Interestingly, if you say that Signal's funding is sketchy and it raised some eyebrows, that would be FUD (see sibling comment). But saying the same about Telegram encryption is for some reason perfectly fine and definitely not FUD. Shouldn't we have the same standard for all claims?

> Interestingly, if you say that Signal's funding is sketchy and it raised some eyebrows, that would be FUD (see sibling comment). But saying the same about Telegram encryption is for some reason perfectly fine and definitely not FUD.

> Shouldn't we have the same standard for all claims?

Huh? Telegram's protocol has been criticized by cryptographers for making specific "odd" cryptographic choices (see See https://crypto.stackexchange.com/questions/31418/signal-vs-t...). It's not FUD to bring that up.

However, it is FUD to imply something concrete based for vague, indirect reasons.

Re: Et Tu, Signal?

#308

I was recently pulled onto Signal by a non-techie who values his privacy. I talked to him about Matrix/Element and he had no idea what that was, but was very happy with Siganl. I must admit, the app is very nice. All I had to do was give it access to my contacts and bam, I am now able to chat with all my contacts. By comparison, Element is much more like a chat program than a phone messenger. It's good for "I want to…

> By comparison, Element is much more like a chat program than a phone messenger. It's good for "I want to connect with that person from GitHub" Element is what messaging should have been from the START: a federated service just like email, where you register an account with your provider of choice, just like email, and start adding/chatting other people after getting to know their address, just like email. So, inste…

There's also DeltaChat: It looks more or less like WhatsApp, but it uses email as the transport and storage mechanisms, and it is seamlessly encrypted with AutoCrypt. It supports both one-on-one and group chats. It has apps for mobile and desktop.

https://delta.chat/

Re: Et Tu, Signal?

#309

Good Morning, I am the CEO of MobileCoin. A few points: 1) I started MobileCoin to fund Signal. That’s it. I believe that a world with a well-funded signal is a better place. In order for signal to compete in the 21st century with messaging apps around the world they need a payment story. MobileCoin is the only thing ever built that is both privacy protecting and fast that meets the standards of data retention signal…

What percentage of the coins does MobileCoin and its founders/early investors currently hold?

Seems your early investors certainly have a large chunk https://threader.app/thread/1335948142022311936

Re: Et Tu, Signal?

#310
post #299
post #212

Earlier quoted context omitted.

The process of reaching consensus on the current state doesn’t have to involve reaching consensus on the past state for all participants . A blockchain can be built such that all historical previous state + the txs required to get to those historical states are discarded after a quorum of nodes reach consensus on it, leaving only the current state. (This is basically what already happens if you do a “network version…

Honestly I don't see how this would help. If every bit of transaction history is public at some point in time, then the transaction history is public, since it is impossible to make someone forcefully forget something.

Transactions don’t need to ever be broadcast to the network as a whole (e.g. via a gossip protocol) — they only need to be submitted directly to the quorum that will execute them.

Think about physical replication in a DBMS: you only need to transact with the master. Physical replication receivers don’t see logical TXs; they just see the new state (= WAL segments) that the master decided on.

Of course, in a Proof-of-Work network, the quorum could be anybody, so your OPSEC is “leaky” — it’s like having forward-secrecy enabled on a public chatroom that anyone can enter and sit in listening/recording.

But in a Proof-of-Stake or Proof-of-Authority network, the quorum only consists of the stakeholders. So, as long as the stakeholders all intentionally discard transactions, then there’s nobody to recover the data from. It’s very similar to private corporations whose service involves intentionally discaring (or avoiding logging) user interactions, e.g. “private” / “anonymous” email services. Just scaled into a federated, “open-but-audited membership” system. In such a system, network governance would likely declare that new stakeholders must have their infrastructure setup security-audited by auditors chosen by the existing stakeholders, at the new stakeholder’s expense, before being allowed to run as a validator for the network.

Post reply on HN