Live data from Hacker News

Signal app downloads spike as US protesters seek message encryption

qz.com

311–320 of 367 posts

Re: Signal app downloads spike as US protesters seek message encryption

#311
post #104
post #95

Earlier quoted context omitted.

I don't think that's a great idea until Signal stops exposing the phone number of the user to everyone else (for all the bashing that Telegram gets on cryptography, it has mechanisms to hide one's phone number and even the fact that one has a Telegram account from others).

Absolutely agree. I really wish Telegram would get off the phone number system, especially after the embarrassing hack in Brazil. It's not explicitly Telegram's fault, but if your primary authentication method is insecure it's at least a little bit your fault. Phone numbers are NOT safe. I don't know why SMS MFA is even a thing, they're worse than passwords. When you use phone numbers or SMS for security, you are put…

> especially after the embarrassing hack in Brazil

What happened?

Re: Signal app downloads spike as US protesters seek message encryption

#312
post #200

Earlier quoted context omitted.

Do you have a reference for the claim that your full contact list is uploaded to servers? That seems important since their privacy policy says that they only use hashes, and it can’t be dependent on SGX since it runs on non-Intel hardware: https://signal.org/legal/#privacy-policy

SGX is for the servers not the clients. Their enclave is open source so you can theoretically audit it using RA. I say theoretically because these schemes all have a core problem when they're not federated - you have no idea what your client is really doing and it's the client performing remote attestation with the enclave. You have no control over it. It could update tomorrow and switch every last bit of encryption…

> That didn't stop [facebook] blocking people from forwarding links related to coronavirus.

Source?

Re: Signal app downloads spike as US protesters seek message encryption

#313
post #232

Earlier quoted context omitted.

no one would believe you...

How does that matter? You have the right to install any apps you want, and wacky questions deserve wacky answers.

How does that matter? Perhaps due to the potential scenario in question being interrogation by law enforcement that doesn't have your best interests at heart, not "who has the better witty retort to score points online?".

Re: Signal app downloads spike as US protesters seek message encryption

#314

Earlier quoted context omitted.

Will only ever happen once Signal ditches their dependency on mobile phone number.

Doesn't whatsapp also rely on the phone number as Id? Why can they have a desktop and browser client?

Browser WhatsApp works through a connection to the phone, and not directly to servers. If your phone is off, Web WhatsApp doesn't work.

Re: Signal app downloads spike as US protesters seek message encryption

#315
post #281

Earlier quoted context omitted.

By quite easy i mean, when you have global surveillance in place. All tor-nodes are public all tor-exits are public, if your system can track connections from one node to another node and then the exit-node everything is clear. https://en.wikipedia.org/wiki/Global_surveillance#Infiltrati... Edit: And that from netzpolitik (highly trusted german source) under 'A global passive adversary' that's the interesting part: h…

It is enough to have at least a few independent relays to cover the trace. Everyone who can should be running a relay node at home I guess. Also we generally need more participants in Tor of course. There is also I2P network, which is even harder to break (unless someone owns practically all nodes there).

Well i run a node (not exit) and yes it's better then nothing, but to fully trust Tor is a big nono, i said nothing else. Protections from private company or country's yes..but protection from GCHQ/NSA probably not.

And no you can trace it thru the ISP's, the problem is the latency, Connection from here to there in that millisecond trace one...and so on.

Re: Signal app downloads spike as US protesters seek message encryption

#316
post #288

Earlier quoted context omitted.

> If the law enforcement is talking to you in the U.S., the only right answer is "I'd prefer to have a laywer here." > Not a joke, for real. Obligatory link to the fantastic "Don't Talk to the Police" lecture from the Regent University School of Law. Watch the whole thing: https://www.youtube.com/watch?v=d-7o9xYp7eE

Here is a very succinct version: Shut The Fuck Up Friday https://www.youtube.com/watch?v=JTurSi0LhJs (fair warning, this will autoplay the word 'Fuck' in the first 10 seconds)

Yes, the advice is good, but this is targetted against "operating an unlicensed dispensary" -- it is important you realize because you think you've broken no law still does not make you safe, you need to not talk to the police without a lawyer, for your own safety, even if you think you've done nothing wrong.

You (or your friends) can go through serious inconvenience and pain, from lengthy and expensive legal battle (during which you may not be allowed to leave the state etc), to conviction and sentance, even if you don't think you've done something wrong. Innocent people and/or people who didn't realize they were breaking a law get convicted all the time.

Talking to the cops will not help your situation. Not even when they say "Look, we may have it wrong, if you just tell us what happened we can get this all cleared up." Not without a lawyer.

Re: Signal app downloads spike as US protesters seek message encryption

#317
post #315

Earlier quoted context omitted.

It is enough to have at least a few independent relays to cover the trace. Everyone who can should be running a relay node at home I guess. Also we generally need more participants in Tor of course. There is also I2P network, which is even harder to break (unless someone owns practically all nodes there).

Well i run a node (not exit) and yes it's better then nothing, but to fully trust Tor is a big nono, i said nothing else. Protections from private company or country's yes..but protection from GCHQ/NSA probably not. And no you can trace it thru the ISP's, the problem is the latency, Connection from here to there in that millisecond trace one...and so on.

If you are speaking about the timing attack, then you should consider I2P. It makes them significantly harder. In general, I agree that if your enemy is NSA, you can do very little. But you can make their life harder, and you should.

Re: Signal app downloads spike as US protesters seek message encryption

#318

Has anyone here successfully convinced their non-techie friends to switch to Signal? How have you done it? I've been trying on and off with my closest friends, but no luck.

My wife. Also required it for all my employees, but that's a bit different.

Re: Signal app downloads spike as US protesters seek message encryption

#319
post #315

Earlier quoted context omitted.

Well i run a node (not exit) and yes it's better then nothing, but to fully trust Tor is a big nono, i said nothing else. Protections from private company or country's yes..but protection from GCHQ/NSA probably not. And no you can trace it thru the ISP's, the problem is the latency, Connection from here to there in that millisecond trace one...and so on.

If you are speaking about the timing attack, then you should consider I2P. It makes them significantly harder. In general, I agree that if your enemy is NSA, you can do very little. But you can make their life harder, and you should.

I2P is absolutely great, a shame that it's no covered so much and Freenet was once also a cool project...i see we are on the same page ;)

Edit: GnuNet, RetroShare and ZeroNet should also be mentioned

Re: Signal app downloads spike as US protesters seek message encryption

#320

I actually like Signal, and would use it a lot more, but don't because of one feature - link previews. I understand the technical reasoning why are they so slow to adopt it, but I (and a group of people I communicate on a daily basis) would probably accept even a half-baked solution like the one on WhatsApp.

You want your encrypted chat application to emit DNS queries to your ISP. As another Signal user, I do not want that. Nor do I want the bloat of this and other features that will make the core functionality worse. Next we'll want Memoji's and animated drawings and fireworks. My point is, there is already an app for that. Signal has a completely different purpose.

You can generate a preview on the sender side. I think WhatsApp does it like that. Since you're the one sending the link, you've already opened it/know what's behind it. The receiver would basically get a thumbnail, with no egress traffic.

As for the DNS, if you're concerned with the DNS of your ISP, you shouldn't be using it anyway (I don't).

Don't extrapolate what I said. I like link previews and don't like Memojis and bloatware. But more often than not I like to know what's behind the URL. Maybe I don't wan't to open the site, or already seen the article, or the preview is enough to get information (like weather?).

If we're on the road to proliferate privacy-conscious behaviour, we need to give something to "the masses", so they can enjoy the experience. And I want my mom and dad using products such as Signal, so I can use it with them. I have no use of it if my friends are not using it, and I'm all alone on the whole network. I don't support bloatware, but some sugar is needed.

Post reply on HN