Live data from Hacker News

Et Tu, Signal?

stephendiehl.com

331–340 of 459 posts

Re: Et Tu, Signal?

#331

Earlier quoted context omitted.

Why another altcoin and not simply ETH or BTC? You state privacy and performance: could you be more specific?

A few things: 1) tx settlement time is ~3 seconds on mobilecoin, p99 latency right now with single block finality. Eth and Btc are great but they aren’t that fast (for payments speed really matters). 2) with respect to privacy, the key innovation of MobileCoin is that when all of the systems are operational, there is no transaction graph stored in the ledger. The links between transactions are known only to the count…

I have not yet read in detail how you use SGX. But setting up SGX requires complicated processes and signing contracts and other paperwork with Intel. (Correct me if this is wrong.)

Given that setting up the "systems" requires a huge effort, I assume that the architecture assumes a single central entity is running all these core systems, right? If yes, does the system rely on these core components to be up? If yes, how does it not rely on a central authority?

Another aspect I don't yet understand: Traditional cryptocurrencies solve the distributed consensus problem through mechanisms like proof-of-work or proof-of-stake. What does MobileCoin use as a consensus mechanism?

Re: Et Tu, Signal?

#332
post #208
post #140

But I thought moving from the walled garden owned by Facebook to another walled garden owned by a Non Profit Organisation whose main maintainer controls the entirety of the platform and discourages any forks/federation would solve all our problems. Surely they would never dare to push shady shit in their application since they are the good guys™. I am shocked.

Agreed, I never really saw the point of moving to Signal since they always felt shady to me. Why go through the effort to convince your friends to move from one shady chat client to another?

Ultimately history has proven your decision to be wise, but there was still a meaningful selling point: Signal was (ostensibly) open source and its developers hadn't yet demonstrated any ill-will or incompetence.

Matrix really was not an option in the early days of signal (and arguably still isn't, for most non-technical users). I adopted Signal even though I disliked its centralization, resigned to the fact that it was a poor compromise but the best available.

In hindsight, though, Signal coaxed many users into its walled garden by being "good enough," which leads to complacency. That has only distracted us from the true importance of embracing and improving the nascent decentralized alternatives.

Re: Et Tu, Signal?

#333
post #326

Earlier quoted context omitted.

MobileCoin has made over 50% of the coins available for purchase. We are currently figuring out how to give away coins while remaining regulatory compliant.

Kinda seems like the sort of thing you would have figured out ahead of time...

Unfortunately cryptocurrency regulations are anything but clear and obvious. This is a new frontier and operating with an abundance of caution is of paramount importance. We respect the hard work all of the regulators are doing trying to figure out this new world.

We're all doing our best to work within the constraints.

Re: Et Tu, Signal?

#334

It’s very odd to me that HN has a problem with premined cryptocurrency, considering equity operates the same way. All startups sell “tokens” (shares) they created out of thin air. Startups also eventually sell them to the public, after having sold them to insiders.

HN missed out on this shitcoin, that's where the salt comes from.

Re: Et Tu, Signal?

#335
post #106

Earlier quoted context omitted.

I remember that Skype, before it was bought and ruined by Microsoft, had P2P chat history sync that worked the following way: once two of your devices were online at the same time, they synchronized chat history among the two running instances flawlessly. It was super reliable and predictable. I am sure that Signal could implement the same peer-to-peer sync scheme with full end-to-end encryption without any secrecy c…

One of the features of the Signal protocol is that each message is signed with a different key so that if one message is somehow compromised it's still impossible to retrieve the others. I think this would break with P2P sync.

Your Signal client has all the messages stored unencrypted (this is true because you can read them all, and search all the local messages).

What's preventing the client from dumping all the messages to a single file, encrypt it with a public key of the other running instance of Signal logged in to the same account, and send it, so that your other device can decrypt the file and import all the messages?

Re: Et Tu, Signal?

#336
I should probably say first that I totally agree with the overall point of the article. This was a sketchy move by Signal and I really question the motivations that played into making such a decision. With that said, there's just something about the way this is written that really bothers me. For starters, the first paragraph makes it sound like Signal was a grassroots movement the entire tech community got behind that then stabbed us in the back, and I can't get over how naive and borderline dangerous that line of thinking is.

"This news really cut to heart of what many technologists have felt before when we as loyal users have been exploited and betrayed by corporations, but this time it felt much deeper because it introduced a conflict of interest from our fellow technologists that we truly believed were advancing a cause many of us also believed in. So many of us have spent significant time and social capital moving our friends and family away from the exploitative data siphon platforms that Facebook et al offer, and on to Signal in the hopes of breaking the cycle of commercial exploitation of our online relationships. And some of us feel used."

I don't understand how any of that is the fault of Signal and not the user. Don't treat the products you use like they mean anything other than the profit motive that built them. It just seems kind of naive to say "every consumer messaging app you use is terrible, come use this one instead and we'll all hope that a massive userbase doesn't inspire them to monetize their platform" when that is essentially the job of what I roughly estimate to be half of the people on HN.

I think it's whack that Signal thought this was a good idea, but I also think it's insane how many people are up in arms as if Signal was once a utility for public good and not the product that it is. They did this because they know how many people bent over backwards to get their loved ones on the platform and they know most people aren't going to get their entire extended family to switch to another messaging app because they added in GarboCoin or whatever the fuck.

Re: Et Tu, Signal?

#337
post #326

Earlier quoted context omitted.

Kinda seems like the sort of thing you would have figured out ahead of time...

Unfortunately cryptocurrency regulations are anything but clear and obvious. This is a new frontier and operating with an abundance of caution is of paramount importance. We respect the hard work all of the regulators are doing trying to figure out this new world. We're all doing our best to work within the constraints.

Yeah but like, what if you find out that you can't distribute the remaining coins in a compliant way? Wouldn't that be something that should have been determined before all the work to integrate with Signal was done? It just feels like if that were a true priority, it wouldn't be in the "implement first, figure the rest out later" category. Even if it's a complicated question.

Re: Et Tu, Signal?

#338
Seems like I dodged a bullet. Didn't install the app, neither bothered to try the service. All the signals (excuse the pun) about this app seemed off to me. Centralized servers, no f-droid listing, used GCM, apparently the devs were hostile to feedback etc. Though can't blame everyone who hopped on the bandwagon

Re: Et Tu, Signal?

#339
post #337

Earlier quoted context omitted.

Unfortunately cryptocurrency regulations are anything but clear and obvious. This is a new frontier and operating with an abundance of caution is of paramount importance. We respect the hard work all of the regulators are doing trying to figure out this new world. We're all doing our best to work within the constraints.

Yeah but like, what if you find out that you can't distribute the remaining coins in a compliant way? Wouldn't that be something that should have been determined before all the work to integrate with Signal was done? It just feels like if that were a true priority, it wouldn't be in the "implement first, figure the rest out later" category. Even if it's a complicated question.

I can assure you that we have the best minds in the regulatory and legal worlds thinking about this and there just isn't a lot of regulatory clarity. If you had told me that 4 years after I started MobileCoin we still wouldn't have guidelines on how to issue a cryptocurrency in the US I would've told you that you were insane, yet here we are. This isn't to point fingers at the regulators, I really think they have a humongous task before them; regulating cryptocurrency is the institutional challenge of a lifetime.

We want to make sure we operate out of an abundance of caution. Correctness is more important than speed.

Re: Et Tu, Signal?

#340
post #104

Earlier quoted context omitted.

Telegram is just so much more usable than Signal. The perceived advantage of Signal over Telegram is LITERALLY not having an option for a cloud-synced chat and ONLY having end to end encrypted chats. That's all. You give up of usability to get that advantage. Explain to your mom why she has to give up Telegram to get basically the same functionality as Telegram secret chats. Signals crypto is used by Facebook and was…

There are no known attacks against Telegram. The problem is entirely that its cryptography was sketchy and just plain weird to begin with. It wasn't wrong , per se, but raised some eyebrows. And then some of the questionable choices were silently fixed removing the ability to MITM, etc, but with no real notice. It's not FUD.

> There are no known attacks against Telegram.

Because there isn't anything to meaningfully attack. Chats and chat backups are not encrypted by default.

Post reply on HN