Live data from Hacker News

Signal partners with Microsoft to bring end-to-end encryption to Skype

signal.org

341–350 of 350 posts

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#341

Earlier quoted context omitted.

Their grades are based on objective assessment of properties of underlying technologies. They are very useful for most people, who are not going to study cryptography for several years and then manually reading and checking source code of every communications software product out there.

No. They're not useful. They were a disaster, and EFF should stop doing them (I think they have?) https://news.ycombinator.com/item?id=10525266

> No. They're not useful. They were a disaster, and EFF should stop doing them (I think they have?)

> https://news.ycombinator.com/item?id=10525266

Seems like most of the critiqued stuff has changed. By the time i got to EFF recomendations Signal was the winner and use of telegram and cryptocat was discouraged.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#342
post #333
post #265

Earlier quoted context omitted.

With Gmail it appears to be a question of getting on a (secret, opaque) white list.

I mean that's the nature of these kinds of lists. We don't tell anyone about how we set up our firewall, do spam filtering, or flag accounts for suspicious activity because then it would be easier to circumvent.

There are plenty efficient rbl lists that are transparent. There's grey listing.

It's not like "today, you feel white-ish enough to not be silently dropped at gw, black-ish enough to go in the spam folder without warning" is the only valid policy to fight spam.

Even simply rejecting with an error (spam suspected) would be better than the silent treatment.

And I don't see anything wrong with telling people how you set up a firewall. We even write books about that.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#343
More than a few comments trying to rationalize why Skype is different under Microsoft. (Supernodes are controlled by Microsoft, not users.) Also some comments exhibiting misconceptions about the relative feasibility of peer-to-peer networking today compared to the past.

Some users want peer-to-peer networks that are controlled by users, not third parties such as Microsoft, Facebook, etc. It seems that corporations are also interested in such networks. But they just want the users, not the ability to exclude third parties (they are a third party).

What is important for these interested users is that Skype changed and how it changed, not why changed.

No explanation, rationale or excuse is a substitute for a peer-to-peer network that is controlled by its users, not third parties.

We know why these user-controlled networks get acquired (or copied) by companies: because they work and they attract many users.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#344

Earlier quoted context omitted.

>the reason Microsoft broke Skype so badly was because they used centralised servers with backdoors for countries who wanted them. That seems like pretty unreasonable tinfoil. There is no reason for Microsoft to want to give information to governments. I assume they don't pay, and the cost is consumer trust. Makes a lot of sense to rearchitect such that you can't give in to government demands.

In retrospect, much "unreasonable tinfoil" has turned out to be fact. Assuming collusion is the safest bet, these days.

riding ockham's razor is a religion for some. but that's ok.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#345
post #264
post #219

Earlier quoted context omitted.

That doesn't match my experience of running a mail sever for decades.

How long since you set up mail for a newly registered (possibly with previous owner) domain hosted on a VPN or rented dedicated server in an ip block that might have had previous owners?

Not sure if this is recent enough, but I moved my self-hosted email to a new address a little over 4 years ago.

The only systems that have had even tiny problems with were Gmail and Microsoft. With Gmail it took a while to build reputation as a non-offender. With Microsoft the first time I sent mail to their way, I got an automated bounce with instructions to forward to a certain address for human verification. That check round took maybe 12 hours and I haven't had any problems since.

I find that pretty reasonable.

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#347
post #345
post #264

Earlier quoted context omitted.

How long since you set up mail for a newly registered (possibly with previous owner) domain hosted on a VPN or rented dedicated server in an ip block that might have had previous owners?

Not sure if this is recent enough, but I moved my self-hosted email to a new address a little over 4 years ago. The only systems that have had even tiny problems with were Gmail and Microsoft. With Gmail it took a while to build reputation as a non-offender. With Microsoft the first time I sent mail to their way, I got an automated bounce with instructions to forward to a certain address for human verification. That…

Sounds like Microsoft (outlook.com and friends?) have improved since I sat things up - I never got a bounce. It'd be nice if Gmail was so considerate.

But how do you know that when you send mail to a new Gmail contact it won't be silently flagged as spam? And how many times will the recipient have to "un-flag" before the behaviour changeges?

> The only systems that have had even tiny problems with were Gmail and Microsoft

The "only" big provider missing from that list is apple (in the West anyway).

I've never meant to claim that smaller providers that know what they're doing aren't capable of sending proper bounces, setting proper smtp error codes on reception or of handling email to postmaster@.

It's just that with Gmail and outlook not being God net citizens - it becomes unreasonably hard to send legitimate email to a large percentage of Internet users. One possible "fix" is to send mail to Gmail users via a Gmail account and Gmail authenticated smtp servers - and so on for outlook.com - but as the number of "silos" one needs to send data to grows, that solution becomes cumbersome. Not to mention if you publish an mx record for your domain, you should be accepting email... That's the whole point...

Re: Signal partners with Microsoft to bring end-to-end encryption to Skype

#350

Earlier quoted context omitted.

This. I wish Signal's own native apps had the user experience of Telegram.

or that telegram just used the signal protocol; either is fine in my book

Yes, that would be great as well but I’ve long since given up on that happening.
Post reply on HN