Live data from Hacker News

Et Tu, Signal?

stephendiehl.com

451–459 of 459 posts

Re: Et Tu, Signal?

#451
post #161

Earlier quoted context omitted.

I've always hesitated to recommend Signal to people due to Moxie's attitude towards the more traditional security and privacy community where things like federation and open source are respected concepts. Tack this on the list and Signal just seems like a crazy thing to recommend now. If they can get the onboarding process on Element to be just a little bit easier, maybe a phone number based default, I'll be dumping…

> I've always hesitated to recommend Signal to people due to Moxie's attitude towards the more traditional security and privacy community where things like federation and open source are respected concepts. My understanding is that is a part of the amateur 'security' community, not the professional or expert one?

Why would you think that? And what is the amateur 'security' community?

Re: Et Tu, Signal?

#452
post #363

Earlier quoted context omitted.

> cons of Telegram? Also, Telegram is not federated. It is just another vendor lock-in. https://github.com/telegramdesktop/tdesktop/issues/6841 https://github.com/telegramdesktop/tdesktop/issues/16068 Contrast that to email. Even if gmail.com bans you or shuts down, you can still use a different email vendor or self-host. (You lose your old email address if you don't own a domain, but you can still communicate with o…

As we've seen from XMPP and Matrix federation comes with it's own set of tradeoffs. Matrix (specifically the element client) has come very far but it's still not at a state where I can reccomended it to non technical acquaintances.

My non-tehnical acquaintances are using it just fine. Any particular issues you've been having?

Re: Et Tu, Signal?

#453

Earlier quoted context omitted.

I think the most common complaint is that group chats are not encrypted, and regular chats are also unencrypted by default.

They are encrypted, just like everything else in the app, just not E2E. There's a big difference between no encryption and encryption that isn't E2E.

Yes, one of those means the server can see all your messages and the other means it can't.

Transport encryption has been the default for almost all internet traffic for some years so it's no longer something that you can reasonably not have.

Re: Et Tu, Signal?

#454
post #363

Earlier quoted context omitted.

As we've seen from XMPP and Matrix federation comes with it's own set of tradeoffs. Matrix (specifically the element client) has come very far but it's still not at a state where I can reccomended it to non technical acquaintances.

My non-tehnical acquaintances are using it just fine. Any particular issues you've been having?

It's been a while since I checked it out but key management on encrypted group chats.

Re: Et Tu, Signal?

#455
post #454

Earlier quoted context omitted.

My non-tehnical acquaintances are using it just fine. Any particular issues you've been having?

It's been a while since I checked it out but key management on encrypted group chats.

Perhaps you tried it before key cross-signing? In that case, you had to verify each of your devices with each of your participants devices. Now you only need to verify once per participant. It's much better now in general.

Re: Et Tu, Signal?

#456

Earlier quoted context omitted.

The MobileCoin Foundation only publishes software, the nodes decide whether they want to run that software or not. Ultimately all of the nodes can run whatever code they want and call it MobileCoin if they can agree upon it. The governance is actually quite simple: a set of decentralized nodes individually choose what software to run and who to peer with. Consensus is an emergent property of that trust graph.

What do you do differently from Stellar or Ripple at the consensus layer which both started out with similar ideas, but quickly found that their validators fall apart due to the strongly-connected validator set requirement not being met? In other words, how do you avoid the exact same fate that both Stellar and Ripple ran into in their consensus models when they also tried to let "node individually choose"?

Consider asking this on their community forum to get more eyes on it: https://community.mobilecoin.foundation

Re: Et Tu, Signal?

#457

Earlier quoted context omitted.

Do you have any examples of Moxie talking about needing to keep up with the Joneses?

Yes in the other article in Wired that was on here he said they felt like it was important to add this feature because other messenger clients we're adding it. That was one of his primary justifications for it along with the promise of adding privacy to payments and making that mainstream, like they've attempted to do with encryption.

I found a quote from Goldbard in the article: "To be frank, there's a moral imperative to do so, because Signal has to offer payments in order to remain competitive with the world's top messaging apps."

https://www.wired.com/story/signal-mobilecoin-payments-messa...

Re: Et Tu, Signal?

#458

Earlier quoted context omitted.

> I've always hesitated to recommend Signal to people due to Moxie's attitude towards the more traditional security and privacy community where things like federation and open source are respected concepts. My understanding is that is a part of the amateur 'security' community, not the professional or expert one?

Why would you think that? And what is the amateur 'security' community?

>>> I've always hesitated to recommend Signal to people due to Moxie's attitude towards the more traditional security and privacy community where things like federation and open source are respected concepts.

>> My understanding is that is a part of the amateur 'security' community, not the professional or expert one?

> Why would you think that? And what is the amateur 'security' community?

Hi - I think that because IME federation and open source are heavily emphasized by amateurs, and much less so by professionals.

By amateur 'security' community, I mean nothing more than it sounds - non-professionals who focus on security, among a constellation of other issues.

My point is that the arsome's comment (the first one) uses "traditional security and privacy community", and I want to clarify what that means. Among professionals, Moxie is much more traditional than the amateurs are, as I understand things.

Re: Et Tu, Signal?

#459
post #7
post #2

Shit. Just as I convinced all my family and friends to move out from whatsapp and I uninstalled the stupid green app. What do we get to do now?

Can't the user just ignore this cryptocurrency BS if they (like myself) have no intention of using it?

Problem is that with the cryptocurrencies, it opens the app to whole new financial legal frameworks and agencies.

Not to mention that with the number of scams with cryptocurrencies It's not inconceivable that either Apple or Google will eventually ban them from App store (apps using cryptos)

Post reply on HN