Live data from Hacker News

Soatok's Informal Guide to Threat Models

soatok.blog

51–55 of 55 posts

Re: Soatok's Informal Guide to Threat Models

#51

Earlier quoted context omitted.

> Please remember that Dhole Moments is a furry blog before complaining about the furry art. It gets exhausting. Articles about cybersecurity gets 100% credibility when made by furries.

I wonder what the reaction would be if the folks beyond the HN crowd understood the extent to which the internet runs on queer / trans / catgirl / furry power?

I have it on good authority that Vint Cerf was one of the original catgirls.

Re: Soatok's Informal Guide to Threat Models

#52
post #45

Earlier quoted context omitted.

> Do we have reason to suspect Google and Cloudflare have inside knowledge about quantum computers? Yes. Both have internal global security orgs that are constantly communicating with other large companies and governments. If they are accelerating (as are others), it is a signal. The reliability of that signal is up to the reader to determine. https://www.microsoft.com/en-us/security/blog/2026/06/30/mic...

> Advances in quantum research and development have shifted the risk horizon. We believe cryptographically relevant quantum computers could arrive sooner than previously expected Aaand, there’s no citation, no reference or link for further reading, no justification for the claim. Not the most reliable signal.

[deleted]

Re: Soatok's Informal Guide to Threat Models

#53
post #45

Earlier quoted context omitted.

> Do we have reason to suspect Google and Cloudflare have inside knowledge about quantum computers? Yes. Both have internal global security orgs that are constantly communicating with other large companies and governments. If they are accelerating (as are others), it is a signal. The reliability of that signal is up to the reader to determine. https://www.microsoft.com/en-us/security/blog/2026/06/30/mic...

> Advances in quantum research and development have shifted the risk horizon. We believe cryptographically relevant quantum computers could arrive sooner than previously expected Aaand, there’s no citation, no reference or link for further reading, no justification for the claim. Not the most reliable signal.

> Aaand, there’s no citation, no reference or link for further reading, no justification for the claim. Not the most reliable signal.

You're thinking like this is an academic release, it is not.

This is more like a caution signal given by multiple global corporations with close ties to intelligence agencies, in some cases being State actors for intelligence. NSA and CIA release products, but they try not to leak their methods and sources. Same applies.

Re: Soatok's Informal Guide to Threat Models

#54
post #49

Earlier quoted context omitted.

> Soatok seems unable to acknowledge that centralisation is a real (privacy, security, reliability, political, …) concern here, nor to see value in the decentralised (federated/P2P) alternative protocols implementing the same double-ratched/PFS crypto primitives. I genuinely do not understand where this impression is coming fron. The only thing I've ever written about this topic acknowledges that centralization has r…

> I genuinely do not understand where this impression is coming fron. I don't want to engage in a citation battle, I just can't care enough for that. Having read those posts about Matrix, XMPP (OMEMO) and a couple others, many months/years ago, they really came across as "screw those amateurs for even trying, Signal is great, and by my very definition of it, only Signal can be". Again, those are not your words, but s…

Let me distill this down to its most basic structure to make sure I'm understanding you.

Supoose we're trying to decide between two services for a long term group chat.

Service A, on the server-side, sees all messages, in plaintext, sent to/from all participants--including other servers. It can log it indefinitely. It sees the whole social graph. Some servers have no k-anonymity (self-hosted, single user), some have thousands of users. They're all over the world, including in jurisdictions the NSA's TAO can operate.

Service B can only see IP addresses and ciphertext. There's only one real 'server", but it has millions of users and the encryption is widely reputed by experts. Its servers happen to be hosted on American cloud providers.

By firmly disagreeing with the linked post, you are saying you prefer Service A on the matter of privacy, only because of the jurisdiction.

Is that really the hill you choose?

Re: Soatok's Informal Guide to Threat Models

#55
post #49

Earlier quoted context omitted.

> I genuinely do not understand where this impression is coming fron. I don't want to engage in a citation battle, I just can't care enough for that. Having read those posts about Matrix, XMPP (OMEMO) and a couple others, many months/years ago, they really came across as "screw those amateurs for even trying, Signal is great, and by my very definition of it, only Signal can be". Again, those are not your words, but s…

Let me distill this down to its most basic structure to make sure I'm understanding you. Supoose we're trying to decide between two services for a long term group chat. Service A, on the server-side, sees all messages, in plaintext, sent to/from all participants--including other servers. It can log it indefinitely. It sees the whole social graph. Some servers have no k-anonymity (self-hosted, single user), some have…

I'm saying that if Service B is under a jurisdiction that has export control regulations (i.e. all of them) and somehow decides that "users from country X are non grata" ; or under a jurisdiction that oppresses on the basis of your political beliefs, skin color, sexual preference… (both of which characterise the current Trump administration, under which Signal operates) then the service operator has no choice but to lock you out of your account, making the whole cypher/crypto argument moot.
Post reply on HN