Live data from Hacker News

Signal 2.0 released with private messaging support

whispersystems.org

51–60 of 174 posts

Re: Signal 2.0 released with private messaging support

#51
post #37

What's the difference between this and Telegram? I'm starting to feel a bit overwhelmed with what messaging app I'm supposed to use. Also, why is ios8 required?

I'm a Signal/TextSecure contributor. There's been a lot of controversy over the Telegram encryption protocol, and any cryptographer that looks at it cringes.

Beyond doubts with the protocol itself, I think the more important consideration is that most people never use it. Telegram is not encrypted by default. Users have to create a special "secret chat" with contacts that is ephemeral, and some Telegram clients don't even support that mode. Last I checked, there was no way to have group "secret chats" in any client at all.

The result is an unfortunate situation where many users seem to think that Telegram is somehow secure by default, when it definitely isn't. Telegram even stores plaintext copies of everyone's entire message history on the server for multi-device sync.

Re: Signal 2.0 released with private messaging support

#52
post #30
post #25

Earlier quoted context omitted.

I'm just astonished that there's even justification for it not being an option. Bang on about easy discovery all you want, there's lots of people who don't want to give out their phone number for no good reason to some strangers.

Get a Google Voice number (Free. Use throw away account) and use that. There are instructions out there on how to connect a Google Voice number to Signal.

I don't want to get any number. I want to have any number of throw-away accounts active in parallel on every device.

Just as with jabber, e-mail, IRC and every other open messaging technology.

Re: Signal 2.0 released with private messaging support

#53

How is it working out? Is the messaging solid between Android and iOS? How is the group messaging working? Sorry, I just downloaded it, but I have no friends on the list yet. I'm impatient. I really want it to work.

I've been using textsecure for a long time now: so far I haven't had any issues messaging new iOS users including mixed groups. In my experience, there might be some mms edge cases when mixing with other messaging apps, but not too many and bug reports are monitored regularly on github.

I gave up on TextSecure after I irrevocably lost several MMS photos that were sent to me :(

Re: Signal 2.0 released with private messaging support

#54
post #31
post #25

Earlier quoted context omitted.

I'm just astonished that there's even justification for it not being an option. Bang on about easy discovery all you want, there's lots of people who don't want to give out their phone number for no good reason to some strangers.

This is nowhere nearly as simple as "you just published your phone number to TextSecure": https://whispersystems.org/blog/contact-discovery/ It is a very real security issue, too. What Matt Blaze is talking about with "extra namespaces" is a giant piece of attack surface TextSecure is avoiding.

You keep talking about "discovery".

I don't want to be discovered.

I don't want my Signal identity to be tied to any phone number.

Re: Signal 2.0 released with private messaging support

#56
post #25
post #21

Earlier quoted context omitted.

I agree with 13. There needs to be a way to have an account that is not tied to a SIM card or any kind of phone number. I'm frankly astonished there's even a debate about that.

I'm just astonished that there's even justification for it not being an option. Bang on about easy discovery all you want, there's lots of people who don't want to give out their phone number for no good reason to some strangers.

Having a way to work without a phone number would also be a requirement to use it on a desktop/laptop or tablet.

Re: Signal 2.0 released with private messaging support

#57
I installed it and texted my friend.

It never asked me to verify his pubkey.

How does key management work? Is it all done through Whisper Systems' servers? If that's the case, how is this effectively better than iMessage? iMessage is also (nominally) quite secure, except for the fact that you have to trust Apple to verify pubkeys, which makes it quite feasible to MITM if you can subvert Apple via legal or technical means.

Re: Signal 2.0 released with private messaging support

#59
post #57

I installed it and texted my friend. It never asked me to verify his pubkey. How does key management work? Is it all done through Whisper Systems' servers? If that's the case, how is this effectively better than iMessage? iMessage is also (nominally) quite secure, except for the fact that you have to trust Apple to verify pubkeys, which makes it quite feasible to MITM if you can subvert Apple via legal or technical m…

Keys are trusted on first use, similar to SSH. The app also provides an interface you can use to verify fingerprints:

https://github.com/WhisperSystems/Signal-iOS/wiki/FAQ#can-i-...

Post reply on HN