Live data from Hacker News

Signal Foundation

signal.org

71–80 of 298 posts

Re: Signal Foundation

#71
This is very very good news.

As a heavy Signal user, from where I sit I personally see the following clear needs:

-Better group support. Right now, to do a group in Signal you have to name the group, which makes it kind of a pain to create ad hoc quick groups. I'm forever naming them "John Sue Bill" or "Jane Roger Amanda". iMessage, by contrast, just automatically makes a group without a name. You get a thread for that group, so you can follow the discussion clearly, and you can leave the group, but it hides the nuts and bolts of the fact that a group has been formed. Also, Signal has no per-group notification settings, so if you're in a "noisy" group your only option is to turn off notifications universally (including one-on-one messages and other groups) or live with it. Lastly, you cannot form a group from Signal Desktop.

-Better support for long messages (or a new product using the same network and security). Signal was clearly designed for short session lengths — brief messages that are composed quickly. But as it has become the catch-all app for encrypted comms — "just use Signal! PGP email sucks!" — many people, at least that I deal with, are trying to use it for email-type purposes. Long messages with arbitrary attachments. It would be nice if, like, putting a line break in a long message didn't mean hitting Control-Enter or Command-Enter. It might even be nice if you could have multiple threads with the same recipient. You know, like email. I am not holding my breath on this one. But if people could email as securely as they chat, using Signal protocol, it would be a huge leap forward in keeping the NSA out of our business. Not to mention Google/Gmail's ad clients etc.

-Ability to search. I can't full-text search my messages, even within Signal. As I use it more and more, this is a hindrance.

-Group video chat. This is very pie in the sky. But a lot of sensitive comms involve groups — think of people organizing a protest, or a corporate takeover, etc. And right now there are few private options.

Re: Signal Foundation

#72

This is a bit of a tangent, but I first heard of Intel SGX (Secure Guard Extensions) via Signal's blog post about secure contact sharing[0], so it's almost relevant :p From what I've read[1][2][3], Intel SGX is vulnerable to Spectre exploits. Does anyone know if this has changed Signal's approach to security at all? Granted, contact sharing was a technology preview, but I'm curious if SGX is still considered a feasib…

Signal's use of SGX was to increase users' trust in Signal - OpenWhisperSystems couldn't log your contacts even if they wanted to. Its up to potential users to decide if they think OpenWhisperSystems will surreptitiously perform an attack on their own secure enclave to secretly log your contact information.

Re: Signal Foundation

#73

This is a bit of a tangent, but I first heard of Intel SGX (Secure Guard Extensions) via Signal's blog post about secure contact sharing[0], so it's almost relevant :p From what I've read[1][2][3], Intel SGX is vulnerable to Spectre exploits. Does anyone know if this has changed Signal's approach to security at all? Granted, contact sharing was a technology preview, but I'm curious if SGX is still considered a feasib…

Regarding the SGX enclave and contacting sharing, the blog post announcement dated 26 Sept 2017 says 'deploying into production...over the next few months'. Can we assume that's happened already? Or are contacts still being exchanged in a way that would allow a middle man to reconstruct an individual's social graph?

Re: Signal Foundation

#74

Earlier quoted context omitted.

I'm not sure of your assumption that lack of total anonymity implies no privacy. They are independently important concepts. You can have privacy (no knowledge of information shared) without anonymity.

That's true, but I believe the concern would be that there's information just in knowing: 1) what's your number, and 2) with whom you connect or communicate. That is, there's still the danger of social graph analysis: "Oh look, this person's communicating with a known journalist!"

The phone network can do that just by correlating traffic to devices, it doesn't need any help from the software running on those devices.

If the target use case was people that could reasonably do the job of limiting the information just the use of their devices leaked, it might matter. But the target use case is replacing SMS and the like, so it really doesn't matter (except that people want to pretend that the use case is something other than replacing SMS).

https://medium.com/@thegrugq/signal-intelligence-free-for-al...

Re: Signal Foundation

#75
post #44
post #39

Earlier quoted context omitted.

Telegram is available on F-Droid. It's similar to Signal with more functionality and greater ease of use - https://f-droid.org/packages/org.telegram.messenger/ You need a phone number that can receive texts for the initial setup, but once you're set up people can add you by @username and never need your number. Stuff like https://www.textnow.com/downloads works just fine for the initial text. Once you have a single d…

Telegram isn't remotely similar to Signal. Telegram communications aren't encrypted by default, and Telegram group chat messages aren't encrypted at all .

This is 100% false. EVERYTHING that goes over the wire is encrypted, always, just like when you're on a TLS website such as your bank.

Group chats aren't end-to-end encrypted, and 1 on 1 chats are only end-to-end encrypted if you make it a Secret Chat.

Re: Signal Foundation

#76
post #8

This is freakin' awesome: A non-profit foundation with $50 million in the bank dedicated to providing usable encryption to the general public, with no other agenda other than the public good. Go read the blog post by Moxie and Brian Acton (who is joining Signal). Very exciting!

I hope they eventually develop a federated , privacy oriented messaging protocol, once the rapid technological evolution settles down. I know Moxie's position on federated protocols [1], but I think we must eventually agree that an open environment with a multitude of providers and implementations is the only way to provide long term privacy - any single provider is vulnerable. It would also be a very useful tool in…

Users don’t want federation.

See also: Adoption failure of Google Talk XMPP, massive adoption of Facebook Messenger and Whatsapp, and AIM before it.

I wish it were different, too.

Re: Signal Foundation

#77
post #27

Any reason Signal isn't available through F-Droid? It may be unjustified but I'm not a big fan of installing privacy conscious apps through Play. Edit: Wait, haven't installed anything yet, but I read the getting started guide. I have to sign up using a phone number? That throws all expectation of anonymity and thus privacy out the window.

The phone number is the contact discovery mechanism on Signal. If you don’t want that, you don’t want Signal.

Me and the persons I want to communicate with are perfectly capable of finding eachother through other means - ids, qr codes, ...

At the same time, maybe I don't want everybody who has my phone number to see that I am on Signal.

Re: Signal Foundation

#78

Since you are in the US how do you keep the US government from interfering with your mission because Signal uses strong encryption? How do you address the EARs (Export Administration Regulations) and ITARs (International Traffic in Arms Regulations)? These regulations look like a tar pit to me.

My experience is that government and gov't contractors have been turning their heads. The proliferation of E2E communication has been too fast to analyze and regulate with respect to WWII era regulations, similar to how cryptocurrency is to the financial market.

Interesting to note:

>Publicly available software under the EAR, as under the ITAR, is exempt from export control. However, before strong dual-use encryption code is made publicly available via the internet or otherwise placed electronically in the public domain, exporters must provide the US Government with either a copy of the strong dual-use encryption code or a one-time notification of the internet location (URL) of the code. This must be done before making the software publicly available. Notification after transmission or transfer of the software outside the US is an export control violation

https://doresearch.stanford.edu/strong-encryption-export-con...

edit: More guidance on what's exempted from EAR is at https://www.bis.doc.gov/index.php/policy-guidance/encryption...

Re: Signal Foundation

#79

Since you are in the US how do you keep the US government from interfering with your mission because Signal uses strong encryption? How do you address the EARs (Export Administration Regulations) and ITARs (International Traffic in Arms Regulations)? These regulations look like a tar pit to me.

Chrome, Firefox and IE ship with very strong encryption (128 bit AES) just fine for many years now.

That cat is out of the bag.

Re: Signal Foundation

#80
Like I recommended for Mozilla, they could use this money to acquire and/or create highly-usable alternatives to many products that are about handling communications or data in trustworthy way. Things like SpiderOak, VPN’s, backup apps for iOS/Android, HSM’s, payment services, paid email… anything that unscrupulous businesses have been a problem for with insecure solutions or them just cheating customers. Each one is turned into a commercial product either shared source or dual-licensed GPL/AGPL. The money coming in improves each both for new features and 3rd party review. Release code as GPL either on component level as they are built or as a whole after development cost was paid for. Many businesses will still pay for GPL-licensed code just to know someone is responsible for it.

Such models will gradually increase the number of trustworthy goods available through trustworthy suppliers over time. That’s the basic concept anyway.

Post reply on HN