Live data from Hacker News

We can do better than Signal

icyphox.sh

1–10 of 290 posts

Re: We can do better than Signal

#2
I wanted to disagree with the headline. Then I read the article and do see their point.

I’ve been a big proponent of Signal for years and donated for the first time during their outage.

But I do think this is a conversation worth having.

I’d also like to understand more about this:

> In fact, the Signal server code [0] hasn’t even been updated since April 2020. You’re telling me it’s undergone no changes?

[0]: https://github.com/signalapp/Signal-Server

Re: We can do better than Signal

#5
Being limited to a phone app and requiring phone numbers is severely limiting as well. Matrix is probably the current best-positioned e2e chat app that should be able to encompass more use cases, but it's difficult to convince users to use anything encrypted when alternatives have more network effects and usability.

Network effects always seem to be particularly egregious gatekeepers for social apps, often keeping users on inferior alternatives for years or decades, as coordinating a mass-switch is too difficult (Signal got particularly lucky with a few recent events or it wouldn't have nearly as many users switching to it right now).

Re: We can do better than Signal

#8
I'm confused about this piece. If there's true E2E encryption (verified by open source client code and review of released binaries) then why does it matter if the server code is backdoored or not? The whole point of E2E is that you don't need to care about the server being able to ever see the text of your messages because it never can.

Re: We can do better than Signal

#9
So one of the things that feels the most damning to me about Signal-like protocols is that you have to inherently trust their server.

Consider this paragraph from the Signal protocol

> ...For example, they may compare public key fingerprints manually, or by scanning a QR code. Methods for doing this are outside the scope of this document.

> If authentication is not performed, the parties receive no cryptographic guarantee as to who they are communicating with.

I have not known anybody that actually does this. If an active attack does happen on somebody, I'm pretty sure they would not notice.

As far as I understand, a decentralized model solves this problem. Don't trust the server? Run your own instance or have some other way of validating clients (via your own PKI infra or similar).

Re: We can do better than Signal

#10
I'm a bit annoyed at "we can do better than X" when, you know what? Maybe we can't.

Yes, it's nice that you and I can install Element and deal with the finicky crypto handshake that for some reason always shows red for me because a friend opened the web UI and closed it before he completed the handshake and now we can never actually make that check go green, and it's nice that Mastodon is distributed but mastodon.host went down one day with all my toots without a word from the administrator, and yeah I know I should have picked a better host (though if you could predict that mastodon.host will die why didn't you tell me?), but my mom can't.

Users value their convenience, and security and privacy are inconvenient. Hell, we started decentralized and over email and newsgroups and personal websites and blogs and it's all Facebook Facebook Facebook now that the Eternal September came around.

If we could do better, we would have done better by now.

Post reply on HN