5 ms·
I feel like Signal is held to a ridiculously high bar when it comes to anything. Is it perfect? No. But come on now; I see other threads on HN where people are
by Caligatio 6y ago
I feel like Signal is held to a ridiculously high bar when it comes to anything. Is it perfect? No. But come on now; I see other threads on HN where people are debating/bashing their use of Intel SGX, really?
Assuming you trust the client builds (or use a verified build) and verify the public key, all of these arguments go out the window with the exception of exposing your phone number. This situation seems like a prime example of a company (Signal) being so transparent that people need to find fault.
- meibo 6y agoMessages arriving out of order when you switch devices and missed notifications isn't supposed to be a high bar for a messenger. Telegram and WhatsApp get these things right, Signal is just lacking at the moment.
- o-__-o 6y ago>when you switch devices Signal requires and only supports a single mobile device, you can link multiple desktop clients to a mobile device. But one cannot have signal on multiple devices.
- Evidlo 6y agoWhy is not wanting vendor lock-in a high bar? After dealing with Messenger, WhatsApp, Face time, etc all my life I'm tired of it. It doesn't matter if the code is open source, I'm still going to be locked in when all my friends move to Signal.
- Caligatio 6y agoI understand what you're saying but I don't know if calling it vendor lock in is quite correct. You can export your list of messages out of Signal and presumably import them to whenever you motivated to do so. Your friends could then join you on the new service and life would continue on. I am personally unaware of any communication service with a universally portable user identifier and that allows you to freely switch upstream providers other than phone service. I think this what you're talking about?
- names_are_hard 6y agoWell... yes, email and sms and telephone. They're protocols that anyone can decide to support and participate in. Honestly SMS was a good solution for my needs for 1:1 messages, it just didn't properly evolve to support the f a featureset we expect from modern messaging.
- Caligatio 6y agoI was actually thinking about this before I posted and discounted email. It has high interoperability but you cannot move your email address to a different provider if you didn't opt to use a domain you owned. This is obvious when you say it but I can port my phone number between phone companies whereas I cannot move my Gmail address to a different email provider.
- Evidlo 6y agoYou can see some proposals for server migration/fallback here: https://github.com/matrix-org/matrix-doc/issues/915 https://github.com/matrix-org/matrix-doc/issues/915
- skinkestek 6y ago> I feel like Signal is held to a ridiculously high bar when it comes to anything. Maybe I can help: I feel Signal is doing a lot right and if I need to send a message right now and be 99.999% sure nobody except the recipient can read it, Signal is my choice. My criticism is mainly directed not at Signal, but at the people trying to promote Signal by trying to trash every other messaging technology. The reason is that until Signal solves: - backups - stable API available for everyone (I don't think they have one) - bots (I mean a bot API for creating bots) - large groups - a number of ux issues - and allow armed forces and other groups that need it to run their own servers ... until then there will be room for other messaging solutions. I'll take it a step further: - if you would be happy to stuff it in a physical envelope - or send it by email - and you don't hold a grudge against Facebook or are willing to live with the thought of FB knowing who you talk to and when then you can safely send it by any messaging service. Fighting about which just keeps people using sms or email, both trivially interceptable by a number of parties. TLDR: 1. Signal is fine, excellent AFAIK 2. there's room for other messaging services as well 3. one doesn't make Signal better by trying to trash other messaging solutions
- fao_ 6y ago> - and allow armed forces and other groups that need it to run their own servers if you can afford to run your own servers, then you can afford to run a build server too and push your own releases with the server patched.
- skinkestek 6y ago> then you can afford to run a build server too and push your own releases with the server patched. I think you are looking in the right direction. The cost for servers were never the reason why others aren't running their own Signal networks AFAIK.
- bromonkey 6y agoI want none of this stuff in a messaging app, it's not a social media platform.
- vbezhenar 6y agoIf they're transparent, why don't they expose their commits to server code to the public?
- Caligatio 6y agoThis is a great example of what I'm talking about. Are you also commenting how you can't see the source of your phone's baseband, Google's services, your ISP's router firmware, WhatsApp's servers, Facebook's service's, etc? Because Signal's client is open source it's considered a unique-to-Signal downside that we don't have access to the server's source. I feel like some people would bring up the server source issue if someone was asking if it would be a good idea to migrate off of Facebook Messenger.
- bilal4hmed 6y agoWell Signal has put itself as a high privacy option, we are open, check out our code. Well we can check the client code but we dont know what you are running on the server. FB, Google etc never claimed to be open source with their infrastructure. So if WhatsApp cant be trusted as to what happens on the server, right now neither can Signal. Can Signal show that what they are running on the server is the same as whats on Github? Are we just trusting them because we have been trusting them all along?
- Caligatio 6y agoYou don't need to trust the server with E2E encryption. If you can review and trust the client, the server only has access to the information that the client sends. Even if they release up-to-date server code, we have no way to confirm that's the code that's running on their servers. People would then complain that they don't have shell access to the servers to ensure the code is what is expected.
- bilal4hmed 6y agoWell one way you could confirm is to run your own instance of the server and run the client against it and the client works as if you are going against Moxie's server Right now if you run the published server code and point the client certain features don't work. Doesn't that sound a little concerning ?
- jokoon 6y agoIf the goal is to protect yourself from the NSA, switching from WhatsApp to signal is not going to change things. Signal could well be a honey pot software designed to attract people who don't want to be listened to by the NSA. I agree that signal is secure and oriented towards privacy, two different things.
- Caligatio 6y agoI believe you're talking about a hypothetical but are you saying that the E2E crypto in Signal is flawed and therefore useful as a NSA honeypot? We've seen from previous subpoena that Signal really only does retain the limited data they claimed and the content is auditably correctly encrypted.