Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
at612
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
at612
10y ago
> From a developer perspective however, encouraging or even tolerating unofficial installation channels for secure communication software is bad. What is your threat model?
2.
▲
by
at612
10y ago
> I really don't see why someone should be on my shitlist for lying to godaddy dot com or whatever giant registrar unless you consider fudging identifying details about something that really doesn't matter, I think I can see wh
3.
▲
by
at612
10y ago
> Is OTR really a practical option? You message seems unclear about it. It depends on your threat model, like other alternatives. I have never initiated an OTR session myself, but I have received one from a contact in anger (whistleblowi
4.
▲
by
at612
10y ago
> It's free. You misunderstand. He is running a company, what do you think their exit strategy is? You may want to look at his previous company and "red phone", I think was his product called. > And normally one would a
5.
▲
by
at612
10y ago
Now gents, a number of you in the comments have wondered about what other alternatives are out there. You may have seen that I specifically advise against Signal, and other users have also expressed concerns about a number other application
6.
▲
by
at612
10y ago
>> Can I run a client from the Git repo and still use all of their infrastructure? > Yes. You can. The thing is, lucideer, the "restrictions" on the use of the source code are engineered to raise the barrier to independen
7.
▲
by
at612
10y ago
> I am really interested why Signal. Why not Telegram? And I would be really interested to know why people are downvoting a perfectly reasonable question.
8.
▲
by
at612
10y ago
> The suggestion that the motivation for this article is profit for the NYT or Moxie is quite destructive. No, that's literally how it works. Media need to sell copy (clicks these days) and companies need to get coverage. And that&#
9.
▲
by
at612
10y ago
Are you aware that the guy behind this signal app sold his previous "secure messaging" thing to Twitter?
10.
▲
by
at612
10y ago
> what's a reasonable heuristic for conducting private business? You need to do a threat analysis. I did not immediately find any good introductory resources via a quick Google search, but try it yourself. Very very briefly, it invo
11.
▲
by
at612
10y ago
> Re: Google Play Services. Here's is the way I understand this to work, so please do correct me if I'm wrong. > Signal uses Google Play Services to notify me that I have an incoming message from Signal. More importantly: a.
12.
▲
by
at612
10y ago
> I'd even argue it's free software Terminology. What you call free software I call open source. As you go on to mention, you can see the source but not use it in any meaningful way. In particular: > but have clarified tha
13.
▲
by
at612
10y ago
> I'm probably just inviting myself to get trolled by replying to this I'm sorry that you get that impression, but I do appreciate your input. > Cryptographer Matthew Green on Signal's crypto and code quality (it was ca
14.
▲
by
at612
10y ago
> Don't want to invest my time into something that will eventually sell out And what do you think the gentleman behind Signal is out there for? His modus operandi: * Start a company, call it something catchy, like Whisper Systems. *
15.
▲
by
at612
10y ago
Just wondering, but why not just use XMPP? You can choose any server that you like or trust, or run your own (on your own or third party infrastructure, up to you), and use OTR for end-to-end encryption if you feel you need to¹. I have been
16.
▲
by
at612
10y ago
> Neither Telegram nor WhatsApp are viable alternatives to anyone interested in privacy. Are you suggesting that the application under discussion here is a viable alternative? If so, how?
17.
▲
by
at612
10y ago
Download Signal? No, thank you. The fact that the guy behind it is hyping it via the New York Times, a generalist publication, instead of validating the thing through professional cryptographers (which he isn't) and recognised privacy
18.
▲
by
at612
10y ago
> It's 2016 and our best crypto messenger options are worse than what we had 10 years ago when Skype was peer to peer, or Jabber with federation. Actually, Jabber with OTR is pretty solid. If need be, you can use throwaway addresses
19.
▲
by
at612
10y ago
For me, the takeaway from that article is this: > Different people will have different testing strategies based on this philosophy, but that seems reasonable to me given the immature state of understanding of how tests can best fit into
20.
▲
by
at612
10y ago
> So distribute keys on smart cards that don't allow you to export the key That's what I covered in the second paragraph. :-) The thing is, both those implementations were a disaster from either a technological or a security po
21.
▲
by
at612
10y ago
> How do you distribute the one time pad in the first place? If you do it insecurely, it's a waste of time. If you can do it "securely", why not just use that secure channel to send the message in the first place? Because
22.
▲
by
at612
10y ago
> all the experts here Which experts? And what are those fundamental flaws?
23.
▲
by
at612
10y ago
> Just get the national government to distribute RSA USB keys to every citizen. I lived in a country that did exactly that. And it was a disaster. The keys were trivially easy to steal, even by accident (personal experience here), and yo
24.
▲
by
at612
10y ago
Exactly. I've had this happen with Dell. Twice, same computer. They ask for the defective drives back, which is fair. I informed them that as they contained company confidential information they would be put beyond use and they were fi
25.
▲
by
at612
10y ago
That's funny. I had a problem with my ADSL connection that lasted for over a month. I spent two hours and forty minutes on the phone, spread over, IIRC, 15-20 calls, with the cycle going 1. "What's the problem", 2. "
26.
▲
by
at612
10y ago
> I haven't seen the third step in the "Cue -> Habit -> Reward" cycle mentioned yet. Good point! I allow myself an Irn-Bru only on run days (and less than 10 miles doesn't count). I don't live in Scotland
27.
▲
by
at612
10y ago
Ironically, long distance running (10+ miles) is easier to do before breakfast, as an empty stomach is useful--digestion stops anyway as soon as your body is in need of some extra red cells to carry more oxygen. A trained person has enough
28.
▲
by
at612
10y ago
> Zuckerberg started The Facebook so people could get easily laid. Off to create a Facebook account, back in a moment. [ I wish this had been explained to me back in 2008 when it first came out and I couldn't see any use for it. ]
29.
▲
by
at612
10y ago
Highest or lowest? I do the latter, obviously, for reasons of self-preservation (learnt this from a dentist).
30.
▲
by
at612
10y ago
Well, I do not work in marketing (and I don't think he does, either) and I see where he's coming from. Like it or not, we (humans) are a social species. And so are bots, mind. :-)
More ›