Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
jlund
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
7 ms
·
1.
▲
by
jlund
4y ago
Hey, HN. While I was helping a friend set up their new iPhone, I noticed that they were prompted to upgrade to a newer version of iOS. When I checked my own phone, I saw that the update had been released more than two weeks earlier — but I
2.
▲
Show HN: Actually Automatic – Get notified when Apple releases a new iOS update
(github.com)
9 points
by
jlund
4y ago
|
2 comments
3.
▲
by
jlund
6y ago
The Nginx configs use modules that are not compiled by default, so most preexisting Nginx binaries in mainstream distros won't work.
4.
▲
by
jlund
6y ago
Does this help? https://signal.org/docs/
5.
▲
by
jlund
6y ago
Just to clarify, the bug you're talking about was in WebRTC. We submitted a patch upstream: https://webrtc-review.googlesource.com/c/src/+/175960
6.
▲
by
jlund
7y ago
Google Play Services aren't required to run Signal on Android either.
7.
▲
by
jlund
7y ago
https://signal.org/blog/license-update/
8.
▲
by
jlund
7y ago
Nice breakdown! Just to clarify, in step 2 of your "Recovery of the secret (by the client)" section, the client is retrieving `split2`, not `split1`.
9.
▲
by
jlund
8y ago
You can read more about the Registration Lock feature here: https://support.signal.org/hc/en-us/articles/360007059792-Re...
10.
▲
by
jlund
8y ago
The Contacts permission is completely optional, and contact information is never stored: https://signal.org/blog/private-contact-discovery/
11.
▲
by
jlund
8y ago
It does. Signal supports runtime permissions[1] and it requests them dynamically while you are using the app (e.g. the camera permission prompt appears the first time you try to take a picture). 1: https://developer.android.com&#
12.
▲
by
jlund
8y ago
Everything in Signal is end-to-end encrypted.
13.
▲
by
jlund
8y ago
I was incorrect about this, and I apologize.
14.
▲
by
jlund
8y ago
Just one additional note that might not be immediately clear from the advisory: Exploiting this requires the attacker to first manually place malware (a malicious JavaScript file) on your computer or on a Samba network share that your compu
15.
▲
by
jlund
8y ago
If the solution to censorship is to constantly switch to new hosts, it would be even easier to do this via a VPN (which wouldn't require you to rebuild your social graph at all, unlike a federated endpoint switch). If the more straight
16.
▲
by
jlund
8y ago
> Time to look for another option then That's the plan. This is covered briefly in the second-to-last paragraph. > so it was never really viable Signal remained running for more than a year and a half in several countries that we
17.
▲
by
jlund
8y ago
Let's say I have an account on a federated server and a censor then blocks my ability to access that server from my home country. While it's true that my friends on other servers might be able to send messages that will arrive on
18.
▲
by
jlund
8y ago
The loss of domain fronting as a viable strategy means that it will be possible to censor Signal in areas where the service was previously working.
19.
▲
by
jlund
8y ago
An aspiring censor could also "easily connect to the broader network" and masquerade as a federated server in order to discover others. This process could even be automated. Federated services also require an identifier, and this
20.
▲
by
jlund
8y ago
The technique that Signal was using to circumvent censorship (domain fronting) will no longer be possible on Amazon: https://aws.amazon.com/blogs/security/enhanced-domain-protec...
21.
▲
by
jlund
8y ago
Unfortunately, federation is not an effective tactic against censorship: https://news.ycombinator.com/item?id=16871352
22.
▲
by
jlund
8y ago
The relevant text is in the subject line of the email: "Notification of potential account suspension regarding AWS Service Terms"
23.
▲
by
jlund
8y ago
It's trivial to block several distributed hosts simultaneously. An aspiring censor would simply find the most common federated endpoints for a given service and block all of them. Only the users of that software would be affected. Ther
24.
▲
by
jlund
8y ago
Hey, everyone. We spent a decent amount of time at Signal trying to come up with alternatives when we first heard rumors that Google was disabling domain fronting on GAE. We're using Souq because it is popular in the countries where we
25.
▲
by
jlund
9y ago
Signal takes metadata protection very seriously: https://signal.org/bigbrother/
26.
▲
by
jlund
9y ago
Nothing about Signal itself is changing. This is Microsoft adopting the Signal Protocol for a new feature in Skype.
27.
▲
by
jlund
9y ago
I am in the perfect demographic for the Bolt: I am a previous Chevy owner (with a car that ran well for over fourteen years!), I want an electric car, and I'm not afraid of being an early adopter. I can't buy one. Chevy doesn'
28.
▲
by
jlund
10y ago
When an adversary intercepts a Telegram SMS authentication code, this gives them pretty much complete access to a user's entire Telegram messaging history. This is true because messages are not end-to-end encrypted by default. The Tele
29.
▲
by
jlund
11y ago
Yeah, I will probably make it possible to choose the list of services instead of singling out Tor specifically. I have heard from some users who only want to run Shadowsocks, for example. The diversity of services really helps keep things f
30.
▲
by
jlund
11y ago
I'm planning on implementing IKEv2 support in Streisand soon. I wanted to get OpenConnect/AnyConnect implemented first. I had not heard of OpenIKED until your comment, and I got really excited, but it looks like the portable versi
More ›