Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
mfwoods
searching Neon…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
1.
▲
by
mfwoods
6y ago
That's true, and in that sense it doesn't really matter if they publish the server source or not (although they really should continue to do so). What does matter is that the client was designed with a possible malicious server in
2.
▲
by
mfwoods
6y ago
No. The clients are open source, and (at least on Android) you are able to verify that the source on Github is the same that was used to compile the client on Google Play with reproducible builds [1]. And even if the servers turn out to be
3.
▲
by
mfwoods
6y ago
But you can verify that the source they publish on Github is the same that was used to built the Google Play version with reproducible builds[1]. Also, Android apps are fairly easy to decompile. They are very likely to get caught if they pu
4.
▲
by
mfwoods
7y ago
It's not, once linked the desktop client can be used independently of your phone.
5.
▲
by
mfwoods
7y ago
> Can I use Signal from desktop only? Yes, the desktop client functions independently from the phone client once linked (so not like whatsapp that proxies everything through your phone). > Can I create an account from desktop? Technic
6.
▲
by
mfwoods
8y ago
Because there is no end to end encryption (other than some very limited temporary one on one chats that only work between two mobile devices) which means the server can (and does) read and store all your messages. Getting access to your ful
7.
▲
by
mfwoods
8y ago
Not necessarily. But storing them in plain text on the server and all history accessible just by hijacking a phone number (or a single text message) is, considering the alternatives, don't you agree?
8.
▲
by
mfwoods
8y ago
I assume they removed it because they don't want anyone to use old insecure code. The RedPhone server hasn't been used for years now and was replaced with a better implementation. You're right there's no official support
9.
▲
by
mfwoods
8y ago
Only the encryption layer of the protocol is the same, they are not really compatible otherwise. I assume it's a design trade-off when you have E2EE and don't store any messages on the server. With Signal (and I assume Wire) you h
10.
▲
by
mfwoods
8y ago
> not proxying through your phone which Signal used to do and maybe still does This is what Whatsapp does. Signal never did and has real multi-device support. > and the Signal server is closed source It's not: https://
11.
▲
by
mfwoods
9y ago
Just because it's on a keyserver doesn't mean it's trustworthy. Keyservers do no verification of any kind on the keys they host. If you(r system) trust the certificate that https://updates.signal.org/ is usin
12.
▲
by
mfwoods
9y ago
You can build it yourself from source. While it's true that the debug version uses different servers, the functionality is there and can probably be enabled in a production build with little modifications. This might get you started:
13.
▲
by
mfwoods
9y ago
You're right, I clarified it a little.
14.
▲
by
mfwoods
9y ago
You still need a phone with a registered Signal on iOS or Android initially to activate the desktop version (sorry if that wasn't clear), but you can turn your phone off after. Edit: It actually has the option to register without smart
15.
▲
by
mfwoods
9y ago
For those that don't want to enable Javascript, these are the hidden Linux instructions: $ curl -s https://updates.signal.org/desktop/apt/keys.asc | sudo apt-key add - $ echo "deb [arch=amd64] https:
16.
▲
by
mfwoods
9y ago
Signal Desktop works without having your phone turned on. It acts like a full, independent client after linking it to your smartphone app (unlike WhatsApp, which does require your phone to be turned on).
17.
▲
by
mfwoods
9y ago
> Also, video chat has been in beta since March 2017. Video chat actually came out of beta in March [0]. The beta was released in February. [0] https://whispersystems.org/blog/signal-video-calls/
18.
▲
by
mfwoods
10y ago
Actually, Signal works without routing the messages trough your phone. Instead they use a browser extension to store the keys client side, which acts as a full client with its own, separate keypair. You could even register only the browser,
19.
▲
by
mfwoods
12y ago
I don't think they intend to contribute back to the original OpenSSL code base, but see this as a OpenBSD only fork.
20.
▲
by
mfwoods
12y ago
That's because there is no video. It's a sound fragment to which they added a single photo (not a render) to make it a video (why? no idea).
21.
▲
by
mfwoods
12y ago
Thanks for reminding, almost forgot about that.
22.
▲
by
mfwoods
12y ago
I just installed update openssl_1.0.1e-2+deb7u5 and libssl1.0.0_1.0.1e-2+deb7u5 on debian wheezy, so it seems the fix is now available.
23.
▲
by
mfwoods
13y ago
Not only that, but these bases usually also have a non-trivial contribution to the local economy. Especially in smal(ler) towns, I'd expect there are quite some people who'd rather have a job because of those bases (directly or in
24.
▲
by
mfwoods
13y ago
According to Wikipedia[1] over 80-90% (or $163 million in 2011) of Mozilla's funding comes from Google. I'd love to see Mozilla be more independent from Google, but I don't think they're going anywhere without them anyti
25.
▲
by
mfwoods
13y ago
I'm not sure what this adds over applying PGP on the server? The way to intercept the message with the server doing PGP would be to either MITM the connection or breach into the server to intercept before encryption. In both cases you
26.
▲
by
mfwoods
13y ago
That small print to use a local account from 8.0 was moved one extra click away to the page you get on when you click on the button to register a new Microsoft Account in 8.1. So it's still there but you have to really look for it.
27.
▲
by
mfwoods
13y ago
Strictly speaking, the minimum should be 4, because TLDs could accept email too (resulting in a@ca).
28.
▲
by
mfwoods
13y ago
I wonder how many of them have a first name starting with a C and saw this contest. I'm guessing none.
29.
▲
by
mfwoods
13y ago
They're also giving away free tickets to Paris for anyone who can prove they're named C. Sans. I don't think that's a very popular surname in The Netherlands.
30.
▲
by
mfwoods
13y ago
He confirmed that Snowden is in Russia. Maybe he wants to get asylum first before he leaves for Ecuador.
More ›