6 ms·
moxie has stated previously someplace that the goals are 1. Simple encryption for everyone to prevent mass data collection 2. Prevent targeted collection for t
by frayesto 11y ago
moxie has stated previously someplace that the goals are
1. Simple encryption for everyone to prevent mass data collection
2. Prevent targeted collection for the crypto enthusiasts
The main focus is on step 1. now and they are doing a great job at it. It's slow like anything new, but I managed to convince my parents to switch so that means it's working!
- hackuser 11y ago> 1. Simple encryption for everyone to prevent mass data collection Google might be the second biggest mass data collector, after the U.S. government. Using Chrome, one of Google's tools of collection (if I understand correctly), wouldn't seem to further that goal.
- kingkilr 11y agoCan you articulate a _specific_ threat model under which this extension fails to protect against mass data collection by Google? Or is this idle speculation.
- kuschku 11y agoGoogle adds Google Analytics to their browser, to automatically report what a user does in Chrome apps, and "accidentally" your whole chat history ends up on Google’s servers? This is not an unrealistic example.
- finnn 11y agolast time I checked Google Analytics doesn't record anything like that kind of data.
- kuschku 11y agoIt records where you click, and when. "Accidentally" logging keys is possible, as Google can modify the content of the JS on request – for example, in case of being served an NSL, Google can be forced to modify the JS to log that.
- linkregister 11y agoRun Chromium, problem solved.
- driverdan 11y ago> Google adds Google Analytics to their browser Source?
- kuschku 11y agoSomeone asked for a hypothetical way Google could, in the future, get the data. As you are doing automated updates, Google can just add Analytics to the browser, and even publish it as something "good".
- devit 11y agoThe threat is that Google (perhaps forced by the NSA, perhaps only for some users) modifies Chrome to include code that logs all keystrokes or specifically detects the Signal extension (or standalone app if Chrome is also installed) and uploads the plaintext of all messages to Google or to the NSA. In other words, you have to trust Google to not insert such a trojan by itself and to not bow down to the U.S. government should it try to secretly force Google to do so. You also have to trust that their security is good enough to prevent third parties from covertly performing such a feat. That's not say that Google should not be trusted or should be trusted less than other parties, but that's the threat.
- thatcat 11y agoThe android app already requires Google content manager to be installed, which is probably why the beta is android only. so its no different from the mobile app really.