10 ms·
Signal and Giphy
- mnx 10y agoThis is a clever way to do this, but it still seems like someone caring about their privacy should just do without gifs. Edit: I should rephrase - I mean someone with a larger-than-usual need for privacy, someone paranoid for a reason. This is great for the typical privacy concious user. But if I was sending documents to WikiLeaks, I would not sum them up with a cute GIF.
- nfrmatk 10y agoWhy should those of us who care about privacy be required to limit the media we use to express ourselves? By including this functionality Open Whisper Systems is giving the privacy conscious a way (albeit experimental) to have our cake and eat it too.
- CoryG89 10y agoI also think it's fine as long as they clearly communicate to the user that their search queries will be transmitted to a server not controlled by OWS.
- AndrewUnmuted 10y agoSomeone else made that media. They're the one expressing something. You, the consumer of that media, are just a distributor of their work.
- morsch 10y agoYou seem to think that those options are exclusive when in fact gif memes are a blatant example of how they aren't. The original creator of (say) a video expresses something, a remixer expresses something when they cut it into a gif, and you're expressing something when you send someone the gif in a conversation. The thing that's expressed is almost necessarily different, and each step involves creative choices.
- thaumasiotes 10y agoWhen Ben Franklin said "those who would give up essential liberty, to purchase a little temporary safety, deserve neither liberty nor safety", he was making the point that, in his eyes, it would be foolish for the government of Pennsylvania, seeking help from the Penn family, to give up their freedom to levy taxes on the Penn family. When someone uses the same quote today, are they making the same point? Martin Luther King was a full-throated advocate of affirmative action, which is to say applying penalties to white people for being white. When someone today talks about "a nation where [people] will not be judged by the color of their skin, but by the content of their character", are they supporting the same idea?
- proaralyst 10y agoIf your aim is to get more people to care about privacy, or to enable those who care about privacy to convince their friends to use a more private app, these things help.
- shalmanese 10y agoExcept that history has shown us that theoretically secure but feature deficient systems lose out to less ideologically pure systems that provide what users want, leaving the sum total amount of security provided to be less.
- kuschku 10y agoEDIT: Deleted the comment because the of attacks in responses, which I can’t respond to due to "Submitting too fast". @dang: If you want users to be able to actually discuss things, allow them to respond to comments attacking them. This is a retarded system.
- nickik 10y agoBasically everything in your comment is wrong. > The prebuilt Signal APK might in fact be completely malicious, you can’t verify anything. https://whispersystems.org/blog/reproducible-android/ https://whispersystems.org/blog/reproducible-android/ This is already more then for all other options. > And as Signal only tries to copy the features WhatsApp and co already have Thats simply not true. WhatsApp does not support gifs, for example. Signal also has some features that others don't. > they’ll get exactly the same security with WhatsApp, Telegram or Threema, and exactly the same features. Telegram is less secure by miles. Threema is less secure by yards. WhatApp is less secure by inches. > "You can create your own federated server" Signal has never claimed that you can "federate" the server. They only mentioned that this is a feature that they might work on in the future. Since they have publicly said that they are not gone do so.
- kuschku3 10y ago> Thats simply not true. WhatsApp does not support gifs, for example. Signal also has some features that others don't. Those are the most minor features. Most competitors have the exact same set of features. > Telegram is less secure by miles. Threema is less secure by yards. WhatApp is less secure by inches. With Signal, Telegram, WhatsApp, and Threema I have to trust their servers, but can verify the client is secure by reading source or reversing it. In neither case can I fork the client to make it more secure, and distribute that fork, while keeping the ability to communicate with users of the official client. > Signal has never claimed that you can "federate" the server. They claimed it would be possible in the future, and I – and many others – only switched to it because of that promise. Because we saw it as something with as much security and customisability as XMPP with OMEMO, but a nicer client. What niche does Signal fill that isn’t already filled by others? It has only minor feature advantages over competitors, and no trust or security advantages. EDIT: Using a second account because otherwise I wouldn’t be able to answer within of a few hours ("You are submitting too fast"...), and by then this discussion would be over.
- StavrosK 10y agoSomeone who wants gifs shouldn't have to compromise their privacy.
- mobiuscog 10y ago<facepalm.gif>
- deleted 10y ago[deleted]
- dmvaldman 10y agohttps://twitter.com/isislovecruft/status/793796012506750977 https://twitter.com/isislovecruft/status/793796012506750977 "Lol dude, I don't know what kind of whistleblowers, dissidents, spies, and revolutionaries you're messaging but mine send all the best gifs."
- mnx 10y agoSo, I am an "HN bro" now... Because I don't think this feature can possibly be up to the highest standards of security, despite being very cool and clever? I guess there are worse things to be called.
- finnn 10y agoAt what point has Signal ever indicated that they were targeting users that were trying to send documents to wikileaks (or require similar levels of privacy/security). They have consistently said they are trying to build a messaging app that normal people want to use over stopping targeted attacks. eg [0] [0]: https://news.ycombinator.com/item?id=10665520 https://news.ycombinator.com/item?id=10665520
- mnx 10y agoWell, than I guess I got the wrong idea about them. I thought WhatsApp was supposed to be "for the common people", and Signal was more targeted towards the paranoid.
- hollander 10y agoSignal is suitable to the paranoid, while targeting "normal" people. Snowden uses it, so that's a good indicator for the paranoid. Similar: If my mom uses it as well, that doesn't mean she's paranoid. (And I'm not saying that you said this.) And interestingly, knowing some paranoid people (by disease not profession), they usually don't care about this.
- mnx 10y agoAnd what I was originally trying to say, is that people like Snowden, or more precisely, people requiring Snowden-like security, should probably not use this feature despite the very impressive way they made it more secure.
- nilved 10y agoThis is Signal jumping the shark. Why is searching gifs their responsibility? Non-essential features should be skipped there is a single shred of security concern, which we can see there is.
- StavrosK 10y agoIt would be interesting for services to publish a public encryption key, so the signal client could encrypt the payload with that. However, that has very limited usefulness, so I don't see it happening soon.
- Arnt 10y agoThat's more or less what TLS+pinning does. Also DNSSEC+DANE+TLS if you want to argue about that.
- StavrosK 10y agoYes, but it's done at a lower level, which enables a host of attacks, like the announcement says. What I'm talking about would just encrypt the payload, so none of the metadata would be encrypted (and thus preserved). Although I guess you'd also need to specify a "reply" public key in the encrypted data, so this is becomes more of a protocol.
- kbart 10y ago"For instance, if someone messages you with an invitation, you might want to write back with a message that says "I'm excited." With integrated GIF search, you could instead do a GIF search for "I'm excited" and send one of the results instead." What? Why? Is it some kind of attempt to become a new "cool" app? Sounds totally useless function to me, but if it helps to get more users, well, maybe that's a good thing.
- ascorbic 10y agoWhy? Because lots of people like sending gifs and prefer to use messaging apps that support them. If it's totally useless to you then fine: don't use it.
- petre 10y agoIt clutters the UI with unecessary stuff. Wire also provides such a misfeature. I would rather disable it, but cannot.
- tdkl 10y agoYou have to specifically click a button to use it. That's a good compromise between jumping through hoops to enable it if opt-in.
- CoryG89 10y agoI think it would be acceptable if these types of things were on by default, and have the option to disable it or opt-out.
- tdkl 10y agoYeah perhaps, but that would complicate the app development quite a bit. I'd rather see company invest developer time in other ways - maybe bringing desktop client support.
- deleted 10y ago
- deleted 10y ago[deleted]
- deleted 10y ago[deleted]
- laluluala 10y agoThis is what Canonical did with Amazon searches on Unity, they proxified them.
- r3bl 10y agoHow is this the same? Canonical proxied every search term you've ever typed to Amazon. In Signal, you have to explicitly click on a button for anything to happen.
- MikusR 10y agoThat fake video on top is interesting. If they can't even get that right what does it say about their Privacy and Security claims?
- dsacco 10y agoEmpirically, absolutely nothing. You can't judge the security of a software based on its marketing material.
- MikusR 10y agoBut you can determine that nobody at signal has used or even seen an android phone.
- moosingin3space 10y agoWhat? Signal/OWS seems to develop new features on Android first, and that animation up top is an Android phone...
- MikusR 10y agoIt's not an Android phone. Android has either on screen Navigation Bar or Physical Navigation Bar not both.
- h4waii 10y agoWhat are you on about? You can enable on-screen buttons while still having physical capacitive buttons. http://m.imgur.com/u5hcJYQ http://m.imgur.com/u5hcJYQ Many 3rd party custom ROMs have the feature, including CyanogenMod, the most widespread open-source build of AOSP.
- MikusR 10y agoNot on stock Samsung phones.
- cryptarch 10y agoIs there a federated and/or self-hosted alternative to Signal with similar privacy and security properties? Even if it supports fewer platforms? I've been getting more and more interested in running my own (and perhaps my friends') infrastructure, but I haven't found anything better than IRC for chat.
- sschueller 10y agoI run a Synapse server (http://matrix.org/ http://matrix.org/) which is federated and works very well. There are many clients but the nicest at the moment is Riot. Full encryption is now available in the Riot webclient and it's coming to the app soon.
- berdario 10y agoI'm just a Matrix (and Signal) user, I haven't yet had a look into its encryption implementation yet, but for those who are interested, I think these are the docs: http://matrix.org/speculator/spec/drafts%2Fe2e/client_server/unstable.html#end-to-end-encryption http://matrix.org/speculator/spec/drafts%2Fe2e/client_server...
- Arathorn 10y agoThere's also https://matrix.org/docs/guides/e2e_implementation.html https://matrix.org/docs/guides/e2e_implementation.html for those interested in the guts of Matrix's E2E and https://matrix.org/docs/spec/olm.html https://matrix.org/docs/spec/olm.html and https://matrix.org/docs/spec/megolm.html https://matrix.org/docs/spec/megolm.html itself. We're currently reviewing the PRs for E2E on the iOS & Android SDKs, and after they land apps like Riot will have (beta) E2E across all of Web/iOS/Android :)
- nextos 10y agoCame in to suggest Matrix and its client http://riot.im http://riot.im. Otherwise XMPP with http://conversations.im http://conversations.im is also a great option.
- 10y ago
- raverbashing 10y agoGood They know that for a bigger adoption they need those usability improvements, at the same time, they make sure additional features don't compromise the security expected from their app
- Bartweiss 10y agoI've been really impressed with Open Whisper's focus on usability and functionality. So many privacy products take the stance of "if you care about privacy, you won't want to do this", and it seriously harms uptake.
- makomk 10y agoMeanwhile, people are accidentally leaking their phone numbers and their contacts' phone numbers because Signal replaced fingerprints that could safely be posted publicly with QR codes that can't, and didn't explain it: https://twitter.com/webster/status/793657469381713920 https://twitter.com/webster/status/793657469381713920
- Bartweiss 10y agoShit, really? I hadn't published any QR codes, but I sure didn't realize that was part of the new system. That's a pretty bad round of dropping the ball... Normally I respect that OWS explains security stuff in detail if you care, but also has a product that "just works" if you use defaults without much knowledge. This is pretty much the exact opposite of that, where they released a dangerous default with minimal explanation even for people who do read their stuff.
- piotrjurkiewicz 10y agoStill no desktop client?
- berdario 10y agoThe desktop app is available since almost 1 year (in closed beta at the beginning), and recently apparently it's also working with iOS https://whispersystems.org/blog/signal-desktop/ https://whispersystems.org/blog/signal-desktop/ It's also a real app[1], independent from the phone's: after the initial key exchange, you can send/receive messages even when your phone is off [1] Compare with the Whatsapp webapp, which solves/sidesteps the E2E encryption among multiple devices conundrum by simply routing everything through the phone. The Signal app is also written with web technologies, so it might not be palatable for everyone, but it's a good compromise imho
- piotrjurkiewicz 10y agoAre you kidding me? Do you consider this Chrome extension as a 'real app' (sic!)? I won't install Chrome just to host Signal extension.
- mahyarm 10y agoAlmost every modern desktop chat app is a web app, which is what a chrome app is. It's how something like franz is possible: http://meetfranz.com/ http://meetfranz.com/
- piotrjurkiewicz 10y agoI all cases of 'modern desktop chat app' you are talking about, I can use it by opening its website with any modern browser. Signal is the only one which requires me to install one particular browser.
- berdario 10y agoIf you open them in a browser when you're offline, you won't be able to load/read your messages (yes, I know about HTML5 manifests for offline data... but that's a mess), but with Signal you can. Moreover, being able to vet/verify the updates (which you can apparently even block altogether) before running the app is of paramount importance for a secure app like Signal. With a run-of-the-mill webapp that's also impossible. Again: tradeoffs. I'd prefer if Signal desktop was built on something different, but I still happily use it as is everyday.
- wst_ 10y agoCan I, as a receiver, turn off this feature? Ex : get text messages instead of gifs.
- newsignup 10y agoWe do not always search for exact phrase so the text might not convey the emotion..
- wst_ 10y agoUnless the API can somehow place proper phrase instead of image. If text would be matching all images, this should work fine.
- pliu 10y agoI don't have an iPhone, but with the Android client at least, you can disable image auto downloading in the settings page. If you hate fun and are dead inside.
- newsignup 10y ago> The GIPHY service could use subtleties like TLS session resume or cache hits to try to correlate multiple requests as having come from the same client, even if they don't know the origin. How would a cache hit mean same user tried to search? TLS session resume, I can understand but cache hit only means same resource was accessed not same user tried to access.
- StavrosK 10y agoYou cache a unique ID and then see if you get a hit.
- newsignup 10y agoWhich unique id? I thought the point of sending it via Signal was to not include any user id or any other id.
- StavrosK 10y agoI don't know which attack the Signal guys had in mind, but usually how this works is that the server serves a file with a unique ID to a person, sees that it gets requested, then serves the same thing again in a subsequent request to a suspect, sees that it's not requested, and treats that as evidence that the two accounts are actually the same person. It's obviously easier when you can correlate this with a single account, but that's the gist of the attack.
- newsignup 10y agoAh! But this will correlate one file to that person and will not be able to correlate multiple file requests that they all belong to the exact same person.
- detaro 10y agoPresumably the clients cache GIFs, maybe even search results, instead of re-fetching them every single time.
- aluhut 10y agoIt makes me sad so see that they waste time on decoration like gif search but they don't have a client I can use on my PC for example.
- Vinnl 10y agoNot perfect, but: https://whispersystems.org/blog/signal-desktop/ https://whispersystems.org/blog/signal-desktop/
- aluhut 10y agoYes I did know about this but you probably know about the obvious problem > Signal Desktop is a Chrome app I'd rather switch to whatsapp before I intentionally install that PUP again.
- finnn 10y agoIt's just Javascript, you don't need Chrome to run it. eg[0] [0]: https://timtaubert.de/blog/2016/01/build-your-own-signal-desktop/ https://timtaubert.de/blog/2016/01/build-your-own-signal-des...
- aluhut 10y agoNot sure if I should laugh or cry. I don't know what half of the stuff is I have to download there on a system I don't usually run. It's nice to know that it is possible to somehow get this running without Chrome and thanks for that but, hell...this is what I'm talking about. Wasting time on decorations that are now available through one button vs. THIS or the PUP version of it.
- knz 10y agoI've given up on Signal (for now at least). Yes the encryption and privacy is great but without a decent desktop client it's hard to get others in my network to switch to it. Two things bothered me about the desktop application - it runs as a Chrome application rather than in a tab (not sure if there is a technical reason for this?). If I care enough out privacy to run Signal then I probably don't want to broadcast to anyone watching my screen that I'm running it (like a boss walking past etc) and would rather bury it amongst my other open tabs. I also couldn't find any obvious way to sign out of or lock the desktop client - if this isn't just user error then it seems like a significant oversight for a secure messaging app to not allow the user to control access if someone else was able to access the computer. It also really bothered me that signal doesn't give me better control over what contacts can see my phone number. When I signed in I could see phone numbers for a contractor I had used for remodelling my home. The desktop client had them listed as someone to message on the default page. It's not a huge deal in this situation but if the phone number was for someone I no longer wanted to be in touch with (a former partner etc) then there was no obvious way in either the Android app or desktop client to block them. I assume that the other user can also see my details - security should include having control over who can see your phone number. Edit: Screenshots from the desktop app as a response to comment below: http://imgur.com/5nK07ER http://imgur.com/5nK07ER - the default screen http://imgur.com/mmEyQWH http://imgur.com/mmEyQWH - the settings UI http://imgur.com/gjdyPsF http://imgur.com/gjdyPsF - showing Signal in my dock for all to see.
- nzp 10y agoGreat! Now that these easy, low-hanging-fruit features are taken care of, maybe we'll get some of the more involved security oriented ones, like, IDK, having an indication if I verified a contact or not so I can, you know, know whether I should verify or not when the opportunity presents itself.
- biznickman 10y agoNow if only my friends would use the service!
- toosmart4u12 10y agoITT: engineers who think they understand product
- zlatan_todoric 10y agoOh great, they are catching up with Wire (https://wire.com/ https://wire.com/). Now if they would just resolve real bugs (like many people not being able to register to Signal), that would be maybe cool (but as they implemented Signal Protocol to WhatsApp and others (if we can trust code we can't see) I can't say I see any point in it). Maybe I am wrong, but it lost that appeal it had some time in past.
- zedred 10y agoWire transmits your plaintext GIF search terms to the Wire server. Their privacy policy even allows those searches to be logged. Combined with Wire's already bad e2e encryption and metadata story, I don't see how you could consider this "catching up."
- hk__2 10y agoReading this title I thought it was a word play on “Signal and Noise” and it’d be a post about how /giphy adds noise to Slack conversations.