3 ms·
Can't say I am really happy about it. The more the Signal protocol is used the more money is spend on attacking it.
by cJ0th 9y ago
Can't say I am really happy about it. The more the Signal protocol is used the more money is spend on attacking it.
- azernik 9y ago"If you haven't been hacked by the Chinese you got to ask yourself, does the shit you're doing really even matter?" I prefer for Signal to be attacked and to matter than to be unattacked and to be irrelevant.
- dmix 9y agoIndeed, it's incredibly selfish and naive to depend on security by obscurity here when you can significantly up the bar from basically one step above full-text all-access for every global spy agency... to a serious encryption system. Regardless, the exposure ship sailed long ago anyway when WhatsApp with their billions of users, including plenty of terrorist groups in the middle east and africa, decided to adopt the platform. Additionally, breaking crypto systems like this in practice, if possible, pretty much always means targeted attacks. Which is a significant difference from the type of mass surveillance which Skype et al currently allow. Even Blackberry bragged about building a system for the NSA/CSEC to provide real-time data access to every BBM being sent in the Toronto area during G20. It's very likely that Skype has a similar system and this change (should) make that fundamentally infeasible.
- mynewtb 9y agos/Chinese/US agencies/
- krastanov 9y agoBut being battle-tested early on is the only way to ensure there are no bugs later on when everybody is using it.
- tptacek 9y agoThat's the opposite of how you should feel. The more money spent attacking Signal, the stronger secure messaging gets. The best thing that could possibly happen for messaging security is for someone to discover a flaw in Signal. Unlike a lot of messengers, where a flaw is unlikely to teach us something other than "people should use Signal Protocol instead of terrible ad hoc protocols", a Signal flaw advances the state of the art.
- dsacco 9y agoThat's a good thing. Well-studied protocols are safer protocols, and significant money can pay for the best expertise in the world.
- wasx 9y agoThe only way you can know if a protocol is secure is if you have a lot of eyes on it trying to break it nine ways from sunday. This is nothing but a good thing.