22 ms·
Signal Foundation
- mtgx 9y agoWhen is the ICO? No, I'm not kidding. Look at Telegram. Who would've thought an open source project would ever get close to a billion dollars in funding? I don't want Signal to wither away or forever remain a niche chat application because of lack of funding, especially if Moxie one day decides he wants to pursue some other dreams of his and doesn't have time to deal with Signal anymore.
- xwvvvvwx 9y agoMoxie is already working on a cryptocurrency project: https://www.mobilecoin.com/ https://www.mobilecoin.com/
- emmanuelindex 9y agoyes, he's working on Mobilecoin since the beginning. I'm wondering when it will ship and if it will be the first project of the Signal foundation.
- r3bl 9y agoLast paragraph in the whitepaper: > MobileCoin is designed so that a mobile messaging application like WhatsApp, Facebook Messenger, or Signal could integrate with a MobileCoin wallet. Pretty sure we're gonna see a separate product that works with IM apps when installed simultaneously.
- rrdharan 9y agoThis seems like a much better setup - $50M and setup as a 501(c)3 - rather than taking on the weird regulatory risk and all the other weirdness associated with Telegram's (IMO crazy) ICO: https://www.forbes.com/sites/jasonbloomberg/2018/02/17/telegram-ico-scam-among-cryptocurrency-scams/#5e4b33fd1cf0 https://www.forbes.com/sites/jasonbloomberg/2018/02/17/teleg...
- JumpCrisscross 9y ago> taking on the weird regulatory risk and all the other weirdness associated with Telegram's (IMO crazy) ICO To make this more tangible, doing an ICO means a prosecutor can personally threaten anyone on the team with violating securities laws. That's a stupid risk to take if you know, as an organization, you're going to fight the U.S. government in court one day.
- mtgx 9y agoI watched the recent hearing on cryptocurrency. The SEC guy seemed to suggest that ICOs need to "register with the SEC" as a security. If they do that and talk to SEC how to best do this, then I think they would be fine? I think Filecoin did something similar.
- tgragnato 9y agoSuch a sum can be dangerous, especially if you're used to a team of 7. But it's also dangerous to dismiss or discourage this kind of experiments. > We believe there is an opportunity to act in the public interest and make a meaningful contribution to society by building sustainable technology that respects users and does not rely on the commoditization of personal data.
- hinkley 9y agoThat sum is only dangerous if they aren't getting good advice from people with experience in nonprofits. If they treat a big chunk of that as an endowment and go after more funding every few years to top off the coffers, they could live on that kind of money for ages.
- tptacek 9y agoThis post explains why they've never taken investor money.
- davesque 9y agoI think the simple answer is that ICOs are too risky and involve too many unknowns. By the way, were you actually associated with Mt. Gox or is that account name just for kicks?
- XR0CSWV3h3kZWg 9y agoWhat would be the incentive to buy?
- xwvvvvwx 9y agoHuge congratulations to Moxie and the team. Signal is a wonderful project and I'm super excited to see what they achieve with such serious resources behind them :)
- pspeter3 9y agoI'm really excited about the possibility of a better client. I want to switch to Signal with my friends but the clients feel so behind Facebook Messenger
- windexh8er 9y agoI've assimilated most friends and all family very easily by educating them about the why. Not to mention if you're a parent explicitly banning sharing of photos with relatives via social media. People accept any small inconvenience or lack of feature quickly. But at this point I'm not following on the "so behind" comment. Care to elaborate?
- qplex 9y agoTheir Android app at least is way too difficult to use. I tried it with my friend some time ago and we just couldn't figure out in a reasonable amount of time how to add each other etc. I consider both of us tech savvy and we have absolutely no trouble with other IM clients or more archaic stuff like IRC.
- windexh8er 9y agoDifficult to use? I'm even more confused as there is literally nothing to do to "add" someone. As I stated our entire family uses Signal across Android, IOS and desktop. That age range in our entire family group is 20s to 70s and I happen to be the only user who would be considered tech savvy.
- qplex 9y agoYes. We didn't have each others phone numbers in our contacts. Manually adding by phone number didn't work. At this point we just gave up. I use prepaids because I travel a lot so my mobile numbers are just throwaways. I'd rather not give _all_ of my contacts to an app anyway. So there really should be a way to manage contacts inside the Signal client and add people via screen names or email addresses.
- cs702 9y agoThis is freakin' awesome: A non-profit foundation with $50 million in the bank dedicated to providing usable encryption to the general public, with no other agenda other than the public good. Go read the blog post by Moxie and Brian Acton (who is joining Signal). Very exciting!
- kodablah 9y agoNot that it matters that much, but where did the 50 mil come from? I didn't see it in the post, but I may have missed it.
- tptacek 9y agoFrom Brian Acton, one of the cofounders of WhatsApp and now Executive Chairman of the Signal Foundation board.
- deleted 9y ago[deleted]
- fossuser 9y agoIt seems like they have a lot of overlapping goals with Keybase.io. I wonder if they're in contact or work with each other.
- weinzierl 9y ago> Over the lifetime of the project, there have only been an average of 2.3 full-time software developers, and the entire Signal team has never been more than 7 people. This is awesome. Amazing what an excellent small team can build.
- tomc1985 9y agoDon't tell SV!
- spullara 9y agoWhen WhatsApp was acquired by Facebook for $19B they only had a little over 50 people.
- TremendousJudge 9y agois it known how many of those 50 were devs?
- mtmail 9y ago"When WhatsApp was acquired by Facebook for $19 billion, the popular messaging app had about 35 engineers and 450 million users." http://www.businessinsider.com/facebook-f8-whatsapp-engineering-2016-4 http://www.businessinsider.com/facebook-f8-whatsapp-engineer...
- tomc1985 9y ago35 still seems high to me
- sitepodmatt 9y agoYou forgot the /s
- Inflatablewoman 9y agoCould this mean that Flock will be making a return? https://signal.org/blog/flock/ https://signal.org/blog/flock/
- deleted 9y ago[deleted]
- rfreytag 9y agoSince you are in the US how do you keep the US government from interfering with your mission because Signal uses strong encryption? How do you address the EARs (Export Administration Regulations) and ITARs (International Traffic in Arms Regulations)? These regulations look like a tar pit to me.
- loeg 9y agoWhy do you think strong encryption will have an export problem now when it hasn't for decades? Keep in mind that Signal is already open source and the algorithm is already widely distributed. Any restriction on export at this time would be closing the barn doors after the horses have all escaped.
- rfreytag 9y agoQuora article on issues in US export of products using strong encryption => https://www.quora.com/What-regulatory-issues-have-to-be-considered-when-exporting-or-building-products-that-heavily-use-cryptography https://www.quora.com/What-regulatory-issues-have-to-be-cons... I hate these regulations but EAR and ITAR with respect to crypto seem to be concerned with the key length and algorithm. Over a certain strength the software using the encryption seems to be still treated as a munition!? I've heard of people who ignore this getting huge fines. And any export to Cuba, N. Kora, Sudan, Syria, and Iran is banned by OFAC (Office of Foreign Assets Control). Yes, the very countries that need Signal the most are banned! Hopefully I'm wrong and we are free of regulatory issues in the US so I'm asking a serious question here - how does Signal solve this problem?
- detaro 9y agoI think the US still requires cryptography products to be registered with the Department of Commerce, but that's about it for non-military products.
- rfreytag 9y agoI've tried reading the regulations (but IANAL) and am almost certain that over a key-length for given algorithms its a munition and an export license or similar is required with regular updates. And then still there is the issue of the OFAC banned countries list. I'm hoping Signal's compliance can show other hackers how to also comply without hassle or fear.
- Arathorn 9y agoCongratulations to moxie and the Signal folks from the Matrix.org team :) The world wouldn't have the increasingly pervasive E2E encryption we enjoy today if not for the double ratchet algorithm, and it's fantastic that they can continue that work as a 501(c)(3)!
- no_identd 9y ago>The world wouldn't have the increasingly pervasive E2E encryption we enjoy today if not for the double ratchet algorithm Too bad the Signal Protocol doesn't actually implement the double ratchet algorithm but a derivative of it that fails to protect metadata making the Signal Protocol leak metadata. Granted, it only leaks metadata leaked by the transport layer anyway, but this makes it pointless to implement the Signal Protocol over something like Tor, i2p or GNUnet.
- meritt 9y agoKudos to Signal for taking this approach and not jumping on the sketchy ICO bandwagon.
- deleted 9y ago[deleted]
- deleted 9y ago[deleted]
- walterbell 9y agoWhat is Signal Foundation's vision for interoperable, open-standard E2E messaging between different central services?
- carussell 9y agoA null vision. Moxie is against federation, and he's against interoperable clients. https://signal.org/blog/the-ecosystem-is-moving/ https://signal.org/blog/the-ecosystem-is-moving/ https://github.com/LibreSignal/LibreSignal/issues/37 https://github.com/LibreSignal/LibreSignal/issues/37
- zeveb 9y agoI really, really wish that he'd reconsider. Interoperability is a huge Good Deal.
- walterbell 9y agoSignal now has the resources to compete with the IETF effort by Mozilla, Google, Cisco, Facebook, Wire, Twitter, MIT and INRIA: https://news.ycombinator.com/item?id=16325803 https://news.ycombinator.com/item?id=16325803
- baby 9y agoI don't think he's against federation, it just doesn't make sense to federate an experiment. Once you've got something really really really solid, then it does make sense. They've been able to iterate their protocol really fast thanks to it not being an RFC or something.
- carussell 9y agoIf you're suggesting that Signal will eventually federate, there's nothing in those two links to support that interpretation. In fact, to the contrary: > Early on, I thought we’d federate Signal once its velocity had subsided. Now I realize that things will probably never slow down, and if anything the velocity of the entire landscape seems to be steadily increasing. > You're free to use our source code for whatever you would like under the terms of the license, but you're not entitled to use our name or the service that we run. If you think running servers is difficult and expensive (you're right), ask yourself why you feel entitled for us to run them for your product.
- y03a 9y agoAny reason Signal isn't available through F-Droid? It may be unjustified but I'm not a big fan of installing privacy conscious apps through Play. Edit: Wait, haven't installed anything yet, but I read the getting started guide. I have to sign up using a phone number? That throws all expectation of anonymity and thus privacy out the window.
- mattl 9y agoF-Droid wants to compile their own binaries, and Signal/OWS/Moxie want to provide checksums and the like for Signal binaries.
- JoshTriplett 9y agoThat's an argument for reproducible builds; building the same source should give the same checksum.
- leshow 9y agoTheoretically, but when you throw in things like build systems often not being deterministic, minor versions of dependencies changing, different OS or slightly different OS version with different libraries; there's a multitude of places to throw the final binary off by a few bytes or more and end up with a different checksum. Signal wants to distribute a binary with a checksum. Once the checksum is different all bets are off, that's why it's not in F-Droid
- izacus 9y agoSo why don't they just also list checksum of the F-Droid binary?
- JetSpiegel 9y agoThey don't trust F-Droid.
- kodablah 9y agoLike probably everyone else, I have an idea on how to use the money: Distributed, persistent, group-possible, configurable chat. What's the difference between person-to-person chat, group chat, twitter, reddit, HN, a discourse forum, etc? Configuration, if you ask me. But distributed is the key though I understand identity, disk, and peer management are difficult.
- faitswulff 9y agoThis is a bit of a tangent, but I first heard of Intel SGX (Secure Guard Extensions) via Signal's blog post about secure contact sharing[0], so it's almost relevant :p From what I've read[1][2][3], Intel SGX is vulnerable to Spectre exploits. Does anyone know if this has changed Signal's approach to security at all? Granted, contact sharing was a technology preview, but I'm curious if SGX is still considered a feasible, "good enough" security measure for Signal Foundation. [0]: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/ [1]: https://software.intel.com/en-us/forums/intel-software-guard-extensions-intel-sgx/topic/754168 https://software.intel.com/en-us/forums/intel-software-guard... [2]: https://github.com/lsds/spectre-attack-sgx https://github.com/lsds/spectre-attack-sgx [3]: https://security.stackexchange.com/questions/176635/how-does-meltdown-spectre-impact-intel-sgx https://security.stackexchange.com/questions/176635/how-does...
- deleted 9y ago[deleted]
- tatterdemalion 9y agoSignal's use of SGX was to increase users' trust in Signal - OpenWhisperSystems couldn't log your contacts even if they wanted to. Its up to potential users to decide if they think OpenWhisperSystems will surreptitiously perform an attack on their own secure enclave to secretly log your contact information.
- porjo 9y agoRegarding the SGX enclave and contacting sharing, the blog post announcement dated 26 Sept 2017 says 'deploying into production...over the next few months'. Can we assume that's happened already? Or are contacts still being exchanged in a way that would allow a middle man to reconstruct an individual's social graph?
- gsch 9y agoGiven that it now takes an order of magnitude more time than it used to for newly added contacts to appear in my list of Signal contacts, I assume /something/ has changed with the way they exchange contact data.
- gburt 9y agoSo, where did the $50 million come from? That is a significant amount of money for what has been a handful of people, not taking venture capital, now operating as a nonprofit to "secure communications."
- darkstar999 9y agoThe article isn't directly explicit, but > Today, we are launching the Signal Foundation, an emerging 501(c)(3) nonprofit created and made possible by Brian Acton, the co-founder of WhatsApp Brian Action funded it himself.
- mashedvikings 9y agoMakes sense only if he didn't spend the $19,000,000,000 on one go when FB bought WhatsApp.
- meowface 9y agoMoxie is and will continue to go down as a legend of the digital age. He carved his spot way back with work like sslsniff/sslstrip, and has proven himself to be a real philanthropist. Kudos to him.
- deleted 9y ago[deleted]
- lawnchair_larry 9y agoHopefully they fix the huge privacy problem that requires people to give out their phone number in order to exchange messages. It still amazes me that they don’t see why vulnerable people, or even most women, are not ok with doing this. Even Apple lets you use an email address.
- mi100hael 9y ago> Starting with an initial $50,000,000 in funding O_O holy smokes that's a lot of "initial funding"
- yeukhon 9y agoI'd like to know how though. They are not VC funded. I supposed Brian Acton funded it?
- OoTheNigerian 9y agoAnytime I hear about signal, I try to sign up and my verification code never comes. It may be something this simple that is holding it back from adoption.
- kobayashi 9y agoI had a similar issue a long time ago. I was able to circumvent the roadblock by signing up on a different device, and then signing in on the original device.
- ycmbntrthrwaway 9y agoReport here please: https://github.com/signalapp/Signal-Android/issues/6027 https://github.com/signalapp/Signal-Android/issues/6027
- OoTheNigerian 9y agoDone https://github.com/signalapp/Signal-Android/issues/6027#issuecomment-367470856 https://github.com/signalapp/Signal-Android/issues/6027#issu...
- RandomCSGeek 9y agoI and a friend signed up for signal a few days ago. I received verification code after few minutes, he received it on next day. Smells like underpowered server to me.
- alborzmassah 9y agoI don’t think I feel good about this. The comments are nice and seem true, but whenever there is so much money involved, even a non profit label I would be suspicious. Are all funding and allocations going to be made public for the organization? People always seem to have a hidden self interest, especially when money is involved.
- a_imho 9y agoI'm neutral, but I was never convinced by Signal's PR pieces. Call me a skeptic but a lucrative field like messaging is always about money. Signal's gimmick was privacy to gain market share, but even if they had a slight edge there back then, the majority did care. even a non profit label I would be suspicious Could be about account optimization purposes. The 50M funding was probably deducted from taxes to begin with.
- beaconfield 9y agoHella awesome news!
- Asdfbla 9y agoPretty amazing and absolutely deserved. After the failures of systems like PGP, which aren't really suitable for the masses, the Signal protocol did a great job at spreading end-to-end encryption. I'm happy to hear that they got some philanthropic funding, even though I don't doubt that Moxie and the others did the work out of principle anyway and might have continued to do so even without the money.
- acct1771 9y agoIMO, saying PGP has failed is like saying cryptocurrencies have failed.
- tomcatfish 9y agoThere is no public interest in PGP from non-technicals
- acct1771 9y agoAnd the only reason Bitcoin is interesting is because "we" have effectively communicated, correctly or otherwise, that there's value in cryptocurrencies.
- Asdfbla 9y agoThe overwhelming majority of people use Bitcoin and other cryptocurrencies through exchanges, they have no interest or knowledge of technical details. So it's not like technical communication has won here, more like greed and ease of use.
- andirk 9y agoI agree with this completely! Bitcoin evangelist Trace Mayer always harps on keeping your private keys and not using exchanges to hold large amounts of coins. And Mayer's an investor in Kraken, one of the big exchanges. I have taught my friends this and they all had interest in it, but some skeptical if they trusted in themself enough to hold onto their coins offline.
- mapgrep 9y agoThis is very very good news. As a heavy Signal user, from where I sit I personally see the following clear needs: -Better group support. Right now, to do a group in Signal you have to name the group, which makes it kind of a pain to create ad hoc quick groups. I'm forever naming them "John Sue Bill" or "Jane Roger Amanda". iMessage, by contrast, just automatically makes a group without a name. You get a thread for that group, so you can follow the discussion clearly, and you can leave the group, but it hides the nuts and bolts of the fact that a group has been formed. Also, Signal has no per-group notification settings, so if you're in a "noisy" group your only option is to turn off notifications universally (including one-on-one messages and other groups) or live with it. Lastly, you cannot form a group from Signal Desktop. -Better support for long messages (or a new product using the same network and security). Signal was clearly designed for short session lengths — brief messages that are composed quickly. But as it has become the catch-all app for encrypted comms — "just use Signal! PGP email sucks!" — many people, at least that I deal with, are trying to use it for email-type purposes. Long messages with arbitrary attachments. It would be nice if, like, putting a line break in a long message didn't mean hitting Control-Enter or Command-Enter. It might even be nice if you could have multiple threads with the same recipient. You know, like email. I am not holding my breath on this one. But if people could email as securely as they chat, using Signal protocol, it would be a huge leap forward in keeping the NSA out of our business. Not to mention Google/Gmail's ad clients etc. -Ability to search. I can't full-text search my messages, even within Signal. As I use it more and more, this is a hindrance. -Group video chat. This is very pie in the sky. But a lot of sensitive comms involve groups — think of people organizing a protest, or a corporate takeover, etc. And right now there are few private options.
- spappal 9y agoSignal has no per-group notification settings Yes it has, at least on Android. Within a group, press the three-dots-menu on top and choose mute notifications. You can choose for how long they shall be muted, similarly to other apps. Adding to your list: - Working backups for text and media.
- StudentStuff 9y ago
- nickpsecurity 9y agoLike I recommended for Mozilla, they could use this money to acquire and/or create highly-usable alternatives to many products that are about handling communications or data in trustworthy way. Things like SpiderOak, VPN’s, backup apps for iOS/Android, HSM’s, payment services, paid email… anything that unscrupulous businesses have been a problem for with insecure solutions or them just cheating customers. Each one is turned into a commercial product either shared source or dual-licensed GPL/AGPL. The money coming in improves each both for new features and 3rd party review. Release code as GPL either on component level as they are built or as a whole after development cost was paid for. Many businesses will still pay for GPL-licensed code just to know someone is responsible for it. Such models will gradually increase the number of trustworthy goods available through trustworthy suppliers over time. That’s the basic concept anyway.
- JoeCoder_ 9y agoI'm hoping they can use some of this cash to make a better desktop client: 1. That can be minimized to the system tray. 2. That can be used when behind an http proxy server. 3. Doesn't require a phone to use. 4. Doesn't take 200MB ram to run.
- mashedvikings 9y agoSo, what are you using the 15,800 MB of RAM for?
- FridgeSeal 9y agoRunning Slack. Gosh
- JetSpiegel 9y ago100 tabs on Chrome?
- baby 9y agoWithout tree style tab?
- kuschku 9y agoRunning 4 instances of IDEA, 2 Android emulators, gradle to build an app, and a browser?
- scottnonnenberg 9y agoYou seem pretty passionate - wanna help us test proxy and system tray support? Tray support behind command-line argument: https://github.com/signalapp/Signal-Desktop/pull/1676 https://github.com/signalapp/Signal-Desktop/pull/1676 Proxy support behind command-line argument: https://github.com/signalapp/Signal-Desktop/pull/1878 https://github.com/signalapp/Signal-Desktop/pull/1878
- nvr219 9y agoawesome
- grooling 9y agoLet's hope they don't backdoor it like they did with WA. Probably already has one. Long time signal and WA user here
- r3bl 9y agoWhatsApp was never backdoored. Even The Guardian backed down after a review of its research process: https://www.theguardian.com/technology/commentisfree/2017/jun/28/flawed-reporting-about-whatsapp https://www.theguardian.com/technology/commentisfree/2017/ju... Quote: > The most serious inaccuracy was a claim that WhatsApp had a “backdoor”, an intentional, secret way for third parties to read supposedly private messages. This claim was withdrawn within eight hours of initial publication online, but withdrawn incompletely. The story retained material predicated on the existence of a backdoor, including strongly expressed concerns about threats to freedom, betrayal of trust and benefits for governments which surveil. In effect, having dialled back the cause for alarm, the Guardian failed to dial back expressions of alarm.
- canjobear 9y agoMaybe they can use their $50,000,000 to make it possible to sign up for their service without a phone number. The hype around Signal is insane to me considering this lack of basic functionality.
- emodendroket 9y agoAlso considering questions like "why does this app want all my contacts?" or "how do I know I can trust the implementation? or, critically, "how much does it even matter when the OS itself might be compromised?"
- acct1771 9y agowww.riot.im
- mightybyte 9y agoThis is great news. Now maybe they'll have the resources to ditch your phone number as your identity. Traveling overseas is really frustrating when you get a new sim card and your Signal identity changes.
- lorenzhs 9y agoYou don't need to re-register Signal when you pop in a different SIM card. I've successfully used it abroad with a foreign SIM card without issue. Of course people won't be able to add you by any phone number other than the one you used to set it up, but that's hardly a concern when travelling.
- roadbeats 9y agoMoxie seems to be the right person in the right position. I’m excited and happy for him.
- la6470 9y agoI don’t know anyone who uses Signal... in fact I haven’t heard of it before. And I am a regular techie guy in Silicon Valley.
- hi41 9y agoKudos to Signal! I derive great inspiration from projects such as Signal but as an average developer I just don't know how to take that inspiration, make a plan and become good programmer.
- grizzles 9y agoI hope they rebadge an android phone the way Fairphone has. Signal would only need to make a small profit to keep it sustainable and that would bring down the handset retail cost pretty significantly. It would be like the Raspberry PI of phones. Signal guys: if you are toying with this idea, hit me up (email in profile), I've put way too much time into researching how to do this as quickly and miserly as possible.
- alberth 9y agoEven though I’m excited, I really hope this isn’t one of this XKCD “Standards” moments. https://imgs.xkcd.com/comics/standards.png https://imgs.xkcd.com/comics/standards.png
- Klasiaster 9y agoThat an account is linked to the phone number is the major problem for me because once you are in another country where you can't receive SMS with that number, you need to create a new account! Matrix is more friendly in this regard, but not as good as Signal in terms of privacy features.
- alexnewman 9y agoWho funded the foundation
- SeaDude 9y agoHm. $50 million when the team has already been successful. Why, when only $1M would suffice? What on earth could $50M do? Remember the old saying: "Mo money mo problems" B.S.
- arglebarnacle 9y agoFoundations are supposed to be self sustaining without actually selling anything, so they require large endowments to endure. That $50M could sustainably spit off as much as $2.5M/year, funding ongoing development indefinitely.
- alexnewman 9y agoMaybe now they can afford to have some features, or group chat that's not the worst in the biz.
- pishpash 9y agoThe longest list of required permissions I've ever seen on Android and tying your identity to a phone number you own?
- anonytrary 9y agoAs a complete layman, I don't understand why this is different than WhatsApp (they claim to fully encrypt stuff, right? Is it worse than this?). If I don't understand encryption and computers, why should I be sold on this? It seems to be aimed towards CS majors who understand the backend benefits. To an end user, it looks like an ordinary chat app. Am I wrong? This seems to have been heavily upvoted; is there a 10x improvement I'm missing?
- Zhenya 9y agoWhile whatsapp messages are, apparently, e2e encrypted - your phonebook and metadata are slurped up by facebook. Signal does not have that goal and have been shown by courts documents to not store the metadata.
- anonytrary 9y agoThe Signal app asks for a ton of permissions. Apparently this isn't decentralized either, so how is it different than Facebook? Did they prove it was mathematically hard/impossible for them to see any of the (meta)data? Have they proven that they are a 100% oblivious broker?
- distances 9y agoThe courts not getting any data, as parent just mentioned, is very strong proof for that.
- anonytrary 9y ago> The courts not getting any data I don't know what that means.
- cwyers 9y agoWhatsApp uses the Signal Protocol, so its encryption is the same as this. The Foundation will continue to advance the Signal Protocol, and presumably WhatsApp can benefit from any improvements.
- 4bpp 9y agoI hate to be the one naysayer, but it seems to me like the benefits of this influx of funding and scope has very few tangible benefits, while predisposing them to a standard failure mode of large and well-funded tech activist organisations where the means (the organisation) are confused for and eventually put ahead of whatever goal they were founded for: see e.g. Mozilla support for EME, the continuing negative news pertaining to Pocket and trying to collect user data. (On the ground, part of the problem may be something of the form: imagine you are the CEO of $foundation, are employing dozens of people and hundreds of volunteers who you have to keep motivated and now you are supposed to tell them they can't do the one thing that might keep their employer going and relevant just because of some philosophical considerations about how compatible it is with the core mission.)
- bad_user 9y agoIt's easier to criticize than it is to build. Mozilla has been doing a lot of awesome stuff and people keep forgetting that their direct competition and threat are Google, Apple and Microsoft, the world's largest tech companies. Mozilla basically had no choice with EME, but to comply. When the majority of HN's userbase has been using Chrome for years, power users, nay, freaking developers which should know what EME means, when Chrome is approaching the monopoly of IExplorer, good luck selling your values to the general public, who don't give a shit as long as their Netflix stream ain't working. Open Whisper Systems has been delivering the best encrypted chat protocol to the masses, their tech being used now in WhatsApp for example. So you can be the naysayer, but IMO these foundations are building and releasing products with a measurable positive impact on the world, whereas most of us here don't ;-)
- 4bpp 9y agoI understand the case in the case of Mozilla, because a browser is an intrinsically absurdly complex product. In the case of Signal, the benefits of having a foundation like that seem unclear to me. What exactly is it that they want to do but couldn't before they had a $50m foundation? The linked page seems very vague about this.
- YTGRK 9y agohttps://youtu.be/XSpOTUKz3Ys https://youtu.be/XSpOTUKz3Ys