7 ms·
I don't know anything about Moxie derailing threads or anything like that but if we just listened to critics all the time then we just wouldn't have anything. S
by okatsu 8y ago
I don't know anything about Moxie derailing threads or anything like that but if we just listened to critics all the time then we just wouldn't have anything. Signal is better than a lot of what is out there and being used as scale and that counts for something. More secure is always better than not secure at all.
- pmlnr 8y agoRead the end of an article as well. We have solutions like Matrix, and like XMPP with OMEMO.
- okatsu 8y agoSignal did what those things failed to do which is to actually gain some popularity outside of HN. I hope Matrix takes off! In the meantime if people are convincing their families and friends to get on Signal then that's a net positive to me.
- ynniv 8y agoWhat's the point of gaining traction if it doesn't deliver on its fundamental promise?
- ashooner 8y agoBecause the theoretical possibility of being monitored on Signal is preferable to the near-certainty of being monitored on Facebook Messenger.
- jsgo 8y ago@ynniv - because if you can coax a friend who isn't on anything but Facebook to use Signal over, say, Messenger, then it is a net win. Is it perfect? No. Is it a better situation than the current? Yes.
- ashooner 8y agoExactly. Signal's most important feature is that it isn't Facebook.
- lmm 8y agoFor most products it's better to have something than nothing, but not for cryptography. Bad encryption can be worse than no encryption, since it leads to a false sense of security. So it's really important to get it right, and worth criticizing even if you don't have anything better.
- okatsu 8y agoThe article isn't about bad encryption though. It's not about a flaw in the signal protocol or something like that. It's stuff like Moxie doesn't like F-Droid. Which is not an invalid criticism but I'm not gonna stop recommending Signal over Facebook Messenger because of that. Regarding false sense of security...eh. I can't speak for endangered activists but everyday people write stupid things whether it's on SMS or Signal. But might as well be on Signal.
- lmm 8y ago> The article isn't about bad encryption though. It's not about a flaw in the signal protocol or something like that. It's stuff like Moxie doesn't like F-Droid. Which is not an invalid criticism but I'm not gonna stop recommending Signal over Facebook Messenger because of that. You have to look at the whole system, not just one algorithm that it uses - if any part of the system is secure then the whole is insecure. Do you believe Signal-the-system is meaningfully more secure than Facebook Messenger (which uses industry-standard HTTPS, so at the low-level protocol/algorithm level it's certainly secure enough)? If so, why/how? If not, why recommend it? (I agree that Signal is more secure than SMS, but so is Facebook Messenger or any number of other messaging apps).
- okatsu 8y agoIsn't the whole point of Signal that it's e2e encrypted and therefore can't really read and share your messages? Whereas Facebook's system is centralized? So yeah you're safe from outside attacks but not internal ones? I mean if you're asking me if I know for certain that Signal is better than Facebook, there's no way for me to know for sure. But at some point there is a level of trust required and I trust a company like OWS more than I trust a company like FB. Call it blind faith, I dunno, but I also have to trust my operating system otherwise I wouldn't get anything done. Edit: although I should add that while it may be labeled as blind faith it's also fueled by experience. OWS aren't the ones that periodically reset my privacy settings or tried to wage war against accounts not using real names etc etc.