3 ms·
I love it. Gonna try and get some of my friends to use this! Plus there's something unabiguously cool about chatting through the terminal... hacker aesthetic
by deusofnull 8y ago
I love it. Gonna try and get some of my friends to use this! Plus there's something unabiguously cool about chatting through the terminal... hacker aesthetic or something like that.
How would you say your privacy + tech measure up against Signal and WhisperSystems? I love those folks and what they build and have been using Signal primarily for texting for a while now.
- giancarlostoro 8y agoI agree, I wish Signal could work in my terminal somehow in a way that's more secure than their "Desktop" application. They were storing the decryption keys in plain text in a SQLite database iirc. I understand why they have to store it, but it's just bad if it's plaintext.
- deusofnull 8y agojesus christ, i didnt know that....
- giancarlostoro 8y agoYeah, it's cause of the way their crypto works, you encrypt the next message with the hash of the previous or something of the sort. Somebody stored it in plaintext for the desktop version, and I believe it's a SQLite DB so it was easy to discover... It sucks, I wish they had at least encrypted it with a pin at the minimum or something? Maybe Yubikey might make sense for Signalin the desktop not sure. Also the messages are stored in plaintext: https://github.com/signalapp/Signal-Desktop/issues/1017 https://github.com/signalapp/Signal-Desktop/issues/1017 They say it's a non-fix cause you can use full disk encryption, and honestly that's what I do anyway, so I'm not as bothered.
- lgierth 8y agoThere signal-cli [1] which works pretty nicely. Uses SMS for initial signup. [1] https://github.com/AsamK/signal-cli https://github.com/AsamK/signal-cli
- wjjdjw 8y agoWhat's your attacker model here? On which operating system can the filesystem be compromised, but your application remains unaffected?
- giancarlostoro 8y agoAny unencrypted file system can have the conversations in plain text extracted, without having to boot the OS or open the application to decrypt the contents.