21 ms·
Moxie Marlinspike has a plan to reclaim our privacy
- 3np 6y agoI was vouching for Signal for all my friends for years, supported them with donations, and was really rooting for them. However, I regrettably can't trust in moxie having the best intentions with Signal anymore. Lost count of the number of times this has been recycled on HN so I'm not taking the time to formulate this extremely well but: * For the longest time, requires phone number as identifier. When asked to remove this restriction, the reply is "so we can bootstrap off the phone's native contact application". But Android and iOS contacts have natively supported e-mail addresses on contacts since forever? And those could be optional? Every time the conversation has gone this far with anyone involved in Signal, silence/ghosting. * The whole PIN requirement debacle - where further amounts of metadata would be uploaded to Signal's servers (encrypted of course, with the PIN as passphrase of the key). Suddenly the app wouldn't start and users were locked out of all their Signal conversations (even reading them) without setting a PIN, no way to circumvent it. We were told this would be a strict requirement to be able to solve the above. After a lot of backlash they rolled it back after a week or so? * Hostility towards alternative implementations. * There's an open issue on GH for verified builds. Since 2015. Signal may be good today. What about tomorrow? I think the only durable and realistic solution (because let's face it, pure P2P for the mainstream is not the latter) is federation. Anyone feeling similarly should check out matrix.org. It may not be ready for the masses yet. But if we consider how we communicate in 5, 10, 20 years from now, it becomes obvious that we can't rely on a single actor as provider, regardless of how good they are today. The only way we get there is with people like the ones frequenting HN getting involved by using it, contributing, filing bugs, hosting home servers and using the clients.
- lrvick 6y agoThese are all exact reasons I have never used Signal. Additionally I find concerning the choice to bet the farm on SGX which has been repeatedly broken with repeated opportunities to extract the keys, at which point cracking small numeric pins is trivial. Moxie simply promised they always patch right away and never take the keys when they have such opportunities to do so. I do believe him, today, but I don't believe he is above being threatened or coerced tomorrow or that he won't get replaced by someone that cooperates better with state powers as happened with VK and countless others. I also took issue with Signal having central network metadata chokepoints his DCs or ISP could do timing heuristics on even if he does not. I tried to engage with Moxie about these issues but he dismissed each as things we will mostly have to accept because he feels it is not possible to create and rapidly improve a privacy focused communication tool for the masses that isn't produced and controlled by a single large company. Moxie is brilliant, and his contributions to cryptography and bringing education on privacy and end to end encryption to millions can't be overstated. The problem is Moxie and Signal are struggling to engineer best efforts under an assumption they treat like a law of nature: No end to end end encrypted messaging platform can succeed without complete centralization. I operate under a different assumption: No centralized platform will ever escape censorship and control by the government it operates under. Moxie has said before he is happy to be proven wrong. I hope as Matrix and others continue to prove him wrong with his own cryptography research that he comes around and rejoins the fight for a decentralized internet with irrevocable privacy.
- tptacek 6y agoYou can't coherently be alarmed by Signal's use of SGX while at the same time endorsing systems that use no cryptography whatsoever to protect the metadata Signal uses SGX for.
- saagarjha 6y agoI’m not sure that that’s the only conclusion you can draw. Some systems choose to not handle that metadata, which often makes them a worse service but they make that choice by looking at the landscape and choosing to not use SGX. The other plausible argument is that Signal uses SGX, which is better than nothing, but in selling it as more secure than it is they do more harm than good.
- JshWright 6y agoSome people choose not to turn their servers on at all. It makes for a worse server, but it's very secure. Security is always about tradeoffs and compromises. A system that is very, very good, but not perfect and widely used is far preferable to a system that is perfect but used by no one.
- saagarjha 6y agoRight, but in this case the choice is "should I be able to discover contacts" and some people just don't desire that feature enough.
- schoolornot 6y agoI have some concerns around the Signal foundation: The initial $50M in funding was a loan, not a donation, from Brian Acton to the new nonprofit Signal Technology Foundation. By the end of 2018, the loan had increased to $105,000,400, which is due to be repaid on February 28, 2068. The loan is unsecured and at 0% interest.[5] The Foundation is completely controlled by Brian Acton, who is the sole "member" of the nonprofit, with the right to appoint or remove every member of the Board of Directors. The Board consists of Acton and Marlinspike. Acton is also the President.[5]
- sk2020 6y agoIs there a reason to suspect Brian Acton’s motives? I’m always skeptical of celebrity-hackers, but I don’t know why I should be worried about Acton in particular.
- walrus01 6y agoI sincerely hope that he is like a younger version of Mitch Kapor, who used his money to launch the EFF. https://en.wikipedia.org/wiki/Mitch_Kapor https://en.wikipedia.org/wiki/Mitch_Kapor I would be very disappointed if I found out that Acton had any hidden motivations behind his philanthropic support.
- codethief 6y agoI think you intended to link the sources but you didn't. Could you still provide them please? I'd be very interested in where those numbers come from.
- joecool1029 6y agoHere's the foundation's Form 990 from 2018: https://projects.propublica.org/nonprofits/display_990/824506840/12_2019_prefixes_82-86%2F824506840_201812_990_2019121216951146 https://projects.propublica.org/nonprofits/display_990/82450...
- codethief 6y ago
- bawolff 6y agoThere is a reason why signal is relatively mainstream succesful (by crypto product standards) and PGP wasn't. Its because its willing to make tradeoffs in the name of usability (while still emphasizing security). A secure messenger product nobody uses helps nobody's security.
- nullc 6y agoMany of the security design flaws in signal have had little to no direct impact on usability. For example, for years we asked for a simple mechanism which could be used to view a users key and mark it as identified, to prevent MITM -- even one buried in a menu for advanced users (who could at least act as canaries against widespread interception). Not only was the request turned down but usually responded to with vigorous personal attacks against the requesters. Subsequently once a fingerprint validation method was added it was gratuitously bound to be pair-wise, making it largely unusuable -- e.g. post a pgp signed signal fingerprint that any of your contacts could use to transfer trust from an existing key. Requests for a non-pairwise version, even as just some advanced thing that grandma never sees ... again, hostility. The constant logic-bombed auto-expiring software that make signal effectively open-source-in-name-only. etc. I think signal is fine as an insecure messanger: Unencrypted communications protocols should have no place in on the internet today. But to advance it as a security tool almost certainly puts people's lives and freedom at risk. Common usage of signal has zero security against MITM: users aren't effectively notified that the contacts keys have changed-- and given how often users lose/wipe phones perhaps that's really the best that can be done for normy friendly software. If that's how it is, that's how it is. Some resistance against passive monitoring is still a critical upgrade. But don't call it secure: if you do people will do and say things using it that they wouldn't otherwise.
- hackerfromthefu 6y agoCan the downvoters please respond to the post with the reasons why they are downvoting?
- nullc 6y ago
- cwkoss 6y agoI've also heard that Signal on android leaks message text because of google's keyboard auto-prediction feature. They should implement their own keyboard or find a way to disable text prediction - and educate their users.
- lrvick 6y agoIn general I would not expect much privacy from a stock Android device on any chat tool considering they shamelessly ship lots of third party blobs carriers demand be included, some of which like OMA-DM toolkits have sweeping permissions on your device. On Apple this is less true, but it is also a centralized black box that grants you no freedom, and apps can be banned at any time with little recourse. You could use something other than Android like PostmarketOS or Librem5 however odds are Signal won't create clients for those platforms considering Moxie has stated publicly he prefers distribution through proprietary channels in order to collect usage stats. Moxie has also stated he will actively fight any third party clients that try to join his network, so we won't likely see many of those attempted for alternative platforms either.
- joecool1029 6y ago> some of which like OMA-DM toolkits have sweeping permissions on your device. Fortunately this seems to be going away. For those not aware as to what you're talking about, this is the proprietary 'rootkit' providers like Sprint had to use to activate CDMA modems on their carriers on many of their devices that did not come with a CSIM. As it's doing a lot with the phone's modem, it needs tons of permissions on the device. Verizon Wireless and Google Fi also had similar apk's that were required to provision phones and update PRL (prority roaming list) information. In the US all modern devices on Verizon are CDMA-less and new Sprint customers are usually activated on T-Mobile network (with fallback to GSM/WCDMA not CDMA).
- jfim 6y agoOn Android, Signal sets the flag on the text entry box that disables IME personalization, the same way that the text entry box works in Chrome's incognito mode. Whether or not Google respects it is not clear, but it does show a little incognito mode icon on the keyboard.
- stefantalpalaru 6y agoThis guy was very active during a weird campaign to bury information detrimental to WhatsApp that would have affected a US operation in Turkey (the one meant to replace Erdogan with Gulen - a friendlier theocrat). https://www.cyberscoop.com/whatsapp-backdoor-guardian-open-letter-zeynep-tufekci/ https://www.cyberscoop.com/whatsapp-backdoor-guardian-open-l... http://technosociology.org/?page_id=1687 http://technosociology.org/?page_id=1687
- neonate 6y agohttps://archive.is/nARhl https://archive.is/nARhl
- bilal4hmed 6y agoOther than matrix, what are some other alternatives or upcomers in the messaging field I should try. Matrix still has a high burden of me setting up my own server and maintaining it. Till their P2P solution doesnt release, they have their own metadata problem.
- olah_1 6y agoThese are all worth keeping tabs on. Ethereum: https://status.im/ https://status.im/ Loki: https://getsession.org/ https://getsession.org/ Gun: https://iris.to/ https://iris.to/ IPFS: https://berty.tech/ https://berty.tech/
- est31 6y agoIn addition to what the siblings said, Threema. Doesn't require phone numbers, is end to end encrypted like Signal. https://threema.ch/ https://threema.ch/ Also they announced that they will open source their client.
- senectus1 6y agoLong time signal user here, threema looks very interesting and seems to be trucking along quite well
- q3k 6y agoWire: open source (AGPL server/clients), can self-host, available as a public cloud service (free for user-to-user comms, paid for orga comms). Disclosure: worked for them.
- axaxs 6y agoWire was my favorite...much more featureful than Signal at least when I was testing them a couple years back. They also had some not so nice things to say about the Signal folks, but that's mostly gossip.
- avhon1 6y agoTox (clients include uTox and qTox) has an... interesting history, but is technically interesting (true p2p), and worked fairly well when I last used it (around 2018). https://github.com/TokTok/c-toxcore https://github.com/TokTok/c-toxcore https://github.com/uTox/uTox/ https://github.com/uTox/uTox/ https://github.com/qTox/qTox https://github.com/qTox/qTox
- cwyers 6y agoWhy is it, whenever Signal is brought up on Hacker News, we get inundated with the people who object to the core decisions of the Signal Project? Would Signal really be better if, instead of having a secure messenger available to the masses, it spent massive amounts of time implementing the things these people want? No. I would be comfortable recommending Signal (or WhatsApp) to a nontechnical friend and communicating with them on it, with the expectation of a certain level of privacy. I spend a lot of time on Hacker News and consider myself a very technical person, and I'm not sure I trust myself to use Matrix in a forward-secure way where it's at right now. If everybody spent the time they spent complaining about Signal working on getting Matrix or whatever to a point where it was usable... well, frankly I don't think it'd be much better off than it is right now, but it seems more likely to bring about results to me than endlessly lobbying to have Moxie do _the thing he thinks cannot be freaking done right_. Right now, Signal exists and can be used securely (given certain common threat profiles) by the typical smartphone user. I'm really tired of people comparing the security that Signal offers to the security of imagined hypothetical messengers.
- nickff 6y agoA great deal of human communication is dedicated to signalling high rank/superiority, or demonstrating familiarity/intimacy.[1] In the case of HN, very few people know much about Moxie, so the only useful signal they can convey is expertise. Many people come here because of their technical or product development background/interests, and the way they show expertise is by second-guessing technical, user interface, and other issues. As a result of this combination of constraint and desire, we get a bunch of comments where HNers talk about how they'd make Signal (as well as every other product) better/more useful. [1] From Deborah Tannen's works
- cwyers 6y agoHuh. I did not expect a serious and insightful answer to my entirely rhetorical question. Thank you!
- saagarjha 6y agoI think this is an uncharitable view, and while it might be true in some cases it is certainly not always the case. Many times the people who point out issues with Signal do it not because they think they want to show off, but because they honestly are frustrated that no product seems to meet their needs and Signal has specific issues that matter to them. I honestly believe “Signal is stupid for relying on phone numbers and SGX” is really just “I don’t trust this things, they have a track history of having issues, I would really like to use this service and am sad that you chose to do this”. Hacker News is often not very good at conveying what it is trying to say, but I remain optimistic that it’s more than a intellect measuring contest.
- olah_1 6y agoSignal’s recent (not even yet out for many) implementation of mention-only notifications has reinvigorated my investment in them. I am a bit more confident now that usernames will eventually come. But the fact that it’s so slow to change is quite ironic, considering that the whole point is “the ecosystem is moving”. Well apparently it moves like molasses.
- StavrosK 6y agoWhat are mention-only notifications?
- codethief 6y agoFrom https://signal.org/blog/new-groups/ https://signal.org/blog/new-groups/ : > You can now get someone’s attention with @mentions in groups. You can mention anyone in a group message simply by typing “@” and selecting them from the picker. […] And you can configure the group’s notifications in Group Details to only notify you when you’re mentioned.
- spurgu 6y agoNot if said moving leads to having to spend all time fixing existing things and leaving little to add new ones. Don't know how true this is though. Re: mention-only notifications I definitely agree - if they exist now for groups then this makes Signal quite an attractive alternative to other messengers. I'm using Matrix for some things now but notifications are set globally (not per client/device). I'd like to keep all channels on mobile on mention-only (I try to minimize mobile notifications in general) but when I have the desktop (or web) app open I don't mind getting all notifications from particular channels. That makes me able to keep up with conversations in real time. And if I want to not be disturbed I just close the app or disable notifications globally (MacOS). With Matrix (at least the Element.io clients) this is not possible so I end up switching the notification settings back and forth...
- elevation 6y agoIt's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech nerds nit pick Signal's implementation, they ignore that the unfederated nature of Signal limits the damage these decisions can cause. Thanks to Signal's security posture, global protection from weak ciphers, buffer overflows, and even SGX, is just one software update away. This even protects you from faults in your contact's clients! Like the key agility that makes the Axolotl Ratchet so superior to GPG, update agility makes Signal infinitely superior to every existing or proposed federated network. The Signal group has an uncompromising commitment to user privacy and a poignant security philosophy. Signal has no competition in its usability class, making hypothetical protections from other products worse than useless for user cohorts who will probably switch back to skype or sms. Signal's detractors do a terrible disservice to the people they dissuade from using it.
- ryukafalz 6y ago> When tech nerds nit pick Signal's implementation, they ignore that the unfederated nature of Signal limits the damage these decisions can cause. It limits the damage that some decisions can cause, but exacerbates others. Signal only allows the first-party client to connect to its network; if the developers were legally compelled to add a backdoor into that client, users would have few options. Its security depends on a single company being perpetually trustworthy, free of influence, and supported. Having used many chat platforms that have been shut down/acquired/etc in the past, that’s not a bet I’m willing to take. I’d also contest the idea that Matrix can never have a client as usable as Signal, but I’ll agree that there isn’t one yet.
- novok 6y agoSignal is OSS and you can start your own fork & network if you want to. App publishing platforms not having a good binary signature verification system is the orthogonal issue that you're bringing up, that would in many ways apply to matrix for most users too. Most will never bother to sideload it.
- maxerickson 6y agoCould Signal use phone number pairs to robustly implement a "make me visible to" discovery method? It could certainly implement contact matching based on number pairs instead of just numbers, but I haven't reasoned through whether it could robustly (and efficiently I suppose) keep other parties from enumerating the number pairs.
- RichardHeart 6y agoI applaud the man for trying really, really, hard to make a difference, and succeeding. I look forward to the day when Signal doesn't require a phone number. Telegram, while requiring a phone number doesn't require you to disclose it to receive messages. Others having your phone number opens you to all kind of other attacks, which are quite bad. Sim swapping, and SS7 attacks. SS7 vulns can disclose your real time location and more.
- sdenton4 6y agoOTOH, Telegram's crypto is... suspect. https://security.stackexchange.com/a/49802 https://security.stackexchange.com/a/49802
- emptysongglass 6y agoSigh. That Stack Exchange answer is incredibly old and points to the flaws everyone knew in MTProto 1, which has been superseded by MTProto 2 for years. MTProto 2 is based on standard crypto primitives that not a single human being has found fault in. Please do your research before putting this stuff out there in the future: it spreads unnecessary fear, uncertainty and doubt.
- akvadrako 6y agoUsing standard crypto primitives isn’t enough. I tried to find a review of the security of telegrams new protocol a few months ago and came up empty. So asking the parent to “ do their research” isn’t helpful. And it isn’t FUD to treat an unknown system as insecure.
- emptysongglass 6y agoYou are welcome to develop your argument and point out where in MTProto 2 you find fault or why using standard crypto primitives isn't enough and what you'd like to see from MTProto 2 to secure it in your mind. The gp comment literally just posted a link to a deprecated comment that painted MTProto 1 as (rightfully) insecure. That was not thorough research and it attaches the FUD associated with an unused protocol to MTProto 2, which I'd again like to remind you and everyone, not a single security researcher or otherwise has found fault in.
- ggm 6y agoThe fundamental point is that he's doing this for good reasons, beyond the trivial in issues lists of a git backed repo: he believes in what he is doing. And, he's doing it in ways which cryptographers I respect relate to: its visible work and its open to critique. I have my own kibbitz about stuff down in the weeds, I think the decision to make a cellphone/SMS identity key in the recruitment and to have one device per identity is a design issue for me and my use case, but I understand this is not a black/white thing, and there were noises made in 2019 about moving to a different model of identity, I an content to wait, but there is the vague meta-question if the ranking of this kind of idea gets exposure too: How do we know the thinking around identity and recruitment?
- baybal2 6y agoCryptography is a black, and white field. Either crypto algorithm is deemed 99.9999999999+% physically unbreakable, or anything less, and it doesn't work.
- elcomet 6y agoExcept that it's not true. Even proven mathematical algorithms can be breaked if not implemented correctly, or some side channels might be discovered along the way. It's not just black and white.
- baybal2 6y agoThis put an even more extreme emphasis on being on the paranoid side, and not leaving anything to the chance, not less.
- thu2111 6y agoThat's what you'd think. Read some advanced cryptography papers and you'll discover it's not quite that simple. There are the exotic hardness assumptions: are those mathematical problems really hard to solve or not? They aren't classical, natural problems like discrete log. Then there are the odd threat models, e.g. plenty of algorithms out there claim to be proven secure in the honest-but-curious model. Although this threat model isn't entirely naive, in the real business world "honest but curious" adversaries do appear in the imaginations of business leaders at least, but most people assume the point of cryptography is to keep you secure against arbitrarily malicious adversaries.
- stevespang 6y agoMoxie Marlinspike is not his real name, it is Matthew Rosenfeld. Registration to the Signal app requires a phone no., so if you desire true privacy - - use a burner phone, and know that you are giving up your GPS location wherever/whenever you turn the phone on and connect. Rosefield, one guy, can be "bought" and you would never even know it, whereas a community of open source developers who all watch each other is a bit harder to infiltrate and take over.
- spurgu 6y agoWeird typos(?) in the article: coördinate, coöperate. Seemingly other sloppy typos like "Signal could only proffer the relevant". No critique against the substance of the article though, seems great so far, love Moxie. Edit: And the date in the URL is October 26.
- thristian 6y agoThe New Yorker's house style is to use a dieresis to indicate when adjacent vowels do not form a diphthong. There's a syllable-break in between the Os of "coöperate", as opposed to between the Os of "chicken coop", so it gets a special marker. See https://en.wikipedia.org/wiki/Diaeresis_%28diacritic%29#English https://en.wikipedia.org/wiki/Diaeresis_%28diacritic%29#Engl... "proffer" is also a perfectly legitimate word: https://www.merriam-webster.com/dictionary/proffer https://www.merriam-webster.com/dictionary/proffer
- spurgu 6y agoWhile being a non-native speaker I still consider myself to have a high grade of English knowledge and I knew about neither of these. Thank you!
- nkurz 6y agoJust to complete the trifecta, the URL date is presumably that of the print issue in which this article will appear. This "cover date" is usually a week or so ahead of the actual printing date: https://en.wikipedia.org/wiki/Cover_date https://en.wikipedia.org/wiki/Cover_date
- deleted 6y ago[deleted]
- Xophmeister 6y agoThe diereses over the o (or any doubled letter) is an old-fashioned way of indicating a syllable break, rather than a longer vowel sound (as in “good”). It’s the New Yorker’s house style. Also, I don’t see any spelling mistakes in the sentence you mention...
- gibmeat 6y agoInteresting article about privacy on a site that contains 41 trackers.
- catchthrow 6y agoDo the trackers change any of the claims in the article somehow? I don't follow.
- zoobab 6y agoRequiring a mobile phone number to use Signal is a NOGO.
- mgbmtl 6y agoYou can use a voip number that forwards sms (ex: voip.ms). You don't need to setup VoIP, just setup SMS forwarding to email. That's what I did initially for my kid on an android tablet, and always did for my data-only phone.
- reportgunner 6y agoSo instead of giving a phone number I should register my Name, Address, Phone Number? Sounds worse than buying a prepaid SIM if you ask me.
- darcys22 6y agoAnother project that is doing interesting stuff in this space is Loki. https://loki.network/ https://loki.network/ They have built a tor/onion network and use it as the backend for their messenger (forked from signal). Its end to end encrypted and doesnt have centralised servers. https://getsession.org/ https://getsession.org/
- ancientworldnow 6y agoSession is exciting but it's currently broken. Group chats don't work properly with messages frequently getting lost and not delivered to all users. We've tried to switch several times for groups that need encrypted group chat with disappearing messages, group admin, and usernames instead of phone numbers (basically making them the only game in town) but it just doesn't work right 100% of the time which is a deal breaker.
- literallycancer 6y agoKeybase doesn't work for that?
- mapgrep 6y agoI thought this was interesting: “ Perrin told me that, despite appearances, ‘Moxie leads from the front, and he just leads by doing. One of his favorite quotes is “The only secret is to begin.” If you want to get good at something or do something, you just do it, and you figure it out along the way.’ “
- fierarul 6y agoIs this a form of personality cult? > Marlinspike is the C.E.O. of Signal, the end-to-end encrypted messaging service, which he launched in 2014; he is also a cryptographer, a hacker, a shipwright, and a licensed mariner. What's all the hype about Signal? It's a bad application. Let's see. Install it. Oh, it starts with a screen about Terms and confidentiality. But... why does Signal get me to agree to things if it's so much about privacy? Are they... reading our chats? OK, next. Oh, it needs access to Contacts and Media to improve communications. Right -- because nothing like that sweet social graph. But I can skip this one. Oh, now it wants my phone number! Experiment complete. Let's uninstall this app. I fail to see how this is any better than Whatsapp.
- amoorthy 6y agoThis old post from Moxie Marlinspike in 2012 about having the worst material possessions made a huge impact on me for some unclear reason. Fun read. https://moxie.org/2012/11/27/the-worst.html https://moxie.org/2012/11/27/the-worst.html
- yetihehe 6y agoAhh, I'm from the camp of "the worst". My girlfriend is from that "the best" camp, but doesn't have too much money. So we can't use that little more expensive aluminum foil, because it's for "special occasions". She got upset because I've slightly damaged cheapest workshop vacuum (it's cheapest, but happened to be rather good quality) using it for heavy duty tasks (and saved 50x it's price by doing those tasks myself). Is this the live one should live? To be slave of your possesions? Do you really need the best tools from the start? I've started with cheapest possible ones and if they break too soon, I'll get better ones. But for now, the almost cheapest ones fully earned their worth.
- BTCOG 6y agoNo, you should make more money, and act accordingly.
- Zak 6y agoI don't find these ideas really contrast as much as they initially appear. Curtis advocates optimizing for some absolute best when shopping for stuff (which as a hobbyist product reviewer I find a bit absurd; few products are one-dimensional enough for that). Marlinspike talks about the value of unplanned life experiences. There's a middle way for a lot of product categories: find an enthusiast community and get their recommendation for a low-cost and beginner-friendly product. It's often listed in their FAQ. The gap between enthusiast-grade and mass-market products in some categories is huge, while the gap in price may not be.
- nickthemagicman 6y agoHe's a great writer, his post on privacy and privacy abuse was eye opening for me https://moxie.org/2013/06/12/we-should-all-have-something-to-hide.html https://moxie.org/2013/06/12/we-should-all-have-something-to...
- Saint_Genet 6y agoI don't know enough about Moxie Marlinspike or Signal to really have an opinion, and was hoping to maybe learn something by reading this but I'm afraid this is more hagiography than profile.
- spurgu 6y agoYeah this might be appreciated way more by those who have some kind of "connection" with/to him already. I first learned about Moxie by watching his sailing documentary Hold Fast[0] (I'm an avid sailor in a similar low-tech gritty way as him) although I just thought he was some random dude. It was only years later, after having used Signal for some while that I actually made the connection. I have lots of respect for the man and love his thinking, writing and outlook on things. His blog[1] has a lot of good reads. [0] https://vimeo.com/15351476 https://vimeo.com/15351476 [1] https://moxie.org/blog/ https://moxie.org/blog/
- deleted 6y ago[deleted]
- PH01 6y agoWhat is it about cryptography that creates a tendency toward hagiographies? During the Snowden Leaks the same thing happened with Jacob Appelbaum and Julian Assange. There was no critical analysis on what they were actually doing or a lot of the advice they were giving people. It's almost like the field somehow requires a defacto head who conveniently fits the media stereotype.
- sheinsheish 6y agoI won’t bother reading this, it seems to be a standard time waster. Coincidentally I saw this yesterday https://youtu.be/IWMZ17Iyu3o https://youtu.be/IWMZ17Iyu3o “What’s wrong with Signal etc. “
- creata 6y agoYou haven't even glanced at the article, which tells us a lot about the fascinating life of a very interesting person, and to add insult to injury, you then link to a video that does nothing but state the obvious (with much melodrama) for 17 minutes. Frankly, this is the laziest dismissal I've ever seen.
- acdha 6y agoIf you have time to watch a long, low-information video you have time to read the article so you can comment knowledgeably.
- skee0083 6y agoSignal is a honeypot that requires a phone number to even use it.
- deleted 6y ago[deleted]
- ir77 6y agoincidentally, does anyone know what happened to happs like whispercore from 2011? are there new apps like that that exist on android or ios? is Adguard DNS about the closest thing to that now?