4 ms·
It is pretty easy to say it is good if you dismiss anyone saying it isn't as bitching. Signal was insisting everyone using a phone number as identifier. We now
by nadmone 4y ago
It is pretty easy to say it is good if you dismiss anyone saying it isn't as bitching. Signal was insisting everyone using a phone number as identifier. We now know there were zero-click iMessage exploits being used by oppressive governments to target politicians, journalists and activists. All they needed was your phone number. It is slightly more complex than that but still you do the math.
- harry8 4y agoIts even easier to criticise it and completely ignore "...but make sure when you do you compare it to the success of literally ever other attempt to bring e2e to the masses." Signal is a stunning success. If you or anyone does better I will cheer and yell about your success often. >We now know there were zero-click iMessage exploits being used by oppressive governments to target politicians, journalists and activists. Firstly citation needed please. Secondly, great, should they have been using email and pgp? Or google chat? Or are you saying the NSA should have just had all comms on their servers without going to any further and targeted effort. Any software project can be criticised. And _should_ be. Just when you do it don't overlook its success which for signal was the first one that actually worked after decades of efforts. Now go do better.
- misnome 4y ago> Firstly citation needed please Pegasus.
- posterboy 4y agoNowhere have you indicated how you measure the success. Number of users is no indicator for quality, for one. Code quality would be a rough guestimate because it is not open. Pick your poison.
- harry8 4y agoWha? Is it bad to quote yourself twice in the same thread? "... success of literally ever other attempt to bring e2e to the masses." Attempt to bring e2e to the masses. How many actually using it is that metric. Before open whisper & signal: how about number of people I knew with whom I could communicate securely with using pgp. 1. Total number of people in the world who could do it. A few thousand tops? You reckon it got to 10k, 100k. I can't imagine it got anywhere near a million... Today: Number of people doing it everyday without thinking about it. Over a billion. Sometimes metrics are so overwhelming that you have to tip your hat to it. This says nothing about any other dimensions of analysis other than "Number of people actually using e2e." It's a hell of a metric we can give credit to Moxie & co. for. That /one/ dimension is just wow. People tried before, for decades. It just didn't work out on that one metric. Something would have to be pretty bad to make that metric not dominate the discussion of overall success. But yeah, this is just the success of getting people using e2e and it's a massive achievement.
- nadmone 4y agoMost of those people aren't using Signal but the Signal Protocol. When people say they want different identities, infrastructure or clients what they are essentially saying is they want to use the Signal Protocol but they aren't Facebook. They can't spent millions on development and maintenance so instead they want to integrate with the existing ecosystem. Signal being successful because it is implemented by different parties and therefor used by many people seems more a counterargument to the state of Signal because it would suggest that Signal would be better if more people could use it for more things.
- posterboy 4y ago> Is it bad to quote yourself twice in the same thread? pretty bad, actually. The reported number of users does nit equate with number of securely e2e protected users
- ragnese 4y agoWhat's not open? Signal is open source.
- deleted 4y ago[deleted]
- bragr 4y agoParts of it are open source. It's not like they'll let you come audit the AWS accounts.
- ragnese 4y agoNo- for sure. But if that's the last argument someone can put forth about trusting Signal, that's pretty damn good. Most privacy/security investigations end by the second paragraph of a EULA where the service tells you that they farm and track every bit of information possible and sell it to third parties before the electrons/photons finish passing through their network cable. And I'm fairly sure that's not what the poster above me actually meant, anyway. When you say "it's not open", do you really think they're saying that in the context of not knowing that the source code we can see is the code that's actually running on the server? If that's what they actually meant, then why would they say that at all, since literally no third-party service is "open" by that definition? They clearly are under a misconception that Signal is closed source or that the protocol is secret or something. They're probably thinking of Telegram, which IIRC, is not open.
- nadmone 4y ago> Signal is a stunning success. That is what those criticizing it disagrees with, at least in that area. It is not a stunning success at letting you communicate with someone without disclosing a phone number. > If you or anyone does better I will cheer and yell about your success often. And that is what people are criticizing about the ecosystem when they say that it is hard to run your own client or infrastructure. > Firstly citation needed please. Search "zero-click iMessage exploit" and pick your favorite source. > Secondly, great, should they have been using email and pgp? Or google chat? Most already do because Signal doesn't really cater to other use cases. When people say they want federation or different clients it is often because they want to replace things like e-mail.
- imwillofficial 4y ago“not a stunning success at letting you communicate with someone without disclosing a phone number.” Which it has NEVER claimed to do. The goalposts moved so fast my neck broke.
- nadmone 4y agoI didn't say it did. The post I replied to, which wasn't you, is arguing that Signal is successful. Therefor it is highly relevant whether it actually is. I don't know which goalpost you are talking about.
- imwillofficial 4y agoThe measurement of success. First it was R2-D2 (I meant E2e, but I like the auto correct so I’m leaving it) encryption, then easily exploited vulnerabilities, now somehow phone numbers got drawn in the mix. Basically you’re you’re shifting anytime you get pinned down and it shows.
- nadmone 4y agoNo, the phone numbers are in the second sentence of my first comment. The exploits are in the sentence after as an explanation to why it was bad to use phone numbers. And that is only one example to make it a reasoned argument. Other such points can be found in the video. I am happy to argue the points but don't make up some characterization. It wasn't "then", "now" or "shifting". I've made the same points all along.