4 ms·
SMS and security are simply incompatible. And either you fall into one of two groups 1. You know sms is insecure and this is a insecure method of communication
by dodgerdan 4y ago
SMS and security are simply incompatible. And either you fall into one of two groups 1. You know sms is insecure and this is a insecure method of communication 2. You think sms sent via signal is secure because it’s a “secure messenger”. It’s clear that HN users will fall into group 1, but the vast majority of people would fall into group 2. So for me this is an overall security win.
- monetus 4y agoThe network effect of signal not being a hub for SMS and e2ee will mean less people using e2ee, IMO.
- dodgerdan 4y agoA few years ago I would have agreed, but right now Signal is doing just fine taking users from WhatsApp (FB TOS changes + ads + social group analysis)and Telegram (sketchy non-e2ee, Russian owned, based in the middle east).
- monetus 4y agoWeird, I am in the southeast U.S. and telegram is eating signal's lunch in the social networks here.
- dodgerdan 4y agoIt’s a big pie, they’re also fairly different. And to be honest it’s only a matter of time before Telegram has a (public) security incident that drives much more people to E2EE messaging.
- monetus 4y agoI'm curious how long it will be before that public incident - they rolled their own cryptography right? With that, I would imagine that if it hasn't been pwned yet, then there would be a disproportionate amount of people trying to break it.
- brational 4y agoRolled their own and off by default.
- stirfish 4y agoWhat people are concerned enough about a Terms of Service change to leave Whatsapp, but struggle with the unlocked icon next to "Insecure SMS" in Signal? What people know that Telegram isn't end-to-end encrypted, but think SMS is?
- NoGravitas 4y agoYeah, I think this is more likely to be the case. People who don't understand encryption but used Signal as their SMS messenger were at least getting opportunistic encryption with any of their contacts who were using Signal. Now they'll probably just uninstall it (like every iOS Signal user I've ever known).
- arise 4y agoSignal has clear UI cues and redundant messaging telling you what actions are insecure.
- dodgerdan 4y agoGoogle did a security research around ssl and a crazy percentage of people think the lock icon is actually a handbag icon. The rest of the research highlighted how most users aren’t able to make informed choices, most people lack the technical basis to make those choices.
- Xelynega 4y agoSo what's the overlap of "people who care enough about e2ee for it to matter whether a message they're sending is encrypted or not" and "people who think the lock icon next to the send button in the encrypted messenging app they downloaded is a handbag" I'm willing to wager it's not as big as you're trying to imply.
- lucideer 4y agoMost of those in group 2 are not using Signal. Beyond that, the minority in group 2 that use Signal are most likely to be using default settings. SMS handling is a non-default option. So you're left with a very tiny minority. Group 1 makes up the vast vast majority of the userbase (and most likely 100% of the evangelising userbase) (Also: if things are unclear for non-technical users, that's a UX challenge, not an absolute)