4 ms·
OK, fair enough. I guess my point was a little bit broader: anyone who knows anything about The New Yorker will think you're ignorant for having written what yo
by md_ 3y ago
OK, fair enough. I guess my point was a little bit broader: anyone who knows anything about The New Yorker will think you're ignorant for having written what you did. Your comment here sort of confirms that.
By all means, you're not the first person to proudly wave their ignorance on the Internet, nor will you be the last, and yours isn't especially egregious by Internet standards. I am baffled that you would want to write a blog post about how ignorant you are and then submit it to the front page of HN. If I were you, I'd, like, not want people to read that?
But, up to you. Good thing you don't use your real name I guess. ;)
> > Just to head off the inevitable deluge of GPG-encrypted emails with dramatic subject lines, we are not doing this in response to any kind of legal threat or pressure. This is just a weekend hack; please don’t make us regret it.
This doesn't say what you said it says.
> tl;dr: it's not reproducible with shared libraries, or gradle and it was just a hack, please don't make them regret doing it.
As I said, in which codebase does the key verification and encryption live--is it in the native code, or in the Java code? I suspect you don't know, or you don't know why that matters.
> Oh, and did you actually run through the steps? Or is it merely enough that having them listed makes you trust them?
Oh, definitely the latter.
- dijit 3y ago> anyone who knows anything about The New Yorker will think you're ignorant for having written what you did. Well, I am ignorant, I don't know the internal workings of every single magazine, but I am aware how the media engine is working since I also work in the entertainment industry. I am sure you are not genuinely claiming that it's impossible for them to be influenced by PR firms or external marketing spend? That you sincerely believe they are never influenced by external marketing of people? How might you suppose they find people to write profiles on? I personally know that it isn't chance. > Good thing you don't use your real name I guess. ;) I do use my real name for whatever it's worth, I have absolutely no problem wearing these statements on my sleeve- if you read the article you would see my real name plastered at the top of the page and a link to my video game credits buried near the bottom of the page in the "Commonly Asked Questions" section. I'm really happy you took the the time to respond to me though, since you are precisely the type of person I'm writing this for; people who are emotionally pro-signal, when in reality there's no reason to be. Do you even read how aggressive your tone is? If you actually had anything meaningful to say I would feel terrible.
- md_ 3y ago> I am sure you are not genuinely claiming that it's impossible for them to be influenced by PR firms or external marketing spend? That you sincerely believe they are never influenced by external marketing of people? How might you suppose they find people to write profiles on? I personally know that it isn't chance. "PR people pitch profiles to writers" is very different from...oh, what did you write? "From everything I personally know about the media, articles like that are usually paid for..." The former is normal journalism. The latter is an ethical breach. So, yes, let's talk about tone for a moment: in your post, you accused multiple people of ethical or legal breaches, on the basis of, oh...your feelings? Very respectful of you! Yes, my "tone" is direct. But I didn't accuse you of anything unethical, did I? > I do use my real name for whatever it's worth, I have absolutely no problem wearing these statements on my sleeve Hahah, OK then. > I'm really happy you took the the time to respond to me though Oh, but I did. As far as I can tell, you made one, and only one, technical claim: that Signal's reproducible builds aren't useful because they don't cover the NDK code. I asked you, twice now, "As I said, in which codebase does the key verification and encryption live--is it in the native code, or in the Java code? I suspect you don't know, or you don't know why that matters." You have twice now failed to reply to that. Care to try for a third time? Edit: Seems like Signal's reproducible builds now do cover native code, though I haven't tried this myself: https://github.com/signalapp/Signal-Android/blob/main/reproducible-builds/README.md https://github.com/signalapp/Signal-Android/blob/main/reprod.... So, like...what was your point again? Other than that you don't know what you're talking about?
- dijit 3y agoYou think it matters where the key lives? Why do you think that? Do you think it irrelevant that your phone auto-updates without consent (citation in TFA), do you think it irrelevant that the reproducible builds are -- not, you wouldn't ever need to touch the key to bypass signal. You want me to go into semantics but anyone with half a technical brain knows that RCE, logging, remote screen capture, or anything that can read memory will easily break security and doesn't have to be colocated with the code that actually does the encryption/decryption. Also I made multiple technical claims: * "third party clients are a no go" * "third party networks are a no go" * "Automatic updates are enabled and forced" (due to "move fast" ;)) * "The code on the server has been provably non-public" * "Forces the use of a globally unique number that can often be tied to personal identity and will always be tied to physical location" Care to answer these? ;) EDIT: seems like Signal has a spotty relationship with reproducible builds but they are trying to keep it and even have an automated job for it, though it seems people are often unable to reproduce: https://community.signalusers.org/t/beta-feedback-for-the-upcoming-android-6-5-release/49995/19 https://community.signalusers.org/t/beta-feedback-for-the-up...