6 ms·
Good, this is why E2EE and user-controlled communications need protected at all costs. Citizens need to defend the right to communicate privately and ephemerall
by branon 2y ago
Good, this is why E2EE and user-controlled communications need protected at all costs. Citizens need to defend the right to communicate privately and ephemerally from government snoops. Because if they can force (or try to) Amazon to fork over comms records, they can do the same to me or to you.
Destruction of evidence is one thing, let them get nailed for that. But they weren't afraid to communicate privately and neither should we.
And we can't let the government hold these antitrust suits up as an example of "this is why we need to break encryption, so we can protect consumers from the big bad monopolies" either. I bet that'll be the narrative at some point.
- hereme888 2y agoAgreed. If their data is safe, the rest of us are safe, too. I'll keep using Signal.
- 1oooqooq 2y agoproblem with signal is that server is an unknown. still a million times better than most alternatives. maybe matrix today can compete. but that's it.
- fragmede 2y agoyou can verify safety number out of band to assert that signal's server isn't mitm-ing you
- gaganyaan 2y agoYou can't actually assert that. You have to hope that they or someone else hasn't found an SGX weakness: https://www.vice.com/en/article/pkyzek/signal-new-pin-feature-worries-cybersecurity-experts https://www.vice.com/en/article/pkyzek/signal-new-pin-featur...
- fragmede 2y agoThat article doesn't contradict that. Signal's new feature is to store users' address book on their servers. That's not great in the case of an SGX break, but that's not the same thing as Signal mitm-ing messages.
- 1oooqooq 2y agothe lack of awareness in this thread... the pin/number-as-id is just the cherry on top. we know nothing about signal infra or why the server code is closed. for all i know mox have the root password on a post it and it's MitM from day one. also they boast about things being easy to verify on client but the default client doesn't and they are very against custom clients... which is very schizophrenic
- fragmede 2y agoThe client code is available though, and that's what's needed to verify that it's not MitM'd. If there's something you'd like to make me and others aware of, I'm all ears. Otherwise you're just casting baseless aspersions.
- dns_snek 2y agoYou're also relying on the client not lying to you, and Signal is openly hostile against 3rd party clients of any kind.
- dwallin 2y agoThis is not two citizens having a private conversation. These are actions and conversations taken on behalf of a corporation. Corporations are given tons of privileges, but in exchange they have additional responsibilities that individuals do not have. If employees cause the company to violate those responsibilities the employees are generally not held directly responsible (unless they were directly violating a law). It’s the company itself who is held liable for the actions of its employees in this case.
- elevatedastalt 2y agoYes but companies are not expected to record all audio conversations going on in their offices, or to put recorders on their employees. In the era of remote work it's common to have ephemeral conversations through text, which are no different from employees chatting at the watercooler. Employees and execs should be free to have those conversations through ephemeral apps. There is no obligation on any company to deliberately create paper trails of everyday conversations b/w employees.
- ethbr1 2y ago> There is no obligation on any company to deliberately create paper trails of everyday conversations b/w employees. You know, those everyday conversations around the water-cooler about how we're going to respond to a DOJ anti-trust lawsuit...
- pylua 2y ago
- anigbrowl 2y agoCorporations are not people
- stefan_ 2y agoThis is funny because a thread over there is gonna be (the same?) people arguing "its the company computer they can spy on you all day you have no rights". Maybe there is a middle ground to be found in the insanity but it's definitely not "privacy rights for limited liability legal constructs".
- 127 2y agoWho are you quoting, exactly?
- HeatrayEnjoyer 2y agoCorporations are not people and does not have a private life, and does not get privacy rights. History has shown time and time again why powerful entities need transparency and accountability.
- dcow 2y agoBut people are people.
- coredog64 2y agoSo why should it be that you and I get along so awfully?
- shermantanktop 2y agoPeople can be corporations. Some people are single-person corporations. Or they run corporations where every significant act by others is directly approved by them. Or they lead corporations which act according to their every whim, stated desire, implied wish, or anticipated future demand. Are they literally corporations? No, but the line is hard to draw. EDIT: or maybe I don’t listen to enough Depeche Mode?
- klyrs 2y agoDid not need that earworm, thanks.
- sumedh 2y ago> Corporations are not people Corporations are people, my friend - Mitt Romney.
- deleted 2y ago[deleted]
- salawat 2y ago>Because if they can force (or try to) Amazon to fork over comms records, they can do the same to me or to you. You are not a corporation. Your existence isn't entirely enabled by an implicit grant of existence that essentially requires you to comply with all relevant regulations in exchange for legal concessions and protections. Now... What you should be worried about is Third Party Doctrine, a legal paradigm by which any communication over a network infrastructure you yourself did not build is suddenly considered non-private. Also CALEA.
- dada78641 2y ago> Because if they can force (or try to) Amazon to fork over comms records, they can do the same to me or to you. Since when am I a trillion dollar company?
- paulddraper 2y agoHm, that's a good point. You're even less able to defend yourself.