13 ms·
Signal 2.0 released with private messaging support
- 13 12y agoStill asks for a phone number. Useless.
- tptacek 12y agoYou want to read this conversation between Matt Blaze and The Grugq before making your mind up on that: https://twitter.com/thegrugq/status/572472282028744704 https://twitter.com/thegrugq/status/572472282028744704
- moe 12y agoI agree with 13. There needs to be a way to have an account that is not tied to a SIM card or any kind of phone number. I'm frankly astonished there's even a debate about that.
- 13 12y agoI'm just astonished that there's even justification for it not being an option. Bang on about easy discovery all you want, there's lots of people who don't want to give out their phone number for no good reason to some strangers.
- mullen 12y agoGet a Google Voice number (Free. Use throw away account) and use that. There are instructions out there on how to connect a Google Voice number to Signal.
- tptacek 12y agoThis is nowhere nearly as simple as "you just published your phone number to TextSecure": https://whispersystems.org/blog/contact-discovery/ https://whispersystems.org/blog/contact-discovery/ It is a very real security issue, too. What Matt Blaze is talking about with "extra namespaces" is a giant piece of attack surface TextSecure is avoiding.
- moe 12y agoYou keep talking about "discovery". I don't want to be discovered. I don't want my Signal identity to be tied to any phone number.
- TillE 12y agoUse other tools. There's plenty of alternatives for secure communication. The OWS apps have a specific purpose that's closely tied to how smartphones are used.
- wtbob 12y agoI think that I'd be happier with social-network discovery: I can see my friends, and those of their friends whom they have shared with me; I can then ask to become friends with those whom I know, and then see their friends, and so forth. My namespace would be local to me, but I could browse my friends' namespaces as well.
- darklajid 12y agoWe're getting back to the issue of 'usability' though. My desktop has no phone number, my tablet has no phone number and .. I have multiple phones, which have different phone numbers. I would like to use a single IM account (hey, like with mail. Or xmpp). TextSecure doesn't allow that. TextSecure is not usable in these scenarios. It's not about "Could TextSecure leak my number", it's more about "The current architecture of TextSecure makes no sense for these use cases and seems to be quite close to WhatsApp et al - even before their agreement". A telephone number is not an identifier, it's not stable and it's not something you can expect as 'given'. This is a broken system. As 13, the thread starter, mentioned.
- edwintorok 12y agoHaving a way to work without a phone number would also be a requirement to use it on a desktop/laptop or tablet.
- jlund 12y agoYou can install Signal on a WiFi-only iPad and use any phone number to register. This will also be the case for the upcoming desktop client.
- aw3c2 12y agoNot useless, but not as great as it could be indeed. I would love to publish my textsecure contact details online but I would never publish my phone number.
- higherpurpose 12y agoAwesome. Is there a rough timeline for Signal on Android? What about the desktop version - will there still be one? (at least a Whatsapp Web/Pushbullet style "desktop app")
- joycey 12y agoFor desktop- https://github.com/WhisperSystems/TextSecure-Browser https://github.com/WhisperSystems/TextSecure-Browser
- simoncion 12y agoFor those who might clone, build, and use without actually reading the readme, take note of this warning by the project maintainers: "warning: This project is still in the prototype phase. It contains many bugs and lacks many features."
- citruspi 12y agoSignal for Android is already available, kinda... It's split into TextSecure for the messaging portion and RedPhone for the call portion[0]. [0]https://whispersystems.org/ https://whispersystems.org/
- desdiv 12y agoThere are some compatibility problems between Signal and RedPhone. I can't seem to get the two to work together for international calling. Googling "Signal can't connect to RedPhone" shows that I'm not alone in this. Guess I'll have to wait for the Android version of Signal.
- matt2000 12y agoOne question I always have with secure systems distributed by app stores, even the open source ones, is how to you verify the source you're reading is the app you're using?
- adrusi 12y agoWell, there are several ways to get read access to the iPhone's filesystem. You can grab the binary from the phone and verify that its the same as when you compile the app on your own machine. No one's going to do that for most apps though.
- citruspi 12y agoSo, I'm not intimately familiar with the code signing process, but I imagine that the bundle on the iPhone wouldn't match the one you would get by compiling the source on your machine. The former would be signed with Whisper System's distribution certificate, which you couldn't do on your system because you don't have their certificate.
- zokier 12y agoCompared to other issues I think stripping/ignoring signatures for comparison should be fairly minor issue.
- maxmouchet 12y agoIsn't there chances that different LLVM versions or flags ends up building a slightly different binary ?
- zokier 12y agoAnd now you are aware of the difficulties in producing reproducible/deterministic builds. This would be a good starting point for further reading: https://wiki.debian.org/ReproducibleBuilds/About https://wiki.debian.org/ReproducibleBuilds/About
- 12y ago
- dcre 12y agoI see it's open source, but is there a good third-party security evaluation of this anywhere?
- dcre 12y agoHa — found one: > You need to have Signal on your iPhone. Full stop. https://twitter.com/tqbf/status/572469319554088960 https://twitter.com/tqbf/status/572469319554088960
- huhtenberg 12y agoThat's an endorsement, not security evaluation. Not exactly the same thing.
- nav1 12y agoThere's a link to it in that conversation: https://eprint.iacr.org/2014/904.pdf https://eprint.iacr.org/2014/904.pdf
- exo762 12y agoYes, there is. http://www.theregister.co.uk/2014/11/03/how_secure_is_textsecure_pretty_well_secure/ http://www.theregister.co.uk/2014/11/03/how_secure_is_textse... https://eprint.iacr.org/2014/904.pdf https://eprint.iacr.org/2014/904.pdf
- itistoday2 12y agoCongrats to the Open WhisperSystems team on this awesome release! My last gripe (phone call results in only one vibration in vibrate mode), is apparently slated to be fixed in 2.0.2 [1]. Once that's in, there'll be no reason for me to use any other voice/chat app on the iPhone! Edit: Apparently it's an iOS issue. Filed rdar://20008371. Plz 2 fix it Apple! [1] https://github.com/WhisperSystems/Signal-iOS/issues/244 https://github.com/WhisperSystems/Signal-iOS/issues/244
- tptacek 12y agoThis is huge. If you have an iPhone, install Signal.
- lukasm 12y agoCan you elaborate more, please?
- scott_karana 12y agoIt's a cryptographically well-audited replacement to iMessage, Skype, and traditional telephony, all of which leave room for governmental and malicious meddling.
- WhitneyLand 12y agoIt's not really a replacement, more of a secure alternative. Ideally it would be possible to totally replace iMessage with Signal allowing non-secure messages from legacy contacts. However, even if the team were so inclined Apple does not provide adequate messaging APIs. For example, there is no way to intercept an SMS message, see message history, etc.
- mahyarm 12y agoTBH I think keeping SMS separate from an ip based communications method is better. Lets not pretend that SMS is secure. The only thing I would find missing are quick reply APIs.
- scott_karana 12y agoHow are IP and SMS traffic different, other than "packet" size and encoding constraints? Both are easily interceptable and spoofable, necessitating strong crypto. I don't see how chacha20/poly1305 is somehow "worse" over SMS.
- 12y ago
- deanclatworthy 12y agoPresumably there are still multiple ways for messages to be intercepted from the user's iPhone: - Physical access or confiscation of the device - Possible backdoor in iOS or the physical iPhone hardware? - Compromise or physical access to a host machine where the user backs up their device. Although, I'm not sure what can be done to stop this.
- lallysingh 12y agoThere's no such thing as perfect security in the real world. Instead, your best bet is to raise the cost of breaking the security that you do have. If you raise that cost above the value of that which you're securing, then you are in good shape.
- qznc 12y agoI recently learned about Sancus [0]. It provides a way to protect an application from the operating system. It requires hardware support though. So not available in any mainstream hardware right now. It also allows very secure DRM. [0] https://www.usenix.org/conference/usenixsecurity13/technical-sessions/presentation/noorman https://www.usenix.org/conference/usenixsecurity13/technical...
- petermonsson 12y agoHow is it working out? Is the messaging solid between Android and iOS? How is the group messaging working? Sorry, I just downloaded it, but I have no friends on the list yet. I'm impatient. I really want it to work.
- rbcgerard 12y agosame here. also, what is the blue button for?
- fsargent 12y agoLeft button/Screen is active conversations. Right side check box blue thing is the Archive. Swipe right on a conversation, and it goes into the right hand side. No idea why it's that way. Very odd. Why even have the option if it's going to be a first level function.
- mayneack 12y agoI've been using textsecure for a long time now: so far I haven't had any issues messaging new iOS users including mixed groups. In my experience, there might be some mms edge cases when mixing with other messaging apps, but not too many and bug reports are monitored regularly on github.
- petermonsson 12y agoCool, thanks. So, I got it working with some friends. The start is rough when you don't have any contacts. There is no hand holding like you'd expect from other messaging apps. Especially the first message to the first contact is a tough discovery. I managed to mistakenly call instead of texting and another friend did exactly the same. The error message when you are not registered yet is also not totally clear. One friend complained that he couldn't see when I had read the message (compared to Facebook Messenger). On the plus side, you've come really far in usable crypto when you're being compared to that.
- mayneack 12y ago
- microkernel 12y agoFantastic! Go-and-install-immediately!
- jscheel 12y agoWhat's the difference between this and Telegram? I'm starting to feel a bit overwhelmed with what messaging app I'm supposed to use. Also, why is ios8 required?
- petermonsson 12y agoSignal does voice calling too.
- cryptomilk 12y agoSignal/TextSecure is Free Open Source Software. There is no company behind the development of the App. It is the Software with the best security model so far. The cryptography behind Telegram is not what you would expect of todays crypto standards. A lot of security researcher have commented on this already.
- aw3c2 12y agoSure there is a company (Whispersystems) doing most the work behind it. As they state: "dedicated development is supported by community donations and grants". This is good, it allows for very focused development.
- nzp 12y agoOpen WhisperSystems isn't a company. WhisperSystems was a company, it was acquired by Twitter which open sourced TextSecure. OWS, is just a name for the community effort around these tools: https://whispersystems.org/about/ https://whispersystems.org/about/
- mayneack 12y agoIs telegram open source? I didn't see it obviously linked from their website.
- Redoubts 12y agoThey publish source for their client programs (some even are GP v3), but they keep the server side stuff to themselves.
- minot 12y agoIf anyone from Whisper Systems is reading, can you please tell me how I can disassociate my number from a Cyanogenmod installed version of TextSecure in my (now formatted and sold) Nexus 4 and get it working with my no sim Nexus 5 with Google Voice/Hangouts?
- clpwn 12y agoYour unregistering options are best summarized here: http://support.whispersystems.org/customer/portal/articles/1476197 http://support.whispersystems.org/customer/portal/articles/1...
- wtbob 12y agoSadly, it's been over a year since that post and the modifications to CyanogenMod and TextSecure haven't taken: I'm unable to unregister either CM or TS, using their tools or their website.
- cheald 12y agoTry these: * https://whispertool.cyanogenmod.org/ https://whispertool.cyanogenmod.org/ * https://github.com/daveio/whisperpush-unregister https://github.com/daveio/whisperpush-unregister Set up TextSecure with the Voice option, then go to Settings -> untick "Push messages". That should perform unregistration, then you can re-register.
- mdaniel 12y agoSomeone should warn cyanogenmod that their SSL cert is expired: https://www.ssllabs.com/ssltest/analyze.html?d=whispertool.cyanogenmod.org&latest https://www.ssllabs.com/ssltest/analyze.html?d=whispertool.c... (although I guess at 5 months over, it falls squarely into the couldn't-be-bothered bucket)
- minot 12y agoI went through the steps and unregistered. It looks like it worked. As for the SSL, my hope is that the EFF and Mozilla project will make it easier to deploy https certificates everywhere.
- mjewkes 12y agoFor those interested, I think Whisper Systems is currently hiring iOS + UX in the Bay Area: https://news.ycombinator.com/item?id=9127708 https://news.ycombinator.com/item?id=9127708
- wyager 12y agoI installed it and texted my friend. It never asked me to verify his pubkey. How does key management work? Is it all done through Whisper Systems' servers? If that's the case, how is this effectively better than iMessage? iMessage is also (nominally) quite secure, except for the fact that you have to trust Apple to verify pubkeys, which makes it quite feasible to MITM if you can subvert Apple via legal or technical means.
- jlund 12y agoKeys are trusted on first use, similar to SSH. The app also provides an interface you can use to verify fingerprints: https://github.com/WhisperSystems/Signal-iOS/wiki/FAQ#can-i-verify-my-contacts-key https://github.com/WhisperSystems/Signal-iOS/wiki/FAQ#can-i-...
- cheald 12y agoThe latter part is the critical bit here; by comparing fingerprints out-of-band you can guarantee that your keys haven't been intercepted and replaced during exchange.
- StavrosK 12y agoWhat's the point of that? Why not just indicate somewhere that the conversation isn't completely secure, rather than have the user believe it is when it's not?
- SpaceInvader 12y agoQuestion: how and where message is stored when my phone is off and somebody will send me a message? How it is encrypted and then decrypted on my device once turned on?
- matthewmacleod 12y agoIt will either be on the remote device, or os Signal's servers, depending on how the implementation works. Either way doesn't really matter; the whole point of encryption like this is to prevent third-party access to your communications. It could be stored at NSA central for all it matters, and you'd still be the only one able to read the message (using the keys on your device).
- SpaceInvader 12y agoI know how encryption works. My question was rather design wise. I.e. Which keys are used to encrypt messages on WhisperSystems servers (my public key? Or sender's?). But I'll have a look on the link below describing modified OTR protocol.
- easyd 12y agoThey are using a modified OTR protocol: https://whispersystems.org/blog/asynchronous-security/ https://whispersystems.org/blog/asynchronous-security/
- SpaceInvader 12y agoThank you easyd. That was a good read :)
- joshstrange 12y agoHmm, about 5 min in and still waiting for a SMS verification message, I assume they are just backed up right now? EDIT: After 20 min of no message I just requested another code (I had done this once or twice before) and it worked.
- stock_toaster 12y agotook me a long time to get the code too.
- zobzu 12y agoGreat app - but I fail to see how that's going to replace GnuPG.
- matthewmacleod 12y agoHave I missed the claim they made that it would? GnuPG is useful, but it's a totally different product.
- zobzu 12y agoThis is related to Moxie's blog post from last week just before the release of this software - which is textsecure for iOS - see http://www.thoughtcrime.org/software.html http://www.thoughtcrime.org/software.html. Man, you guys can't remember a thing for a single week?
- konklone 12y agoBoo on all who downvoted this bit of snark.
- iaskwhy 12y agoCan anyone explain what's the difference between using Signal and using WhatsApp (assuming TextSecure is the default protocol being used - is it?)?
- vitno 12y agoSignal is open-source while WhatsApp is proprietary. WhatsApp also uses the 2-part ratcheting developed in Aoxotle my understanding is, but they are not mutually compatable on-the-wire transport.
- frabcus 12y agoOnly the Android version of WhatsApp has encryption, as far as I can tell. Also WhatsApp (i.e. Facebook) get the metadata still - who messaged who, and when.
- furyg3 12y agoWhatsApp is a closed-source proprietary app owned by Facebook. Metadata is owned and kept by them, and normal chat data is also theirs. They claim they have started using the textsecure encryption mechanisms on their apps, but this appears to only be true for the most-recent Andriod app. So there is a high probability some or all of your messages are either not encrypted or encrypted with a key that you do not have. For these messages the police or other government agency could retrieve via a warrant or other means. Whatsapp uses a subscription model and they can decide to change the terms or costs at any time, or discontinue the product. They are not very transparant and take a long time to implement changes / fixes that they promise will be implemented. The app has a very large user base in many markets. Signal is a free open-source iOS app from whispersystems, licensed under the GPL. It's counterpart on Andriod is testsecure/redphone, which will eventually be reimplemented and rebranded as Signal for Andriod. It is secure by default, all messages are encrypted using private keys of the participants... whisper does not have they keys (so they can not turn the keys or content over to anyone). You can audit this since it is an open source app, and if you would like to fix a bug or work on a feature you can do that as well. It does not have nearly as big of a user base as WhatsApp, and needs some love before usability/features/bugginess are on-par which whatsapp (shouldn't be too hard to match as WhatsApp itself is not very feature rich and often quite buggy itself). Signal has taken it's time in development (Textsecure for iOS was 'on track' to be released in summer of 2013)... You can also make secure phone calls with Signal/Redphone, but not WhatsApp.
- marknutter 12y agoThe "screen security" feature on iOS appears to do nothing. Not exactly confidence inspiring.
- dguido 12y agoIt stops iOS from saving screenshots of the app when it closes. When an app launches on iOS, it initially draws the UI from a saved screenshot while the app is loading. This creates a privacy risk since that image may contain sensitive info.
- marknutter 12y agoOh, wow, I thought it was some sort of lock screen for the app. There should be a description.
- cheald 12y agoTextSecure has the option to lock the app after a timeout (or on command), and not unlock it until a passcode is given. I suspect Signal has something similar.
- AceJohnny2 12y agoWhy is the iPhone app called Signal whereas the Android app is called RedPhone? (as an aside, I love the screenshots for RedPhone https://play.google.com/store/apps/details?id=org.thoughtcrime.redphone&hl=en https://play.google.com/store/apps/details?id=org.thoughtcri...)
- joycey 12y agoI've contributed to the development of Signal 2.0, and you can also check out this blog post. https://whispersystems.org/blog/signal/ https://whispersystems.org/blog/signal/ On Android you can use RedPhone for secure calls and TextSecure for secure text messages. These calls and text messages are compatible with calls and text messages in Signal iOS. Someday TextSecure and RedPhone on Android will be integrated into one unified product called Signal.
- frabcus 12y agoGreat! The TextSecure brand is unfortunately dead to me. Although I liked the idea in theory of the SMS backwards compatibilty layer, in practice it confused people and caused technical problems which stopped many of my friends using it. With a reboot as a product with the new name Signal, I can market it again. Needs an Android version first though!
- higherpurpose 12y agoI agreed to that from the first day I used it. It's strange that the developers themselves don't realize it. Just kill SMS support. Nobody needs it anymore. I mean for crying out loud, data-only apps such as BBM and Whatsapp became most popular in poor countries, so I don't think the "but not everyone has money for data" argument works anymore.
- unhammer 12y agoI disagree. Most of my contact list doesn't use TextSecure/Signal; when I want to send someone a message I don't want to have remember if they use textsecure in order to open the optimal app for messaging them with. Maybe I'd even first open textsecure, then be disappointed that they're not in there and have to open the plain sms app. How annoying that would be. Nobody needs SMS if everyone could just use the same app. But my brother uses a dumbphone and my mother uses an iPhone with nothing but iMessage and I use an Android and don't really feel like installing whatsapp or whatever the latest fad is just because one or two of my friends has it. Over SMS I can communicate with them all, and if any of them ever install textsecure I get encryption as a bonus.
- mperham 12y agoI installed 2.0 and added the phone number of a friend also using 2.0. I click the + icon and I see my friend's name grayed out so I can't send him a message. What does that mean?
- mullen 12y agoHas your friend installed the 2.0 client on their iOS device? My wife has not, so her status is also greyed out on my iPhone with 2.0 installed.
- mekal 12y agoHas anybody with an iphone bothered to check the privacy policy yet? https://whispersystems.org/signal/privacy https://whispersystems.org/signal/privacy (404 with a link to Moxie's homepage) Annnd its fixed the second after I post...dang it. 404's still link you to thoughtcrime.org. Possibly a mistake.
- runn1ng 12y agoMaybe a stupid question What good is open source, when the developer can still add a backdoor later and put the backdoored version on iOS store? I still need to trust the developer. (And Apple, too, but once I can't trust Apple I can no longer the OS itself and just throw the phone away)
- d2xdy2 12y agoI think the premise of that sort of thing is that in theory, you could build your own copy and install that, or at least check it against the pre-compiled version.
- runn1ng 12y agoYes, but I cannot do that with Apple's iOS (well, I can, but I have to buy certificate for 99 dollars)
- d2xdy2 12y agoPerhaps its incorrect thinking, but I trust that Moxie and the gang aren't going to screw me over. But, yeah, in theory, you can download it and compile it. The fact that you would have to also buy a certificate from Apple to do it is just a detail. You _can_ do it.
- robflynn 12y agoAt some point, you have to decide if the $8.25/mo is worth the added security, I suppose.
- ggggkhigggj 12y agoOpen source is, indeed, a red herring when talking about iOS or Android. It's a buzzword more than anything. And if anyone thinks you're somehow safe because people can audit the open source version of a closed iOS app, they are delusional. You also have the baseband CPU on many devices, which can read unencrypted memory anyway. So it is a hopeless case. Which is why this whole secure text craze HN is on is just insane. You'll never beat the momentum of iMessage or WhatsApp. But worse, there is not even any point! Trust begins and ends with a closed device.
- ogig 12y agoI was waiting for this, even donated some time ago. Went to install it but it requires iOS8 so my perfectly functioning iPhone 4 can't run it. Is very hard to keep older iOS support? Side rant: I hate Apple is leaving my hardware off the grid. It is well cared, like new, battery is ok, no reason to think about replacing other than iOS8, and that sucks.
- stormbrew 12y agoThey addressed it in this github issue: https://github.com/WhisperSystems/Signal-iOS/issues/614 https://github.com/WhisperSystems/Signal-iOS/issues/614 I'm also disappointed in this. The people I most want to use this with are also the people who have an iphone4. I don't get the impression it'd be impossible to backport it from that post, so some enterprising individual could maybe do just that...
- dguido 12y agoI'm surprised they didn't mention how amazingly insecure it is to be running a phone that old. If you're running a private messenger like Signal, you might not want to install it on a device vulnerable to bootrom exploits that negate all the advantages of disk encryption.
- stormbrew 12y agoWhile this is true, they also, through TextSecure, support many android phones that are probably in much worse shape on that front. It's also not like web browsers refuse to use TLS because your computer's running a compromiseable version of Windows.
- droopyEyelids 12y agoThat analogy sure stopped and made me think. What a sticky issue. SHOULD browsers do that? What if your bank website refused to allow you to sign in from a machine running unpatched XP? I think right now there might not be enough exploits targeting banking on XP machines to justify that inconvenience, but it seems like a responsable argument could be made for both cases.
- _jomo 12y agoTextSecure for Android is only distributed via the Play Store. So I built it myself only to notice that Google Play Services are required for chat. I think depending on proprietary / data gathering apps is the wrong approach for an open source privacy app. It actually makes me sad. There was an issue about "This requires Google Play" on GitHub [0] which was closed by moxie with "TextSecure only requires GSF for data channel messaging. To use SMS/MMS, it doesn't." Great. I'm not paying 3 cents to send a few bytes of text via SMS. I'll rather just stick to WhatsApp/Telegram. There are a lot of issues on GitHub that makes searching them a little hard, but it seems like there is ongoing development for websockets instead of (Google-) Push messages. [1][2] 0: https://github.com/WhisperSystems/TextSecure/issues/560 https://github.com/WhisperSystems/TextSecure/issues/560 1: https://github.com/WhisperSystems/TextSecure/issues/1000 https://github.com/WhisperSystems/TextSecure/issues/1000 2: https://github.com/WhisperSystems/TextSecure/pull/2423 https://github.com/WhisperSystems/TextSecure/pull/2423
- anonbanker 12y agoInstall textsecure from F-droid. EDIT: not only is textsecure not on f-droid, but f-droid itself is woefully insecure: https://github.com/WhisperSystems/TextSecure/issues/127 https://github.com/WhisperSystems/TextSecure/issues/127
- ultramancool 12y agoIt actually seems to indicate that F-Droid has addressed every last obstacle Moxie has posed, even the more ridiculous ones. They're now even willing to distribute developer signed versions if reproducible by their build server. He seems to be standing by this ridiculous "F-Droid is harmful" non-sense with no good reasoning at this point. Hopefully someone will talk some sense into him sooner rather than later.
- dTal 12y agoWhat's weird is that F-Droid uses the same distribution model as any ordinary Linux distro, where it is assumed that all binaries are compiled from source by the distro maintainers, if for no other reason than to build them against system libraries. The binaries themselves are guaranteed to be built directly from public upstream repositories, in an automated fashion - rather like FreeBSD's ports or Arch's PKGBUILDs. The real reason Moxie doesn't like F-Droid seems to be that it doesn't provide him with analytics "with a nice web interface that displays graphs and trends of time" - rather a nasty conflict of interest in a product that bills itself as "private" and "secure", if you ask me.
- dombili 12y agoCongrats on the launch of Signal 2.0. I hope it'll be a popular app, but I have a question slightly off topic: Why can't we get an app like Signal for the desktop? Yes, I'm aware there are alternatives for the desktop (mainly Pidgin + OTR), but none of them work like Signal does (ease of use) and frankly I don't really trust using them. I'd like to think I'm ignorant on the subject and there's a good alternative out there, and if so, please do tell.
- jarito 12y agoAll the protocols for Signal / TextSecure are open source. Seems like people will probably implement desktop clients at some point, which would be really nice.
- clpwn 12y agoThat's currently in the works as a browser extension: https://github.com/whispersystems/textsecure-browser https://github.com/whispersystems/textsecure-browser You can keep track of its progress there :).
- dombili 12y agoYeah, I'm aware of that, but doesn't that require a smartphone with TextSecure installed? I don't own a smartphone. (I accept that I'm a weirdo.)
- tga_d 12y agoNo, just requires a phone number. It's still under development, but if you're curious you can check out install instructions here: https://github.com/WhisperSystems/TextSecure-Browser/blob/master/CONTRIBUTING.md https://github.com/WhisperSystems/TextSecure-Browser/blob/ma...
- dombili 12y agoHuh, I didn't know that. Thanks for the link.
- 12y ago
- subliminalpanda 12y agoBlocked in Oman, can't register :(
- Avalaxy 12y agoArgh, I kept reading "SignalR 2.0". This post was so confusing...
- saghul 12y agoIs there any documentation out there describing how the encrypted groupchat works? OTR can also give you 1-to-1 encryption, but not encrypted groupchat, so this is great news which I'd like to read more into.
- wtmt 12y agoSeems like it's not tested well. I updated to Signal 2.0 on an iPhone 6 with the latest iOS 8.x. It said that none of my contacts have Signal (that's true) and had a link titled "Invite your friends". Tapping on that took me to the home screen. Killed it and tried a few more times. No use. If it were as usable as Telegram, I'd insist my contacts to switch. But not right now.