Hacker Newsnew | past | comments | ask | show | jobs | submit | user3939382's commentslogin

The only time the People have anything in our sick phony republic protected is when their interests happen to coincidentally align with those of an adversarial oligarch. Not interested in digging through the 15 layers of competing interests, corporate spin, lies, and economics to determine if that’s the case here but it’s sad in any case that stories like this are the only hope we the People have of getting any crumbs out of this system.

I don’t think it’s dead at all. I use it as a phase transition to let the agent decide when discovery is sufficient, as an intermediate phase between that and implementation. Even as a human dev you rarely go tinkering with files all over without first forming a plan.

Or they’re running into a steep diminishing return slope on R&D vs performance and are using stewardship as a cover.

I just spent a week writing a harness around the existing tunnels to make this by hand.

You're not a scapegoat you're fodder for a social warfare diversion to enable the treasury to be looted by both parties while the economy collapses. DC's puppeteers don't give a shit about anything unless it starts with $

What in the enlightened centrism?! All 3 branches of government are controlled by conservatives, as is the fourth estate.

Sorry you’re right the old men with a D on their nameplate in DC really love and care unlike the “other” side.

I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".

Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there.

I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.


It's binary because you decide to use it or not. If your threat model contemplates run of the mill adversaries you don't need Signal. If it contemplates nation states you don't want it.

>Figure out your adversaries, how much power they have and what they are willing to spend.

All of it.


Unless your adversary is divine this isn't true. In general people who believe this way make really bad trade-offs and as a result probably have worse security than most people.

Go on.

A bare minimum for a company that offers private communication services to people like whistleblowers and activists is that they clearly/plainly explain to their users what their risks will be when using the service. Signal fails at this. They outright lie to their users. They've started permanently keeping sensitive user data in the cloud, but they've refused to update their privacy policy to reflect that. Misleading or lying to users about their risks when their lives and/or freedom are on the line is unforgivable and disqualifies Signal as being a service anyone should consider.

I'm doubtful that this is true. Lying in a privacy policy is a crime.

Look for yourself. The very first line of their policy is "Signal is designed to never collect or store any sensitive information"

At one point in the distant past that was actually true! They used to brag about how many times the government came to them requesting information only to be turned away because they never collected any of that in the first place.

In 2020 they introduced a major update where they started keeping user's name, phone number, photo, and (worst of all) a list of their contacts in the cloud. This is exactly the same information governments had been requesting from them. There is no way to opt out of this data being collected. You can opt out of setting a pin, but if you do that a pin is auto-generated for you and the data still gets uploaded even though you won't have any access to it.

In 2025 they added yet another new feature called "Signal Secure Backups". This was an optional feature that let users store actual message content in the cloud as well. They've refused, for years now, to update their privacy to reflect any of that. Their privacy policy is frozen as of May 25, 2018

See: https://web.archive.org/web/20250117232443/https://www.vice....

https://web.archive.org/web/20230519120156/https://community...

Personally, I think their refusal to update their privacy policy is a big fat dead canary warning users that the service has been compromised and shouldn't be trusted. They may be under gag orders from saying so outright, but while the US government can order companies not to tell the public something, they can't force them to say something. For that reason, unless somebody sues them over it, I doubt their privacy policy will ever be updated.


WhatsApp is also sufficient for the average person. So is SMS. But they're not even slightly secure.

The average person might be legit worried about dragnet (non targeted) evensdropping of non encrypted communication. This is rational given what Snowden said.

So for the average person, WhatsApp (which is E2E encrypted) is probably quite secure. SMS is not.


Both of them are dragnet surveilled. WhatsApp is theorised to do this through its automatic weekly backups.

Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?

I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?


> Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?

While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data.

I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connections.


It's true someone snooping at either end of a conversation could over time correlate timing and sizes to show that two users are communicating, but that's the most they can do. Signal is not peer to peer so you're not connecting to your recipient, and signal itself has enough raw volume that simply correlating sizes and timing of a small number of messages wouldn't really be sufficient to know who is communicating with who.

I think they could make that significantly more difficult by adding csprng delays and padding to the messages. That way you can't really effectively correlate timing and sizes without direct access to signals inner workings. I'm not sure what signal's actual throughput is, but if think as a paid feature it could be economical.

Another crazier way would be to send every message to a large number random latched recipients. Good way to 1000x your bandwidth.

> The metadata is as valuable as the data.

This can be true if you are able to get ahold of a user's device and access their signal messages. It's not true in most other cases. I don't particularly care if you know that I am talking to someone specific as much as I care that you don't know what I'm saying.


> Ex-NSA Chief: 'We Kill People Based on Metadata'

> Hayden made the remark after saying he agreed with the idea that metadata - the information collected by the NSA about phone calls and other communications that does not include content - can tell the government "everything" about anyone it's targeting for surveillance, often making the actual content of the communication unnecessary.

https://abcnews.com/blogs/headlines/2014/05/ex-nsa-chief-we-...


> Signal is not peer to peer

Isn't it? I think it has a setting, disabled by default, to proxy connections via a Signal server. If you're not doing that ... it must be P2P? Probably with the IP address of the person you're communicating with in the header of every packet?


This setting is "Always relay calls", and the only difference it makes is for already established calls. Messages and calls setup always go through Signal's servers.

> the surveillance networks can capture metadata - who talks to who and when

If this is part of your threat model then I would suggest a different tool such as SimpleX since it uses onion routing and can be configured to always use private routing/relays.


I'm not familiar with SimpleX, but keep in mind only some types of onion routing is secure against a global passive adversary. Famously Tor is not.

One idea I had for an improvement to Tor wrt sybils was to split traffic up and send different pieces to different nodes, possibly using different circuits for the pieces, so that even if you have control over all the nodes in one path, you most likely won't have full control over all the paths it sprays the pieces over.

Nym is apparently good against a global adversary.

Session uses onion routing. SimpleX does not.

> SimpleX does not.

https://simplex.chat/faq/

> Private message routing is, effectively, a two-hop onion packet routing.

And actually, it's even better than that:

> Private message routing routes packets (each message is one 16kb packet), not sockets. Unlike Tor and VPN, it does not create circuits between your client and destination servers. The forwarding server creates one shared session between itself and the destination, and forwards all messages from you and other clients to that destination server, mixing messages from many clients into a single TCP session.

> As each message uses its own random encryption key and random (non-sequential) identifier, the destination server cannot link multiple message queue addresses to the same client. At the same time, the forwarding server cannot observe which (and how many) addresses on the destination server your client sends messages to, thanks to e2e encryption between the client and destination server. In that regard, this design is similar to onion routing, but with per-packet anonymity, not per-circuit.

> This design is similar to mixnets (e.g. Nym network), and it is tailored to the needs of message routing, providing better transport anonymity than general-purpose networks, like Tor or VPN. You still can use Tor or VPN to connect to known servers, to protect your IP address from them.


Wait, so what about the keywords in my meta tags?


FWIW Kagi has worked hard on their pricing over the last few years and has been trying different models. They're not "big search" the price is what it is so it can exist as a business. 100% fine to not be a customer obviously, but then you forfeit your license to complain about Google spying on you and ruining the web. Like they're trying to solve the problem. IMHO speaking just for myself I feel a moral duty to support them.


You can not find the value of 10 searches a day for 5 dollars and complain about Google. Yandex,DDG and Bing are major search engine choices.

Kagi has limitations like not showing sites with ads which many people with ad blockers don't mind.


What do you mean Kagi doesn't show sites with ads ?

They lower the rank of sites with ads often pushing them out.

Kagi lets you re-rank sites, and also lets you ban results from sites you don't like.

I agree on all your points. I'm just saying, that the $5 tier is not a honest to good option. The $10 one is but they can make the $5 one genuine too by increasing the quota. I'm sure they have done their research and maybe increasing it will cannibalize the $10 tier.


$2000-3,200 for a phone?

My next phone is an e-ink Mudita Kompact with a hardware kill switch. I can run a service to bridge iMessage if I decide I care.

With every year since they arrived in 2005 or so and especially accelerating since 2010, smartphone capability has grown with their creepiness. The expectation that you own one has almost turned into a demand. It's a total turn off. You don't need these capabilities, life goes on without it just fine. The drawbacks for your mental health and privacy are material.


Things like configs and install locations are always where you expect on NetBSD. It’s quite refreshing. Linux feels very messy in comparison.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: