Thing is, this better be a really important case. Because if users migrate and stay on Telegram, it could be much harder for Brazilian courts to get records in the future.
Yeah, that's the way that I see it. I don't believe this is the right kind of gambit to be playing. Not only would I expect Telegram to be even more likely than Facebook to tell the judge to shove the subpoena up his arse, he has escalated a war with a company that often is very good at fighting all of its battles on its own terms.
I am now very curious who the subpoena was going after.
Why would it be harder? Telegram has the entire plaintext message history for every message all of their users have ever sent, WhatsApp doesn't. It's much easier for Telegram to comply, not harder.
I'll defer to you on this one as you're an expert in the field.
The problem WhatsApp has right now in Brazil MIGHT be caused by them simply not posessing the information the judge wants them to hand out. But I am heavily speculating here, since I neither know what information they were asked for, nor whether the data in question was end-to-end encrypted.
The problem with WhatsApps encryption is of course that you have no way to check the encryption status of a conversation. It seems to only work for one-to-one messages between Android users as of the end of last year. Maybe this has changed in the meantime. Maybe the encryption has been enabled for more or less users in the meantime. Who knows.
http://www.theguardian.com/technology/2014/nov/19/whatsapp-m...
Sure, here's how Signal implements forward secrecy in their messaging apps:
https://whispersystems.org/blog/asynchronous-security/
Unlike Telegram, Signal is end-to-end encrypted, which means that Signal themselves cannot read your messages, and therefore could not be compelled to divulge them. Because of forward secrecy, even if recordings of an encrypted exchange are made (and as far as I can tell Signal does not record them), they cannot be later decrypted with a compromised key.
WhatsApp, Telegram etc. are going to eat Signal's lunch because of the UX and I would like that not to happen.
There are also features some consider good UX but Signal shuns because they create confusion regarding the security properties (i.e. self-destructing messages). Signal's number one priority is security while that is not nearly as important for Telegram in practice. A lot of the UX advantages the latter has can be traced back to this essential difference.
I agree though that something like messaging multiple people without creating a group first is more or less UX-only and would probably make sense (groups are anyway a client-side abstraction only in Signal, servers have no concept of them, so making anonymous or automatically named groups on the fly should be doable)
Also probably getting in touch with OWS on their mailing list is more effective than hoping they notice random posts on HN. It is not the most contributor-friendly project on the planet but clearly articulated and focused posts are usually answered and so are issues/pull-requests that conform to their stated guidelines (do not add extra options, do not put security second, etc.)
1) It was not immediately obvious to me that I have to select the name to msg. iMessage deals with this by having a specific messaging icon that makes it clear.
2) I was able to guess that the grayed out names meant no messaging but then again I tried to call multiple of these contacts and it does not seem to work properly in that that I can't seem to reach those people. Not sure if this is broken... Part of this is the legacy of Redphone/Textsecure so as Signal spreads as a single app across platforms, I'm hoping this issue somewhat goes away. [1]
3) It would certainly be nice to have the whole contact list be visible instead of just the known contacts with Signal/Textsecure/Redphone along with the ability to easily share an invite to others to use Signal via iMessage, email etc. (use the standard iOS share dialog) I'm willing to bet this gets a lot more people to see/use/invite others.
4) I would argue that groups/multi-device is the same abstraction in this case (each device would be a hidden subcontact) hence it should be possible to get multi-device support in short order if group support is already there.
I don't believe any of the things I've listed above have security implications but I could always be wrong. Maybe I'll file some tickets this weekend if I have some time.
I did some digging and found the link below. Requiring people to understand and handle an issue around a bloom filter is a bit much. That part should just work.
[1] http://support.whispersystems.org/hc/en-us/articles/21274348...
Here's the situation: people hem and haw about Telegram's cryptography, but what we should really be talking about is that Telegram is not using end to end encryption by default. Telegram stores your entire plaintext message history server-side. There is nothing worse when it comes to privacy, but it's very easy to write slick clients when they're just views onto the server and all the logic happens there.
I'm pretty sure that you are aware that UX is a problem. I'm saying this because I do think UX is a priority for users and hence for widespread adoption.
There are legitimate reasons why Telegram is more popular and as evidenced, security first is not a sufficiently valid sell for Joe User. Obviously, there are also fundamental reasons why Telegram should not be used as you have pointed out above.
I want to see Signal succeed which is why I've made the comments about.
While I have your attention, maybe you could clarify the protocols used between Signal and WhatsApp. Is there a scenario which there will be interoperability? I believe that you previously alluded to the implementation of e2e being separate in WhatsApp but it would be nice to get some clarity around this. Thanks.