Signal AMA on Reddit
reddit.com
reddit.com
Never is a long time. Non-profits can become for-profits. Non-profits can also spin off of their profitable components as for-profits -- just like the Mozilla Corporation is a for-profit owned by the non-profit Mozilla Foundation. Non-profits can sell ads and sell your data.
And, of course, non-profits can get money hungry just like any other organization. Look at how ICANN has found ways to vacuum up billions of dollars from the internet.
They also may not technically have any investors, but they have a de facto investor in the form a $100m loan from WhatsApp founder Brian Acton who is also on the board. He could have made it a gift, but did not -- which implies he wants the money back at some point. Signal will need a lot of donations to pay that money back -- or they could decide to sell ads or data.
All that said, I'm happy Signal is doing well, and applaud their efforts. I hope they succeed.
They have invested years giving it for free, now the ask the price (data) and users go away.
It is still essential in many countries, and many users, including myself, are unable to switch.
This is why companies first offer a product for free to gain a user base, and only then think about monetization.
> It is unlikely that we will ever federate with any servers outside of our control again, it makes changes really difficult.
I think as long as there is no federation there will always be the "benevolent dictator" situation, which often doesn't end up well in the long run.
At the same time, I'm sure that I couldn't convince my non-tech friends to switch over to a federated protocol like Matrix. The clients have been getting better, but they still lack a lot of mainstream UX. So, while Signal is better than WhatsApp for now, I think the only sensible solution is a federated protocol.
0: https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
I understand wanting to focus on security and privacy at the cost of all else, but if the goal is to get as many people on a reasonably safe messenger app as possible, UI/UX is unavoidably going to be a focal point — it can't just be made an afterthought, or as is the case with many FOSS projects disregarded almost entirely.
With Element, you first need to create a username that in the format <username>:<server>. This is a new notion and non-tech users don't know what this is about. I usually need to explain "it's like email, but instead of the @ there's the :".
Furthermore, there is this new concept of "Rooms" that people are not used to.
Also, there are some UX flaws like that you need to include the @ when adding use (it won't find the user if I try to add "joe:matrix.org", I need to enter @joe:matrix.org). This even threw me off for a minute or so in the beginning.
There are some clients that look and feel more like WhatsApp (like Nio), but they are still in early development. So, I'm hopeful.
See the clients here: https://matrix.org/clients/
Though if I compare Matrix and Keybase, there's a clear winner in terms of UX and depth of features. I will be missing that but there's no indication Matrix or Signal will reach feature parity before it's replaced. (A new messaging protocol and no isolated subservers with their own chat rooms? Really? This is why people are switching to Discord in increasing numbers)
what does cause friction is if clients expect the users to enter their own server details beyond their email address.
i find that very annoying in irc clients for example, where i have to know the details for the network to connect to. jabber/xmpp clients generally did a bit better. and i don't know how well matrix is doing it. but making this easy for the user is a matter of interface design.
there is nothing inherent in federation that makes this hard for users. the only thing is having to choose a server. but for my family for example i would choose the same server as myself, and i'd want to send them a link to sign up. that link could then provide a way to open the messaging client with proper settings in place.
if it is more complicated now, then that's a problem, but one that can be fixed
Side note: isn't it good to be centralized while the app is quickly rolling out new features? Then a switch to federation would be better when all the features are enabled?
The source code is all public and freely licensed, client and server. Anyone could pick it up, turn it federated, and run it. But it’s unlikely Signal would choose to federate with any other servers.
> Side note: isn't it good to be centralized while the app is quickly rolling out new features? Then a switch to federation
It’s pretty clear from Moxie’s words on the topic that he has no desire to federate Signal in the future. He’s solidly convinced that the agility necessary to build a userbase on top of a secure messenger will be lost if he has to spend resources bringing the rest of the ecosystem in line with new developments.
Could you communicate with both the federated version and the centralized version? If so, I don't see the issue. If not, why?
I'm sorry if this is a dumb question. I'm really curious but I don't know much about this space. What is Signal doing that restricts you from talking to it?
https://old.reddit.com/r/technology/comments/kt91qk/signal_p...
https://teddit.net/r/technology/comments/kt91qk/signal_priva...
So the work is happening. But it's pretty major surgery, so it takes time.
That is, why is the user forced to update in order to use the application, even if no critical security issues arose?
The passage of time is not a good excuse for a mandatory update.
Because they’re adding new features, both security improvements and user‐facing sugar.
Moxie’s thoughts on this are well‐known: he believes he can build a better and more secure messenger by keeping deployed clients as closely aligned as possible. Even if you disagree (and plenty of people disagree, as we see in almost every Signal comment thread), it’s at least a valid opinion to hold. https://signal.org/blog/the-ecosystem-is-moving/
So there's no point in auditing a Signal release.
So as Signal becomes more and more disagreeable (something that's bound to happen with any actively changing software), you're forced to take it or leave it.
It's a trap.
I am a user of Signal, and have been using it for a number of years now, but this concern remains.
https://www.reddit.com/r/technology/comments/kt91qk/signal_p...
Probably signal occupies a far greater mind share than it's userbase actually warrants. If they say they have 10000 DAUs, more people will write it off as worthless rather than he interested in trying it.
I have 8 contacts on Telegram, one(!) conversation. Meanwhile everyone from family and friends is at Telegram now and used to be on WhatsApp.
I wish Signal all the best: it is totally impressive, they got their incentives aligned totally unlike WhatsApp and to a larger degree than Telegram I think.
Personally I'm rooting for Matrix, but for now, based on my limited understanding Signal seems to hit the sweet spot where "kind of easy to use" overlaps to a large degree with "trustworthy".
Also, should anyone get banned from mainstream messenger because they live in the wrong country or have the wrong opinions they can run their own.
This is a huge step forward :-)
https://old.reddit.com/r/technology/comments/kt91qk/signal_p...
It's a lot faster for me and also more information-dense.
I wanna try to move away from Whatsapp too, but when your "Secure" app fails to work because no one trusts your digital certificate, I inevitably start questioning your claims of both quality and security... Everybody will stick to the old product if the new one isn't polished....
Maybe your version of Signal is too old?
FetchError: request to https://textsecure-service.whispersystems.org/v1/config failed, reason: unable to verify the first certificate
I installed signal desktop app just now. It's 1.139.4 - Do you have the same?
I use it on Debian. Works fine.
It seems that some information would be revealed in that process that could be mined to eventually de-anonymize people based on relationship networks (assuming nothing easier is possible).
Does anyone here know if there's any reason not feel that is a serious vulnerability?
Yes, it’s documented: https://signal.org/blog/private-contact-discovery/
>(and provable)
As the post says, their non‐SGX method requires you to trust the server: “This has meant that if you trust the Signal service to be running the published server source code, then the Signal service has no durable knowledge of a user’s social graph if it is hacked or subpoenaed.”
To eliminate that requirement, they developed an SGX‐based method: “Since the enclave attests to the software that’s running remotely, and since the remote server and OS have no visibility into the enclave, the service learns nothing about the contents of the client request. It’s almost as if the client is executing the query locally on the client device.”
Of course, there are plenty of attacks on SGX (I’m not enough of a cryptographer to know how practical they are to apply to Signal’s methods or not); but at some level you are going to have to trust servers you don’t control, whether your system is federated or centralized. I’m mostly willing to give Moxie the benefit of the doubt here.
I've hated this about Signal since first beginning to use it. Forcing everyone to use a phone number makes it so much harder to have a partially anonymous way to communicate.
I can't help but feel this was intentional to prevent use by those wishing to remain anonymous. I don't believe they'll ever actually do this.
If they could have they would have done so already imo. Perhaps they are fighting whatever restrictions force them to do this. We can only hope.
My belief is that various governments prevent Signal from allowing anonymous registrations and will continue to prevent them from allowing it.
I expect that what they will allow is something like "you can now register with a gmail account". That is the same restriction since you need a phone number to register for a gmail account these days.
And then that got retweeted by Jack Dorsey. Now..I am a little worried. Do I want anything that has Jack’s paw prints on it. Since he and Zuckerberg turned up like creepy ideological twins at the senate hearings, I can’t tell them apart.
The first question on the Reddit AMA resonates. WhatsApp was great before FB bought that out. Who is to say it won’t repeat with Signal and someone else?
I believe signal to be one of the best options right now. However, I'm also running a matrix server and working to convert my friends to that.
These challenges are never going to stop, but federated messaging is a big step forward.
Having an exit plan makes me less concerned about a centralized service - if FB/TWT/etc buy Signal many parties are strongly incentivized to fork the code and provide migration paths.
It seems every mainstream researcher now agree that the message delivery part of WhatsApps is now trustworthy.
That said the metadata and incentives story is about as bad as it can get[1] and in the backup department your chats can be uploaded wholesale to iCloud and/or Google Cloud if one of your contacts from the same conversations enable cloud backup.
[1]: Owned by Facebook and they shut off the revenue stream so the only way they can make money from it is by squeezing it of the metadata they get or introduce ads.
But a for-profit company can select all of the nonprofit’s board members and thereby largely control the nonprofit.
This happens all the time w/conservation groups and environmental non profits and their unholy alliance with real estate mafia.
I also have no idea what that means, other than it looks like some kind of fluidity is allowed?
Here is an interesting read (HN thread/comments mentioned in the article too)
[..] By March of 2017, 15 months in, the leadership realized it was time for more focus. So Brockman and a few other core members began drafting an internal document to lay out a path to AGI. But the process quickly revealed a fatal flaw. As the team studied trends within the field, they realized staying a nonprofit was financially untenable. The computational resources that others in the field were using to achieve breakthrough results were doubling every 3.4 months. It became clear that “in order to stay relevant,” Brockman says, they would need enough capital to match or exceed this exponential ramp-up. That required a new organizational model that could rapidly amass money—while somehow also staying true to the mission.[..]
[..] That structure change happened in March 2019. OpenAI shed its purely nonprofit status by setting up a “capped profit” arm—a for-profit with a 100-fold limit on investors’ returns, albeit overseen by a board that’s part of a nonprofit entity. Shortly after, it announced Microsoft’s billion-dollar investment (though it didn’t reveal that this was split between cash and credits to Azure, Microsoft’s cloud computing platform).
Predictably, the move set off a wave of accusations that OpenAI was going back on its mission. In a post on Hacker News soon after the announcement, a user asked how a 100-fold limit would be limiting at all: “Early investors in Google have received a roughly 20x return on their capital,” they wrote. “Your bet is that you’ll have a corporate structure which returns orders of magnitude more than Google … but you don’t want to ‘unduly concentrate power’? How will this work? What exactly is power, if not the concentration of resources?”[..]
https://www.technologyreview.com/2020/02/17/844721/ai-openai...
We need a protocol with competing federated servers. It's old news: Matrix, XMPP, IRC, e-mail.