Signal adds a payments feature with a privacy-focused cryptocurrency
wired.com
wired.com
> Speaking solely as a person who is really into encrypted messaging, it terrifies me that they're going to take this really clean story of an encrypted messenger and mix it up with the nightmare of laws and regulations and vulnerability that is cryptocurrency.
Moreover, there are three other points I'd add:
1. I don't like "do everything" apps like WeChat or Line. One of Signals strengths was UX that focused on it's core competency. Early in Signal's development they would add privacy features. Lately they have been adding social features. This, however, feels especially out of left field and likely to hurt the UX.
2. This smells like dev resources will be spent building and maintaining something not related to messaging.
3. I've always had a "don't let perfect be the enemy of good" rationalization that gives Signal autonomy to grow a privacy centric messaging app despite the deficits (e.g lack of federation). In contrast, I personally associate "crypto" with "scam". There have been so many shady ICOs and pump-dump schemes around crypto. This will taint the product for those of us who don't think of crypto currency as being anything more than pump-and-dump schemes and a way to buy dab rigs online.
It's only when you're transferring them back to dollars/yuan/yen/etc. that it's suddenly currency from a government.
Technically, yes. Legally and sociopolitically, no.
And if you intentionally muddle the data streams, that brings the full force of anti-money laundering, tax evasion and terrorist financing law against you. It gives almost any government a free pass to do what it wants.
Freedom to speak privately is, in most democracies, popularly recognised as a right. Freedom to pay using dark money is not. Attaching the second to the first weakens both.
Bitcoin Core (the software) is not registered as a money transmitter anywhere in the world, its developers are fine and never got into any trouble.
We agree. There is a legal difference between a custodial exchange and noncustodial wallet. Just as there is a difference between a non-money messaging system and a noncustodial wallet. The comment you are responding to concerned itself with the latter.
This is intentional and relates to Signal's growth in the past few years. It's not "a hacker tool for nerds" it's "a friendly, easy to use chat app with stickers & voice messages (also strong encryption)."
IRC does one thing and does it well, and barely anyone uses it. The "clean technical vision" story isn't enough on its own.
Except it's not, strong encryption and privacy emphasis goes against easy to use. I recently got my family to switch to Telegram (because I like the interface) - my sister works in an environment where she has to have a separate work phone without a camera and everything synced up out of the box, history, etc. Brother lost his phone - same thing, has chat histories and everything is back to normal. I use Telegram on desktop and mobile and it synces instantly.
Compare that to Signal, you don't even sync between active devices and you can forget about having old conversations on a new device. And just to give you a scope of how important messaging history to people is (I've seen people say nobody cares about IM history) - designer from work is lugging around her Android phone year after switching to iPhone just for WhatsApp history (it doesn't sync between OS-es).
or just respect reasonable limits?
Does it make sense to destroy one feature for the illusion of having both?
Elements.io and telegram (to a much lesser extent) are safes. You place something there and it is locked. Signal, whatsapp, et al promise to be safes, but as soon as you place something, a hidden camera scan all the documents and print copies in a hidden printer at your home safe.
Would you trust that safe? would you still even call them safes? Yet some product manager/marketer convinced you that these are essential features for a "easy of use safe".
Telegram stores all history (except secret chats, which are a pain to use) server-side and effectively unencrypted.
> you don't even sync between active devices
I use Signal on a phone and a laptop, switching between the two frequently throughout the day and see the same conversations on both. (Edit: I realised you probably meant multiple phones, yes I see that's not yet supported.)
>and you can forget about having old conversations on a new device.
There's been a manual, secure transfer process between Android devices for years. More recently they've added an easy OTA transfer process for Android->Android, or iOS->iOS.
Here's the iOS announcement: https://signal.org/blog/ios-device-transfer/
I've had multiple issues with this before I gave up on Signal, it wouldn't show history when I initially paired up even when importing forever, then randomly stopped being connected and required me to pair again (losing everything on PC again)
> There's been a manual, secure transfer process between Android devices for years
Doesn't help much when you lose your phone.
I guess what I'm trying to say for most people the value of having your chat messages hosted in the cloud > security.
I have a smartphone that I control. I have a desktop computer that I control. I use an application on both computers that lets me send secure messages between device. The application somehow can sync new messages but refuses to let me import old ones. How insane is that? But apparently integrating with cryptocurrencies was above that in the todolist.
Signal is clearly a great protocol, but man is it seriously in need of a great implementation...
>But Marlinspike and Goldbard counter that Signal's new features won't give it any control of MobileCoin or turn it into a MobileCoin exchange, which might lead to more regulatory scrutiny. Instead, it will merely add support for spending and receiving it.
Oh, that's going to be a recipe for a great user experience again. You can send MobileCoin super easily... after you've gone on some crypto exchange platform to trade a highly speculative asset into one of your wallets. It's basically like Venmo indeed.
Stickers on the other hand are something that does attract many casual users and has no security implications.
Payment features... I think it's a bad idea for many different reasons but it might attract many users if it's not too complex.
Frequently messages aren't even synchronised between those two or they're out of order. Also, the desktop client itself is a bit of a joke.
Signal should in theory also be able to just sync/backup everything to the desktop client, this would largely solve the inability to transfer between Android and iOS issue.
I don't understand why such basic quality of life improvements have yet to be implemented, especially since they are especially desirable for less technical users.
I don't see how these relate. Signal isn't explicitly aimed at high security targets, although it works for them (seeing the Snowden endorsement). Signal is about bringing encryption to the masses. Making E2EE the default choice for everyone. Is is much more about mass surveillance. Your sister has a different threat model, one where they are also concerned about the physical device being compromised (i.e. stolen, hacked, or being physically accessed).
These are different threat models. For E2EE for the masses you need things like stickers and for it to be "fun" in addition to being a tool. In your sister's threat model she's more concerned about the tool over the fun part. It is a work phone after all (I mean this is why they take out the camera).
E2EE for the masses is pointless if you can't appeal to the masses. Cypher nerds will always have their fun toys to communicate with but we are also in dire need for something that prevents mass surveillance. That is, after all, one of the fundamental necessities of a democracy: being able to speak your mind without fear of government spying/involvement (this is the reason they got funding from Radio Free America in the past). Unfortunately this means some compromises need to be made. But as far as I'm concerned Signal has done far better than any service I've seen and the relative leak is near zero. The weak points are SGX and pins, which only hide some minor metadata (even fully leaked this would be better than WA or Telegram).
Facebook would have no trouble funding a basic iCloud-GDrive bridge if there was enough demand for it.
You can get away with this when you're the established player, but when you're the new guy every annoyance is a reason to revert to the previous app.
happening right now as a test
Yes there are sacrifices and trade offs for the security signal offers and it’s not 100% as convenient as Facebook messenger in that regard, but it’s also not 100% as cumbersome and impractical as GPG email. It strikes what I consider a decent balance of being secure and private and usable enough for non-technical users. Yes the message history story is lacking, I lost my messages moving iPhone to iPhone because I did it wrong and yeah it made me sad for a moment but I’m philosophical about it I guess. Dust to dust and all that.
Sadly, Signal's developers don't think trade offs exist
Of the three (WhatsApp, Telegram, Signal) I find WhatsApp to be the worst from a UX pov and Telegram the best. Personally, I find this exodus of users from WhatsApp to be a good thing even for no other reason than having to deal less with their UX.
Signal is not much better UX wise, but at least it gives hope of being better because they have to compete and because they are open source. If they fail to bad at growing the project or providing the infrastructure, someone will eventually fork and setup a separate network. WhatsApp has no pressure. It is in Facebooks interest to eventually migrate everyone to FB Messenger.
Otherwise, agree with the thrust of your statement. I believe getting Signal into the hands of more users is an overall net good and if stickers are the answer then get to making some stickers.
I think we’re violently agreeing.
The whole "not available in the US" messaging around MobileCoin, no doubt to avoid regulatory attention, gives this particular ponzi scheme a very nice ring.
I, for one, welcome this; the larger market is asking for a privacy-focused WhatsApp alternative, and Signal could be it.
The counter argument would be seeing the success of WeChat in China and wanting to reproduce that success AND expecting that if they don't do it someone else will do it and take their market.
Whether that's true or not I don't know but if I believed it was true then your arguments wouldn't matter since I'd believe not doing it is an existential risk.
In contrast, any crypto-currency based solution will be inherently distrusted, and few if any states will endorse it. It is more likely to be actively discouraged by many states, and the crypto support may well end up as a pretext to ban Signal on economic rather than censorship grounds.
It is overall a disaster of an idea.
I don't like using SMS for 2FA because it encourages people to social engineer the phone company to port the victim's phone numbers. I wouldn't want crypto in my messaging app for a similar reason.
Right now hacking a user's Signal account means you get some txt messages. Big deal. With payments there is now real reason to try to hack Signal accounts because some percentage of them will contain money.
Just FYI but those Stellar drops are worth over 500 USD right now.
I associate nootropics with scams but I definitely don't think all nootropics are scams. If someone said, here buy this pill that will make you smarter I'd be incredulous.
My point was cryptocurrency has a deserved bad reputation (for the reasons I mentioned).
I love the lofty ideals but the reality is the altcoin world especially is a minefield of scams. That reputation will hurt a messaging app that has done a pretty good job of building good will.
In such cases, Signal could easily be banned in such countries outright.
What all these "tech" companies tend to do is to exploit a captured audience. They are generally not focused on doing one thing well (producing a product or providing a service), they are more focused on building a following and then doing with those users whatever they like. One of the most blatent examples of this line of thinking is Microsoft's acquisitions. They acquire companies in order to get access to users. The "technology" is secondary. Another example is WeWork. They started introducing WeEverything. The product or service being offered is what is important. It could be anything. Instead the focus is on building an audience and exploiting that captured audience. One can apply this analysis to almost any "tech" company. "Growth" is the number one focus. No one really cares about what it is the company purports to be selling.
## Linux
### Linux Requirements
- CMake 3.1 or higher
- Clang
- OpenSSL => 1.0.2 (Optional)
### Linux CMake Configuration
The linux build can be configured using the standard CMake flow with a few options
```
mkdir build
cd build
cmake -DBUILD_OPENSSL=true \
-DCMAKE_BUILD_TYPE=Release \
-DCMAKE_INSTALL_PREFIX=USER_INSTALL_LOCATION ../The promotion of pseudonymous and anonymous digital payment systems such as cryptocurrencies is vital to a healthy and functioning society.
There are also entirely anonymous cryptocurrencies with no readable public ledgers. Everything is still decentralised, no centralised control of any kind, but you can't see what people are doing (Monero and Zcash being good examples. Signal uses Mobilecoin, which still needs to stand the test of time).
There is still a long road to go before there is a fool proof anonymous, liquid, consumer friendly, usable cryptocurrency, but it is the last bastion of defense against complete total state and corporate surveillance. - One of the greatest threats to human life, on par with climate change.
Your use of the word "craptocurrency" is rather childish and naive. Eventually you will take a closer look at the situation and reconsider. Good luck
I will leave this https://www.theengineroom.org/dangerous-data-the-role-of-dat...
Just in terms of avoiding confusion, you might want to reach out to mixin.one to try to replace that document with one that clarifies that the design outlined there was not used? Or publicise the actual design a bit better? (I couldn't find a link to this repo on the MobileCoin website, which is why I searched for the whitepaper elsewhere in the first place).
[1] https://blog.dshr.org/2018/10/gini-coefficients-of-cryptocur...
Yes, and I do say that. Decentralization is a lot less interesting if most people just end up centralizing anyway.
Almost every bitcoin exchange.
It's typical to pool user funds into a relatively small number of addresses.
But don’t the calculations equally assume coins spread out across multiple addresses aren’t owned by one person, when in fact they often are?
That's definitely unfriendly tax treatment. Is it different from the tax treatment that applies to national currencies?
In fact, company stock is WAY worse, because the majority of people are legally prohibited from investing in private companies unless they're an accredited investor (already rich). So, only rich people (other than founders and early employees) are allowed to buy in at super low prices before handing off the bag to the public.
Cryptocurrency removes the underlying asset and simply sells shares of artificial scarcity. It’s only as valuable as what people decide to trade it at, because it doesn’t represent ownership of anything other than itself.
Is there a limit to how many shares a company can issue? No, a board can technically issue shares unto infinity. There is no guarantee of scarcity, no guarantee they will not raise more money.
That company would have value whether or not it was explicitly sold as a stock. The value doesn’t come from the stock.
So when a company has no profit but a high valuation, is this the market correctly discounting future predicted cashflows and giving a company fair value, or is it some sort of scam? Ex: Is NKLA actually a $5.2b electric vehicle company? How about the spade of Chinese IPOs that ended up being vaporware?
Cryptocurrency removes the underlying asset and simply sells shares of artificial scarcity.
The scarcity isn't artificial. It's mathematically provable, open source and auditable. If you think you can manufacture "fake" btc on the blockchain, feel free to try. If you think you can successfully fork and create a whole new chain, you're also welcome to try.
It’s only as valuable as what people decide to trade it at, because it doesn’t represent ownership of anything other than itself.
This is actually factual for anything in existence. A piece of bread. A $100m painting. You're starting to figure out what peculiar creatures humans are.
The scarce asset is the company, not the shares. Yes, they can issue more shares, but those shares still represent the same company plus the new investment money raised by raising the shares. They're not creating more company out of thin air when they issue more shares.
EDIT: To clarify some misconceptions in the comments below: When a company sells more shares into the market they are not simply diluting away existing shareholders. The keyword is that they are selling shares, meaning they take money in exchange for shares. The company's value increases by the amount of money they take in exchange for the sale.
Example: If a company is worth $1,000,000 and has 1,000,000 shares outstanding, each share is worth $1. If the company decides to sell another 100,000 shares and the market buys them at $1/each, there are now 1,100,000 shares outstanding and the company is now worth $1,100,000 because they took in $100,000 of cash via share sales. Existing shareholders have not lost any money or value.
If a company sells 100,000 shares at a dollar each, the company is now worth $100,000 more because they now have another $100,000 on their balance sheet. No value is lost in this process.
> This is why a stock will tank when a company talks about diluting their existing shares by creating new shares out of thin air.
Companies can't just declare that more shares exist and dilute away shareholders like you said. They either issue them as stock based compensation, which is an expense, or they sell the shares to buyers, which means money goes toward their bottom line.
You're confusing percentage dilution with absolute diluation.
The shares represent the value of the company. The value of the company has increased by the amount of money raised. Each share represents a lower percentage of the company, but this is offset by the fact that the value of the company has increased by the amount of money raised. The shares have not been diluted on an absolute value scale.
Owning 10% of a company worth $1mm is the same value as owning 5% of a company worth $2mm.
If you own 10% of a $1mm company that raises another $1mm by selling more shares, you now own 5% of a 2mm company. Your percentage ownership is diluted, but your value has not been stolen.
This is basic pre- and post-investment math. Shareholders are diluted on a percentage basis, but not on an absolute basis.
Issuing new shares is not always a good move and sometimes it might cause investors to lose money and percentage ownership, but sometimes it might be a good move and result in investors gaining money (though still getting their ownership diluted).
I care how much of future profits will be returned to be, which does depends on the percentage I end up owning. A round needs to enable a bigger gain than the fraction it dilutes everyone.
No. Your shares were _diluted_ by the company issuing new shares. Now your 100 shares are worth half as much. Shares have predicted forward value embedded in their valuation. When you buy a share, you're betting that company will continue to grow. If it's having to raise money and issue new stock, odds are it's struggling with cash on hand. Maybe the bet will work out for you. Maybe not. Stocks are gambling, though, don't let yourself believe otherwise.
That's not correct. A company sells shares in exchange for cash. That cash is owned by the company, which is represented by the shares.
Companies can't simply dilute away their shareholders like you're suggesting. The money raised by selling shares doesn't simply disappear.
Did I get diluted?
Yes, they can and yes they do, all the time. That's not only precisely how VC funding works in the early stages of a startup raising seed money and subsequently doing Series A, B, etc. that's also how public financing works via new share offerings on a public marketplace like NYSE or NASDAQ.
GameStop is about to do precisely this very thing: https://abcnews.go.com/Business/wireStory/gamestop-finally-a...
The cash they receive has no forward value. $1 will be worth $1 in 10 years. When you buy shares, you are betting on future value. When a company trades new shares for cash, it is trading some portion of its future value for cash today.
Not only that, but the cash on hand can disappear rather quickly (after all, they are raising it to spend it) depending on the company's expenditures, cost of new customer acquisition and whether its growth strategy is working or not.
Also, shareholders are the last to be compensated in the event of a bankruptcy or liquidation. Bondholders take preference.
The concept of "pre-money" and "post-money" valuations exist for precisely this reason. You can read more here: https://www.investopedia.com/ask/answers/difference-between-...
If a company raises $1mm on a $9mm pre-money valuation, the company is now worth $10mm ($9mm valuation + $1mm raised) and the extra shares correspond to the $1mm raised.
Onwership is diluted on a percentage basis, but the Series B and C investors didn't steal value from previous investors through dilution. There are more shares because there is more money in the company.
No, the company is worth it's last share price x number of shares outstanding. A company is worth what the market will pay for it, not for what some bean counter guesses is the value.
Yes, they didn't "steal" value, they traded cash for present and future potential value.
That cash doesn't just get parked in a bank account (it gets spent) and the company valuation isn't static, it changes based on market perception all the time.
You are thinking in snapshot accounting terms and not in real market valuation terms. Dilution typically causes price per share to fall unless growth is outpacing the dilution significantly.
They absolutely can. When you buy shares, or exercise options, in an early stage company the documents clearly specify that the shares can be diluted, which is how it's on solid legal footing.
HAHHAHHAHHHAHAAAA come on man.
Every Bitcoin represents 100,000,000 tradable assets. If there are 30,000,000 Bitcoin in circulation that means there are 100,000,000x30,000,000 individual assets available to hold and trade. Do the math, and then realize that we’ll arrive at the heat death of the universe before Bitcoin is ever actually scarce.
Bitcoin has a fixed supply, Bitcoin's daily rate of creation cannot be increased or decreased unless everyone agrees to it.
Depending on the voting rights embedded in the share, your ownership is likely meaningless. It doesn't guarantee you rights to dividends necessarily and even if it does, the company can just choose to never issue a dividend (like Amazon). It doesn't necessarily grant you voting rights for the Board of Directors either. Worse, you have to go through a 3rd party broker to buy a share or trust a company like Robinhood to hold your shares for you. As we saw with GameStop, they can rug pull on you at any time. With decentralized cryptos like BTC & ETH, that can't happen from your own private wallet. You can always transact.
Cryptos such as BTC & ETH are provably scarce, not artificially scarce. You can validate supply at any time by running your own node and joining the network. You don't need anyone's permission to do that. It's a public blockchain.
That's not true. The shares still represent a claim on the underlying company.
If someone wants to acquire the company, they have to compensate you for the shares that you hold.
Companies can't simply wave a magic wand and steal value from shareholders. There's more to stock ownership than voting rights.
ETH is probably not the best example here because they have rug-pulled people with a hard fork.
"People" here being criminals that exploited a flaw in the DAO, yeah?
[1] Yes I know that wasn't the real reason why trading was halted
The sentencing of criminals in republics is very removed from democratic action (see drug criminalization).
Show us the votes, then. Did a majority of miners and/or coinholders vote to hard-fork?
Yup, and I don't want public votes to decide the amount of money I have.
Unfortunately, there is no alternative. The value of what you have is decided by what people are willing to pay for it in markets. If people decide that they value the forked ETH that doesn't provide the money to the people who stole from the DAO more than the version where those people have all of the money, then it is going to be more valuable. You don't escape this problem with fiat either.
Basic market mechanisms like this are pretty much inescapable.
As I said, there is no escaping market mechanisms, as value is market contextual. Certainly, there are assets with more or less stable value, but that is still due to the whims of what people (ie. the "public") are willing to pay.
If I'm, say, from a persecuted cultural group, I'll want to keep my wealth in an asset that has the same value whether I or someone else own it. Precious metals fit this bill better than both fiat and public-ledger cryptocurrencies.
What was forcibly altered? Perhaps the meaning of "force" is different for you than it is for me.
The code is the contract, enforced by a decentralized network of actors. Of course that network can at any point change the contract if the majority of them agree to do so – how else would it work? The key is that there is no way for individual actors to modify contracts at will – you need consensus. It's the difference between oligarchy and democracy.
He's referring to the grandparent comment's definition, not yours. The GP's definition is:
>>Early adopters mine or buy large proportions at negligible prices while late adopters mine or buy negligible proportions at large prices.
By that definition, anything that goes up in value is a "multi-level marketing pyramid scheme".
No because the company's income doesn't come from selling more stock, but from selling valuable products. (Companies that don't have actual revenue are indeed multi-level marketing pyramid schemes and there are some of them around, but they're the exception rather than the rule).
That kinda smells pump and dump like to me. Lest we forget, the end of the previous bull runs in 2013 and 2017 wiped out some people that made bad investment decisions (and there's no guarantee another black swan event won't happen again in the future). Not to mention, whenever there is news of someone losing their wallet keys, Bitcoiners breathe a sigh of relief, knowing that that's one more person that has to permanently HODL. Gross.
Yes agreed. Though I would add that this is a paradigm shifting technology, so there may be something substantive underlying all of this Bitcoin hype.
As for crypto as a whole, Ethereum has real world use cases, like stablecoins and NFTs, and an extensive multi-pronged development effort to expand its capabilities, in particular scalability, that cannot be dismissed as mere hype.
Just on the basis of fee revenue alone, and the assumption that this turns into income for ETH holders once the platform switches to Proof-of-Stake, Ethereum's current valuation can be justified with only the assumption that its price-earnings multiple will match that of relatively mature and low-growth industries like electronics.
Adding to this, unlike Satoshi Nakamoto, which I believe to be the alias for a team and not a single person, Vitalik Buterin at least is not shrouded in mystery and is out in the open. I'll give credit where credit's due. He's pretty upfront about his pet projects.
I don't share your enthusiasm for stablecoins and especially NFTs, though that's an entirely different can of worms.
For now, I'm happy to see where this all goes as I watch from the sidelines and not capitulate to FOMO. Yet so far, I can't help but feel that the market effects surrounding the ETH network is nothing but grifts and rich-on-paper showboating. Plus, my God those gas fees...
There is no valid reason for the vast majority of what is supposedly a currency to be owned by the company that created it. Imagine if PayPal launched but required everyone to transact in fractional shares of PayPal to get anything done. Oh and by the way, those shares are majority owned by the founders, but they’ll sell you some so you can send them to your friends.
This is ridiculous.
That’s the problem.
If Signal was serious about this they would have launched their own fork instead of pitching a pre-mined coin to their users.
Agreed. They either would have launched their own fork and distributed the vast majority to their users, or at the very least chosen an existing project that was fairly well distributed.
This makes me believe they primarily did this in return for an incentive from Mobilecoin.
Marlinspike's been an advisor to MobileCoin from like... the beginning. The article also notes that neither he nor Signal own any actual MobileCoins.
> MobileCoin has not yet paid Signal anything for integrating MobileCoin. We intend to donate a great deal of money to Signal over the coming years.
For all the criticisms of cryptocurrency (and I have many...), I don't particularly see anything on MobileCoin's work that indicates the usual shady cryptocurrency stuff. I'm not sure it belongs in Signal, but I do think this stuff can be evaluated without people starting conspiracy theories.
I find it conspiracy-theory in nature to assume otherwise; I think it could've been handled better from a server source code side but I don't really see why this has to be an assumed bad faith thing.
If Signal had built this themselves, in house, nobody would bat an eye.
You're stretching hard here.
> I love Signal and I started MobileCoin to help fund their work.
I don't see how it's a conspiracy theory that this is a backdoor way of funding Signal when the CEO literally says that MobileCoin was created as a way to fund Signal.
Is it potentially a bad business model? Yeah. Is it necessarily some backdoor funding deal? I dunno, I don't really buy it.
A bunch of decently well of people decided to do a few handshake deals to make each other a whole bunch of money. That's how most of the world rolls so this is simply par for course.
This statement would work better if that's what I was doing, but I'm not.
You (and nobody else) on this thread knows for sure what's going on there, and if Moxie's been advising MobileCoin for years I don't see how it falls under a handshake deal.
There is nothing to indicate that he, or Signal, are directly profiting from this, other than some MobileCoin people saying they want to donate to Signal (which is a good thing - I'm really not bothered by that particular point).
Also feel free to read anything by the Basecamp guys (yep, the guys behind Rails).
It won't get you or the investors (another) yacht, but there exist a number of companies that delight their customers and change history far more than many attempted unicorns.
I'm pretty sure more than one WikiCoin has been pitched too.
This commingling of business interests means there's more angles of approach, and much more risk exposure.
What value do you provide? at least when I buy vbucks from Epic I know I'm getting fortnite skins with it.
Why should we run a node free of charge when you extract all the profits of our efforts?
When I see statements like "there's no economic incentive."
I read "I want all the profits, and screw everyone else".
If you genuinely wanted a decentralized network, then you would provide fair compensation for the added value the node provides against attacks on the network.
So far this scheme has worked out fine for the original creators of Ripple-- who've extracted hundreds of million selling their massive premine to an ignorant public, then abandoned the original and did it again. What we're seeing from signal now is just a third generation of the same scheme, preempting the ripple founders from doing it again (or maybe they're involved behind the scenes, who knows?).
So long as there seems to be no consequence except a massive windfall (SEC fines against ICO/premines have tended to be a fraction of 1% of the funds raised), it's unsurprising to see them continue.
The fact that it may kill one of the more useful secure messaging apps as a side effect? Welp. This is why we can't have nice things: Collectively, we're better at funding borderline scams than public goods.
If one wishes to subject their wealth to the whims of a massively centralized cartel of "rationally self interested" HOLDers, maybe it's better to deal with the devil(s) one knows.
Problem solved.
Surveillance on daily spends is not valuable. What's valuable is things connected to your identity, specifically associations with other individuals and companies.
The vast majority of people simply don't care about this. I mean I have a hard enough of a time to get people to care about privacy-centered messaging apps. Getting them to even begin to comprehend the myriad of cryptocurrencies and the confusing space of DeFi is simply not going to catch on. To them, there's really no benefit outside of "number go up" and so-called store of values, which conveniently have the nasty side effect of requiring users to do their own OpSec. That's actually harder than you think.
And that's not even accounting for how scam-ridden the entire space is to begin with. Who can they even begin to trust? Seems like an oxymoron for a trustless system, when the fact is they aren't even sure if they can trust themselves.
I find it mildly hilarious too, that places like BNY Mellon and JP Morgan are exploring cryptocurrency storage options. Now we are back to "trusting" those darn evil banks everyone gets triggered about.
See how weird this rabbit hole gets?
If I created a coin today and sold 1% of the supply to you alone, on what basis would you want to store any value in that currency? Given constant buy demand, The currency's market value is defined by what I do. This is why organic price discovery for a currency is important.
E.g. the only cryptos I've seen people accepting on dark web markets are Bitcoin and Monero.
I'm not a fan of PoS because it looks like a ponzie scheme (unless it's done like eth where initial distribution is done via mining)
This is actually worse than PoS, because PoS uses standard public key cryptographic to validate ownership of coin in the chain to stake, it at least in theory can achieve "trustless" validation.
This on the other hand is just a shitty attempt to outsource database maintenance to untrusted 3rd parties, using SGX, while forcing them to pay for S3 hosting because they can't implement a DHT to do proper decentralized file transfers.
/me glances at the great big pile of Satoshi coins...
more of the same cryptocurrency themes:
1. decentralization for Thee and not for Me
2. regulated by math.... aaand the developers' / founders enormous, unaccountable and unilateral leverage over liquidity.
Except for that small initial 1 million that stayed with Adam
the integration with signal made the valuation of mobilecoint jump from around zero to 65$. I hope the signal team got some mobilecoins in return for the favor.
except for that giant cache of untouched (so far) bitcoins from the start.
> Blockchain analysts estimate that Nakamoto had mined about one million bitcoins before disappearing in 2010
I believe that everyone has a fundamental right to secure, private communication. Some people may hold the same belief for the right to transfer funds. I don't agree and I suspect many others feel the same. That tension alone makes this look like a bad decision to me.
Sadly, now it feels like Signal was just a long game trojan for Marlinspike to onboard users to a cryptocurrency pyramid scheme. This has nothing to do with its core functionality and it makes me question the developers' motives.
I've wasted my influence with my non-technical friends convincing them to adopt Signal, and I don't forsee convincing them to switch yet again to something different.
The state of secure messaging is really bleak. I wish Matrix had an IM-style client that was decent enough for non-technical users to adopt.
This has bitten me before. Now I'm thinking that every recommendation and suggestion to adopt must come with a "for now this is the best way to do it, but it will probably change again". And somehow try to prepare the non-technical people for that.
Except for Matrix, because it is decentralized.
Is it really that hard to imagine unobtrusive UI that makes this as optional as sending GIFs, stickers or location data? Or did the later features already kill Signal for you?
See Element [1] which uses Matrix [2]. It feels like IM, and is super simple to onboard new users. I'm not involved with it, but I'm a huge fan of the Matrix ecosystem.
If you want group chats to be mixed in with 1-1 chats, try SchildiChat [3], a fork of Element.
[1]: https://element.io/
[2]: https://matrix.org/
Have you tried fluffychat on android? Or any of the other clients https://matrix.org/clients-matrix
Fundamentally, Element "feels" more like an IRC client than a typical IM client like Signal. It isn't focused on direct, one-off, or small group communications (this isn't a technical thing and it has nothing to do with federation, it's simply the UX paradigm that Element has adopted).
The SchildiChat fork looks promising, although it's clearly too early to recommend it. It's not even available on the Google Play store, which makes it unsuitable for non-technical users.
At the risk of sounding like a Signal simp: don’t use this feature if you’d don’t like it? I have no idea whether this is a good or bad idea, I figure the proof of the pudding is in the tasting and I haven’t had a chance to try the signal payments feature, but I’m willing to extend the benefit of the doubt here at least as far as “I’ll withhold judgement til I can try it for myself.”
I really don’t get the ire on this. I think it’s good that whisper systems is forward looking and trying to be innovative and dynamic and go where users are rather than just sit around waiting to become irrelevant. Not all experiments or risks will pay off but that doesn’t mean risks and bets are bad.
How do I prove that I didn't use it? And why on earth would I want a messaging app to put a target like that on my back if I'm not even using the feature? With this feature, the likelihood of someone demanding access to the app grows from almost zero to pretty significant.
Signal for iOS still doesn't support message backup like the Android version.
And Telegram introduced a feature to import old Whatsapp chats into new Telegram conversations, a form of "backup". This was great when I was migrating away from Whatsapp, and made the decision between Signal and Telegram easy for casual conversations where encryption wasn't a priority.
What are the arguments?
Don't you think that as data becomes more and more valuable, "freedom of transaction" is a natural evolution of "freedom of communication"?
In an environment where only "legally valueless" data circulates freely, the few entities that are actually able to monetize this data become gigantic monopolies (Google, FB, ...), while most individual parties are either forced to play by their rules (Youtube, Patreon, ...) or filtered out by startup costs.
The whole issue is a real minefield and I don't have a firm stance. And obviously the fiat money system has gaps and flaws there too. I'm sure much of the HN audience would disagree with me here from a libertarian point of view. But I think it's safe to say that the issue of transaction privacy & freedom is not as straightforward as that of speech (which itself is really not that simple).
They are in WhatsApp, too. At least Facebook still claims that after the Snowden leaks :) And: Did you verify this? Did you check the source code at signal's android/ios client repo? Did you also verify that no untrusted third party receives your backed up private keys?
Why do you trust Google more than Facebook? [1]
[1] https://github.com/signalapp/Signal-Android/blob/d74e9f74103...
I'm not trying to troll here. I'm trying to point out that babbling about crypto is easy. Verifying it, and actually caring about it is another thing. Most users are probably also the wrong audience for early adoption of TOX.
How is using Google for domain fronting for the purpose of censorship circumvention "trusting Google"? They don't get to see the message content (just like Facebook doesn't see the content for WhatsApp).
> Did you also verify that no untrusted third party receives your backed up private keys?
Private keys are not backed up in either service, as far as I know.
> Did you check the source code at signal's android/ios client repo?
Given the lack of reproducible builds on iOS/the app store, any source code audit is pointless if the app vendor is included in your threat model.
Those that only run open source software like myself have no secure way to run Signal short of compiling every release by hand which is impractical. Moxie has stated he will not support anyone but his team compiling or distributing Signal binaries so third party signed builds via privacy focused app stores like F-Droid are out. All builds must also use Signal centralized servers even though that centralizes TCP/IP metadata, etc.
Not to mention you need to show government ID to get a SIM to use the Signal wallet for said private currency/messenger in 200 countries.
Secondly having a decentralized currency whose servers can only run on Intel machines with Intel SGX is a very centralized supply chain as well.
A single supply chain attack on Intel microcode or related SGX updates could run malicious code and game over for the currency globally? A government that sees MobileCoin as a threat could make Intel do this.
With a SPOF on the supply chain of the only client people are expected to use and another SPOF on the only hardware enclave people are supposed to use for servers... decentralized is technically true but not used in the same way as most other projects that use that word.
I will keep an eye on this experiment though, because there are some unique ideas here which could have value should your trust anchors expand beyond Intel and Signal.
> Those that only run open source software like myself have no secure way to run Signal short of compiling every release by hand which is impractical.
I think you mean either of two things:
1. running the APK they build on a device without Google Service does not work
2. running the APK they build on a device means it's no longer running only libre software
1. is not true, so I assume you mean 2. I guess that's true, but in practice I think that the compiled dependency doesn't do anything if you don't have the services on your phone (don't quote me on that). It's not free software, but it's still better than the competition.
(I'm aware that the code will try and use Google services, then if it fails it falls back to websocket(?) - so the actual Services don't have to be present, but the compiled APK contains the non-free hooks to use it if present? I tried to use the word encumbered to reflect that)
> If you run a libre device without the Google Play store (non-Google android build) then the software cannot function.
is just not true. I don't have the Google Play Store (I'm on a non-Google Android build) and Signal functions just fine.
(Well, mostly fine - it has to maintain its own connection because of course it can't use Google's tooling for that, so it supposedly has more battery impact.)
https://github.com/signalapp/Signal-Android/blob/1f578ebd2c1...
here too about 11mins in - https://www.youtube.com/watch?v=e9afDQ_M5CU
For everything else: Yes, by setting a randomized long Signal PIN since SGX is effectively used to add entropy to Signal PINs[1]. You can also disable Signal PINs – in this case Signal will simply set a randomized long PIN for you.
There are less than 200 countries in total, unless you get very creative with states that are arent recognized more more than a handful of other countries, like Abkhazia or Transnistria.
You also dont need ID to buy SIM cards in the US, so I'm curious on how valid this assertion is.
I do wonder how long the US (or, for example, Finland) will remain a holdout in this regard.
It is unfortunate that I don't see many from Signal on this forum, as it'd be nice if someone would just clarify this already considering the popularity of it as a feature request.
.....
>>The UK also has receiver verification. If I try to send to an account and it doesn't match the name I'm sending to, my bank will warn me. How do you stop impersonation?
A: Signal relies on phone numbers for identities. Other apps that integrate MobileCoin may have a higher threshold for identification.
.....
Reads to me like phone numbers are not going away.
The same goes for virtual/VoIP numbers. No skypein etc.
It's a regulated market, so should the need arise to keep the identity of all subscribers in the future, it is likely not much more than a counter-terrorism-related law away.
To get counts, I also analyzed the table in the annex; it lists exactly 200 countries (checking each of them, that's because in addition to 193 UN members, it includes two non-member countries: Kosovo and Taiwan, and five other non-countries: French Guiana, Greenland, Hong Kong, Macao, Svalbard).
Of these, 34 are listed as "SIM registration not mandated" and further 7 are listed as "SIM registration under consideration", the rest are "SIM registration mandated", i.e. 159 countries.
Basically the whole world requires it except for North America/UK and a few smaller countries mostly in Europe. Also notable that countries without ID requirement mostly happen to be the ones with very low prepaid SIM penetration (see the map on page 6 [page 8 of the PDF]) so their unidentified SIM usage is presumably low anyway, though it remains a possibility in those countries.
Edit: Sorry, 6 are listed as "State of SIM registration inconclusive" which I have missed, so "SIM registration mandated" count should be 153.
Clicking build in Android Studio?
Particularly because the software is timebombed and stops working after a while (and also blocked on the server side if you bypass the client side timebomb).
Feature bloat is one of the worst things for a security conscious product. The more features, the more attack vectors. Nobody asked for payments in Signal. Where did this idea come from? It was never put forward prior to this, it was never on the road map. That only makes me even more suspicious of this decision, which leads to my second point...
MobileCoin has all the appearances of a scam. 85% of the coin is owned by the creators. The price rapidly shot up at the end of March. The social media of the developers was posting rubbish for a long period of time. There was no mention of this collaboration beforehand. This has all the hallmarks of a pump and dump. Have the Signal devs been duped? Or are they wanting to cash in on Signal's rising popularity?
Anybody at all with an interest in Signal needs to let the foundation know that this Beta needs to be scrapped, and that payments should never be added.
The UK has a problem with authorised push payment fraud. Banks can recover funds which have been sent as a result of phishing / fraud. How can I reverse a payment on your platform if it was fraudulent?
The UK also has receiver verification. If I try to send to an account and it doesn't match the name I'm sending to, my bank will warn me. How do you stop impersonation?
There's no cost to sending payments on most mainstream banks. How much do you charge?
Most banks let the user block receiving payments from specific accounts. How do you stop harassers sending unwanted money?
Thanks!
A: MobileCoin is as fast (or faster in some cases) than a bank payment in the UK with greater privacy. As far as settling back to Fiat, if that's what you're asking about, the velocity of that depends on on-ramp and off-ramp integrations which will come over time (but it looks like there's no reason MobileCoin can't help developers deliver payments at the same speed as banks).
>>The UK has a problem with authorised push payment fraud. Banks can recover funds which have been sent as a result of phishing / fraud. How can I reverse a payment on your platform if it was fraudulent?
A: Payments on MobileCoin cannot be reversed at the protocol level. If you want escrow and reversibility, you should use a wallet or payment service that supports those primitives. We believe that developers will build such services on top of the foundation of the MobileCoin protocol.
>>The UK also has receiver verification. If I try to send to an account and it doesn't match the name I'm sending to, my bank will warn me. How do you stop impersonation?
A: Signal relies on phone numbers for identities. Other apps that integrate MobileCoin may have a higher threshold for identification.
>>There's no cost to sending payments on most mainstream banks. How much do you charge?
A: Fees are set by the foundation (which has a stated goal of keeping transaction fees to around $.04 when the network isn't congested). Currently fees are higher as they need to be adjusted by a foundation vote.
>>Most banks let the user block receiving payments from specific accounts. How do you stop harassers sending unwanted money?
A: Signal doesn't allow people you haven't keypaired with to send you funds. If you have accepted a message request from someone, they can send you money.
It gives readers a better sense of your ability to answer the questions accurately, in addition to letting people make assessments based on the potential conflict of interest.
Also, responding here and inviting discussion on a technical level is possibly the best thing you can do for perception of Mob, because this is a forum where those questions are likely to get asked.
Edit: I see you've done that in another post on this thread. Since we don't have anything like flair it would also help people who don't read the whole thread.
I know the next question is signal specific but do you have any details on how they'll maintain privacy for pegging which is likely just to require an on/off ramp. Surely this is just no better if the majority of transactions have an associated log on an exchange?
The one venmo-like thing people do use a lot in the U.K. is probably something like revolut for dealing with different currencies and international transfers (either for travel in Europe or for migrant workers sending earnings abroad for family or retirement). But a service that’s only available in the U.K. isn’t much use for that.
I also personally don’t really see the privacy use. I think I’m willing to give up a reasonably large amount of private information about the people on either side of a transaction if it is effective at reducing fraud and making transactions reversible.
First time I read about that, how does this work in practice? A person regularly sends you small amounts such that all you see is their name whenever you log into your bank account?
If you were regularly recieving money from someone, then it looks like you're in business with them - and you'd have a hard time pricing you're not if they then staged some other activities (i.e. shipping you stolen goods, which they then have stolen from your doorstep by an associate).
Imagine getting a dozen messages saying
£0.01 From: Your Stalker Ex. Ref: I just want you back!
Or similar. It's a real problem.
idk, but this sounds like a great problem to have.
I myself will take all the spam you can send at 50 cents per message. ( I already sort about $200 worth of free spam daily at that rate)
I can imagine some other folks could set them at min 5 dollars per attached message and get use of such a thing.
Now wonders if an email layer can be added to transactions with this coin and a reply that can serve other digital assets..
patreon without the fees? onlyfans without the (insert their cut plus visa/mc cut here) - email with little to no spam..
I'm ready to help make this a thing.
In russia government can send your organisation money from abroad via an agent and then shut you down as a 'foreign agent'.
They could do this with traditional banking systems as well. Presumably the Russian government has a high degree of surveillance with regard to their domestic banks like every other nation in the world has. Creating a false financial trail is made slightly easier with crypto currencies, but for a nation state it's not hard to do with traditional banking systems.
In cases where you've been sent unwanted money your obligation is typically to return it, but that specific type of use-case is often not considered when people design things. If you end up in a situation where anyone can send you money and you can't return it, you're in big trouble because the sender might be causing you to unintentionally get involved in a violation of the law and leave you without any method to undo it.
Also, why do the Signal developers trust SGX so much and have stayed completely silent about SGX vulnerabilities – even when the cryptographers whose quotes they used to put on the signal.org home page[1] are increasingly critical?[2]
Finally, why is there no open communication about major events like the Signal PIN UI fuckup last year or the server issues earlier this year? Foundation or not, if no communication is happening and they're not demonstrating that they're capable of openly admitting mistakes and learning, they're not gaining the trust of anyone.
Don't get me wrong, I've been a die-hard fan of Signal since the early TextSecure days and have convinced > 100 people to switch but I'm starting to have a bad aftertaste and some of my friends (equally big Signal fans) are, too.
EDIT: Looks like the Signal server repo[3] was updated today, as this article[4] (in German) attests to. I had last checked the repo this past weekend. I suppose the repo hadn't been updated to keep the MobileCoin thing secret but I do wonder: Why not simply create a private branch instead of risking one's reputation for openness?
[0]: http://web.archive.org/web/20210311053716/https://github.com...
[1]: http://web.archive.org/web/20200201112751/https://signal.org...
[2]: https://blog.cryptographyengineering.com/2020/07/10/a-few-th...
[3]: https://github.com/signalapp/Signal-Server
[4]: https://www.golem.de/news/crypto-messenger-signal-server-nic...
Maybe because the marketing of their sketchy token scheme depends exclusively on the illusion of SGX security.
Given the Snowden leaks and everyone's experience with what Facebook etc. do with our data, I wouldn't call that a "benign" adversary at all. Besides, even if Signal itself is benign, someone who manages to hack the Signal infrastructure might not be.
> The alternative to using SGX in these situations is to hand over the data in the clear to Signal servers.
This is not correct. The alternative would be to tell users to choose a passphrase with enough entropy. In that case, SGX wouldn't be necessary. Unfortunately, they didn't do that, so now a lot of users have chosen a short PIN and their data will be compromised should SGX ever fail to live up to its promises. (This is what I meant by "Signal PIN UI fuckup" – the word "PIN" alone suggests choosing a short number over a long passphrase.)
That is quite an understatement. This is like Facebook saying "we will protect your privacy, but there is a slight delay".
Compared to the ICO crypto shenanigans of Telegram and now this I don't see a reason to switch. People also kept trying to get me to use Brave instead of Chrome, and the first time I opened it there was crypto advertisement everywhere.
All the SGX stuff is about making metadata more private for features that absolutely must be done serverside. So a compromise in SGX is more an issue if Signal itself becomes adversarial or gets compromised. Most services only rely on this for security and don't use things like SGX to hide things from themselves.
Traceable by Google every time you open the App... and using Google's Backup service to store the private keys unencrypted. Well, so much for E2EE.
This combined with what went on with LibreSignal and legal threats from moxie made me realize it's just a company selling privacy claims without proof.
(if you don't think this is true, use AppWarden or decompile the APK. Play Services, Firebase and Recaptcha are still integrated years after LibreSignal was forked.)
> Google PREF cookie
The PREF cookie is for Google's safe browsing feature. How on Earth would that find its way into Signal? (I doubt the link preview feature uses that, given how much effort they put into making sure they get it right[2].)
> Traceable by Google every time you open the App...
How so? AFAIK the Signal app doesn't connect to the Google servers directly (reCAPTCHA aside – I have yet to see it in Signal but even then it would be a one-time thing), so even if the cookie existed, it wouldn't get transferred anywhere. The Firebase Cloud Messaging library / Google Play Services on your phone do connect to Google but they carry unique identifiers, anyway (or otherwise push notifications would not work). If you don't want that, use a phone without all the Google stuff – Signal works fine without it (though it might need more battery).
> and using Google's Backup service to store the private keys unencrypted
Could you provide a source that's more accurate than "decompile the APK" or "read the source code"? AFAIR the app's database is encrypted at rest by a key in the phone's hardware key store precisely because the Signal developers did not want Google Backup to get access to the app's data. (Which is why they ended up rolling their own backup solution.)
> This combined with what went on with LibreSignal and legal threats from moxie made me realize it's just a company selling privacy claims without proof.
What legal threats? (I'm familiar with the discussion but I have yet to see Moxie threatening anyone.)
[0]: https://signal.org/blog/giphy-experiment/
It does connect to google's servers for pretty much everything [1] - you can look for these constants in the codebase and you'll find lots of things that would worry any netsec person, including the key backup related stuff.
Signal doesn't only use firebase for the sake of Push Notifications. Also have in mind that push notifications/firebase is unnecessary with a high priority notification, which is what e.g. other f-droid FOSS forks of other apps use instead.
> What legal threats? (I'm familiar with the discussion but I have yet to see Moxie threatening anyone.)
Granted, most of the discussions in LibreSignal's repo [2] got very heated very quickly. Can't find the twitter thread of @moxie at the time, and lots of replies in there got deleted from both sides. Maybe someone else can provide an archived version or screenshot? [3]
> Could you provide a source that's more accurate (...)?
Make an Access Point, use smartphone to connect to it. Run Wireshark, and you'll see what's happening. Use an AOSP ROM and use the Signal Download without Google Play Services (to be sure that it's not Google Play noise you're observing) [4].
[1] https://github.com/signalapp/Signal-Android/blob/d74e9f74103...
[2] https://github.com/LibreSignal/LibreSignal/issues/37
> Make an Access Point, use smartphone to connect to it. Run Wireshark, and you'll see what's happening.
That won't help when it comes to how stuff is encrypted locally, i.e. the hardware-backed encryption[0].
PS: I think I updated my comment while you were already responding.
[0]: https://blog.elcomsoft.com/2019/08/how-to-extract-and-decryp...
I remember reading all those threads (the one on GitHub and those on Twitter) back in the day and, honestly, I didn't come away impressed by the way some people treated Moxie. I've been in his shoes a few times now (trying to build a product that works – technically and economically – with team of anarchistic techies) and can empathize with the path he's taken. Not understanding his POV is no excuse for being rude, though. Now, since you posted the link, I went through that GitHub thread again and my impression has stayed the same. A few quotes:
> Wow, moxie0 just sounds sounds like a giant cunt. Anyone who uses a binary compiled release of Signal from the Google Play Store for security is a fucking idiot. (https://github.com/LibreSignal/LibreSignal/issues/37#issueco...)
> FUCK YOU OWS!!! (https://github.com/LibreSignal/LibreSignal/issues/37#issueco...)
> I must say, you [moxie] really are the worst anarchist I've ever encountered in my life; but I'm no authority on the matter. Writing good software doesn't give you a license to bully other projects around unless they give you a WhatsApp-level payout. How about you keep your narcissism tucked in so that secure messaging in general doesn't have to suffer from it? (https://github.com/LibreSignal/LibreSignal/issues/37#issueco...)
> That post [by moxie] is pure politics. It's a bunch of feel-good phrasing, cringe-worthy in its superficial slickness, that obfuscates what is really a giant policy-level middle finger from in terms of Open Whisper Systems shifting away from free software and into a centralized, All Rights Reserved commercial outfit. (https://github.com/LibreSignal/LibreSignal/issues/37#issueco...)
Here's what the people in the thread had to say who didn't get all personal:
> [Directed to someone else on the thread:] Whatever your take on what "the right thing" is, there is no need to get personal. And as previously said, Signal is free software - that entitles you to the source code, and no more. Noone is in the right to demand that OWS do anything else, and that includes most of what is being said in this thread. (https://github.com/LibreSignal/LibreSignal/issues/37#issueco...)
> I thank @moxie0 for replying when asked by @mimi89999, providing his (OWS) point of view in a polite and useful way, bringing up some truly interesting aspects of the issue. I can understand @cjeanneret's frustration, feeling just one step away from a truly free and secure messaging system, but this is no excuse for being rude. (https://github.com/LibreSignal/LibreSignal/issues/37#issueco...)
Have you actually looked at that code? It's for domain fronting[0], so nothing shady, and it's only used when you're in Egypt, UAE, Oman, Qatar, or Iran. Have a look at
https://github.com/signalapp/Signal-Android/blob/d74e9f74103...
vs
https://github.com/signalapp/Signal-Android/blob/d74e9f74103...
and, finally,
https://github.com/signalapp/Signal-Android/blob/d74e9f74103...
> you can look for these constants in the codebase and you'll find lots of things that would worry any netsec person, including the key backup related stuff
I just ran a recursive grep on the entire repository and the file you referred to is effectively the only place where a google.com URL shows up in the code (apart from two or three more instances which are not suspicious, either).
Maybe I'm missing something, so feel free to prove me wrong, but right now my impression is that you're spreading FUD for no good reason.
For what else does it use Firebase?
> Also have in mind that push notifications/firebase is unnecessary with a high priority notification, which is what e.g. other f-droid FOSS forks of other apps use instead.
That's news to me. OTOH I'm not familiar with the term "high-priority notification" outside the FCM realm. Unfortunately, a quick Google search only yielded results related to FCM. Could you explain what you mean?
I'm the CEO of MobileCoin. If anyone has any questions please feel free to ask here. We've been working on this project for four years and it has been a labor of love. There's a lot of new technology here.
We exist in a highly regulated space so it's possible some questions will require reaching out to lawyers to make sure we answer them in a way that's compliant so please don't feel offended if a response takes a while to come back.
The best set of docs for how the whole thing fits together is our book "The Mechanics of MobileCoin"[0].
We'll be around here and on our forums [1] to answer questions. Please also check out our foundation website[2]. The github[3] is also a lot of fun, especially the section on Fog[4].
[0]https://github.com/UkoeHB/Mechanics-of-MobileCoin/blob/maste...
[1]https://community.mobilecoin.foundation
[2]https://mobilecoin.foundation
[1] https://support.cloudflare.com/hc/en-us/articles/200172706-C...
Often repeated but false. Early adopters mine or buy large proportions at negligible prices while late adopters mine or buy negligible proportions at large prices.
The same is true for stocks, gold, and pretty much anything else you can invest in.
In retrospect it would have been a good deal to buy AAPL for $1.50 in 2005, but what can you do. That doesn't make Apple a ponzi scheme.
Other way of saying it, is that early participants in a pyramid scheme don’t have guarantees that they’ll find enough people for the scheme to be successful.
1. how does MobileCoin make money?
2. how many coins do you / does MobileCoin own?
3. related to that, are there mechanisms in place to prove that this is not a pump and dump? Or simply, how do I know it's not one and it's here for the long-term?
4. what's the threat model of the blockchain you're using? E.g. for Bitcoin, the chain is compromised once 51% of the hashing rate belongs to collaborative evil miners (as a rough approximation). What about MobileCoin? When would something bad happen? How is it prevented?
5. how does MobileCoin compare with privacy-oriented cryptocurrencies such as Monero?
P.S.: you might wanna add a F.A.Q. section somewhere for the questions I've mentioned and the others in this HN thread, right now we either have to blindly trust the claims on https://www.mobilecoin.com/ or going through the 133 pages of https://github.com/UkoeHB/Mechanics-of-MobileCoin, there should be some intermediate tech documentation (or does it exist already?)
MobileCoin pre-mined the coins and is selling them to users. According to other comments, they hold 85% of the coins.
The CEO is commenting in this thread with a link to buy the coins. They make money by selling these coins.
MobileCoin isn't even on the list of cryptocurrencies you can make a donation in.. which makes this seem more like a cash grab rather than something that was thought out.
2) I have to check with the lawyers on whether we can disclose exact amounts, but our intention is to own a small minority of coins over the long term. We want the supply to circulate.
3) I don’t know how to prove this other than to tell you that MobileCoin is here to stay. You’ll know us by our deeds.
4) the threat model is 100% of nodes being compromised with an active attack against SGX. If there is even a single honest machine, the network will scream on any fault.
5) MobileCoin is fast and privacy-protecting (and it works on mobile without consuming tons of energy). There aren’t any other cryptocurrencies that presently fit that bill.
Shameful.
This smells of centralisation.
I know Moxie seems to put near-complete trust in SGX, but many security professionals don't.
My question, to both you and (especially) Moxie: Why do you trust Intel SGX so much (for Signal but now also MobileCoin)? Why are you not worried about vulnerabilities? As you're surely aware, even Matt Green who is/used to be(?) the biggest fan of Signal[0] is very concerned[1] about SGX. I don't question your intentions but the fact that Signal as an organization has stayed completely silent about this is… worrisome and at the very least taints its reputation of openness and trustworthiness. With MobileCoin now relying on it, too (more or less), this only seems to be getting worse.
[0]: http://web.archive.org/web/20200201112751/https://signal.org...
[1]: https://blog.cryptographyengineering.com/2020/07/10/a-few-th...
What is the identity and distribution behind the current mobilecoin nodes? What are the requirements for running a node? Since there is no node rewards how will nodes funded in the long term (10+ years)?
Does mobilecoin employ something similar to Dandelion++? What prevents nodes or those running fog from performing timing based attacks? Is mobilecoin suseptable to any other attacks (e.g. Poisoned output, subaddress association)?
How will the mobilecoin foundation and continued development be funded in the long term (10+ years)?
If SGX is found to be vulnerable/no longer fit for purpose is there a mitigation plan?
Why does it make sense to integrate MobileCoin into anything? Why not use Monero or zCash? Sure, you can definitely explain this to me, but nothing explains that to general people on your GitHub page. Same thing on your foundation page, which simply has logos and "Private Payments for everyone" [1].
I've spent a lot of time working on blockchain and perceptually, it feels like you're trying to sell snake oil here. For example, the mechanics paper [2] starts with "Cryptography. It may seem like only mathematicians and computer scientists have access to this obscure, esoteric, powerful, elegant topic." Cryptography is a tool. What's obscure about it? People are using it right this second. Why is it esoteric?
The paper then continues with a brief overview of 'blockchains' (why the scare quotes?). In the same paragraph, it states that the purpose of blockchains is that "no piece of money can be duplicated or created at will" but this is only one of many points of the entire point of a blockchain. Why does it not explore other facets of blockchains if the goal is to be introductory?
Then, in the fifth paragraph, the paper remembers that people may not be reading this for the first time with no experience, and suddenly jumps up to 11, with this paragraph. Note, this paragraph is one single 91-word jargon-filled sentence:
> MobileCoin is a standard one-dimensional directed acyclic graph (DAG) cryptocurrency blockchain, where blocks are consensuated with an implementation of the Stellar Consensus Protocol, transactions are validated in SGX secure enclaves and are based on elliptic curve cryptography using the Ristretto abstraction on curve E25519, transaction inputs are shown to exist in the blockchain with Merkle proofs of membership and are signed with Schnorr-style multilayered linkable spontaneous anonymous group signatures (MLSAG), and output amounts (communicated to recipients via ECDH) are concealed with Pedersen commitments and proven in a legitimate range with Bulletproofs.
While I want to assume good faith here, I find that the blockchain community often has a history of attempting to "smooth over problems" with lots of jargon and hoping for the best. This sentence, when run through Hemingway [3], gives it a post-graduate reading level. But that's not anything about the cryptography: the paragraph/sentence is simply unreadable to most people. It serves no purpose in the middle of this section.
While I'm sure you'll mention that this is a preview document, you're pointing people to it as the primary resource for people to learn "how the whole thing fits together."
Other warning signs that make me wary are everywhere.
The foundation about page has the Intel, Azure, and IBM logos under a "powered by" footer [4]. The meaning is ambiguous, and the intent is clear: you want to use these big tech company logos, because they're recognized. Yet, this is the exact same thing companies do when they're sponsored by other companies. To the untrained eye, these are indistinguishable things. Is MobileCoin sponsored by Intel, IBM, or Azure? If not, you should remove the logos. It feels like a "trust play." You're not linking to any sites or providing any information as to your relationships with these companies, but it seems like you just have cloud services with Azure and IBM, and use Intel SGX.
There's a typo on the "Foundation Trusted Nodes" page (two words slammed together): "MobileCoin Consensus is built on trust relationships between individuals and organizations who are running MobileCoin Consensus Validator Nodes.Determining" [5].
So, I suppose, if I had a question, it's: why, in all of this documentation and all of the websites that you've linked to, is there not a single "you should use MobileCoin over Monero and zCash because of ..." comparison? Why does it seem more like it's interested in propping itself up and being trustworthy, rather than conveying details about how it's superior to its competition for mobile payments?
[0]: https://github.com/mobilecoinfoundation/mobilecoin
[1]: https://www.mobilecoin.foundation/ & https://archive.is/ktf3o
[2]: https://github.com/UkoeHB/Mechanics-of-MobileCoin/blob/maste... (archive: https://files.catbox.moe/1wal8z.pdf)
[3]: https://hemingwayapp.com/
[4]: https://www.mobilecoin.foundation/about & https://archive.is/JNDbG
[5]: https://www.mobilecoin.foundation/foundation-trusted-nodes & https://archive.is/Pr868
There's a missing reference on p. 61 (physical page 68)
> ...Chapter ?? discusses how enclaves fit into the broader picture of consensuating transactions and growing the MobileCoin blockchain.
I assume it means chapter 10.
> MobileCoin also remains even more volatile than older cryptocurrencies, with constant price swings that will significantly change the balances in a user's Signal wallet over the course of days or even hours—hardly the sort of issue that Venmo users have to deal with. (Since March 27, MobileCoin's value has shot up nearly 600 percent, possibly due to rumors of the impending Signal integration or possibly the result of a "short-squeeze.")
> To try to tame that volatility problem, Marlinspike and Goldbard say they imagine adding a feature in the future that will automatically exchange users' payments in dollars or another more stable currency for MobileCoin only when they make a payment, and then exchange it back on the recipient's side—though it's not yet clear if those trades could be made without leaving a trail that might identify the user. "There's a world where maybe when you receive money, it can optionally just automatically settle into a pegged thing," Marlinspike says. "And then when you send money it converts back out."
https://www.wired.com/story/signal-mobilecoin-payments-messa...
https://www.gov.uk/government/publications/tax-on-cryptoasse...
The larger problem here for Signal is US legal claims could nuke it off the (very) centralized Apple App Stores and Google Play Store. Then what?
This would have to involve KYC or harsh limits.
You also had to provide a phone number to get a Google or Apple account to install Signal because anonymous signed install methods are not supported, which moxie says is intentional to collect analytics.
Signal may have end to end encryption but being anonymous is a clear non goal.
Signal distributes a standalone APK for android, which does function without google play services.
You must turn on Untrusted Sources which disables meaningful signature verification.
Now you must hope you don't get MITMed every time you update.
It is a joke they seriously expect people to sideload.
They need to provide a deterministic and easily auditable F-Deoid repo or let the F-Droid team compile/sign it for them.
Neither will happen though because moxie has been very open about the fact he wants the analytics that comes with google/apple tracked installs, user privacy be damned.
Also, it doesn't disable signature verification at all -- it just changes to what is essentially a TOFU model. You can verify this by installing, say, NewPipe from vanilla Fdroid, then adding the NewPipe repo and installing a build from there. It will fail unless you completely remove the original app (from all the profiles on the device!) and install the new one afterwards. This is due to different signatures between repos.
In any case, I agree with your wider point about Signal's rather concerning distribution strategy. I would like to see inclusion in Fdroid, or at least a custom third-party repository. Unlikely though.
In my country it’s actually easier to legally open a verified trading account on a local cryptocurrency exchange than it is to get a voice/SMS SIM if you’re not a registered local resident.
No. This is simply not true. You don't arrive at the value of a set of "things" by multiplying the best price for a single "thing" by the number of "things" you want to sell. That's not how the world works.
If I sell you a printout of a drawing for $1, printing out a trillion copies of this drawing does not make me a trillionaire.
> For now it's listed for sale on just one cryptocurrency exchange, FTX [...]
Great. So let's see what the actual value of this token is, by looking at the order books of the markets on the FTX exchange where this token is traded. There are two markets:
1. MOB/USD: https://ftx.com/trade/MOB/USD
2. MOB/USDT: https://ftx.com/trade/MOB/USDT
The most liquid market appears to be the MOB/USD market, so I will focus on this.
The MOB/USD order book tells us that, if you wanted to sell as much MOB you could while pushing up the sell price by at most 10% (from 61.15 to 67.27), you would end up earning $2.5MM USD.
If you consumed all sell orders (that are displayed on the site) the sell price would be pushed up to 73 USD per MOB (a 20% increase) and you would earn a total of 3.75MM USD.
Now, compare this figure to the alleged value of this token (17 billion USD). The actual value -- let's be generous and say 10MM USD -- turns out to be just ~0.06% of the claimed value of $17 billion USD.
At this point, if you really need this broad functionality Signal are aiming to provide, why not Status.im? At least their tech is cool.
This basically confirms my suspicions
Hopefully Matrix/Element continues on their current path and doesn't ruin their chat protocol/client by pushing some altcoin onto their userbase.
I thought Signal was already financially secure.
I only wish it were done differently - maybe we'll get answers to these questions:
- Why not airdrop everyone a 100 pieces of whatever coin (or even just 1, assuming the coin can be subdivided into tiny bits)? I'm asking because I believe the value of this kind of coin usage will come from its daily users, not from exchanges, but that's a long game. Even if today it's worth 0, if the UX is good enough and it proves to be secure, people will start assigning value to it.
- Why pick a cryptocurrency almost noone has heard of? For example, related to the above question, why not buy or mine a million Doge and gift every account a 1 doge (presented as 1 thousand mili-doge)? People will start assigning (more) value to it sooner or later if it's easy to use. Feel free to substitute almost whatever instead of Doges (maybe something with PoS and give the users the warm fuzzies with apparent increase in value).
It's not like MobileCoin was created by the same person who created Signal.
Nevermind .. that's exactly what it's like.
The rabbit hole is deep on this one.
Since Signal's sever is centralised, uses SGX and they have no intention of federation it makes sense that the cryptocurrency they chose has similar tradeoffs.
Mobilecoin is a pre-mined Monero rip-off (that Moxie has clear links to) with centralised Ripple-esque consensus, and puts UK Signal users into uncharted regulatory waters. Downright sleazy.
What wonders will Intel's Signal subdivision offer next?
There were rumors in late January that Signal was looking into Mobilecoin but that seems unrelated, and I'm not sure I buy a short-squeeze scenario as mentioned on Twitter.
Having inside information on this announcement was highly profitable.
For other uses cases they can use a cryptocurrency directly (even MobileCoin) from another app. I can understand that cryptocurrencies are very interesting from a technical and cryptographic point of view. But in their current state most of them a more for speculation and doing state of the art computer science.
Therefore I think this totally useless in the signal app.
Deleted the app. Also left a note in status so others can see the msg and delete the app also.
2. Moxie gets paid for being on their advisory board
3. Moxie directs his non-profit to integrate MobileCoin in secret
4. MobileCoin offers 1/5 of their premine for sale.
5. Signal announcement spikes price to $60
How accurate is this?
The fact that Moxie is collaborating with MobileCoin has been known for years.
EDIT: See links in https://news.ycombinator.com/item?id=26718488
Super dishonest and untrustworthy.
To be honest, that was exactly the impression that I got back then. So to me, yesterday's announcement was no surprise at all. Whether I like it, is a different matter.
Everything on the internet is being corrupted with adding cryptocurrency scams where they absolutely don't belong, it turns Signal from an obvious recommendation into something that makes me hesitate. There's something to be said for focusing on doing one thing well, and that doesn't mean turning a communication platform into a kitchen sink.
A case could be made for it being bloat, but most consumers don't care, and for Signal (or any messaging app) to be successful, it needs to appeal to the common denominator.
And frankly, if this means I can send money to a friend without Google getting yet more data about me, then even better.
Smoking causes cancer, but smoking these specific cigarettes won't. Do you see the problem with trying to describe such an absurd situation to somebody?
You're making a different point now though, you're saying that people will associate it with scams which will hurt adoption. You initially wrote that the UX would be so bad that you'd have to convince users to bear with it anyway.
I don't know how they implemented it on the client side, but it's possible they kept it light, as they've been doing since the beginning. We'll see soon enough.
In terms of reputation, this is a long-term battle. Signal used to be quite unreliable in a lot of aspects, and hurt adoption. Now it's much better, making the migration from other messengers way smoother. If they're able to implement safe, private and convenient payments, that's one feature other messengers won't have to lure users away from signal.
I think you're confusing UI and UX. Yes, the UI could be kept light but the user experience can still be confusing because a payments feature is… surprising. Why would a messaging app come with a payments feature if not to make money and exploit the user?
Not saying that this is happening here but this is what people think, i.e. the emotional experience.
> just click through the scam marketing, ICO offers and "airdrops"
That's what I meant by UX.
> user experience can still be confusing because a payments feature is… surprising
Everything new is "surprising", that's a low bar. Chat apps in China have had this feature for years now, and it's also a feature in WhatsApp, a direct Signal competitor.
Signal providing this functionality is scope creep.
Yet, those features have almost become synonymous with messaging apps. The market and consumers seem to want these services combined, so here we are. My point was that sending money is a feature that more and more messaging services have. Hangouts (or whatever the hell it is called these days), Whatsapp, Telegram, etc.
Personally, I would have liked it more if this wasn't tied to some no-name cryptocurrency, but oh well.
I think those would all be considered in scope for a chat platform--theyre all various ways to share and communicate.
When people want to send "money" to other people, they usually imply that they want to send units of the local currency, like USD or EUR. And they usually imply that the value of these units should stay the same during transfer. If I want to pay my share of a restaurant visit to my friend who covered the check, I'd like the 30$ I'm sending to still hold enough value when they arrive in his bank account to actually cover my share. A cryptocurrency intermediate that swings +/- 20% in value within minutes (and that we both have to pay conversion fees in order to acquire/redeem for $) is of exactly no use at all for such a use case.
The founder of Signal actually created MobileCoin.
Before you label MobileCoin a scam, I would encourage you to take a look at the Github. I think you'll see that we've made a lot of very carefully considered choices on how to deliver a great payments experience without many of the compromises other cryptocurrencies have chosen. Of note, the speed of transactions, much greener energy design, privacy-protections, and mobile-first UX are differentiators. Many cryptocurrencies have some of these features, but I don't know of any other that has all of them.
Believe me, I have a lot of feelings about how absurd cryptocurrency has become in the last decade. At its core, I still believe that there is something beautiful in decentralized ledgers and I think that this is the way that the world will settle debts over the next hundred years. Signal chose MobileCoin because nothing else met their performance and privacy standards. In order to meet those goals we wrote a lot of new technology that is fundamentally different from how other cryptocurrencies are architected today (check out our oblivious RAM implementation, for example: https://github.com/mobilecoinfoundation/fog).
I love Signal and I started MobileCoin to help fund their work. For me, a world with Signal in it is a better place.
Signal has obvious financial connections to MobileCoin, something that frankly nobody else has ever heard of before today. I find it really difficult to believe that MobileCoin paying Moxie (which you've acknowledged), and Signal/Moxie happening to choose MobileCoin for inclusion in Signal when nobody wanted it was a coincidence. It's insulting to the intelligence of the reader to even make that claim.
> Before you label MobileCoin a scam, I would encourage you to take a look at the Github.
What would that tell me?
https://news.ycombinator.com/item?id=26715013
This seems incompatible with the spirit of the quote in the article.
What I would still like to see for more transparency:
- legal commitment from the Signal Foundation that no employee owns any MOB
- disclosure of money transfers between MobileCoin and any Signal Foundation employee
Maybe some of this information could already be extracted given the statuses of the entities involved?
[0]: he benefits indirectly because if MobileCoin stays up, he'll probably stay as a technical advisor
What about the LLC?
The problem here is not that people think that MobileCoin is not a useful technology or is not innovative. From what you are describing it actually seems like a good combination of features that are particularly suited for the messaging use-case.
The problem is in the way the coins were pre-mined. It seems (we don't really know from the outside) that the knowledge that Signal would be using MobileCoin has been known early on. With that knowledge it is very easy to make money by pre-mining coins. The proper analogy here is insider trading. It is immoral and that is why people are calling this a scam.
https://twitter.com/fluffypony/status/1379559273504641025
I guess the whitepaper mentions it, but that isn't suprising considering koe wrote it.
Anyway Signal is itself pernicious by being tied to a phone number and to Google Play services, and by being very choosy about who gets ports.
I had high hopes for Matrix, once they got E2EE, but they have flubbed that by requiring a very heavyweight bounce server that won't fit on (e.g.) your typical home router or super-cheap cloud VM. Matrix should enable a place to keep your message archive independent of the bounce server, and allow gatewaying a non-public storage service via the lightweight bounce service.
But Element.io's business model is tied to heavy-weight bounce service.
Also anyone can run their own servers, and Dendrite can run on very modest hardware like a Raspi.
And as others have said, Synapse really isn't that heavyweight these days (thanks in part to the performance improvements driven by Element!)
It's not tied to Google Play Services, you can download a standalone version from signal.org. As for phone numbers, the developers have been working on getting rid of them for a while now – there's already a good amount of code on GitHub.
I think what Signal is doing with MOB is pretty important work for many non-western countries, and I wish them all the best.
Cryptocurrencies don't solve third world banking, at all. You still get paid in fiat, which you then have to convert to crypto (using a bank), and you will never be able to have most people get paid in crypto because then the government can't get taxes reliably (thus they will ban it).
"When disagreeing, please reply to the argument instead of calling names. 'That is idiotic; 1 + 1 is 2, not 3' can be shortened to '1 + 1 is 2, not 3.'"
If they really must integrate crypto with the main app I'd rather they used a stablecoin since a highly volatile cryptoasset isn't very useful. Also, I can't be bothered with the tax implications.
We believe in Signal's mission and we think that the world is a better place with Signal in it.
Moxie, as an individual, is a paid technical advisor to MobileCoin but the reality is that we could never pay Moxie what his time is worth. I am thankful that he has chosen to help make this project a reality.
>Moxie advises MobileCoin
>MobileCoin gets integrated into Signal
Hm, yes, must just be one large coincidence that this "integration" happened.
>>The UK also has receiver verification. If I try to send to an account and it doesn't match the name I'm sending to, my bank will warn me. How do you stop impersonation?
A: Signal relies on phone numbers for identities. Other apps that integrate MobileCoin may have a higher threshold for identification.
For all intents and purposes Moxie is 100% in control of the Signal network and could shut it down or release a malicious update that plaintexts messages at any time.
I've been a longtime signal user (since the textsecure/redphone days). I've always given moxie a pass on his controversial decisions (no federalisation, no 3rd party clients, no fdroid repo, relying on Google play services, being slow to release serverside source code) because the team was small and obviously had to cut corners somewhere.
But learning that they spent their time adding support for a (premined?) cryptocurrency just because it's Moxie's pet project is disheartening. What are the odds that this would've been merged into the project if it had been a merge request opened by someone from the outside?
Want to run signal with no payments integration or with a Bitcoin wallet instead? Too bad.
I wish there was a way to decentralize that value :-P
I still love the idea of it and I hope it actually gets good/usable one day. Until then, I can recommend it only if you want to be an early adopter, but not if you want a good experience.
The media capabilities are nothing like IRC.
In fact I moved to Element because Conversations had trouble with media.
It's certainly not the IRC/Discord/Slack replacement that I was hoping it'd be, where lots of "randoms" can join and a community develops.
The UX is still going to be unacceptable for most non-technical people, so I definitely can't convince my friends to switch from Discord, even for our private group.
What is preventing "randoms" from joining ?
What are those "unacceptable UX issues" ?
BTW, if you really care about it you could insist like I generally do that it's either you or Discord/Slack.
This isn't helping.
I'm finding this announcement creates some uncertainty in my head about Signal's long-term future.
Sell turn key servers for people that lack the time or interest to run their own.
Federated and ethical.
At this point if you want federated it probably makes more sense to just use Matrix.
MobileCoin is pre-mined and the majority of coins are held by founders and the MobileCoin organization. They want to sell you coins, so partnering with Signal to force you to buy their coins to transact on the app gives them a revenue stream.
If they simply added Monero, they wouldn’t be able to sell you coins.
TLDR: UX
Fees are also in a similar range (0.01).
Also moxie replied in his twitter about why not monero stating they wanted a "non custodial" integration, not sure what he means but you can ask him.
> ‘Mechanics of MobileCoin: First Edition’ is an adaptation of ‘Zero to Monero: Second Edition’, published in April 2020.
[1] https://github.com/UkoeHB/Mechanics-of-MobileCoin/blob/maste...
"Every program attempts to expand until it can process _payments_. Those programs which cannot so expand are replaced by ones which can."
In the Wired article, they argue why this doesn't put a target on Signal's back as they are not becoming an exchange. Good for them, but what about Signal users' backs?
With this feature, the range of reasons why the authorities might justifiably want to have a look at the contents of my Signal app has just widened dramatically.
If you're using this feature in the UK, you are well advised to read the HMRC guidance on the taxation of cryptocurrency:
https://www.gov.uk/hmrc-internal-manuals/cryptoassets-manual...
I don't want this stuff in my messenger. It's supposed to send messages, not money. This is just going to accelerate my departure from Signal - or at least the official client.
Side point, I think one of the greatest and less discussed risks of crypto is government. Its hard to see them allowing loss of currency control. Currency is so economically important for control & profitable e.g. There much talk the support on the attacks on Libya/Gadhafi was in part due to his desire for an independent currency. So unless crypto spreads so widely pre-regulation its politically unviable to move against, I wonder if we will see governments step in against crypto, at least as a day-to-day transaction option at some point.
Add the feature, but come up with a solution that is currency agnostic.
SCRT network is a similar project that uses SGX but supports smart contacts so they could have a Maker like pegged token.
I can't wait till we stop sprinkling bitcoin over everything. At least when we go back to ads we'll stop getting the spam from bots trying to claim their free $0.00003 in cryptocoin of the week
I think the article might be inaccurate. According to this, there's at least four exchanges currently:
Now the same thing has happened on Signal; HN's favourite messaging app. So why is this met with warm welcoming arms especially when they are also going into cryptocurrencies?
Maybe the HN sentiment back then was filled with those who missed the crypto bull-run of late 2017 and the same ones have missed it again last year.
First, indeed the sentiment changed radically between now and then. For some reason, this subject has always attracted irrationality on HN. Back then any comment vaguely positive about cryptocurrencies would accumulate downvotes, now threads are full of clearly invested shills (you can see it in this very thread).
Secondly and more specifically, Stellar, being a simple Ripple fork with an equally dubious token distribution, was a weird fit for Keybase.
MobileCoin, while having some of the same downsides (federated, centralized token holders distribution) has a more interesting design, and is closer to the actual cryptocurrency/cypherpunk spirit thanks to its fully private transactions and balances.
In the other thread it was not: https://news.ycombinator.com/item?id=26713953
MobileCoin smells so much more like a ruse than Stellar.
There is a near zero-chance my friends and family would have done this without buy-in from their nerd contact. I sold it hard. And this same nerd has been talking about cryptocurrencies too, almost exclusively that they are at best tulip-craze scams, at worst just a way to bait drug dealers and law enforcement onto your device. Not to mention the hideous environmental impact (and you are about to talk about proof-of-stake, just ... don't.)
I can not stress enough how much I want this experiment to fail.
Now, I guess I need to find a good Matrix ecosystem to join.
I highly recommend giving Element [3] a try - it's polished and easy for non technical people to use, end-to-end encrypted and OSS.
[1]: https://matrix.org/
[2]: https://matrix.org/clients/
[3]: https://element.io
I have more hope for other clients like Fluffychat.
The UK recently removed themselves from the EU so they are once more in a position where they can play host to new financial instruments and potentially benefit from that. Crypto currencies have the potential to be very disruptive to the modern financial system. Not the worst move for them to allow some experiments to happen in their jurisdiction. If something like this takes off, it has the potential to capture quite a bit of value. If it doesn't work out, it's easy enough to get rid of it.
It's also interesting that particular block chain is based in San Francisco. The SEC is allowing this to happen, apparently (probably for the same opportunistic reasons the British allow this). These MobileCoin guys are well funded apparently and not by means of an ICO but by good old VC cash. VCs are smelling money, that's why this stuff is happening and why the SEC is being a bit hands off here. There are quite a few block chain companies operating in the US actually. There already is quite a bit of VC money locked up in that.
It's also an interesting counter move to Facebook's Libra as well and kind of embarrassing for them that particularly Signal is doing this given that it is backed by one of their former Whatsapp founders. Libra in turn was a counter move to Telegram's plans (yet to materialize) and inspired by China's WeChat.
1. The system is not distributed
2. The server is not open source and there was no notice that open sourcing the server will stop.
3. there is no public roadmap nor a away to make feature requests
And that’s not all by far.
My go to messenger is matrix.
https://github.com/UkoeHB/Mechanics-of-MobileCoin/blob/maste... << Page 81 is where you want to go.
Or did you modify it to fit a different use case?
(thanks for answering questions!)
Finally, we wanted to perform consensus on encrypted values so that the nodes wouldn't be able to censor transactions.
Imagine I have a private key to an address with 10 coins. Imagine I spend the same amount of money (10 coins) on Mars and Earth at the same time. There is a 10-lightminute gap between Mars and Earth. Assume Mars and Earth have a similar number of Stellar nodes. What happens in Stellar Consensus?
In a Zcash-style spend circuit, the bottleneck is typically the Merkle inclusion proof, which takes say 32 hashes (assuming a limit of 2^32 note commitments). If we're comfortable with using one of the newer arithmetic hashes like Poseidon, that's about 10k constraints. Any of the modern argument systems (Groth16, Plonk, STARKs, etc.) can give proof times well under a second with a circuit of that size. If we want to optimize further, we can get proof times down to around 10-20ms (single-threaded) by using an arithmetization that's carefully tailored to our circuit's bottlenecks.
If we stick with traditional primitives like SHA-256, the circuit becomes substantially larger, but with modern techniques we can at least get proof times under a second. Happy to talk through the options if it would be useful.
1) Creating a backup of their wallet on disk.
2) Sending their coins somewhere, but not broadcasting the transaction to the network, instead storing it in a file.
3) Restoring from the backup
4) Sending the coins to a different address = double spending them.
5) Broadcasting the transactions in a very close timespan to conduct the double-spend.
The network needs to prevent this by storing, in an non-forge-able fashion such as PoW, which transaction happened first.
How does your system guarantee that?
https://github.com/mobilecoinfoundation/mobilecoin/tree/mast...
How does this solve network splits or honest disagreements?
How do you prevent the sybil attack then if there is no scarcity?
I.e. what prevents an individual from spinning up 10 million nodes to get more voting power?
Thanks for clarifying!
So you're expecting people to
- manually add peers to be able to use the network.
- manually monitor the said peers for if they do malicious transactions, and manually ban them if yes.
Right?
How is this supposed to work considering that:
- most users won't care about manually adding peers. They'll just add EVERYONE who offers to be added so they can be done with it and use the system.
- most users probably won't even understand what a malicious transaction is in the first place.
- the few who do will for sure not have the time to monitor a network which does dozens or in the future even thousands of transactions per second.
This seems just humanly impossible, there's by no means sufficient human time available to manually monitor a P2P network's content if the said content is super boring and complex.
If it were a distributed social network you could expect people to e.g. manually flag spam because using a social network implies reading the posts contained in it.
But manually reviewing money which strangers send to each other is boring as hell, who will do this?
Because I can get bank notes from an ATM and pay anyone in cash without having an intermediary verify my identity when money changes hands.
>>Those outputs contain the entire original supply of MobileCoin (250 million MOB)[1]
Is the entire supply of 250M MOB available for sale on FTX, or is only a restricted number of MOB tokens available for sale to UK residents? Is it fair to assume that the MobileCoin Foundation has no plans for an airdrop (unlike Stellar)?
[1] "Mechanics of MobileCoin", v0.0.39, pg. 133
Geee 1 hour ago | unvote [–]
There are 250 million units of mobilecoin, and majority of them are owned by the founders. Only 37.5 million have been distributed. With current price ($65), they're worth $14B already. This makes the project a scam and impossible for it to work as a reliable money that holds value. Bitcoin had no pre-mine and has been fairly distributed from the start.
MobileCoin uses a fork of the Stellar Consensus Protocol, which is a consensus protocol that by design, relies on a small set of trusted third parties to establish consensus.
This does not give it highly credible censorship resistance, yet MobileCoin was chosen as the sole cryptocurrency that Signal is integrated with. Why?
Haven’t seen the git updated in a while.
No updates in the repo for over a year and no answers from the team. The whole crypto currency thing is also a red flag for me. Matrix seems to be the better option by now...
Their unquestioned faith in Intel SGX is somewhat pathetic to be fair.
Matrix is a little more promising, but Element (at least on matrix.org servers) is slow, especially at scale.
Wayback Machine for March 11: http://web.archive.org/web/20210311053716/https://github.com...
If so, maybe make that more clear or prominent?
Mobilecoin feels hi tech
Storing keys in SGX and using attestation to ensure only valid nodes access them is significantly more secure than not using the SGX.
Using SGX gives a Signal user’s phone the same level of security as using a hardware wallet like Ledger Nano.
”Running MobileCoin in an SGX enclave allows nodes to securely manage keys for users. A client can perform remote attestation to its MobileCoin node before transmitting its keys into the remote enclave along with a short recovery PIN. The MobileCoin node can then rate limit authenticated access to the keys, while the enclave prevents the node operator or anyone who compromises the node from circumventing the software and attempting to brute force access to the keys directly. In this way, user keys can reside safely in a node and survive across application reinstalls or lost devices, without having to trust the node operator or the security of the node computer, and without having to memorize or safely store extremely long recovery passphrases.”
> 5. Will I need to put my keys on a remote server to scan the blockchain for incoming transactions?
> Keys will never leave your mobile device. This is a challenging problem and we are very excited to share our solution when we release our mobile SDK software.
[1] particl.io
iHXtgfsScSiaqKFMev8mC5Yogz8uZhTJSUVBM1vkECKPaVVxp9woYvbZJPso4SNx5oCkiU5XrAGZj6XwZMrYGzQztntDUKRka2RHnc6d9NPYaorT7E21jEWobERA77Uzny4VoeChDA9m2MihDLTB47BoJ3S2Lhuhp8U Kbo6jyRpo2zcr5ZucssuBVENGUS4fTK7qZZY8qMXHd9B1MNbA2MgBBzb5fBjberr6v4NKBVo3oFNCS1J3ryX13ZszByxjEU
The UI seems fairly unobtrusive, but I don't know if that's just because I have no contacts that can receive it so I'm not being shown some of it.
I also have no idea how to actually get Mobilecoin to play with. There's no built in way to buy it. They just give you an address you can send to from an exchange.