Interview with Signal President Meredith Whittaker
wired.com
wired.com
Big props for that (and for the interviewer for looking it up). A lot of nonprofits are glorified jobs programs for politically connected individuals.
Nothing is pure-as-the-driven-snow perfect, but I use Signal.
You could still attract a very large talent pool for $200k/yr, especially given the mission, and doubly especially if this is remote work and not based in SF/SV.
Anyone whose worked with a dozen or so people will know they're never equal. There's generally at least one 'guru' in the group who knows the ins, outs, and why's of everything. At big companies they'll get split up so there's only one per team, with maybe a couple roaming super team for anything truly major.
But I've certainly met engineers who are worth at least 2 lower engineers.
Moreover, not all spectacular engineers are worth working with; there’s a lot to be said for someone’s ability to be worked with and to be a leader, in addition to just pure knowledge or capability. Being able to work on teams matters, and being able to lead them (while being respected, respectful, and educating) matters even more.
The latter pieces of being a “strong engineer” are the pieces that are the hardest to learn for most engineers, because we spend so much time pretending it’s only the code that counts. Great engineers who realize and understand how to push their colleagues and themselves to grow while pushing the company forward? They are worth their weight in gold.
What hasn’t been mentioned is that Signal is an extremely high-profile target for rogue actors and nation-states. Employing staff with personal financial troubles in sensitive positions can contribute to the temptation to use access for personal gain. This is one way intelligence services groom double agents. Despite what appears to be very high salaries they won’t get rich in the Bay Area— but it seems like it’s above a threshold where one of these engineers would feel desperate.
Also: I imagine having a WhatsApp founder as a board member/funder helps here, as they famously built and scaled globally before their acquisition with only 20-30 engineers…
Paying more is still a valid form of defense against petty corruption, though.
I've seen stories of actors in Hollywood banking $15M from a movie, buying all sorts of property with mortgages, boats, cars, all on credit, then losing it all due to default without that next movie.
Behaviour indeed.
― Charles Dickens, David Copperfield
https://www.goodreads.com/quotes/90487-annual-income-twenty-...
did you mean 400K? That IS in the 990.
So true!
https://www.wired.com/story/signal-mobilecoin-cryptocurrency...
I also converted my friends and family. What's very nice for building trust is their transparency report on how funds are spent.
It's just a really elegant solution for cross-platform messaging, the security is a great bonus.
However, Signal was not blocked by the great firewall and we were able to communicate freely on it.
But now I'm wondering why isn't Signal blocked? Does the CCP have a backdoor into it somehow and therefore doesn't feel threatened by it?
There are "Military Grade" message and voice encryption technologies that avoid these issues by always sending a fixed amount of traffic to all parties, but that tends to be impractical for mobile apps.
To you point though, it sounds like Signal is not actually allowed to operate in China so there's nothing to explain after all.
As long as the average Chinese citizen cannot effectively create an account (because the activation SMS cannot reach their phones) the Chinese government may allow existing users of signal (who activated the account abroad) to communicate with signal.
It still isn't the simplest explanation. The simplest one is probably that there were simply too few Signal users.
The complete source code for the Signal applications and the Signal server is available on GitHub. This way, anyone can review the code for security and correctness. An existing backdoor would mean that every expert review of the source code in this field has been faulty. And the fact that I can set up my own Signal server and compile my own client supports Signal's claim of being a secure messenger.
The possibility of manipulation through Apple and the App Store process remains. However, this is by no means the simplest solution.
I believe weak/no backup encryption to be the primary attack vector against otherwise well-designed e2ee messengers.
The two options, roughly speaking, are: Force users to store some high-entropy passphrase (which most users will then store somewhere not very secure), or let them pick their own passphrase (which won't be very good). This is what WhatsApp does.
A third one would be to allow a short passphrase and guard that by a server-side HSM or maybe SGX, which Signal seems to be somewhat fond of; I'm glad they're not doing that.
Almost nobody uses these in practice, so I think my point largely still stands.
I'm pretty sure that, given their stance on this issue on iOS, they'd start locally encrypting the message database using a key stored in the Android Keystore system (which won't be backed up or extracted).
https://support.signal.org/hc/en-us/articles/360007059752-Ba...
————
> Where can I find the backup file?
> Your backup folder is listed under Signal Settings profile_avatar.png > Chats > Chat backups > Backup folder. Use the files app or plug your phone into a computer to go to the folder.
> For older versions of Signal, the backup file signal-year-month-date-time.backup can be found at /Internal Storage/Signal/Backups or /sdcard/Signal/Backups
Lack of backups is not a retention/deletion policy. Signal chats can, in fact, have a deletion policy set. Instead it directly ties retention to "how long can I last without losing or erasing my phone", which is not a useful proxy.
Anyone sufficiently motivated to keep messages forever can (a) set up the desktop client and back up its data store or (b) set up signal-cli and save everything that comes out of it.
No backups doesn't defeat this, it just makes life harder for everyone who relies on scrollback. Imagine if email worked this way.
Sure, but defaults matter.
Telegram has that. Just forget to log for 6 months and poof.
This might well be her most important statement.
I wrote off Signal when I heard about MobileCoin, and didn't look at Signal again, and didn't known MobileCoin left.
I've encountered this argument ... repeatedly. Let's explore the DIY route:
If you can build your own Signal server, you too can serve you and your own circle of friends. The bar is not that high (Java and VPS).
Signal clients are even easier but it remains mostly an unique build-challenge due to not so strong documentation and by the virtue of mastery of multi-platforms. Having said all that jazz, step back and ask yourself this, what am I losing by building my own Signal-protocol network?
Anonymity
Now, you would easily stick out like sore thumb to all the Internet overwatch, even within VPN tunnels.
That's a risk for me.What am I actually gaining?
Not much: a more unique hash signature of client app (it has downsides); the ability to perform a unique but slight tweak of hash/key/encryption algorithm using same Signal protocol (dangerous rabbit hole), and avoidance of XDR/NDR/IPS/IDS firewall, and the biggest one: zero spreading of hashed contact info (more on this below).
-----
Alternatively, let's take the original route: your own client against "the" Signal server:
Now, Signal protocol would be open to misshapen protocal usages (think "fuzzing"). Might be a good thing but certainly not at this early stage; do we have the manpower to stand guard over a protocol like ISC Bind9 team do with their DNS?
The one area that is not firmed up 100% (more like 99.999%) yet is the Privacy Information Protection axiom and that is centered around the exhanges of hashed "Contact" address book.
This there is largely understudied and under-whitepapered: how to exchange contact info in safe privacy order just to build your network: I keep that Signal client app option off for now and manually add my contacts. That's why I think that Signal team is moving away from telephone number.
So i am now dual-tracking usage of libsignal.
I wish such cruft would be removed from Signal.
I literally just removed some code from 2021 that was echoing huge JSON files into build logs that nobody looked at.
It reduced the pipeline run duration from 45 to 30 minutes.
Now, a crypto coin will probably be harder to remove, but there's a weird inertia around long-lived repositories where people are afraid to make any changes. Although I hope the crypto portion is feature-flagged and can be somewhat easily disabled.
I stopped donating to Signal when they added it and I can't imagine I'm the only one.
Then perhaps, "Now that SGX has been completely destroyed by a class break when will MobilCoin support be removed along with signals other security dependencies on SGX?"
https://www.theverge.com/23409716/signal-encryption-messagin...
I understand that people love signal, but I don't understand why: outside of what appears to be propaganda such as this.
btw; Downvotes only make my belief stronger that unironically there are actual shills on HN. The way people are bleeding to defend it as “the one true secure messenger” is about as convincing as Epstein killing himself.