HNHacker News
TopNewBestAskShowJobs

haffenloher

90 karma · joined November 3, 2015

submissionscomments
haffenloher··on Signal Introduces Stories
> Repeatedly refusing to fix this widely reported issue with non-sensical explanations

What are you referring to? An option to choose your backup location got added two years ago. It works on Android 10 and above.

https://github.com/signalapp/Signal-Android/commit/ee3d7a9a3...

haffenloher··on You can change your number
It does not proxy through your phone. After the initial setup, you can switch off your phone and the desktop client will work just fine.
haffenloher··on Notes on privacy and data collection of Matrix.org (2019)
> nobody is able to fund huge servers with millions of users without infinite money. For example, Signal and Telegram are both struggling with that currently

I'm willing to believe that this is true for Telegram, since they do pretty much everything on the server. With Signal, though, message databases and most business logic are client-side, so the servers are surprisingly dumb and lean. Signal spends way more on salaries and wages than on its servers. In 2019, Signal paid more to Twilio for SMS verification than it did to AWS for hosting: https://projects.propublica.org/nonprofits/organizations/824...

haffenloher··on Large-scale Abuse of Contact Discovery in Mobile Messengers [pdf]
> if you newly join Signal, every Signal user in your address book will be notified

No. People who have your number in their address book will be notified.

haffenloher··on Jeffrey Epstein’s Harvard connections show how money can distort research
> Werner Von Braun was an actual nazi. He was also a great scientist.

Some recent research suggests he might not have been that great a scientist after all. The story goes that he was an impostor who got to his position mostly due to his influential father and whose main skill was managing others who did the actual work.

Here's a bachelor's thesis from 2018 and an interview with the author - both in German, unfortunately:

https://www.christopherlauer.de/wp-content/uploads/2019/01/C...

https://wrint.de/2019/01/15/wr903-wernher-von-braun/

haffenloher··on PSU punishes prof who duped academic journal with hoax 'dog rape' article (2019)
I work in academia in a STEM field. I've never seen or heard of a reviewer asking for access to the raw data used to produce a paper. Reviewers typically operate under the assumption that you're not trying to deliberately mislead them about how you collected and evaluated your data (and I think they have to, at least with how the system currently works).

What often happens is that, although the time they get to spend on a single paper is limited, reviewers still come up with important criticisms that end up leading to substantial changes (sometimes multiple rounds of them) or even an outright rejection.

haffenloher··on Encrypt Your Face: Signal Messenger
Weird, I don't remember ever seeing that and I don't have a last name set. Can't you just "confirm" it not to include a last name?
haffenloher··on Signal is finally bringing its secure messaging to the masses
That's been fixed a few months ago. The setting now sticks until you manually change it back or your contact replies with a Signal message.
haffenloher··on On Privacy versus Freedom
In the context of this talk, APN means "Apple Push Network", I think. The concern is that even if the service doesn't ask for a phone number directly, it does still have an APN or GCM/FCM push token. Through the push provider, that token can probably be linked to the user's phone number.

> With unlocked smartphones, it is possible to remove the SIM card, clear any APN settings and access WiFi.

If you're willing to do all that, I suppose getting some free VoIP number for registering with Signal (e.g. through Textnow) won't be too much of a hassle?

haffenloher··on On Privacy versus Freedom
Maybe I'm misunderstanding what you're trying to say, but remote attestation is in fact exactly what they're doing with their contact discovery: https://signal.org/blog/private-contact-discovery/
haffenloher··on Technology Preview: Signal Private Group System
Two small corrections: Signal-Android's backup works with a passphrase only (no QR codes involved) and does not cause safety number changes on restore.
haffenloher··on Neonicotinoids disrupt aquatic food webs and decrease fishery yields
Thanks for the link. I found the article to be pretty convincing until I decided to check out the WaPo article the author references in this paragraph:

> Pyrethroid insecticides are supposedly low in toxicity to mammals and birds, but as the Washington Post has reported, it turns out they are highly toxic to most insects, including beneficial insects like honeybees; in fact they are considered far more harmful to bees than any neonic.

In the linked WaPo article, though, the only mention of "Pyrethroid" is this:

> Since the E.U. moratorium went into effect in 2014, farmers in England have struggled with increased pest pressure, Carreck said. Many have turned to pyrethroid pesticides, which have unknown consequences on bees and other beneficial insects. Pywell emphasized that if the E.U. continues the moratorium, we need to investigate what alternative pesticides are doing to bees.

:(

haffenloher··on Cryptography Dispatches: Hello World, and OpenPGP Is Broken
For an explanation on how Signal achieves forward and future secrecy, see https://signal.org/blog/advanced-ratcheting/ (or https://signal.org/docs/specifications/doubleratchet/ for something more detailed).
haffenloher··on Cryptography Dispatches: Hello World, and OpenPGP Is Broken
Sure. Messaging via Signal (or via any other modern mobile messaging app) is designed to be asynchronous and doesn't require all participants of a chat to be online at the same time.
haffenloher··on An Analysis of the ProtonMail Cryptographic Architecture [pdf]
> It seems Nadim (the author of this paper) took it really badly when we called him out for intentionally spreading fake news this weekend.

Is this seriously your official response to this paper? Is this an official company account?

haffenloher··on Technology preview: Sealed sender for Signal
> You do need to be aware of the risks around whatever phone number you use to bootstrap your way in possibly being reallocated.

They recently added an optional "Registration Lock" feature to address this: https://support.signal.org/hc/en-us/articles/360007059792-Re...

haffenloher··on Video calls for Signal now in public beta
> they're wasting resources implementing video chat which noone really asked for

Could you expand on this? What data are you basing this on?

haffenloher··on Encrypted messengers: Riot, not Signal, is the future
https://whispersystems.org/bigbrother/eastern-virginia-grand...
haffenloher··on Encrypted messengers: Riot, not Signal, is the future
> Certainly a NSL might compel OWS to add additional logging

NSLs cannot be used for that. They're a legal tool that can be used to extract certain types of information (such as subscriber information and maybe a little bit of transactional information) that a service provider already has stored on their servers [0]. However, they cannot be used to force a service provider to write and deploy code.

[0] NSLs are not magic - https://www.youtube.com/watch?v=YN_qVqgRlx4&t=20m16s

haffenloher··on Encrypted messengers: Riot, not Signal, is the future
> What if I never want to share my location, take pictures, or send files?

Don't use these features and / or disable the corresponding permissions.

haffenloher··on Encrypted messengers: Riot, not Signal, is the future
> For that matter, there's no stopping Google from doing the same.

That's the exact reason why package signing is decentralized in the Android ecosystem. All apps in the Play Store are signed by their developers.

haffenloher··on Encrypted messengers: Riot, not Signal, is the future
This is a common misconception: NSLs are a legal tool that can be used to extract certain types of information (such as subscriber information and maybe a little bit of transactional information) that a service provider already has stored on their servers [0]. However, they cannot be used to force a service provider to write and deploy code.

[0] NSLs are not magic - https://www.youtube.com/watch?v=YN_qVqgRlx4&t=20m16s

haffenloher··on Egypt has blocked encrypted messaging app Signal
> Switching from Signal to WhatsAPP is very expansive because you need to rebuilt your social [graph]

It's not and you don't, because your entire social graph is on your phone, in your address book. That's precisely the point. As the identifiers and contact lists are owned by the users and not by the messaging service providers, switching between messaging services (taking your social graph with you) is about as easy as it gets. See https://whispersystems.org/blog/contact-discovery/

haffenloher··on Egypt has blocked encrypted messaging app Signal
NSLs are not magic [0]. They are a legal tool that can be used to extract certain types of information (such as subscriber information and maybe a little bit of transactional information) that a service provider already has stored on their servers. However, they cannot be used to force a service provider to start collecting data or build a backdoor.

[0] https://www.youtube.com/watch?v=YN_qVqgRlx4&t=20m16s

haffenloher··on A Formal Security Analysis of the Signal Messaging Protocol
Let the SMS verification expire and do a phone call verification.

Concerning multiple devices: I use Signal on my phone and on two desktops, works perfectly fine.

haffenloher··on A Formal Security Analysis of the Signal Messaging Protocol
Yeah, they prefer if you don't distribute your builds (i.e. something named Signal and / or using their servers) to other people (because they don't actually know what's inside the builds, they've got no update channel, etc.)
haffenloher··on A Formal Security Analysis of the Signal Messaging Protocol
> You can compile Signal yourself, and install it on a rooted phone [...] OWS doesn't then allow you to use their servers for routing/discovery etc

? That's a misunderstanding. You can of course use the official servers with your self-compiled version. (side note: I also don't think your phone needs to be rooted for this)

haffenloher··on A Formal Security Analysis of the Signal Messaging Protocol
You can still register with some landline or VoIP number if you want.
haffenloher··on A Formal Security Analysis of the Signal Messaging Protocol
Unfortunately, hashing provides no meaningful protection here. The preimage space (i.e. the set of all possible phone numbers) is just too small. See https://whispersystems.org/blog/contact-discovery/
haffenloher··on A Formal Security Analysis of the Signal Messaging Protocol
> You cant even use a online voip phone number for this app.

That's incorrect. Signal works perfectly fine with any mobile, landline or VoIP number.

Page 1 of 2Next →