this post was submitted on 20 Sep 2024
342 points (98.0% liked)
Technology
61051 readers
3686 users here now
This is a most excellent place for technology news and articles.
Our Rules
- Follow the lemmy.world rules.
- Only tech related content.
- Be excellent to each other!
- Mod approved content bots can post up to 10 articles per day.
- Threads asking for personal tech support may be deleted.
- Politics threads may be removed.
- No memes allowed as posts, OK to post as comments.
- Only approved bots from the list below, to ask if your bot can be added please contact us.
- Check for duplicates before posting, duplicates may be removed
- Accounts 7 days and younger will have their posts automatically removed.
Approved Bots
founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
How is Signal compromised?
It's not, unless they're some sort of cryptography expert with a peer-reviewed white paper pending publication. The Signal protocol (GPLv3) is extremely robust and has almost no capacity for metadata generation, and both the app and server-side code are under the AGPLv3 (technically if they were compromised they could use different, unaudited server-side code, but refer back to "basically no metadata"). Signal has essentially no capacity to be compromised; they can't even bait and switch users with a pre-compiled app whose source code isn't the publicly available one and actually has a backdoor because their builds are reproducible and it would be caught immediately.
Maybe they take issue with the crypto bullshit, which is valid but doesn't compromise messaging security. Maybe they don't like that they took away SMS, which I completely agree with, but also actually makes it marginally more secure. Either way, I seriously doubt if they had any mathematical insight into Signal being "compromised" that they would be here hanging around on Lemmy right now.
Be that as it may, it's still an incredibly short sighted decision to use a centralized service that is under 3rd party control for real security sensitive applications.
Yeah, that does bother me. But it's also a lot easier to build a centralized service like that than to get people on a decentralized one.
If you really want something private and are willing to jump through a few hoops, Simplex exists. But most people aren't willing to jump through a few hoops, and even Signal (a pretty low bar) is a hard enough sell as it is. And that's why I use Signal, because it's my best chance to get people onto something better. In other words, don't let perfect be the enemy of better.
Yet pretty much everyone uses the same one: gmail.
Sure, and I use Tuta. Those are outliers, the vast majority use gmail, or at least the vast majority in my circles do.
It's the same thing as the network effect, just a little less ubiquitous, people will tend to use whatever everyone else uses. Getting something new like email (SMTP) is a huge endeavor, it's a lot easier to just build a centralized service and get people to use that, and most people will use the same provider anyway.
I don't like it, but I understand why it works and is so common.
No, those being outliers means the email argument isn't particularly strong, especially when talking about a new standard. If most people use a single service anyway, why would a company go out of its way to make something decentralized? And for something like encrypted chat, that's a lot of extra work.
What, by starting as a government system using a completely different protocol, then adapting to always-online network connections (i.e. universities) at a time when spam didn't really exist?
The 70s and 80s were a very different time, and regular consumers didn't use email until it had gone through several iterations. Even so, most people used a single implementation (sendmail on BSD) for quite some time before anyone else got involved.
The internet today is a very different beast, you can either try for an open standard, or you can try for user acquisition. Almost nobody seriously goes for the open standard anymore, unless it's an iteration of an already existing open standard.