this post was submitted on 20 Dec 2024
267 points (97.2% liked)

Technology

60058 readers
2443 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 2 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] rottingleaf@lemmy.world 1 points 17 hours ago
  1. Not just that, but also it's small in description. If you read their papers, they are very easy to understand. I suppose that's intentional, clarity and simplicity are among the main criteria of anything intended for security.

  2. "A lot of eyes" is overvalued. There are a lot of eyes on every nation-state in history too, you tell me how that works.

  3. It doesn't matter because of protocol design. They've solved very complex problems and have not stopped doing that. E2EE is the wrong buzzword, zero-knowledge is the right one. No, I'm not remotely qualified enough to explain what that is.

  4. Still supply chain attack on clients is the most probable, but not much they can do with it. It's similar to fearing trojans on user devices. Yes, 3-letter agencies and such most likely will do that, not bother with pressuring Signal developers. And no, there's not much you can do to defend against a targeted attack, if it's targeted, then you've already bothered people you shouldn't have.

  5. Well, it's not as if one could avoid that. It all lies in the area of smart contracts and distributed computing then, and see point 1, right now Signal's protocol can be in general strokes understood by someone like me. If they make something like that, it won't be. Everything is a compromise.

There’s functionally less “trust” here than any messaging application on the planet.

I think Wire and maybe Session use slightly modified Signal protocol. But Signal itself is the thing, made by people with clear vision of the whole architecture, model, which is not limited to protocols, but also to sociology, human psychology, politics. And they've explained literally every architectural decision of theirs in articles.