> if you're a stock holder, certain places (like interactive brokers) Any specific examples?
> From a developer perspective however, encouraging or even tolerating unofficial installation channels for secure communication software is bad. What is your threat model?
> I really don't see why someone should be on my shitlist for lying to godaddy dot com or whatever giant registrar unless you consider fudging identifying details about something that really doesn't matter, I think I…
> Is OTR really a practical option? You message seems unclear about it. It depends on your threat model, like other alternatives. I have never initiated an OTR session myself, but I have received one from a contact in…
> It's free. You misunderstand. He is running a company, what do you think their exit strategy is? You may want to look at his previous company and "red phone", I think was his product called. > And normally one would…
Now gents, a number of you in the comments have wondered about what other alternatives are out there. You may have seen that I specifically advise against Signal, and other users have also expressed concerns about a…
>> Can I run a client from the Git repo and still use all of their infrastructure? > Yes. You can. The thing is, lucideer, the "restrictions" on the use of the source code are engineered to raise the barrier to…
> I am really interested why Signal. Why not Telegram? And I would be really interested to know why people are downvoting a perfectly reasonable question.
> The suggestion that the motivation for this article is profit for the NYT or Moxie is quite destructive. No, that's literally how it works. Media need to sell copy (clicks these days) and companies need to get…
Are you aware that the guy behind this signal app sold his previous "secure messaging" thing to Twitter?
> what's a reasonable heuristic for conducting private business? You need to do a threat analysis. I did not immediately find any good introductory resources via a quick Google search, but try it yourself. Very very…
> Re: Google Play Services. Here's is the way I understand this to work, so please do correct me if I'm wrong. > Signal uses Google Play Services to notify me that I have an incoming message from Signal. More…
> I'd even argue it's free software Terminology. What you call free software I call open source. As you go on to mention, you can see the source but not use it in any meaningful way. In particular: > but have clarified…
Just wondering, but why not just use XMPP? You can choose any server that you like or trust, or run your own (on your own or third party infrastructure, up to you), and use OTR for end-to-end encryption if you feel you…
> Neither Telegram nor WhatsApp are viable alternatives to anyone interested in privacy. Are you suggesting that the application under discussion here is a viable alternative? If so, how?
> It's 2016 and our best crypto messenger options are worse than what we had 10 years ago when Skype was peer to peer, or Jabber with federation. Actually, Jabber with OTR is pretty solid. If need be, you can use…
For me, the takeaway from that article is this: > Different people will have different testing strategies based on this philosophy, but that seems reasonable to me given the immature state of understanding of how tests…
> So distribute keys on smart cards that don't allow you to export the key That's what I covered in the second paragraph. :-) The thing is, both those implementations were a disaster from either a technological or a…
> all the experts here Which experts? And what are those fundamental flaws?
> IMO we should aim for a Crypto like Signal presents it; You mean by leaking the plaintext in the device logs? By having to trust a single party which is known for being economical with the truth (e.g., when he was…
> Just get the national government to distribute RSA USB keys to every citizen. I lived in a country that did exactly that. And it was a disaster. The keys were trivially easy to steal, even by accident (personal…
Exactly. I've had this happen with Dell. Twice, same computer. They ask for the defective drives back, which is fair. I informed them that as they contained company confidential information they would be put beyond use…
That's funny. I had a problem with my ADSL connection that lasted for over a month. I spent two hours and forty minutes on the phone, spread over, IIRC, 15-20 calls, with the cycle going 1. "What's the problem", 2.…
> I haven't seen the third step in the "Cue -> Habit -> Reward" cycle mentioned yet. Good point! I allow myself an Irn-Bru only on run days (and less than 10 miles doesn't count). I don't live in Scotland and Irn-Bru is…
Ironically, long distance running (10+ miles) is easier to do before breakfast, as an empty stomach is useful--digestion stops anyway as soon as your body is in need of some extra red cells to carry more oxygen. A…
> if you're a stock holder, certain places (like interactive brokers) Any specific examples?
> From a developer perspective however, encouraging or even tolerating unofficial installation channels for secure communication software is bad. What is your threat model?
> I really don't see why someone should be on my shitlist for lying to godaddy dot com or whatever giant registrar unless you consider fudging identifying details about something that really doesn't matter, I think I…
> Is OTR really a practical option? You message seems unclear about it. It depends on your threat model, like other alternatives. I have never initiated an OTR session myself, but I have received one from a contact in…
> It's free. You misunderstand. He is running a company, what do you think their exit strategy is? You may want to look at his previous company and "red phone", I think was his product called. > And normally one would…
Now gents, a number of you in the comments have wondered about what other alternatives are out there. You may have seen that I specifically advise against Signal, and other users have also expressed concerns about a…
>> Can I run a client from the Git repo and still use all of their infrastructure? > Yes. You can. The thing is, lucideer, the "restrictions" on the use of the source code are engineered to raise the barrier to…
> I am really interested why Signal. Why not Telegram? And I would be really interested to know why people are downvoting a perfectly reasonable question.
> The suggestion that the motivation for this article is profit for the NYT or Moxie is quite destructive. No, that's literally how it works. Media need to sell copy (clicks these days) and companies need to get…
Are you aware that the guy behind this signal app sold his previous "secure messaging" thing to Twitter?
> what's a reasonable heuristic for conducting private business? You need to do a threat analysis. I did not immediately find any good introductory resources via a quick Google search, but try it yourself. Very very…
> Re: Google Play Services. Here's is the way I understand this to work, so please do correct me if I'm wrong. > Signal uses Google Play Services to notify me that I have an incoming message from Signal. More…
> I'd even argue it's free software Terminology. What you call free software I call open source. As you go on to mention, you can see the source but not use it in any meaningful way. In particular: > but have clarified…
Just wondering, but why not just use XMPP? You can choose any server that you like or trust, or run your own (on your own or third party infrastructure, up to you), and use OTR for end-to-end encryption if you feel you…
> Neither Telegram nor WhatsApp are viable alternatives to anyone interested in privacy. Are you suggesting that the application under discussion here is a viable alternative? If so, how?
> It's 2016 and our best crypto messenger options are worse than what we had 10 years ago when Skype was peer to peer, or Jabber with federation. Actually, Jabber with OTR is pretty solid. If need be, you can use…
For me, the takeaway from that article is this: > Different people will have different testing strategies based on this philosophy, but that seems reasonable to me given the immature state of understanding of how tests…
> So distribute keys on smart cards that don't allow you to export the key That's what I covered in the second paragraph. :-) The thing is, both those implementations were a disaster from either a technological or a…
> all the experts here Which experts? And what are those fundamental flaws?
> IMO we should aim for a Crypto like Signal presents it; You mean by leaking the plaintext in the device logs? By having to trust a single party which is known for being economical with the truth (e.g., when he was…
> Just get the national government to distribute RSA USB keys to every citizen. I lived in a country that did exactly that. And it was a disaster. The keys were trivially easy to steal, even by accident (personal…
Exactly. I've had this happen with Dell. Twice, same computer. They ask for the defective drives back, which is fair. I informed them that as they contained company confidential information they would be put beyond use…
That's funny. I had a problem with my ADSL connection that lasted for over a month. I spent two hours and forty minutes on the phone, spread over, IIRC, 15-20 calls, with the cycle going 1. "What's the problem", 2.…
> I haven't seen the third step in the "Cue -> Habit -> Reward" cycle mentioned yet. Good point! I allow myself an Irn-Bru only on run days (and less than 10 miles doesn't count). I don't live in Scotland and Irn-Bru is…
Ironically, long distance running (10+ miles) is easier to do before breakfast, as an empty stomach is useful--digestion stops anyway as soon as your body is in need of some extra red cells to carry more oxygen. A…