Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Gee, thanks for contributing to the conversation and providing a useful alternative.

The only semi-popular better option I can think of is Matrix, but getting people on Signal is already hard enough and using Matrix on a mobile device is (last I checked) far from ideal.

Security is a gradient, not an all-or-nothing. Signal is vastly better than almost every other electronic communication method.



Once its compromised there is no gradient anymore and you never know when things are compromised because three letter agencies will anyway not tell you.


Given the risk of xyz agency, there seem to be only a couple options to me:

- side-load a peer reviewed apk so you can check the sigs and make sure all crypto is being done locally (and to make sure that the implementation is solid)

- manage your own keys like you would with traditional pgp emails. Give your public to your friend. Force them to send anything sensitive using it. Maybe change to symmetric keys from asym but rotate occasionally. But you still have to trust the app you use to do this unless you want to do it manually each time.

*These don't necessarily solve the Metadata issue


> side-load a peer reviewed apk

Signal has open sourced clients with reproducible builds (on Android) and their encryption library has been reviewed by multiple 3rd parties to great acclaim.

PGP lacks forward secrecy, meaning if a key does get compromised all of your past correspondence is now also compromised.


This solution works then, right? So given this implementation (and not a play store or ios download), one should be safe from xzy snooping?

Edit: As someone that has heard of forward secrecy but not how it relates to pgp, these were helpful reads:

https://signal.org/blog/advanced-ratcheting/

https://signal.org/blog/asynchronous-security/


So what do you use instead?


It's not about what to use, it's about having expectations of zero privacy when communicating online. Expect everything to be potentially public.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: