Hacker Newsnew | past | comments | ask | show | jobs | submit | mmooss's commentslogin

> LLMs do not desire, they hacked websites because OpenAI/Anthropic let them.

"let them" could imply that the LLMs wanted to do it.

The intent is on the part of the people. The LLMs did it because OpenAI/Anthropic intended them to do it and designed them to do it, and we can assume specifically instructed them to do it.

As the people controlling the machine, and as the world's leading experts, I think we can assume intent until proven otherwise.

Notice other bad behavior, which would be undesireable to the vendors, doesn't happen: How about simple rudeness? Trolling lies? SHOUTING!


> Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?

While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data.

I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connections.


What about their built-in cryptocurrency? It's a perfect use for it. They could require payment post-install yet before message can be sent.

True, if they're not even going to allow that for payment then they might as well remove it from the app altogether. Because what's the point if they don't even believe in it themselves.

Nobody uses that and I think it was pre-mined. They should have implemented Monero but the UX isn't there. Maybe a Monero light wallet server run by Signal.

They probably avoided Monero to not attract the additional scrutiny. They don't even accept donations in Monero.


They avoid Monero because Signal and the EFF are actually the feds and this is all theater.

I always thought they didn't want monero because they were pushing their own crypto thingy. Which indeed nobody uses.

I've literally never seen anybody mention it, much less use it since it was announced.

I learned, and thought everyone else learned, that the safe characters for POSIX filenames are:

  ABCDEFGHIJKLMNOPQRSTUVWXYZabcdefghijklmnopqrstuvwxyz0123456789_-
That is, the only safe non-alphanumeric characters are dash "-" and underscore "_". Period "." is also considered 'safe' but is tricky for obvious reasons and [IMHO, for the most reliability] best avoided except where necessary.

Authoritative source: POSIX.1-2024 standard, sec. 3.265 Portable Filename Character Set

https://pubs.opengroup.org/onlinepubs/9799919799/basedefs/V1...


Sometimes, if your file starts with a dash things can be tricky. Don't make any mistakes removing a file named '-fr'

> alternative of unmonitored transit seems worse

Almost all private cars are unmonitored (in this respect).


> A new study reveals that horse personality is not only a matter of genetics, age, or breed but also systematically linked to how horses are housed, ridden, and cared for, and to the quality of the relationship they share with their owners.

I expect that genetics, age, and/or breed affect human expectations of the horse (e.g., 'this breed is aggressive'), which affects how they treat the horse, which affects personality.

Same with dogs. Pit bulls encounter lots of fear and human aggression, and are used for aggressive purposes by humans who expect that.

Same with humans, sadly.


Signal's mission is to provide maximized privacy in a form the non-technical public can use.

A messaging service filled with bots and spammers is not usable, and possibly not affordable to Signal (what proportion of resources would be spent on spam/bots). What is a more private, usable solution for filtering them out than using a phone number?

Lots of security geeks want Signal to adopt practices unusable to the public. They've made clear that unsusable security is not in their mission.


> in a form the non-technical public can use.

That happens when public uses it, en masse, in the first place. And as it is today the "public" has no reason/incentive in switching to it and that naturally keeps the "non-technical public" away from it.

So who is this serving eventually? A very few, mostly "technical public", in complete contrast to what you have said.

I suspect Signal's goal is something entirely else. For them it's just two things:

1. Some sort of shallow ideology (started with the founder and the flame kept alive by the later leaders who often come across ideological groupies; the last bit is a bit strong but whatever)

2. Executing based on that for the sake of executing that because they can

What their intention is not: Signal ever becoming IM app of choice anywhere and possibly they might have their reasons for this. One of those reasons could be affordability as you have said it.

Note: in case this wasn't clear, the moment you attach a "phone number" you make it inherently unsafe for most, like 99.353959353%, of "general non-technical public" to use Signal and remain really unidentifiable. Once they are identified - in most countries (and now even in places like USA it seems) only thing needed after that is being "picked up" and rest will be just sung even without a device. I mean it's so absurd to even not think about it is that it's ridiculous. So no, it is DEFINITELY not "non-technical public can use".


> And as it is today the "public" has no reason/incentive in switching to it and that naturally keeps the "non-technical public" away from it.

I know plenty of non-technical users on Signal. Based on news reports, it's used widely by activists. I see journalists advertising their Signal contact information for tips. It's recommended government-wide in the US by CISA and is pre-installed on US intelligence community computers, including in the CIA.


True they can make their choices but it also means I won't support them in any way. Or recommend them.

I'd use something that's truly decentralised but signal is just another walled garden like WhatsApp. Just one that promises to behave better. But what's a promise worth these days?

A decentralised network would mean a guarantee that they can't do anything bad. I'll take that over promises and good intentions any day.

I don't care about the masses. If signing up for a matrix account is too annoying for them they don't really care about privacy anyway. After all it's the same they have to do for any online shop. Just create a username and password. Somehow it's not a problem for the masses if they wanna order a phone charger but for matrix it's suddenly 'too complicated'?


People like you who equate signal and WhatsApp are also responsible for not making any progress due to ideological stubbornness it’s something that I absolutely despise from a part of HN crowd here.

Great, I'm happy to be a nail in the coffin of the signal advocacy.

Remember how everyone jumped on Google when they promised to do no evil? Now they're one of the most abundant mass surveillance companies in the world and we can't move away because they're too big to fail. The same with WhatsApp. People jumped on it because it was good, then nobody left when meta bought it because all their friends were on it.

Signal is one sale away from being evil too. They might not sell it but we've been conned so many times by big tech that I will only take technical guarantees, not promises that can be broken. We have to avoid getting locked in again.

And really, lots of progress is made in real open communications. Matrix is getting more mature by the day. NATO uses it, the French government and several others. And the good thing is, you can always run your own server and connect to the hive. Nobody can tell you what to do, nobody can tell you to surveil your users like the EU is planning to do.

We need something truly open. Not a WhatsApp light.


Signal is a small organization and nothing like Google. Signal is a non-profit and their code is open source.

Their code is open source but you can't really do anything with that. You can't run your own server on the network, and they've previously stated they don't want third party implementations of clients.

Again, I don't trust promises anymore. Eventually they're going to need more money and that money will come with strings attached. If some org like Matrix would get bought people would just decouple themselves from their network. With Signal we can't do that because they are the only operator.


> Their code is open source but you can't really do anything with that. You can't run your own server on the network, and they've previously stated they don't want third party implementations of clients.

There are third-party forks and clients. Parts of the US government use one.

https://news.ycombinator.com/item?id=49678919

Also, you can audit the code.


> signal is just another walled garden like WhatsApp

For me the difference is in the ownership. Who owns each. Which is BigCorp? That’s why I trust one more than the other.


Ownership can change. That's the problem. It happened to WhatsApp itself! Meta bought a network with the userbase that was already too big to leave.

> What is a more private, usable solution for filtering them out than using a phone number?

Since when is giving out your phone number a "more private" option ?


You don't have to give out your phone number. You can mint an arbitrary "username" and give the username out to people.

> You don't have to give out your phone number. You can mint an arbitrary "username" and give the username out to people.

You are deliberately missing the point.

Signal are gatekeeping these new advanced security features behind a phone number wall (soon to become paywall if some posts here are to be believed).


If it's not, let us know a solution (to Signal's actual problem as stated in the GP) that is more private.

One possible solution is to only be able to contact someone if you have received an invitation code from them out of band. E.g. "scan this QR code to add me on signal". Such an invitation code should default to single-use but users should be allowed to generate standing invitations so that businesses and the like can print and post one in their store or whatever. Start getting spam from one of your standing invitations? Just revoke it and make a new one. Presumably the Signal folks can come up with more alternative solutions than the half baked one I came up with after thinking about it for a minute, they're clever cookies.

Welcome back to “key signing parties”. PGP never got enough adoption. At least Signal is simple enough that the (ahem) leaders of the US can (mostly) manage to use it.

Unfortunately, in an end to end encrypted messaging system, an identity is denoted by some sort of long number. That is an inescapable fact. Trusting a third party to correctly map, say, a phone number to a cryptographic identity number eventually results in the sort of attacks we have been seeing with phone oriented encrypted messengers recently like WhatsApp and Signal. The PGP people were doing the right thing when they were doing education in the form of key signing parties. That is something the user needs to know.

Anonymous messengers have no real choice and have to use some sort of number for identity. See Briar, Session or Tox for examples.

My comments on Signalgate 1.0:

https://articles.59.ca/doku.php?id=em:sg


> attacks we have been seeing with phone oriented encrypted messengers recently like WhatsApp and Signal

Could you give an example of an actual attack of this kind on Signal? The 'Signalgate' event was someone mistakenly inviting the wrong person to a chat.


Allegedly, Signalgate was caused by Apple helpfully mapping the wrong number to a name. Then Signal mapped that number to the wrong cryptographic identity.

A Third Party Breached The Intercept’s Signal Tip Line and Has Been Soliciting Whistleblowers https://www.dropsitenews.com/p/intercept-signal-tip-line-bre...

Twilio Incident: What Signal Users Need to Know https://support.signal.org/hc/en-us/articles/4850133017242-T...

Russian State-Backed Hackers Intensify Attacks on Signal Messenger Accounts https://thecyberexpress.com/signal-attacks-russian-fackers-t...


Leaders of the US use an Israeli backdoored version of Signal (TM-Signal) TeleMessage by Smarsh was used by DOD, CPB, and others for records retention reasons... also hacked to smithereens.

Requiring manual key verification is a bad design that doesn't scale or benefit most people.

People seem to get on with Discord invite links just fine. You don't have to do the "confirm that all these emoji are the same on both your devices" dance to stop spam.

> People seem to get on with Discord invite links just fine.

Discord is used by a narrow group of technically literate people. Signal is for everyone. Your grandparents probably don't use Discord, but if they can text then they can use Signal.


Imagine setting up a chat for an organization you're working with - will you be willing to process 20 out-of-band QR codes? 50?

On a smaller scale, it's clear that Signal believes a functioning address book is necessary for end user adoption. For example, by default Signal notifies you of people in your phone contacts who are on or who later join Signal.

> Presumably the Signal folks can come up with more alternative solutions

I have yet to see a solution better than the one they chose, for their requirements. Notice that there are none in this discussion.


MTV's The Real World began in 1992. Did it inolve a writers' strike?

Edit: Looking at Wikipedia's account, there are many reality TV shows going back decades before that. Some are game shows and other things - t's hard to tell what matches the modern model.


The OP addresses that:

"When people wave off Waymo or bus lanes or bike lanes because car culture is fine, they mean it works fine for them."


Most people hate all drivers except themselves.

> de-identified

The issue always is, was the de-identification effective?

With a birtdate, gender, and zip code, ~85% of Americans can be uniquely identified.[0] Much data contains much more unique information than that; I imagine most data about you has identifiable fingerprints - where you go, what you bought at the grocery store, your medical conditions, movies you watch, music you listen to, entertainment choices, hobbies, etc.

An LLM is the perfect tool to identify someone based on that data.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: