• 0 Posts
  • 13 Comments
Joined 2 months ago
cake
Cake day: January 13th, 2025

help-circle


  • Yeah, I just meant people are used to decades of using meaningful usernames. Having to use a cryptographic key has traditionally made it very difficult to get enough people to adopt to make it worth adopting yourself as a technologically savvy person. I never would have used Facebook in a million years if it wasn’t for the fact that it was the only place I could get in touch with many people. Having to build your networks in-person is tedious for many people and sharing the codes securely through other means is cumbersome if you don’t have an existing method for sharing.

    Just like HTTPS needs several layers to make it work and still relies on an untrustworthy and corruptible thing like DNS to verify the destination and it’s keys are the thing you’re expecting to connect to. There’s no secure way to share the route to your device electronically in a user-accountless system with no secure, trusted middleman translating names to addresses unless you do it in-person.





  • I mean it’s kind of like the “humans evolved from monkeys” or whatever primate you want to substitute for monkey. No, they branched off from a common ancestor though.

    I mean lots of people get mixed up between BSD, Linux, UNIX, and all the variations over the years. Is MacOS a version of Linux? No. Is a human a type of ape? No. Are MacOS and Linux way, way closer than either are to Windows, hell yes. Just like people are way closer to being monkeys than swallows. There’s a lot of mixed breeding in both examples and a lot of total incompatibilities as well.


  • But it’s a difficult concept for the average person to not have an account, but everything is device oriented. Same problem with people not using gpg for email. Having to maintain a thing similar to a private key that’s not memorizable like a username and password and back that up in case your device is lost. Is a big hurdle for many. And then additionally having to share a qr code or link through some external means for someone to connect with you rather than just telling them to download an app and enter your username HSS always been difficult.

    So, IMHO, Signal has the best implementation possible with the level of usability that many nontechnical people expect in a chat application, even if it’s not the most secure. I am interested to see how SimpleX solves these issues in the future, though.






  • “There’s nothing to suggest that these people will be approached with any claims directly.”

    No, but they’ll be pressured to testify with the threat of such a lawsuit. And if the RIAA wins, then ISPs will likely start giving the names to them openly so they can start those lawsuits back up again, at least in the US where it’s again no longer considered an essential utility service by the government thanks to Republicans. There’s a reason they’re not targeting the bigger ISPs that have enough money to fight back anymore. This way they can get a judgment to use against them later.


  • Yeah I think hashes in the same folder are only valuable as a check to make sure you downloaded the file successfully. Which isn’t a big issue for at least the around 80% of internet users who have access to broadband. They are only useful for security if the hash is on the website that you click on and then you download and verify it manually.


  • Yeah, IMHO Signal is the right balance of usability and privacy. Problem with not having a user ID is that you can’t easily use the application on multiple devices at the same time and if you lose the device, or don’t properly migrate to a new device, you will have to start over building your connections to others.

    But the real issue with no user ID or centralized platform is discoverability. Same reason things like gpg for email never caught on. You can’t just type in a person’s phone number, username, or whatever and start talking to them. It only works if you have another line of communication with each person to set up the connection. This is usually the deal-beaker.

    But the problem with user IDs is that anyone can create as many as they want and use them to avoid spam and abuse filtering. So that’s why phone number is used by Signal as a unique identifier. It’s not 100% unique, but it’s good enough to deal with all but the most determined abusers.