Hacker News new | ask | show | jobs
by sroecker 3559 days ago
Please do not use Telegram. It' closed source and uses some half-baked crypto. Signal is open source and is actually end-to-end encrypted.
7 comments

Wire[1] is also an excellent option. Unlike Open Whisper Systems they wont hang you from a tree for building a third party app. Signal wont work without Gapps or Google Play Services on your Android phone and Google Chrome for desktop.

[1] https://wire.com/

Signal does work with MicroG (https://microg.org/), an open source reimplementation of Google Play Services.
But that still requires using the Google Play Services library in the Signal APK, still doing analytics.
I tried Wire after this WhatsApp news came out initially and brought about 10 people (friends/family) to it. They're satisfied how it works.
Signal is pseudo-open-source but will not allow you to use it except via the closed-source google play services, so I still wouldn't have confidence in it.
Yes. Also, on what payroll is Moxie now? He was working with Facebook on WhatsApp and then worked with Google on their new messaging app.
This is incorrect. There is an open source reimplementation of Google Play Services (https://microg.org/) and Signal works beautifully with it.
And wherefrom can you get Signal except for the Google Play store? I was looking for it a while ago to install on my phone but only found two other projects which were threatened by moxie and then shut down.
I compile my own binaries. Not too bad actually.
So the Signal APK does NOT depend on the Google Cloud Messaging library anymore, which pulls in 40k LOC of analytics?
Telegrams clients (and the e2e encryption) are open source. For instance: https://github.com/DrKLO/Telegram

Curious if you know why the crypto is half-baked. Has it been broken?

edit: found Signal server, I think: https://github.com/WhisperSystems/TextSecure-Server

Nice it's out there. This will help Signal live a long time.

Exactly. Not to mention if it becomes popular it will get sold to megacorp in a heartbeat.
I'll give signal another try, last time I couldn't register.
A lot of people here use twitter.

Why must things be provably sure to have any value?

No windows phone client :-(