Hacker News new | ask | show | jobs
by ProAm 3397 days ago
> because it implies that Signal was broken

It does mean Signal is pointless to use however. Why encrypt if your communications are picked up prior to encryption? Akin to putting your seat belt on after the car has crashed.

3 comments

No, no, no!

Defense in depth! Do you stop using TLS on your banking website every time a Windows 0day comes out?

Because your opponent might not be the CIA and because your phone might not be compromised.

So in that case switching to something less secure will instantly make your problems worse.

Of course, Im only speaking in the context that you are worried about the CIA or other governments.
Even if you are worried about them it still does not mean that you have been compromised. And if you do worry about them: don't use your phone (or any computer, for that matter) for sensitive stuff.
Of course, my original point was don't count on Signal to protect you. That was my whole point.
"Akin to putting your seatbelt knowing full well a thermonuclear attack is always possible."

Yes, catastrophic compromise is possible, but that does not render all security measures moot. A precious few attackers have the capability for such attacks, they are very costly to develop and therefore very precious and well kept secrets, to be used on high profile targets.

Unless you are a spy, a terrorist, a state official with significant power or a dissident against the likes of Russia or China, end-to-end encryption like Signal will keep your communication private.

> Unless you are a spy, a terrorist, a state official with significant power or a dissident against the likes of Russia or China, end-to-end encryption like Signal will keep your communication private.

Maybe, if one person can do it so can others. It would be foolish to assume you are safe just because the US government doesn't deem you a person of interest. It might be far fetched, but now that the world knows it's possible to bypass encryption you cannot ignore the fact that Signal may not work at all.