Hacker News new | ask | show | jobs
by HNisCIS 33 days ago
That's all nice but it's also the defacto option for non technical people who need state actor resistant security and if they can just be subpoenaed to get the verified ID of the account holder that defeats the entire use case
1 comments

Signal is not an anonymity tool–it is a privacy tool. It is not anonymous in any way. If you need anonymity you should use SimpleX over Tor.
Simplex is run by borderline grifters and Tor isn't a messenger.

I don't understand why this is so controversial. If you follow the news on the slightest the game right now is feds raiding journalists, taking their devices and then trying to unmask their sources. It doesn't matter what XYZ is "for", when the stakes are this high we need to be protecting people full stop.

You are using an Ad hominem ("Simplex is run by borderline grifters"), Straw man ("Tor isn't a messenger"), appeal to consequences ("It doesn't matter what XYZ is "for", when the stakes are this high we need to be protecting people full stop."), and an implicit no true Scotsman ("defeats the entire use case").

>Simplex is run by borderline grifters

The developers' character is irrelevant—the code is open source (agpl) and trustless. The whole point of e2ee is that it doesn't matter what the server is running.

>Tor isn't a messenger

I never claimed it is—Tor is an anonymity network that helps make SimpleX the most anonymous messenger. You run Orbot on your phone routing your SimpleX traffic through it. SimpleX has no identifiers, and Tor protects the network level so you have no traffic that can be correlated.

>I don't understand why this is so controversial. If you follow the news on the slightest the game right now is feds raiding journalists, taking their devices and then trying to unmask their sources. It doesn't matter what XYZ is "for", when the stakes are this high we need to be protecting people full stop.

You aren't addressing my point. You can't make a great service with a threat model that encompasses every threat. Signal is a great option for everyday messaging—its architecture was never designed to be anonymous, it is centralized and mainstream. High stakes don't change what a tool was built to do; recommending it to journalists as though it provides anonymity is the wrong thing to do. Signal sacrifices anonymity in order to gain popularity.

I will say Signal is fine for 99% of journalists and their sources. The only metadata that Signal provides to law enforcement is account creation date[1].

[1] https://signal.org/bigbrother/district-of-columbia/