Hacker News new | ask | show | jobs
by some_furry 24 days ago
> Soatok seems unable to acknowledge that centralisation is a real (privacy, security, reliability, political, …) concern here, nor to see value in the decentralised (federated/P2P) alternative protocols implementing the same double-ratched/PFS crypto primitives.

I genuinely do not understand where this impression is coming fron. The only thing I've ever written about this topic acknowledges that centralization has risks, but a perfectly decentralized system that doesn't properly encrypt data end-to-end is bad for user privacy.

The cryptography needs to be excellent. "But decentralization" doesn't cut it.

https://soatok.blog/2025/07/09/jurisdiction-is-nearly-irrele...

Disagreeing with me is one thing, but claiming I seem "unable to acknowledge" anytbing is dishonest.

1 comments

> I genuinely do not understand where this impression is coming fron.

I don't want to engage in a citation battle, I just can't care enough for that. Having read those posts about Matrix, XMPP (OMEMO) and a couple others, many months/years ago, they really came across as "screw those amateurs for even trying, Signal is great, and by my very definition of it, only Signal can be".

Again, those are not your words, but something about the tone and the way you compare them made it sound that way.

Also, even if that's besides the initial point, I firmly disagree with the premise of the post you just linked. For the same reason mentioned in a sibling comment stating that the real world isn't binary even though IP addresses might be: A centralised service is political no matter what. If not their admins, their hosing provider or executive power may decide to censor you based on your country of origin, political beliefs, ideological activism or any other reason out of your control. Signal's crypto protects what's in the envelope, but does little else (neither can it) against a motivated state-actor fingerprinting you beyond the service boundaries, and guess what, we know it to be a fact for the jurisdiction Signal is operating under.

Let me distill this down to its most basic structure to make sure I'm understanding you.

Supoose we're trying to decide between two services for a long term group chat.

Service A, on the server-side, sees all messages, in plaintext, sent to/from all participants--including other servers. It can log it indefinitely. It sees the whole social graph. Some servers have no k-anonymity (self-hosted, single user), some have thousands of users. They're all over the world, including in jurisdictions the NSA's TAO can operate.

Service B can only see IP addresses and ciphertext. There's only one real 'server", but it has millions of users and the encryption is widely reputed by experts. Its servers happen to be hosted on American cloud providers.

By firmly disagreeing with the linked post, you are saying you prefer Service A on the matter of privacy, only because of the jurisdiction.

Is that really the hill you choose?

I'm saying that if Service B is under a jurisdiction that has export control regulations (i.e. all of them) and somehow decides that "users from country X are non grata" ; or under a jurisdiction that oppresses on the basis of your political beliefs, skin color, sexual preference… (both of which characterise the current Trump administration, under which Signal operates) then the service operator has no choice but to lock you out of your account, making the whole cypher/crypto argument moot.