Hacker News new | ask | show | jobs
by some_furry 23 days ago
Let me distill this down to its most basic structure to make sure I'm understanding you.

Supoose we're trying to decide between two services for a long term group chat.

Service A, on the server-side, sees all messages, in plaintext, sent to/from all participants--including other servers. It can log it indefinitely. It sees the whole social graph. Some servers have no k-anonymity (self-hosted, single user), some have thousands of users. They're all over the world, including in jurisdictions the NSA's TAO can operate.

Service B can only see IP addresses and ciphertext. There's only one real 'server", but it has millions of users and the encryption is widely reputed by experts. Its servers happen to be hosted on American cloud providers.

By firmly disagreeing with the linked post, you are saying you prefer Service A on the matter of privacy, only because of the jurisdiction.

Is that really the hill you choose?

1 comments

I'm saying that if Service B is under a jurisdiction that has export control regulations (i.e. all of them) and somehow decides that "users from country X are non grata" ; or under a jurisdiction that oppresses on the basis of your political beliefs, skin color, sexual preference… (both of which characterise the current Trump administration, under which Signal operates) then the service operator has no choice but to lock you out of your account, making the whole cypher/crypto argument moot.