(no title)
uph | 8 years ago
Removing encrypted sms messages wasn't inexplicably dropped. It was explained and one of the reasons was terrible security https://whispersystems.org/blog/goodbye-encrypted-sms/
You don't need anything Google on your phone to use Signal. https://signal.org/android/apk/
dTal|8 years ago
I don't buy any of the arguments on that SMS page. In particular, all the hand-wringing about metadata rings hollow when OWS has simply arranged it so that they have access to it all, instead of a federated network of telcos, making themselves a single point of failure. The only argument that rings true is "iOS does not have APIs that allow us to programatically send/receive SMS messages", but I don't feel I should have to suffer for Apple's failings.
I applaud the offering of APK downloads, which Moxie has historically resisted calling them "insecure" (I can see his perspective but when the alternative is giving Google root, I'm afraid we're going to have a difference of opinion on what constitutes "security"). Unfortunately, when using Signal without Play Services, as I understand it battery life is much worse due to the implementation. I appreciate that "push notifications" without a central service is a difficult technical problem to solve efficiently - this is a large part of why I regard the dropping of SMS support, which solved it, as a screwup.
Lastly - if I seem like I'm giving OWS a hard time unfairly, it's because of their repeated insistence on centralised services (both Google's and their own) and resistance to any sort of federation or anything that costs them control or information. I'm glad that the situation is (slowly) improving, but these are indicative not just of technical difficulties, but a deep ideological difference. I am not afraid to say that I am mistrustful of this One True Encryption solution when its authors seem so willing to compromise on fundamental issues.
I am also mistrustful because whenever a "controversial" decision is made, the real reason is always accompanied by copious FUD. The SMS thing is one example. The F-Droid affair is another (Stated reason: F-Droid is insecure. Real reason: F-Droid strips analytics).
nindalf|8 years ago
Markoff|8 years ago