TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Ask HN: Is Signal still a good app to use for encrypted messaging?

20 pointsby rwolalmost 5 years ago
How secure is it?

14 comments

rmrfstaralmost 5 years ago
Its use of SGX for secure value recovery is highly problematic [1].<p>@matthew_d_green twitter feed has a regular stream of high-quality Signal commentary.<p>[1] <a href="https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2020&#x2F;06&#x2F;new-exploits-plunder-crypto-keys-and-more-from-intels-ultrasecure-sgx&#x2F;" rel="nofollow">https:&#x2F;&#x2F;arstechnica.com&#x2F;information-technology&#x2F;2020&#x2F;06&#x2F;new-e...</a><p>[2] <a href="https:&#x2F;&#x2F;twitter.com&#x2F;signalapp&#x2F;status&#x2F;1262844332278603777" rel="nofollow">https:&#x2F;&#x2F;twitter.com&#x2F;signalapp&#x2F;status&#x2F;1262844332278603777</a>
h2odragonalmost 5 years ago
Probably at least as secure and very likely moreso than pretty much any other option. cite as &quot;random redneck off the internet&quot; and due yer own dilligencing, of course.<p>I must say its preferable for plain old SMS messaging, if nothing else, for the options it offers and the stable sane behavior.
shervinafsharalmost 5 years ago
Depends on what you need. EFF previously used to have a scorecard[1] for all the messaging applications, but they reconsidered the model of their recommendation and put together a good set of articles on the topic which ask questions to consider and provide privacy and tech context. Here&#x27;s one: <a href="https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2018&#x2F;03&#x2F;thinking-about-what-you-need-secure-messenger" rel="nofollow">https:&#x2F;&#x2F;www.eff.org&#x2F;deeplinks&#x2F;2018&#x2F;03&#x2F;thinking-about-what-yo...</a><p>The rest are linked from here[2].<p>[1]: <a href="https:&#x2F;&#x2F;www.eff.org&#x2F;pages&#x2F;secure-messaging-scorecard" rel="nofollow">https:&#x2F;&#x2F;www.eff.org&#x2F;pages&#x2F;secure-messaging-scorecard</a><p>[2]: <a href="https:&#x2F;&#x2F;www.eff.org&#x2F;de&#x2F;deeplinks&#x2F;2018&#x2F;03&#x2F;secure-messaging-more-secure-mess" rel="nofollow">https:&#x2F;&#x2F;www.eff.org&#x2F;de&#x2F;deeplinks&#x2F;2018&#x2F;03&#x2F;secure-messaging-mo...</a>
评论 #23522790 未加载
viraptoralmost 5 years ago
It all depends on the context &#x2F; your threat model. Do you want to prevent a service provider from reading your messages? It&#x27;s good. Do you want to be the next Snowden? Probably not. Do you trust people you talk to? Etc.
评论 #23527687 未加载
upofadownalmost 5 years ago
Pretty much anything will fail if the end device is compromised. It&#x27;s probably good up to that point. Otherwise you will have to look into some sort of air gapping to a physically secure device dedicated to messaging (e.g. Yubikey).<p>As always, it depends on the threat model...
rogerkirknessalmost 5 years ago
If you have to ask, you&#x27;ll just have to trust it.
cpachalmost 5 years ago
Yes. Signal is the gold standard of messaging apps.
aaron695almost 5 years ago
Rather than conspiracies theories of, depends if you are a spy or not.<p>Anyone want to explain where Signal fails for top level spying and Nation States are coming after you?<p>And what the safer alternative is?
评论 #23522843 未加载
评论 #23529748 未加载
zhalmost 5 years ago
What about <a href="https:&#x2F;&#x2F;status.im&#x2F;" rel="nofollow">https:&#x2F;&#x2F;status.im&#x2F;</a> instead - OSS, e2e encrypted by default.
probinsoalmost 5 years ago
you have to understand and read their security model in order to assess whether it is an appropriate technology for your context. every time you use a security advertised platform read the threat&#x2F;security model.
besusalmost 5 years ago
Wickr is another alternative with really tight security throughout it&#x27;s app to stack.
parliament32almost 5 years ago
Signal is still considered the gold standard for secure messaging on mobile.
wideawakealmost 5 years ago
Depends on threat model. For most people. Yes.
giantg2almost 5 years ago
Best way to avoid interference or maintain security is to adopt old school tactics. Look at the war games the military played to prepare for Iraq and how the low tech red team comms worked.
评论 #23526480 未加载
评论 #23521923 未加载