TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Technology preview: Sealed sender for Signal

292 点作者 rayvy超过 6 年前

11 条评论

tptacek超过 6 年前
Two observations:<p>1. You should look into what other messengers do with sender&#x2F;receiver pairs information. One very popular competing messenger logs pairs permanently, serverside, in order to make UI features work.<p>2. One of the least popular attributes of Signal (on Hacker News, at least) is its lack of federation and ability to interoperate with third-party clients. This feature is a pretty crystalline example of the kind of protocol change you can make when you control all the mainstream clients, and that would be an absolute nightmare for a protocol where you didn&#x27;t.
评论 #18334572 未加载
评论 #18333612 未加载
评论 #18346013 未加载
评论 #18333440 未加载
评论 #18333956 未加载
评论 #18334348 未加载
amaccuish超过 6 年前
Here&#x27;s an idea, Signal, how about removing the requirement that everything be tied to phone numbers?<p>BBM back in the day worked great with their unique &quot;PINs&quot;, that could be shared by QR code, and I could reject an &quot;add&quot; request.
评论 #18333070 未加载
评论 #18332777 未加载
评论 #18332881 未加载
评论 #18334753 未加载
评论 #18332601 未加载
评论 #18332638 未加载
esotericn超过 6 年前
I&#x27;m confused here. It seems the identities are trivially linkable via the IP address.<p>The Signal servers can&#x27;t determine cryptographically that the message originates from Device A. But it is certainly from device A, because this isn&#x27;t a peer to peer protocol.<p>It seems to me like what you&#x27;d need to make this work is some sort of intermediate layer, a bit like onion routing, that would have messages arrive at the Signal servers without basically giving everything away in the source IP field.<p>With general use of NAT there&#x27;s a N-to-one mapping of identities to IP addresses, sure, but this seems to be technically true whilst in many cases completely erasing any benefit of this entirely.
评论 #18338792 未加载
geofft超过 6 年前
I&#x27;m not sure I understand the feature. It protects the sender&#x27;s identity <i>from their servers</i>, or <i>from the recipient</i>? What&#x27;s the use case &#x2F; threat model?<p>I think it prevents their servers from correlating my identity and my IP address etc., but since I want replies and I&#x27;m asking the server about replies, doesn&#x27;t that operation tell the server what my identity is anyway?<p>(There are some comments here talking about anonymous messages, but that doesn&#x27;t sound right since the phone number is apparently kept in the encrypted, inner envelope, and also how would you route replies if you didn&#x27;t have an identity of some sort for the sender?)
评论 #18333090 未加载
评论 #18332932 未加载
评论 #18338823 未加载
评论 #18333349 未加载
StudentStuff超过 6 年前
This is an unexpected move, perhaps Briar, Matrix and other distributed platforms are putting more pressure on Signal to show forward progress on the serious metadata issue with Signal and most other centralized platforms?<p>Its been a rallying cry&#x2F;common complaint by those who are technically inclined and privacy conscious for years now, surprised OWS would choose to give credit to the problem.
评论 #18333084 未加载
ngngngng超过 6 年前
How does signal do media messages? All the time i&#x27;ll open signal and see someone sent a picture but I have to download it. If signal doesn&#x27;t store anything on it&#x27;s own servers but ip and timestamp, where is this media message stored after it&#x27;s sent but before I received? Am I just downloading it from the device that sent it to me? That would explain why it&#x27;s so unreliable.
评论 #18333256 未加载
评论 #18332943 未加载
评论 #18332829 未加载
Paul-ish超过 6 年前
Without cover traffic, its not clear to me that this would prevent a correlation attack from an adversary with resources.
评论 #18333417 未加载
评论 #18341397 未加载
评论 #18333601 未加载
faitswulff超过 6 年前
You can test out the sealed sender feature on the beta releases of Signal: <a href="https:&#x2F;&#x2F;support.signal.org&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;360007318471-How-do-I-join-Signal-s-beta-" rel="nofollow">https:&#x2F;&#x2F;support.signal.org&#x2F;hc&#x2F;en-us&#x2F;articles&#x2F;360007318471-Ho...</a>
tmin超过 6 年前
How to fight spam if sender identity is not known? Currently I get at least a few marketing calls a week and don&#x27;t know how to make them stop other than blocking the numbers.
评论 #18332831 未加载
评论 #18332748 未加载
评论 #18332637 未加载
akhilramolla超过 6 年前
TO signal, Verify my identity, send me an OTP.
Confiks超过 6 年前
Can the URL be changed to the Signal blog post at <a href="https:&#x2F;&#x2F;signal.org&#x2F;blog&#x2F;sealed-sender" rel="nofollow">https:&#x2F;&#x2F;signal.org&#x2F;blog&#x2F;sealed-sender</a>?
评论 #18332968 未加载