Hacker News new | past | comments | ask | show | jobs | submit login

I have a lot of respect for moxie helping create the signal protocol. I think the problem is many extend that respect to take his word as gospel for everything else, including stuff like this that is total nonsense.

1) We -can't- just take the backend of signal and deploy our own because all clients are hardcoded to use Signal central servers. You currently -must- trust central Signal servers to not store metadata and the government their servers live under. You totally can have end to end encryption -and- have federation as Matrix.org and Riot.im have well demonstrated.

2) There is no reason at all you need to be centralized to encrypt SMS via the signal protocol. The Silence project has already demonstrated this https://silence.im/




tbf, decentralisation + e2e crypto is hard, as we've discovered at Matrix & Riot. You can have some wonderfully nasty situations if you don't know which devices (or even users) are in a given room, because the room is by definition not globally consistent due to being decentralised. Although we're doggedly working through addressing all the edge cases which result; my guess is that it's about 6x more work than the equivalent centralised service.




Join us for AI Startup School this June 16-17 in San Francisco!

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: