Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Signal is actually quite sufficient as an email replacement. You can send media attachments, and even include several recipients. It is unquestionably a better encrypted messaging system than PGP.


"It is unquestionably a better encrypted messaging system than PGP." You're going to have to back that up. In no way is Signal more secure or private than PGP. Signal is simply easier to use for a very small use case, text messaging.


Unless you actually need to send email with Signal, or want to be anonymous, since Signal uses your phone number.


pgp does not provide anonymity at least not in the widely accepted form. every message has the recipient keyid in plaintext, unless you --throw-keyids but then you run into incompatibilities and inconveniences that make the whole exercise user unfriendly and widely unsupported.


> pgp does not provide anonymity

Not quite true.

> every message has the recipient keyid in plaintext

The keys are not required to be centralized in any particular location. There is no way to tie a key to an individual, unless that individual wants to be associated with that key id.

It's common practice to post anonymous, encrypted messages on mailing lists or newsgroups. All you can really tell in those cases is that the recipient is a member of that mailing list or subscribes to the newsgroup (though it's not for sure, with the use of remailers, etc).


It provides pseudonymity. KeyIDs exist but they're not inherently tied to e.g. your real-world location the way a phone number is (to an attacker with access to the towers). Whereas OpenPGP can reasonably be combined with e.g. Tor.


By the way, is it possible to use Signal to communicate with people using WhatsApp? Probably stupid question, but since they both use Signal protocol, phone number and stuff I would guess it should be possible to write a bridge that reveals to the MITM (FB) only your phone and the fact you are talking to the person they know, and blatantly lie about everything else, such as your contacts, seen messages (if desired), etc.


> media attachments

How large?

> several recipients

How many, in what countries?

Is the communication anonymous?

Can I use it in such a way that obfuscates the message's recipient?

Can I send an encrypted message when the Signal servers have been DOSed?

If seized, can the controllers of the Signal servers get the contents of my entire phone contact list?

I believe that Signal is adequate for a small subset of encrypted message cases, but not as a good replacement for encrypted emails.


Larger than the 10 MB attachment limit of most email providers.

I'm unaware that Signal is geographically limited in any way.

Signal is anonymous as your phone number is. PGP isn't anonymous either, so this seems like an irrelevant criticism.

Again, you can obfuscate the recipient as much as you can obfuscate a phone number. You can't obfuscate the email address you're sending your encrypted email to.

This depends on how they use contacts to match users. I believe they only collect a hash of the phone numbers you choose to share with them.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: