ee cummings?
- 0 Posts
- 41 Comments
For sure, I do understand the concerns. Government subpoenas and metadata leaking are real problems, and it’s hard to design algorithms well in order to minimize the leakage. But Signal is designed in such a way that the only information that they can possibly collect on any user is (1) phone number, (2) account creation time, and (3) time of last connection with their server. This is true even if they are compelled to release information about their users, even under duress. This has played out in court many times, and Signal is unable to comply with government demands for any information other than exactly these three things: https://signal.org/bigbrother/
I’ve done 5 years of research into designing private messaging systems specifically, and the more I learn about Signal the more I believe that they’re really the gold standard of privacy, to the degree that it’s shocking that they’re a non-profit and provide their service for free. Knowing how hard it is to design a secure messenger, and how few eyes are actually on most open source projects, people should always be cautious about smaller projects promising stronger privacy guarantees.
The other concerns you brought up (anonymity, targeted government investigations, device compromise, etc.) are super valid and important. But I think Signal also does the best of any private messenger in their UI/UX design, to be as clear as possible about what they keep private. At some point, it’s not clear to me how Signal would protect users who (for example) use their full name and think they’re anonymous, or users who don’t put a password on their phone. They’ve really nailed the “private messenger” part, and I’m just trying to emphasize that the concerns in this comment thread and linked github essay are mostly unfounded, thankfully.
When you register with Signal, they do know your phone number. This gives them the information that “the person who owns this phone number is registered with our service.” That is not linked in any way to what leaves the client when you send a message because, I cannot stress this enough, you don’t send your phone number or identify yourself in any way to Signal’s servers when you send a message. Please take a look at the client source code yourself.
I won’t be replying anymore, have a great one! There are better things to use my PhD in cryptography for.
I’ll just say one last time: none of this information ever leaves your client device, so even if signal wanted to know the phone number of a message sender, or which group chats you’re in, they have no access to this because it all never leaves your phone. As long as you’re running the correct client code, the server can be arbitrarily malicious, and it doesnt matter.
Have a great day
These are super cool parts of signal’s architecture, that are not obvious to understand, but you can truly verify client side that (1) signal only sees an IP address, no phone number, associated with each outgoing message, and (2) signal has no idea who is in which group chat and which permissions you have in those chats.
The first one is pretty simple: you don’t prove to signal who you are, signal just routes packets and lets the receiver verify that the sender is who they say they are by verifying a short lived certificate attesting your identity.
The second one is more interesting: group chats are implemented as a complete graph of direct messages between all participants. In order to update the group state, you send Signal a zero-knowledge proof that you are a member of the group, which convinces Signal that you can add or remove people, without ever revealing your identity. This same mechanism is used to prevent griefing, spam, and DDOS attacks for sealed sender.
Again, both of these can be verified by only looking at the client source code, and nothing else.
More info: https://signal.org/blog/sealed-sender/ https://signal.org/blog/signal-private-group-system/
Can you explain how signal will build a social network graph when it doesn’t know who sent any message, which group chats you’re in, or who is on your contact list? Again, none of this ever leaves your device without being encrypted, which you can check by looking at the client source code.
I don’t really understand why you think this, can you explain? Signal stores, and has access to, no message metadata. They don’t know who your contacts are, which group chats you’re in, when you’re sending messages, or who you’re talking to.
To be convinced of this, take a look at the client source code, and compile the app yourself. None of this information ever leaves your phone without being encrypted or otherwise masked. No analysis of their server code is required to be convinced of this.
Spacenut@lemmy.worldto
Mildly Infuriating@lemmy.world•Most of plant based leather uses a lot of polyurethaneEnglish
448·4 months agoI don’t really understand all the hate/cynicism towards vegan leather. Like yeah obviously plastic is bad for the environment, but raising cows and dumping thousands of tons of chromium into rural waterways for the tanning process aren’t good either. Leather is actually far worse for the environment by some metrics.
Plus there’s the fact that most leather is sealed with plastic/acrylic to increase its longevity anyway, unless you’re buying something wicked expensive.
Spacenut@lemmy.worldto
Privacy@lemmy.ml•out of the loop, what's the problem with signal?
7·4 months agoThis doesn’t really make sense to me, what do you mean? Client-side you do different computation for sealed sender delivery/receipt. What’s your normal standard of trust that a hosted, open source project is running the same code that they’ve made public?
I think if they store any metadata that we don’t know about, the lie runs very very deep, like to conspiracy theory levels that don’t really make sense for a registered nonprofit: https://signal.org/bigbrother/
Spacenut@lemmy.worldto
Privacy@lemmy.ml•out of the loop, what's the problem with signal?
91·4 months agoIn regards to Signal, this is largely not true. Sealed sender has been signal’s metadata hiding protection for like 6 years or something. The only information signal has is your phone number, your account creation time, and the last time you contacted their servers.
They also have a server implementation on github, so it seems to be open source to me. (I could be missing something though)
You are right though, that it uses centralized servers and requires a phone number, which are sticking points for a lot of people.
For real I don’t really understand all the hate PETA gets. I think the most you can accuse them of is not being strategic in their messaging, and doing some pretty dumb stunts over the years. Everyone I’ve ever met who’s involved with PETA has seemed like genuinely a good person who’s trying to help animals.
Of course there’s also the “PETA kills pets” stuff, but if you do one google search you’ll see this is astroturfed lies/exaggerations from the meat industry, so I don’t pay that any mind.
Spacenut@lemmy.worldto
Selfhosted@lemmy.world•If you have one, how much do you pay for a domain name? Any cheap registrar recommendations?English
4·6 months agoI bought a class 1.111B domain from the .xyz registrar: 6 to 9 digits followed by .xyz, so you can use your phone number. They sell them for $1/year, and $1/year for whois privacy. So I paid $20 to have my domain for the next decade :)
Spacenut@lemmy.worldto
World News@lemmy.world•Boiling lobsters alive to be banned in UK animal cruelty crackdownEnglish
1·7 months agoUnited States Department of Agriculture. PSD Online. Available at: https://apps.fas.usda.gov/psdonline/app/index.html#/app/advQuery.{/ref}
The majority (77%) of the world’s soy is fed to livestock for meat and dairy production. 7% is fed directly to animals as soybeans, but the remainder is first processed into soybean ‘cake’.{ref}Soybean cake (sometimes referred to as soybean meal) is a high-protein feed made from the pressurization, heat treatment, and extraction processing of soybeans. The oil is extracted from the soybeans to leave a protein-rich product.
Per the source above, although it’s fair if you missed it because it’s in the footnotes
Spacenut@lemmy.worldto
World News@lemmy.world•Boiling lobsters alive to be banned in UK animal cruelty crackdownEnglish
2·7 months agoI understand the core of your argument: “animals can eat parts of the plant that humans can’t, so it’s most efficient to use those as animal feed instead of wasting them.” But this is not really engaging with the source I posted above, showing that, indeed, farmed animals are directly fed only 7% of all raw soybeans produced in the world, but 69% of all soybeans are specifically produced to be turned into high-protein processed animal feed, for a total of 76%.
From your previous comments though, it doesn’t really seem like you’re engaging in good faith. Feel free to have the last word, have a great day
Spacenut@lemmy.worldto
World News@lemmy.world•Boiling lobsters alive to be banned in UK animal cruelty crackdownEnglish
31·7 months agoCmon let’s be real, again this is a very simple trophic levels thing. If you truly care about the suffering of all the field mice and bugs and whatever being killed in soybean monocultures, and their other various environmental harms, then surely you would be vegan, because 75% of all soybeans grown globally are used as animal feed. (Source)
Spacenut@lemmy.worldto
World News@lemmy.world•Boiling lobsters alive to be banned in UK animal cruelty crackdownEnglish
8·7 months agoThat’s ok, totally understandable. Just read the comment again
Spacenut@lemmy.worldto
World News@lemmy.world•Boiling lobsters alive to be banned in UK animal cruelty crackdownEnglish
312·7 months agoLet’s suppose that you actually genuinely care about reducing the amount of plant suffering in the world. If this is the case, surely you would be vegan, because 3/4 of our total agricultural land is used to grow plants to support animal agriculture. (Since grass feels pain just like soybeans do, this includes pasture land.) So far fewer plants would be killed if everyone was vegan.
Of course, you don’t actually live your life in a manner consistent with believing plants feel pain. I don’t think anyone would think twice about swerving into some flowers to avoid a dog in the street for fear of causing suffering to the flowers.
I mean I think bees are harmed in the production of honey, it’s just that most people don’t care about bee welfare. Commercially they’re bred by crushing the male to extract semen, and any operation above hobby scale will clip the wings of the queen so that the hive can’t escape.
Then you necessarily need to replace their ideal food source with something that is nutritionally much worse for them (basically sugar water), and then hope that they survive on that long enough to make more honey for us to take.
Imo “backyard eggs” are really small potatoes, especially when like 98% of eggs globally come from factory farms. But even in that case, egg-laying hens are basically bred to suffer. They lay an egg every 1-2 days, compared to like once a month in the wild, which takes a huge amount of energy and nutrients. And we’ve bred them to produce eggs too big for their bodies, so that even when they’re treated really well, the vast majority of hens have bone fractures.
That’s why animal sanctuaries will usually either feed the eggs back to the hens, or give them medication to stop them from laying at all.
Of course, this is on top of the fact that 100% of egg-laying hen breeders, everywhere, kill the males shortly after birth because they can’t lay eggs. See this for more information.



So cute!
Call me a radical communist hippie but I think these animals shouldn’t be skinned alive, anally electrocuted, and gas chambered just so people can wear fur coats