Hacker News new | past | comments | ask | show | jobs | submit | antisocialist's comments login

> Now, there exists a minority of extremely technical computer user for which Signal is a nonstarter (because you need a smartphone and valid phone number to enroll in the first place). > there presently isn’t really a good recommendation for private messaging that meets their constraints.

You don't need a phone number or a phone for https://haven.xx.network and there are others.

If nothing is recommended, fine, but it's simplistic to not recommend or even consider the 3-4 apps that don't have those limitations. If you didn't have time to investigate or couldn't find anything else, say so.


Not if you disable your IPv6 stack.

Or you can be smart and "easily" address such probing attacks in your FW rules... https://nvd.nist.gov/vuln/detail/CVE-2024-50252


> Not if you disable your IPv6 stack.

The same technique can be used for IPv4. Disable both and become invulnerable to probing!


Why stop there? Probes traverse the whole TCP/IP stack, best to stop them early at layer 1: https://www.bit.nl/news/115/88/Cut-here-to-activate-firewall...

That's interesting - it turned out markets, as distorted by Obamacare and so on as they are, weren't off by a lot.

He couldn't find services he needed and decided to build it himself. But after many years of trying he couldn't build a sustaining biz that provided such service.


If you wanted to project an appearance of having read the article before injecting your opinion, you failed wildly.

The author appears phenotypically female (https://medium.com/@abi_75893/about) and writes early on that a motivating factor was her severe menstrual pain. I'm very confused how you decided to use male pronouns here.

It's possible "antisocialist" was commenting to push their own agenda without actually caring about or engaging with the actual article.

>But after many years of trying he couldn't ...

she


So many SJWs, so little time!

Who would have thought the people who can't stand free speech may not be an "asset" on a social networking platform...

Hope they're employing mods from the Third World otherwise that low price of theirs may need an adjustment...


It may be valid against closed source apps, but I don't see how it can be more secure than build-and-self-host OSS apps for private messaging.

They say don't roll your own encryption protocol (if something similar or same already exists and it's maintained), but these guys just can't resist.

Using a secure decentralized messenger to share a download (or upload) location on a Hidden S3 Service or one of those decentralized S3 services can't possibly be worse than this.

To commenter in https://news.ycombinator.com/item?id=40289777: BitMessage doesn't solve anything, it uses broadcast and Bitcoin peer nodes that first get the message know where it came from. And BitMessage is not an illegal content hazard of any kind (what a ridiculous statement!).


There are private chat apps that don't use phone numbers, but not many and all have other challenges.

https://privacy-checkup.info/en/recommendations/messenger

xx Messenger hasn't used phone numbers (it's optional) ever, but unfortunately although it still works it's no longer updated because development has been focused on a more modern approach which is desktop-only (https://alpha.speakeasy.tech/). Because of that xx Messenger still lacks other features such as group chats and file attachment support which exist but is unstable and limited in terms of attachment size.

Speakeasy supports DM & group chats, and Echoexx (https://echoexx.tech/) is DM only (currently in closed alpha testing; open alpha starts late this month). Both are browser-only for now and require WASM support. Speakeasy supports native (cMixx) device-independent crypto identity, Echoexx supports ENS (.eth) ID and will add support for native cMixx identity later.

Given that no feature-rich app with strong privacy will ever match features of low-privacy apps (if for no other reason, simply because secure & private alternatives cost a lot more to develop and therefore fund, while simultaneously removing ways to recoup those costs), people should simply use multiple apps for different purposes.


Surprised you did not mention Matrix/Element.



Or Threema.


Yep, whoever gets hold of those records can cross-reference logs from the same time to narrow down or even outright identify Signal chat participants.


In other words, Nostr can't do almost anything that matters.

> First, I want a replication strategy.

xx Network has message replication built in.

> Third, someone needs to delete some of these NIPS.

xx Network lets you delete messages.

> Fourth, it needs a dedicated blob store protocol.

For blobs, clients should be able to plug in to any 3rd party blob storage (e.g. Crust Network). This secondary storage is needed only for large attachments and isn't strictly required in messaging. If you think about it, you could upload large attachments anywhere and send links in messages. Look how Teams or Outlook work with One Drive.


Oh hey David Schaum has entered the chat to shill their thing


I don't agree with many points from that blog post, but I agree with your comment about phone numbers.

xx Messenger doesn't require user's phone number (it's optional, if the user wants to make it easier to be found by phone number).

Messaging clients on some other networks also don't require phone numbers, but that makes it harder to find people. xx Messenger allows the creation and use of network nicknames that can be ported to other apps.

Source code:

https://github.com/xxfoundation/elixxir-xx-Messenger-Android

https://github.com/xxfoundation/elixxir-xx-messenger-iOS

(Mobile app hasn't been updated for a while; the reason is development of a unified Web-based desktop and mobile client is going on here - https://github.com/xxfoundation/elixxir-speakeasy-web/tree/d... - and it may eventually replace xx Messenger).

xx Network allows 3rd party clients. There's an SDK - https://xx.network/developers-mixnet/ - to make that easier.

Disclosure: I own xx coins.


The "I don't trust Signal" articles were one of the things that inspired me to push for making xxm first over other apps. Since then a few other options have also sprung up (Session, cwtch, simplex to name a few).

Also, it wasn't mentioned in the articles, but another issue solved by us and many of these other messengers is use of a private keyboard instead of the vendor/isp ones that can spy on users.

Unfortunately, I learned the hard way that better privacy and security will not beat convenience and network effects when you are competing with "free", so we are changing our approach.


Not enough xs


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: