Hacker Newsnew | past | comments | ask | show | jobs | submit | more HelenePhisher's commentslogin


Previous submission of the tweets in German here: https://news.ycombinator.com/item?id=29892505


Part of that might be that non-english searches in DDG are a horrible experience.


Not in German, IME.


»[...] we found that App Tracking Transparency made no difference in the total number of active third-party trackers, and had a minimal impact on the total number of third-party tracking connection attempts. We further confirmed that detailed personal or device data was being sent to trackers in almost all cases. ATT was functionally useless in stopping third-party tracking, even when users explicitly choose “Ask App Not To Track”.«

This is ridiculous. That's privacy theatre!


No, this is definitely a COVID scenario. There have been spot checks in the past because of the high number of refugees but this was back in 2015 or 16. Took a sleeper in February this year, crossed four borders, no checks at all.


Spot checks happened all the time. I had my passport checked once crossing from Austria to Italy on a train, in 2003.


What are your levels when you use supplements?


I think the German and the South African Postbanks are not related.


I wonder if that is really such a big thing ...? Is Google (the Ad and online service company) really a competitor of Amazon (the online retailer)? In what way does Google make use of trends in online shopping? And furthermore: how many companies out there are harvesting emails, and what technology are they using? Most emails are sent using e2e encryption/Tls nowadays. Gruber mentions Edison Mail in the article ... are there more? And do webmail/freemail services sell these data to big data companies?

In that light, I think I like that move by Amazon. It protects their data and my data as well. Win-win.


I guess no. They don't even put order information in emails when items are in the delivery vehicle and determined to be delivered that day. You just see the price information, not the items. That feels indeed a bit inconvenient for me particularly when I ordered a couple of things and this order is split up in different deliveries.


No end-to-end encryption per default, and if I activate it I’m not able to see the conversation on other devices. Signal does that better.


- end-to-end encryption

- able to see the conversation on other devices

You can choose only one. Otherwise I can't see how it would be end-to-end encrypted. Your devices should create some sort of a group chat to make this work.

Group chats have large enough attack surface and "end-to-end encryption" will create false sense of security.


Signal has end-to-end encryption and you are able to see the conversation on other devices from the point you link your devices.

What it does not have is the ability to send your conversation history to your linked devices (which I find a bit odd, if you can trust a device with your present/future conversations, you should be able to trust it with your past, or at least be able to opt in in trusting it with sending over your past conversations). I hope they will provide this in the future.


All you need is for the two instances of the app to use separate sets of key pairs, where the keys have been generated on the device itself and the private keys never leave the devices, to share the private key for the conversation between the two devices. I don't know if Signal or any other app does this, but it's 100% conceptually possible.


Huh, why? If you have the same private key on your devices, you can do E2E encryption on the same conversation on multiple devices, no?


I use Signal on multiple desktops. It's a good experience and really works well. I can choose both.


In general there is a simple rule: either usability or security.

All general consumer grade tools are fighting with this equation: How can we make an app which will appeal to the broad audience which will be easy to use.

I can't say anything about signal but in general if something is easy to use and you can chat super secure with your grandma then most likely it isn't secure how you might think it is and it's actually an issue because you may want to send data which otherwise you wouldn't if you know you're on compromised channel.

Sharing history between e2e encrypted devices is a tricky thing because you should have forward security with some ratchet keys.


Other products manage, so it's clearly not a case of "You can choose only one".


How does end to end encryption make that better?

I am genuinely curious. Is your threat model too severe that you really need to hide your conversations?


I don’t want to discuss the reasons for encrypted communication, sorry. Citizenfour was a good movie though.


Why is this utterly stupid question coming up again and again? Go ask your peers/yourself why feel the need to share all of your conversations with the government and other 3rd parties who in the best case just want to sell you shit.


Could you please "open source" all your conversations to provide ground for reasoning "I have nothing to hide".

So, and we can discuss threat models.

Thank you.


I don't mind; in public groups its for everyone to see.

Snooping by the government or by the corporations? Which one is more insidious?


I would prefer to have none, hence e2e encryption.


High expectations of privacy. I prefer to hide everything, even mundane stuff, than wished I had and I didn't.


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: