Practical Cryptography

Looks like some guys basically recreated Firefox Send. Haven’t tried it yet.

(Not the same as magic wormhole)

Oh no.

I don’t blame signal here, I blame capitalism. Running something like this takes capital. Afaik they don’t have capital.

Bruce thinks it’s nuts too.
https://www.schneier.com/blog/archives/2021/04/wtf-signal-adds-cryptocurrency-support.html

1 Like

The WhatsApp guy gave them $50 million a few years ago.

Gonna be honest. I’ve never gotten a look at the books for a product the size of signal. 50 mil could be everything or peanuts. I feel like my point potentially still stands.

That said, I do agree with Schneier, my tossing the blame at the feet of “trying to keep the lights on” in no way means I think this is a good idea.

More info on that initial funding

I don’t know what to think about Signal lately. The cryptocurrency thing is a fiasco, but this piece by Moxie is crazy (good):

Highlights:

By a truly unbelievable coincidence, I was recently out for a walk when I saw a small package fall off a truck ahead of me. As I got closer, the dull enterprise typeface slowly came into focus: Cellebrite.

we found that it’s possible to execute arbitrary code on a Cellebrite machine simply by including a specially formatted but otherwise innocuous file in any app on a device that is subsequently plugged into Cellebrite and scanned.

it’s possible to execute code that modifies not just the Cellebrite report being created in that scan, but also all previous and future generated Cellebrite reports from all previously scanned devices and all future scanned devices in any arbitrary way

In completely unrelated news, upcoming versions of Signal will be periodically fetching files to place in app storage. These files are never used for anything inside Signal and never interact with Signal software or data, but they look nice, and aesthetics are important in software. […] There is no other significance to these files.