Hacker News (curated)new | past | comments | ask | show | jobs| show hidden

Signal, Apple iMessage, and WhatsApp have to announce at some point that they will simply stop providing services to any country/region that insists on breaking E2EE. All you'll be left with is unencrypted RCS.

It's a bit of a 'nuclear option', but at the end of the day, once one jurisdiction forces them to break the math, every other one will as well.

IMHO, it's the only way to force the proponent(s) of these proposal(s) to see the folly of their ways (and it's no guarantee that they will).



There are peer to peer (or otherwise decentralised, e.g. multiple servers operated by many different people) alternatives to Signal. I haven't tried any of them, nor do I know which ones have been audited. But if the worst comes to the worst, there are alternatives that are hard to block.

In particular I remember reading about DeltaChat which piggiebacks on normal email infrastructure, making it really hard to block without massive collateral damage.


Been using matrix for years now. Even operating a server for a small community. It is slightly more involved for regular users though so that is not the best but otherwise works. Setting up your own federated instance is quite simple, there is an Ansible playbook around to make it even easier. You could even isolate it and have it only for your org. From what I know there is some traction to get it adopted in a bunch of agencies eu-wide.

Huh, I guess that works. I never considered it as a Signal replacement. It always seemed closer to an IRC (and I guess Discord and maybe Slack) replacement to me. But yeah I do believe it has end to end encryption for individual communication as well.

I loathe how difficult Matrix is for normal people though. It's a nightmare to find a client, get an account, connect to your server, set up push notifications, and then navigate to a chat, much less set up encryption.

Fine for us, my mom is never managing.

Hopefully if it gets more mainstream some of these things get smoothed out, because it's nice once it's working.


FWIW, iMessage is largely unencrypted already. Yes, the messages themselves are E2E encrypted, but most people do not enable Advanced Data Protection, but do enable iCloud Backups, which causes messages only to be encrypted at-rest with keys that Apple holds [1]. And even if you enable ADP, most people that you communicate with didn't.

A similar situation applies to WhatsApp. On iPhone, the messages are stored in iCloud Backups. On Android they can be backed up to Google Drive but E2E encryption is not the default.

The only exception is Signal, which opts out of iCloud and Android backups and had to roll their own backup solution for E2E backups.

So in practice, US law enforcement can probably already access iMessage/WhatsApp messages.

[1] See footnote 9: https://support.apple.com/en-us/102651


As someone who uses Signal and WhatsApp, I would be extremely happy if those companies blocked access in my jurisdiction if such laws are implemented. In fact, if they agreed to insert backdoor access I would never trust them again, even if they subsequently reversed it.

We have to be willing to suffer personal inconveniences to stand up to these types of policies.


They don't have to. Signal, in particular, since it's not connected to massive revenue streams, can just wait to see if the country blocks it.

> IMHO, it's the only way to force the proponent(s) of these proposal(s) to see the folly of their ways (and it's no guarantee that they will).

I'm pretty sure they'd see it as a win, at least unless it led to massive public backlash. So why not skip that step and just give them the backlash?


Sorry, maybe I'm dumb. Why would "gatekeepers" poke the bear?

There was already a tweet/post from the Signal CEO in which she said that if the Chat Control v2 law was enforced (aka client side scanning of messages before encryption), that they would simply leave the EU market instead of complying.



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact | github