frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Signal creator Moxie Marlinspike wants to do for AI what he did for messaging

https://arstechnica.com/security/2026/01/signal-creator-moxie-marlinspike-wants-to-do-for-ai-what-he-did-for-messaging/
44•aarghh•2h ago

Comments

vaylian•1h ago
previous discussion: https://news.ycombinator.com/item?id=46600839
lrvick•1h ago
What he did with messaging... So he will centralize all of it with known broken SGX metadata protections, weak supply chain integrity, and a mandate everyone supply their phone numbers and agree to Apple or Google terms of service to use it?
fsflover•37m ago
Not sure why you're gettimg downvoted. This is exactly what he did to instant messaging; extremely damaging to everyone and without solid arguments for such design.
maqp•25m ago
Or, he took a barely niché messaging app plugin (OTR), improved it to provide forward secrecy for non-round trips, and deployed the current state-of-the art end-to-end encryption to over 3,000,000,000 users, as Signal isn't the only tool to use double-ratchet E2EE.

>broken SGX metadata protections

Citation needed. Also, SGX is just there to try to verify what the server is doing, including that the server isn't collecting metadata. The real talking is done by the responses to warrants https://signal.org/bigbrother/ where they've been able to hand over only two timestamps of when the user created their account and when they were last seen. If that's not good enough for you, you're better off using Tor-p2p messengers that don't have servers collecting your metadata at all, such as Cwtch or Quiet.

>weak supply chain integrity

You can download the app as an .apk from their website if you don't trust Google Play Store.

>a mandate everyone supply their phone numbers

That's how you combat spam. It sucks but there are very few options outside the corner of Zooko's triangle that has your username look like "4sci35xrhp2d45gbm3qpta7ogfedonuw2mucmc36jxemucd7fmgzj3ad".

>and agree to Apple or Google terms of service to use it?

Yeah that's what happens when you create a phone app for the masses.

josephg•9m ago
> You can download the app as an .apk from their website if you don't trust Google Play Store.

I wish apple & google provided a way to verify that an app was actually compiled from some specific git SHA. Right now applications can claim they're opensource, and claim that you can read the source code yourself. But there's no way to check that the authors haven't added any extra nasties into the code before building and submitting the APK / ios application bundle.

It would be pretty easy to do. Just have a build process at apple / google which you can point to a git repo, and let them build the application. Or - even easier - just have a way to see the application's signature in the app store. Then opensource app developers could compile their APK / ios app using github actions. And 3rd parties could check the SHA matches the app binaries in the store.

rcxdude•5m ago
This is what F-droid does (well, I suspect most apps don't have reproducable builds that would allow 3rd-party verification), but Signal does not want 3rd-party builds of their client anyhow.
Maken•8m ago
>over 3,000,000,000 users

Is that a typo or are you really implying half the human population use Signal?

Edit: I misread, you are counting almost every messaging app user.

rcxdude•3m ago
Yeah, whatsapp uses the same protocol.
pousada•26m ago
Do you know a better alternative that I can get my elderly parents and non-technical friends to use? I haven’t come across one and from my amateur POV it seems much better than WhatsApp or Telegram.
rcxdude•7m ago
The issue being there's not really a credible better option. Matrix is the next best, because they do avoid the tie-in to phone numbers and such, but their cryptographic design is not so great (or rather, makes more tradeoffs for usability and decentralisation), and it's a lot buggier and harder to use.
b65e8bee43c2ed0•59m ago
what did he do for messaging? Signal is hardly more private than goddamn Whatsapp. in fact, given that Whatsapp had not been heavily shilled as the "totally private messenger for journalists and whistleblowers :^)" by the establishment media, I distrust it less.
anilgulecha•52m ago
He implemented E2EE in Whatsapp as well.
bigfishrunning•36m ago
Yeah, it seems kind of funny how Signal is marketed as a somewhat paranoid solution, but most people run it on an iPhone out of the app store with no way to verify the source. All it takes is one villain to infiltrate one of a few offices and Signal falls apart.

Same goes for Whatsapp, but the marketing is different there.

t3netet•21m ago
Even if you discount Signal he did more or less design the protocol that WhatsApp is using https://techcrunch.com/2014/11/18/end-to-end-for-everyone/

Also while we would expect heavy promotion for a trapped app from some agency it's also a very reasonable situation for a protocol/app that actually was secure.

You can of course never be sure but the fact that it's heavily promoted/used by people on both the whistleblowers, large corporations and multiple different National Officials at the same time is probably the best trustworthyness signal we can ever get for something like this.

(if all of these can trust it somewhaat it has to be a ridiculously deep conspiracy to not have leaked at least to some national security agency and forbidden to use(

pdpi•11m ago
> Signal is hardly more private than goddamn Whatsapp.

To be fair, that is largely because WhatsApp partnered with Open Whisper to bring the Signal protocol into Whatsapp. So effectively, you're saying "Signal-the-app is hardly more private than another app that shares Signal-the-protocol".

In practical terms, the only way for Signal to be significantly more private than WhatsApp is if WhatsApp were deliberately breaking privacy through some alternative channel (e.g. exfiltrating messages through a separate connection to Meta).

jaapz•11m ago
> Signal is hardly more private than goddamn Whatsapp

Kind of because Whatsapp adopted Signal's E2EE... And not even that long ago!

colesantiago•48m ago
The website is: https://confer.to/

"Confer - Truly private AI. Your space to think."

"Your Data Remains Yours, Never trained on. Never sold. Never shared. Nobody can access it but you."

"Continue With Google"

Make of that what you will.

irl_zebra•40m ago
Looks like using Google for login. You can also "Continue with Email." Logging in with Google is pretty standard.
colesantiago•36m ago
It is not privacy oriented if you are sharing login, profile information with Google and Confer.

It wouldn't be long until Google and Gemini can read this information and Google knows you are using Confer.

Wouldn't trust it regardless if Email is available.

The fact that confer allows Google login shows that Confer doesn't care about users privacy.

pousada•24m ago
You don’t have to use Google login though? People building solutions like this that aim for broad adoption have to make certain compromises and this seems OK to me (just talking about offering a social login option, haven’t checked the whole project in detail)
maqp•12m ago
My issue is it claims to be end-to-end encrypted, which is really weird. Sure, TLS between you and your bank's server is end-to-end encrypted. But that puts your trust on the service provider.

Usually in a context where a cypherpunk deploys E2EE it means only the intended parties have access to plaintexts. And when it's you having chat with a server it's like cloud backups, the data must be encrypted by the time it leaves your device, and decrypted only once it has reached your device again. For remote computing, that would require LLM handles ciphertexts only, basically, fully homomorphic encryption (FHE). If it's that, then sure, shut up and take my money, but AFAIK the science of FHE isn't nearly there yet.

So the only alternative I can see here is SGX where client verifies what the server is doing with the data. That probably works against surveillance capitalism, hostile takeover etc., but it is also US NOBUS backdoor. Intel is a PRISM partner after all, and who knows if national security requests allow compelling SGX keys. USG did go after Lavabit RSA keys after all.

So I'd really want to see this either explained, or conveyed in the product's threat model documentation, and see that threat model offered on the front page of the project. Security is about knowing the limits of the security design so that the user can make an informed decision.

throwpoaster•46m ago
Add a defunct cryptotoken?
temp8830•22m ago
Hey, Telegram had one. He had to get to feature parity.
frankdilo•32m ago
I do wonder what models it uses under the hood.

ChatGPT already knows more about me than Google did before LLMs, but would I switch to inferior models to preserve privacy? Hard tradeoff.

moralestapia•25m ago
Backdoor it?
voidfunc•20m ago
Do what he did for messaging? Make a thing almost nobody uses?
anonymous908213•16m ago
If this is how little you think of an app with ~50 million monthly active users, I take it making apps with a billion MAU is something you routinely do during your toilet breaks, or...?
maqp•8m ago
3 billion WhatsApp users use protocol built on his labor, every day.

Just the Browser

https://justthebrowser.com/
180•cl3misch•2h ago•72 comments

Michelangelo's First Painting, Created When He Was Only 12 or 13 Years Old

https://www.openculture.com/2026/01/discover-michelangelos-first-painting.html
15•bookofjoe•34m ago•9 comments

Show HN: I built a text-based business simulator to replace video courses

https://www.core-mba.pro/
38•Core_Dev•12h ago•13 comments

Show HN: The Analog I – Inducing Recursive Self-Modeling in LLMs [pdf]

https://github.com/philMarcus/Birth-of-a-Mind
7•Phil_BoaM•38m ago•1 comments

OpenBSD-current now runs as guest under Apple Hypervisor

https://www.undeadly.org/cgi?action=article;sid=20260115203619
319•gpi•11h ago•33 comments

List of individual trees

https://en.wikipedia.org/wiki/List_of_individual_trees
218•wilson090•14h ago•80 comments

Interactive eBPF

https://ebpf.party/
87•samuel246•6h ago•5 comments

The spectrum of isolation: From bare metal to WebAssembly

https://buildsoftwaresystems.com/post/guide-to-execution-environments/
59•ThierryBuilds•4h ago•19 comments

Training my smartwatch to track intelligence

https://dmvaldman.github.io/rooklift/
27•dmvaldman•1d ago•15 comments

Apple is fighting for TSMC capacity as Nvidia takes center stage

https://www.culpium.com/p/exclusiveapple-is-fighting-for-tsmc
720•speckx•23h ago•436 comments

Pocket TTS: A high quality TTS that gives your CPU a voice

https://kyutai.org/blog/2026-01-13-pocket-tts
510•pain_perdu•1d ago•120 comments

Cue Does It All, but Can It Literate?

https://xlii.space/cue/cue-does-it-all-but-can-it-literate/
41•xlii•4d ago•11 comments

Dev-Owned Testing: Why It Fails in Practice and Succeeds in Theory

https://dl.acm.org/doi/10.1145/3780063.3780066
3•rbanffy•39m ago•0 comments

Briar keeps Iran connected via Bluetooth and Wi-Fi when the internet goes dark

https://briarproject.org/manual/fa/
441•us321•18h ago•256 comments

psc: The ps utility, with an eBPF twist and container context

https://github.com/loresuso/psc
3•tanelpoder•58m ago•0 comments

Inside The Internet Archive's Infrastructure

https://hackernoon.com/the-long-now-of-the-web-inside-the-internet-archives-fight-against-forgetting
383•dvrp•2d ago•94 comments

Show HN: pgwire-replication - pure rust client for Postgres CDC

https://github.com/vnvo/pgwire-replication
16•sacs0ni•5d ago•6 comments

Bringing the Predators to Life in MAME

https://lysiwyg.mataroa.blog/blog/bringing-the-predators-to-life-in-mame/
40•msephton•2d ago•7 comments

Signal creator Moxie Marlinspike wants to do for AI what he did for messaging

https://arstechnica.com/security/2026/01/signal-creator-moxie-marlinspike-wants-to-do-for-ai-what...
44•aarghh•2h ago•30 comments

pf: Make af-to less magical

https://undeadly.org/cgi?action=article;sid=20260116085115
31•defrost•5h ago•2 comments

Linux boxes via SSH: suspended when disconected

https://shellbox.dev/
245•messh•17h ago•136 comments

Ask HN: How can we solve the loneliness epidemic?

641•publicdebates•21h ago•1010 comments

Show HN: Hc: an agentless, multi-tenant shell history sink

https://github.com/alessandrocarminati/hc
12•acarminati•6h ago•2 comments

Claude is good at assembling blocks, but still falls apart at creating them

https://www.approachwithalacrity.com/claude-ne/
278•bblcla•1d ago•201 comments

My Gripes with Prolog

https://buttondown.com/hillelwayne/archive/my-gripes-with-prolog/
121•azhenley•14h ago•66 comments

Altaid 8800 (2024)

https://sunrise-ev.com/8080.htm
13•exvi•4d ago•2 comments

Prime chains

https://www.johndcook.com/blog/2026/01/10/prime-chains/
29•ibobev•4d ago•8 comments

Data is the only moat

https://frontierai.substack.com/p/data-is-your-only-moat
179•cgwu•19h ago•39 comments

Show HN: OpenWork – An open-source alternative to Claude Cowork

https://github.com/different-ai/openwork
203•ben_talent•2d ago•44 comments

Go-legacy-winxp: Compile Golang 1.24 code for Windows XP

https://github.com/syncguy/go-legacy-winxp/tree/winxp-compat
121•Oxodao•4d ago•63 comments