Live data from Hacker News

Ask HN: Is Signal still a good app to use for encrypted messaging?

news.ycombinator.com

21–30 of 34 posts

Re: Ask HN: Is Signal still a good app to use for encrypted messaging?

#21
Its use of SGX for secure value recovery is highly problematic [1].

@matthew_d_green twitter feed has a regular stream of high-quality Signal commentary.

[1] https://arstechnica.com/information-technology/2020/06/new-e...

[2] https://twitter.com/signalapp/status/1262844332278603777

Re: Ask HN: Is Signal still a good app to use for encrypted messaging?

#24
post #8
post #6

Best way to avoid interference or maintain security is to adopt old school tactics. Look at the war games the military played to prepare for Iraq and how the low tech red team comms worked.

Exactly. If you think you need Signal, you probably really need to STFU.

Or you can communicate outside of electronic channels.

My point is if you are concerned that the government is monitoring your communications (presumably related to the protests), then electronic methods are not reliable. Even if the encryption is solid, they could start jamming the frequencies used.

Re: Ask HN: Is Signal still a good app to use for encrypted messaging?

#25
post #8
post #6

Best way to avoid interference or maintain security is to adopt old school tactics. Look at the war games the military played to prepare for Iraq and how the low tech red team comms worked.

Exactly. If you think you need Signal, you probably really need to STFU.

Do you work for Chinese government?

Re: Ask HN: Is Signal still a good app to use for encrypted messaging?

#26
post #25
post #8

Earlier quoted context omitted.

Exactly. If you think you need Signal, you probably really need to STFU.

Do you work for Chinese government?

No. If I was, I would advocate that you use it so that you become dependent on the technology so that the government could strategically shut it down when they want to (rf jamming).

Re: Ask HN: Is Signal still a good app to use for encrypted messaging?

#27
post #24
post #8

Earlier quoted context omitted.

Exactly. If you think you need Signal, you probably really need to STFU.

Or you can communicate outside of electronic channels. My point is if you are concerned that the government is monitoring your communications (presumably related to the protests), then electronic methods are not reliable. Even if the encryption is solid, they could start jamming the frequencies used.

Good point. But this stuff is always cat and mouse. The mafia bigshots figured out that they couldn't talk on the phone in the 60s and 70s once the FBI started aggressively pursuing wiretaps. So they shifted.

In the 2000s, drug dealers figured out that Nextel direct connect weren't tracable... so Nextel kiosks sprung up in the hood and you'd see them all over. After that, prepaid burners were the next thing, followed by BlackBerry, etc.

If your organizing protests in such a way that are going to attract surveillance, "Use X" is dumb advice. It depends on the situation and what consequences you can sustain. An activist may want to be arrested. A Federal employee may sacrifice their career just for being present. Context matters, but the smart path is to leave your phone at home.

Re: Ask HN: Is Signal still a good app to use for encrypted messaging?

#28

Rather than conspiracies theories of, depends if you are a spy or not. Anyone want to explain where Signal fails for top level spying and Nation States are coming after you? And what the safer alternative is?

The biggest issue with signal is the forced reveal of your phone number. There are several good alternatives. Wickr and session come to mind.

Yeah I didn't particularly like that about Signal. If a malignant person were trying to keep tabs on a person (victim) using Signal, they would be able to see that the victim has switched to encrypted messaging (letting the malignant person know the victim is at least partially onto them). Thinking about the use case of a person trying to avoid a hacker/stalker here for example.

Re: Ask HN: Is Signal still a good app to use for encrypted messaging?

#29

It all depends on the context / your threat model. Do you want to prevent a service provider from reading your messages? It's good. Do you want to be the next Snowden? Probably not. Do you trust people you talk to? Etc.

Maybe this is a bit nitpicky, but Snowden himself does offer Signal to people [1] and is listed on the Signal homepage as "using Signal every day" [2].

  [1]:https://twitter.com/Snowden/status/986277159252750336?s=20
  [2]:https://signal.org

Re: Ask HN: Is Signal still a good app to use for encrypted messaging?

#30

Earlier quoted context omitted.

The biggest issue with signal is the forced reveal of your phone number. There are several good alternatives. Wickr and session come to mind.

Easily fixed by hosting your own Signal server and recompiling its phone apps, no?

"Easily"
Post reply on HN