Earlier quoted context omitted.
>1) Make mass surveillance impossible. By giving NSA the only thing what they want: metadata from Google >2) Stop targeted attacks against crypto nerds. Who don't have google services on their devices and don't use google chrome... yeah. Thanks for helping me so much. The Senate is considering reauthorizing the law the NSA says authorizes it to collect hundreds of millions of online communications from providers like…
> By giving NSA the only thing what they want: metadata from Google What metadata does Google get from Signal messages? The time/date you received a message, the size of the message... Is there anything else?
Moxie Marlinspike Makes Encryption for Everyone
71–80 of 144 posts
Re: Moxie Marlinspike Makes Encryption for Everyone
#72Not for people who don't want Google on their device. He only wants distribution via Google, and even went as far to demand that free/libre Play-alternative F-droid removed their build of TextSecure. See: https://fdroid.eutopia.cz/
I think we're missing some information here. The supplied link says that the applications have been renamed due to legal threats. This seems completely reasonable to me. The names of the apps are trademarks and for a security product, who builds it is important to the integrity of the mark. I'm trying to remember how Android works, but I seem to recall that you need to sign the packages differently on Play and Fdroid…
Re: Moxie Marlinspike Makes Encryption for Everyone
#73Earlier quoted context omitted.
I think we're missing some information here. The supplied link says that the applications have been renamed due to legal threats. This seems completely reasonable to me. The names of the apps are trademarks and for a security product, who builds it is important to the integrity of the mark. I'm trying to remember how Android works, but I seem to recall that you need to sign the packages differently on Play and Fdroid…
> He decided not to. That's completely his right. He doesn't go into a lot of detail about why he has decided this, but it's completely up to him. He doesn't like how F-Droid uses centralized signing keys which are stored online: https://github.com/WhisperSystems/Signal-Android/issues/127#...
Re: Moxie Marlinspike Makes Encryption for Everyone
#74Not for people who don't want Google on their device. He only wants distribution via Google, and even went as far to demand that free/libre Play-alternative F-droid removed their build of TextSecure. See: https://fdroid.eutopia.cz/
I'm using a BlackBerry OS 10 device, which can run Android apps, and I even have Google Play running on it, but Google Play Services is stubbed for a large part on BB10, making some apps (such as Google Maps, Google Calendar, and Signal) impossible to use.
Why a security/privacy oriented application such as signals wants to bind so strongly with Google's services, I don't understand.
Re: Moxie Marlinspike Makes Encryption for Everyone
#75Earlier quoted context omitted.
> By giving NSA the only thing what they want: metadata from Google What metadata does Google get from Signal messages? The time/date you received a message, the size of the message... Is there anything else?
The person you are communicating with.
Re: Moxie Marlinspike Makes Encryption for Everyone
#76Earlier quoted context omitted.
What you have described is pretty much an opposite of how F-droid works. One can't just take binary (whether official or compromised) and upload it there. [1] Instead, to publish an app there, you need to provide source code repository [2], and their build farm would build it, sort-of [3] providing guarantee that source code you can inspect is the same one you got running on your phone. [1] There are exceptions, i.e.…
Signal has reproducible builds for Android: https://whispersystems.org/blog/reproducible-android/ ...that just doesn't work with F-Droid. And building on their farm means that you have to trust them, and their build farm becomes a prime target if you want to infect lots of apps at once. In the play store, you sign your build, and Android will only let you install builds signed with that same key as updates. By moving…
Re: Moxie Marlinspike Makes Encryption for Everyone
#77Watch his documentary "Hold Fast" to get a glimpse of just how unique and interesting a character he is. Anarchists yachting? Yes, more, please
Re: Moxie Marlinspike Makes Encryption for Everyone
#78Earlier quoted context omitted.
The person you are communicating with.
No, that's not how it works. The GCM message is empty, it just wakes up your device which then fetches the actual message from the Signal servers.
Edit (as i can't post you reply to your answer):
And based on the NSA principle of the "thee levels of distance" everybody is reachable as long as some common numbers are in our contact lists which we happily upload.
Re: Moxie Marlinspike Makes Encryption for Everyone
#79Watch his documentary "Hold Fast" to get a glimpse of just how unique and interesting a character he is. Anarchists yachting? Yes, more, please
Re: Moxie Marlinspike Makes Encryption for Everyone
#80Earlier quoted context omitted.
I don't buy his arguments. It's one thing to say we have to be on Google Play Store or we have to use phone numbers despite the privacy implications because that is what people use. But ignoring much of the developing countries (see whatsapp), China or the people who are your strongest user base by saying "you can just" isn't pragmatic at all. Nor is it actually reasonable that we should expect to or rely on a few pe…
> But ignoring much of the developing countries (see whatsapp), China Moxie says Signal works fine in China: https://github.com/LibreSignal/LibreSignal/issues/37#issueco...
"Signal itself works, but since Google is blocked no phones are sold with Google Play Store and even if you hack it onto your phone (which will break when it wants to update play services) it will drain your battery trying to connect to blocked services. Unless you use vpn (which will drain battery by itself and also eventually be blocked), but notifications probably still won't work because of the phones original firmware. So yes it works if you hack it onto your phone and then remove play services and checks the application manually. Until it wants to update the app that is, which is often.
Point. It doesn't really work because it only supports the Google Play Store, even as most Chinese phones can load apps directly (because of the fragmented ecosystem). So at least it doesn't work in the "prevent mass surveillance" way.
I guess maybe it works from the Apple App Store? (which isn't blocked)"