Live data from Hacker News

Wrong signal

it-kollektiv.com

1–10 of 84 posts

Re: Wrong signal

#2
Given that we've seen exactly how little information Signal maintains about its users [0], this seems to me to be alarmist spreading of FUD, potentially to advance the author's agenda of dfederation in Signal, which the developers have already addressed at length already [1].

For example, their assertion that "... metadata is abundantly available here" appears to be patently false, given [0].

0: https://www.aclu.org/blog/free-future/new-documents-reveal-g...

1: https://whispersystems.org/blog/the-ecosystem-is-moving/

Re: Wrong signal

#3
There are always security trade-offs (especially when it comes to ease of use) but until you can show me a better app, which I can get my non-techy friends to use, Signal remains the best option for the mass market.

Re: Wrong signal

#4
post #2

Given that we've seen exactly how little information Signal maintains about its users [0], this seems to me to be alarmist spreading of FUD, potentially to advance the author's agenda of dfederation in Signal, which the developers have already addressed at length already [1]. For example, their assertion that "... metadata is abundantly available here" appears to be patently false, given [0]. 0: https://www.aclu.org/…

Regardless of the merits of Signal, much of the criticism voiced in that article is nonetheless valid. Signal and other chat platforms employing the protocol are run as data-silos by design, using strongly identifying codes (phone numbers) as the required identifier — i.e., it is nearly impossible to create a throw-away account, because getting an anonymous phone number is no longer a practical possibility in a lot of (Western!) countries.

Whether or not such metadata is available to adversaries (either through OWS or gathered elsewhere) depends on who your adversaries are and whether or not a corporate entity can be trusted to be completely transparent about what kind of data they retain.

As for [0]; even if no relevant metadata is collected today by whoever owns the servers, nothing stops the party providing the service from doing so tomorrow.

Re: Wrong signal

#5
post #2

Given that we've seen exactly how little information Signal maintains about its users [0], this seems to me to be alarmist spreading of FUD, potentially to advance the author's agenda of dfederation in Signal, which the developers have already addressed at length already [1]. For example, their assertion that "... metadata is abundantly available here" appears to be patently false, given [0]. 0: https://www.aclu.org/…

> appears to be patently false

Even if it is claimed that the metadata miraculously wasn't collected (provided it really wasn't collected under some other publicly invisible arrangement, which is still technically doable) that doesn't prove it is impossible to do so, especially as the result of another secret request.

I don't see the "FUD" in the article. It seems very popular using labels instead of talking about issues, but please, please don't.

The phone number problems were known since long, and the Signal's explanation "it's easier for the average user this way" doesn't explain why other alternatives aren't even allowed.

It's obvious there are certain goals behind Signal, and those with different goals have to organize themselves. What they surely can't do is claiming to have right to decide what Signal (as a company) does. If those who have clear needs want to introduce their own solution, they surely have to demonstrate what the Signal doesn't solve, and that's surely not FUD.

Re: Wrong signal

#6
post #2

Given that we've seen exactly how little information Signal maintains about its users [0], this seems to me to be alarmist spreading of FUD, potentially to advance the author's agenda of dfederation in Signal, which the developers have already addressed at length already [1]. For example, their assertion that "... metadata is abundantly available here" appears to be patently false, given [0]. 0: https://www.aclu.org/…

Federation was only addressed insofar as Moxie Marlinspike the developer noted it would be hard to keep the protocol updated if the servers were shared (he compared his tech to Facebook and WhatsApp, and described federated email as "stuck in time").

There's nothing unduly alarmist about the article, but it makes appropriate claims about (among other things) the security limitations that Signal has resigned itself to by remaining unfederated. Read TFA.

Re: Wrong signal

#7
post #4
post #2

Given that we've seen exactly how little information Signal maintains about its users [0], this seems to me to be alarmist spreading of FUD, potentially to advance the author's agenda of dfederation in Signal, which the developers have already addressed at length already [1]. For example, their assertion that "... metadata is abundantly available here" appears to be patently false, given [0]. 0: https://www.aclu.org/…

Regardless of the merits of Signal, much of the criticism voiced in that article is nonetheless valid. Signal and other chat platforms employing the protocol are run as data-silos by design, using strongly identifying codes (phone numbers) as the required identifier — i.e., it is nearly impossible to create a throw-away account, because getting an anonymous phone number is no longer a practical possibility in a lot o…

We should learn from the failures of the past (PGP) and not forget that in practise all electronic communication (by phone, email, etc.) has been completely unprotected for pretty much everyone. With large services like Gmail and Facebook mining the data, the situation is arguably even worse.

So the less than perfect steps we have been seeing recently (widespread transport encryption in email, end-to-end encryption in WhatsApp and Signal) are a huge improvement.

Re: Wrong signal

#8
post #2

Given that we've seen exactly how little information Signal maintains about its users [0], this seems to me to be alarmist spreading of FUD, potentially to advance the author's agenda of dfederation in Signal, which the developers have already addressed at length already [1]. For example, their assertion that "... metadata is abundantly available here" appears to be patently false, given [0]. 0: https://www.aclu.org/…

Centralization is a _huge_ privacy issue. Specially when combined with real world data, like a phone number.

Let's assume OWS is playing nice, and they really don't store any relevant metadata. How can we be sure that a third party is not eavesdropping their communications?

Even with end-to-end encryption, given enough time, an attacker can easily build a user relationship network, something _very_ dangerous in the wrong hands.

If you really care about privacy, you should consider options like BitMessage, Onion.chat, Ricochet, Tox or GNU Ring. Or, as a middle ground between those (which are quite mobile unfriendly, due to its P2P nature) and Signal/WhatsApp/Telegram, a federated service like XMPP (as the article suggest) or Matrix.

Re: Wrong signal

#9
post #4
post #2

Given that we've seen exactly how little information Signal maintains about its users [0], this seems to me to be alarmist spreading of FUD, potentially to advance the author's agenda of dfederation in Signal, which the developers have already addressed at length already [1]. For example, their assertion that "... metadata is abundantly available here" appears to be patently false, given [0]. 0: https://www.aclu.org/…

Regardless of the merits of Signal, much of the criticism voiced in that article is nonetheless valid. Signal and other chat platforms employing the protocol are run as data-silos by design, using strongly identifying codes (phone numbers) as the required identifier — i.e., it is nearly impossible to create a throw-away account, because getting an anonymous phone number is no longer a practical possibility in a lot o…

The critics are valid, the solutions are not (for activists, as it's it focus)

Conversations.im was (or is, haven't checked in a month) logs encrypted chats on cleartext by default, and history shows why that is a bad idea [0]

Until today I haven't seen a single XMPP that protects metadata, the roster is always on cleartext, to support omemo you are storing yet more info always, etc.

If the answer to Signal issues is XMPP, there is a lot of work to do before to even suggest going this path.

[0]: https://trac.adium.im/ticket/15722

Re: Wrong signal

#10
This is a fairly clear and level headed criticism, while I think the 'problem' of centralisation is over stated and the accusations about Signal's motivation are unfounded I do appreciate that the author(s?) understand why Signal is popular - "The success of OWS can also be attributed to elitist and bureaucratic positions in the open source community. "

I don't see the federation issue as being particularly relevant - at least not until someone else actually sets up a non-OWS server and gains some users for it.

Post reply on HN