Live data from Hacker News

Wrong signal

it-kollektiv.com

21–30 of 84 posts

Re: Wrong signal

#21
It sometimes feels like the security community is a bucket of crabs where any time something starts getting traction due to ease of use a lot of others try to pick at it due to it not being perfect even if many of those things are trade offs

- phone numbers allow for signal to be a drop in replacement for other messaging apps with minimal to no registration required, I doubt I could have gotten my mother to use signal without switching from texting being so low-friction.

- lack of federation means ows can control spam better unlike in a federated environment where lazy/malicious operators can cause lots of problems. Take a look at the 2 big federated protocols email and irc where due to spam and other issues they are both increasingly centralized.

Re: Wrong signal

#22
Spot on, incredibly accurate reveal.

MarlinSpike is not his real name, and he will "sing like a canary" if the FEDS ever come calling, installing code for a backdoor or even a man in the middle attack for them on his servers.

It has always bothered me he demands your real phone number to register - - as well as he forbids anyone that uses his code from running it through their own servers (they must run only through his servers).

Add to the fact that he only allows distribution through the Google Play store means he likely eventually intends to sell off to a BigBox corporate player (and with the deal all your metadata too).

Re: Wrong signal

#23

I'm happy to use Signal today. In the long run federated protocols and servers demonstrated their resilience regarding third parties and time, see irc for example. Probably Signal is just a reference implementation, the big deal is implementing Signal protocol in different systems (whatsapp, allo, fb messenger..). Having said that, I would be happier to not give my phone number for registration, and contact discovery…

> the big deal is implementing Signal protocol in different systems (whatsapp, allo, fb messenger..) Strongly disagree. The point of Signal is not just that it's encrypted. The point is that the source code is GPL and the service is free. Holding up a bunch of closed-source, proprietary, for-profit applications as examples of success only serves to obscure what should be the real goal: decentralized, anonymous, metad…

> what should be the real goal:

You are describing what should be the goals in your opinion, not the one of Signal's developers.

Having something that works to show (Signal), was a big point to sell to those, closed and already used by many people, systems; so having a non federated Signal means they can iterate more often and change things how they more or less want.

Re: Wrong signal

#24
I love Signal. I use it as the primary means of contact for several close friends and have contributed patches. However, it drives me nuts that OWS won't allow federation or LibreSignal and requires phone numbers as user IDs. In the past, their justification has been that their primary goal is thwarting dragnet surveillance and none of these proposals further that goal (which is debatable in itself). I wish they would move more in the direction of an actual open source standard like they sort of purport to be rather than just an open source library with a closed implementation.

Re: Wrong signal

#25
Im surprised nobody has mentioned Quellen-TKÜ -- is there any evidence that governments can force handset vendors to push malware to devices?

I don't believe this, as it would make programs like QUANTUM* unneeded. Why subvert global internet infrastructure if the providers do the dirty work?

This would be explosive if true

Re: Wrong signal

#26

Spot on, incredibly accurate reveal. MarlinSpike is not his real name, and he will "sing like a canary" if the FEDS ever come calling, installing code for a backdoor or even a man in the middle attack for them on his servers. It has always bothered me he demands your real phone number to register - - as well as he forbids anyone that uses his code from running it through their own servers (they must run only through…

> he will "sing like a canary" if the FEDS ever come calling

You mean like when they came a month or so ago and all user data that OWS could hand over for the accounts in question was two timestamps?

Re: Wrong signal

#27

This is a fairly clear and level headed criticism, while I think the 'problem' of centralisation is over stated and the accusations about Signal's motivation are unfounded I do appreciate that the author(s?) understand why Signal is popular - "The success of OWS can also be attributed to elitist and bureaucratic positions in the open source community. " I don't see the federation issue as being particularly relevant…

The article also shows the problems with federation, although they do not acknowledge it:

> The drafted protocol is called OMEMO and combines the advantages of jabber and Signal. Even though the XEP Process will still take some time, the protocol is stable and can already be used today. On Android devices, users have the ‚Conversations‘ client [8], which offers an experience comparable to Signal, and on the desktop there is a plugin for ‚Gajim‘ [9, 10] under active development, which still has room for user experience improvements. Using one of the readily available tutorials, it is possible today to get started on Linux and Windows. iOS users will have to wait some time due to license issues.

Re: Wrong signal

#28
I do not see any comments to tackle the weakest link: exploits on the OS. Federated or not, the tunnel can be encrypted. On the servers static data can be encrypted. How can a regular user know his/her device's OS is not compromised? That is the problem to solve now and it seems that a formally verified OS code is the only long path.

Re: Wrong signal

#29

I do not see any comments to tackle the weakest link: exploits on the OS. Federated or not, the tunnel can be encrypted. On the servers static data can be encrypted. How can a regular user know his/her device's OS is not compromised? That is the problem to solve now and it seems that a formally verified OS code is the only long path.

That's not an argument for or against Signal, though, as it affects all messenger apps in the same way. While OS trustworthiness is an interesting topic, it's not really the one being discussed here.

Re: Wrong signal

#30

I love Signal. I use it as the primary means of contact for several close friends and have contributed patches. However, it drives me nuts that OWS won't allow federation or LibreSignal and requires phone numbers as user IDs. In the past, their justification has been that their primary goal is thwarting dragnet surveillance and none of these proposals further that goal (which is debatable in itself). I wish they woul…

You probably already know this, but OWS detailed their reasoning for not supporting federation at this time in their blog a while ago: https://whispersystems.org/blog/the-ecosystem-is-moving/
Post reply on HN