I'm happy to use Signal today. In the long run federated protocols and servers demonstrated their resilience regarding third parties and time, see irc for example. Probably Signal is just a reference implementation, the big deal is implementing Signal protocol in different systems (whatsapp, allo, fb messenger..). Having said that, I would be happier to not give my phone number for registration, and contact discovery…
I'm surprised to see that matrix.org / riot.im is not mentioned as an alternative to Signal. They have a federated, open protocol, usable open-source apps for web/Android/iOS, registration without a phone number (even email is optional), do not require Google Play, and support double-ratchet encryption (in beta, it's not activated by default yet, but it will be activated by default in private rooms in the future).
Wrong signal
31–40 of 84 posts
Re: Wrong signal
#32Yet, they "worked with" Facebook and WhatsApp to incorporate their protocols presumably providing them with an alternative license. It sure would be nice if companies who wish to add encryption to their messaging products, but didn't have the pull of the bigger guys to warrant OWS's attention, could just use an LGPLed library to do so. If OWS's mission is to bring about widespread encrypted communications, playing favorites with a few larger messaging companies seems to send the wrong message.
(The points made in the article, while valid, seem to be splitting hairs relative to the overall net good Signal has provided.)
Re: Wrong signal
#33My main beef with signal is that they release their encryption libraries as GPLv3 not LGPLv3, preventing the use of them in any commercial product that doesn't want to open their source code. Yet, they "worked with" Facebook and WhatsApp to incorporate their protocols presumably providing them with an alternative license. It sure would be nice if companies who wish to add encryption to their messaging products, but d…
Re: Wrong signal
#34> Signal uses servers controlled by OWS. Other organizations could conceivably operate their own servers because OWS open sources the software, but because OWS strictly opposes federation (meaning the interconnection of independently operated servers which the XMPP protocol (jabber) or e-mail allows), only the users connected to the OWS-run server can communicate with each other.
I've tried to write about why I don't feel like this is going to be a part of our future here: https://whispersystems.org/blog/the-ecosystem-is-moving/
However, I would love it if someone proved me wrong. The Signal clients and server already support federation, so there shouldn't be any technical hurdles stopping the people who are really into federation from using our software to start their own federated network that demonstrates the viability of their ideas.
If anyone needs help doing that, let me know. I'd be happy to help.
> If a government does not approve of the use of Signal, it can simply block a single server farm, solving the problem for the state actor, and resulting in total loss of service to the users.
The authors of this article conflate a lot of things with federation. Federation = anonymity, federation = metadata protection, federation = censorship circumvention.
I don't think any of those are true. Email is federated, and I run my own mail server, but almost every single email I send or receive has GMail at the other end of it -- so running my own server does not provide me with any meaningful metadata protection, even though it is a federated protocol. The idea that everyone in the world is going to run their own mail server (or messaging server, or whatever) has not born out in practice, even in environments that natively support federation.
I think serious metadata protection is going to require new protocols and new techniques, so we're much more likely to see major progress in centralized environments that can change rather than federated environments that are stuck in time (in the same way that Signal Protocol is now on over two billion devices, but we're unlikely to ever see even basic large scale email end to end encryption).
In the case of censorship circumvention, I think it's much more common that people use censorship circumvention tools like VPNs or Tor rather than changing their entire federated identifier (and somehow re-discovering their entire social graph doing the same) every time a service gets blocked, particularly since censorship isn't just as simple as host-level filtering these days.
Again, I think we're more likely to see the incorporation of these types of censorship circumvention techniques into centralized rather than federated services.
> The community reacted to this by developing a version that does not rely on GCM, however, OWS refused to merge the changes into the Signal code.
I don't believe this is true. To clarify this for casual readers, no data at all is transmitted over GCM. GCM is only used as a push event to tell the Signal Android client to wake up and connect to the Signal server to retrieve messages from the queue if the app isn't in the foreground.
This is pretty fundamentally just how Android works. However, people who want to use Google's OS without any Google services flash custom ROMs onto their devices that are missing this dependency.
I have said many times that I have no problem with supporting these custom ROMs. But I would like someone from that community to submit the PR: "I would consider a clean, well written, and well tested PR for websocket-only support in Signal. I expect it to have high battery consumption and an unreliable user experience, but would be fine with it if it comes with a warning and only runs in the absence of play services."
Nobody has done it.
> The final point of criticism is that OWS distributes the Signal app exclusively via Google Play while actively preventing the distribution of independent builds.
We'd love to distribute Signal outside of Play, and have written about what we would need to be able to do so. As of yet, nobody from the FOSS community has stepped in to help.
We'll get there eventually on our own, but we have a lot of work on our plate, and have to set our priorities according to what we think is important for Signal as a whole.
> The community’s demands for decentralized web services controlled by the users themselves, or by designated professionals elected by the users, seems like a burden to them.
I do not feel like the FOSS community is a "burden," however I do wish they recognized that many of their desires are unique to a very small minority of Signal users. I wish that they'd take more responsibility for manifesting those desires themselves.
This is the second time in two months that someone from the FOSS scene has written up a list of complaints, but as far as I know, in neither case have the authors ever contributed anything to Signal in an effort to meet their own needs.
Re: Wrong signal
#35There are always security trade-offs (especially when it comes to ease of use) but until you can show me a better app, which I can get my non-techy friends to use , Signal remains the best option for the mass market.
Phone-number as identifier is pretty terrible user-experience choice. I am traveling and my phone-number has changed half-a-dozen times in the past year alone, my email has been the same for over a decade. I tend to use Whatsapp because other people already have it but I have absolutely no motivation to use encourage other people to use Signal. Edit: Whoever down-voted this, want to explain how this isn't a huge user…
The phone number linking seems completely superfluous and has destroyed the user experience for me by preventing me from connecting with anyone else.
This design decision will become increasingly anachronistic in the near future, as phone numbers further diminish in importance.
Re: Wrong signal
#36It sometimes feels like the security community is a bucket of crabs where any time something starts getting traction due to ease of use a lot of others try to pick at it due to it not being perfect even if many of those things are trade offs - phone numbers allow for signal to be a drop in replacement for other messaging apps with minimal to no registration required, I doubt I could have gotten my mother to use signa…
The criticism of signal's closed ecosystem is not new, this is just another write-up of what has been criticized numerous times before.
Re: Wrong signal
#37It sometimes feels like the security community is a bucket of crabs where any time something starts getting traction due to ease of use a lot of others try to pick at it due to it not being perfect even if many of those things are trade offs - phone numbers allow for signal to be a drop in replacement for other messaging apps with minimal to no registration required, I doubt I could have gotten my mother to use signa…
I still have the biggest difficulties to persuade my "normal" friends and relatives to prefer signal over whatsapp.
Everybody thinks whatsapp is more user friendly and convenient. In the end this is the key to adoption we should not forget that.
Re: Wrong signal
#38Spot on, incredibly accurate reveal. MarlinSpike is not his real name, and he will "sing like a canary" if the FEDS ever come calling, installing code for a backdoor or even a man in the middle attack for them on his servers. It has always bothered me he demands your real phone number to register - - as well as he forbids anyone that uses his code from running it through their own servers (they must run only through…
> he will "sing like a canary" if the FEDS ever come calling You mean like when they came a month or so ago and all user data that OWS could hand over for the accounts in question was two timestamps?
Re: Wrong signal
#39It sometimes feels like the security community is a bucket of crabs where any time something starts getting traction due to ease of use a lot of others try to pick at it due to it not being perfect even if many of those things are trade offs - phone numbers allow for signal to be a drop in replacement for other messaging apps with minimal to no registration required, I doubt I could have gotten my mother to use signa…
The entities most harshly critical of Signal are supporters of other messaging applications and protocols.
I think the most important thing to understand about secure messengers is that messaging in general is a back-ally knife fight of a market, one of the most vicious I've seen in my career. Perhaps it's because of the WhatsApp outcome and a general belief that there's another such outcome for some other messaging app. Or it could just be the network affect. Messaging applications themselves are interesting UX challenges, but as programming challenges they're pretty close to socket projects. So there are a lot of entrants in the market. Whatever the reason, the knives are out for Signal.
I don't so much care what messaging system you use to talk to your friends or chat with your gaming guild. But if you have real adversaries, the security part of your messaging system has to work, even more than the messaging part. For that situation, Signal is the only messaging system I'd recommend unreservedly.
Re: Wrong signal
#40I do not see any comments to tackle the weakest link: exploits on the OS. Federated or not, the tunnel can be encrypted. On the servers static data can be encrypted. How can a regular user know his/her device's OS is not compromised? That is the problem to solve now and it seems that a formally verified OS code is the only long path.
That's not an argument for or against Signal, though, as it affects all messenger apps in the same way. While OS trustworthiness is an interesting topic, it's not really the one being discussed here.
Quoting:
There are many things users can and maybe should be concerned about: Hackers, providers, promoters, crooks, spooks, shareholders or maybe the person on the next seat in the bus. Do they want to prevent their data from being used for other purposes than communication itself? Maybe they want their messages to be tamper-evident, or perhaps they want plausible deniability or immunity against eavesdropping? What is the use of end-to-end encryption when there could be a key logger or a rootkit on their device, transmitting everything they do to a remote entity? Encouraging users to believe in a general sense that Signal makes their communication safe, will tend to promote a false sense of once-and-for-all security (regardless of the indisputable and substantial increase in end-to-end encryption). It is very important to remember that even though encryption will increase security, some information should not be stored in IT systems at all – and especially not if they are provided by a third party.
However this is no argument against the use of the Signal messenger or protocol itself. We instead want to think about the problems created or supported by OWS‘ promise of security.