Live data from Hacker News

Wrong signal

it-kollektiv.com

51–60 of 84 posts

Re: Wrong signal

#51
post #39
post #21

It sometimes feels like the security community is a bucket of crabs where any time something starts getting traction due to ease of use a lot of others try to pick at it due to it not being perfect even if many of those things are trade offs - phone numbers allow for signal to be a drop in replacement for other messaging apps with minimal to no registration required, I doubt I could have gotten my mother to use signa…

This isn't the security community. The security community is pretty much unanimous in supporting Signal over all other secure messengers. That's not to say that security people aren't critical of Signal, which isn't perfect for all the reasons this blog post points out --- Grugq is a pretty good source for these kinds of criticisms through the lens of an infosec person. But security people tend to deliver these criti…

> This isn't the security community. The security community is pretty much unanimous in supporting Signal over all other secure messengers.

Sorry, but I am still yet to see the proclaimed unanimous support for Signal as a messenger. As a protocol – sure, most infosec professionals obviously support Axolotl, but this does not imply your statement in any way.

> The entities most harshly critical of Signal are supporters of other messaging applications and protocols.

So the support for Signal isn't that “unanimous” after all, is it?

Otherwise, of course they will if they think that Signal has lost the proper direction for some reason (according to their view). Even many protocol supporters prefer using something like WhatsApp or Wire, the former due to its purported network effect and the likes of the latter because of features like E2E encrypted file transfers, 1:1 video or group calls w/o apparent security trade-offs compared to Signal.

> I don't so much care what messaging system you use to talk to your friends or chat with your gaming guild. But if you have real adversaries, the security part of your messaging system has to work, even more than the messaging part. For that situation, Signal is the only messaging system I'd recommend unreservedly.

In the end, it turns out that this is your personal opinion, not that of the security community as a whole (hint: there is none), which is fine if you didn't misrepresent it in most of your post. The networks of other people may or may not choose to go a different way, although some (or even many) of them may support the same core technologies, just because they do not agree with some decisions OWS made along the way and don't want to reconsider for any reason opposing parties have presented, e.g. in articles like the one we are commenting under.

To sum up, feel free to suggest Signal as an instant messenger, but please be careful with your supporting claims because there are other great and upcoming messengers out there like Matrix, Wire, Onion.chat, GNU Ring, any of the mentioned elsewhere Telegram and WhatsApp, or many, many others. Signal has legitimate reasons on its side that will make your argument weigh more than unjustified claims that it should apparently be the end-all and be-all of one's instant messaging needs.

Re: Wrong signal

#52
post #39

Earlier quoted context omitted.

This isn't the security community. The security community is pretty much unanimous in supporting Signal over all other secure messengers. That's not to say that security people aren't critical of Signal, which isn't perfect for all the reasons this blog post points out --- Grugq is a pretty good source for these kinds of criticisms through the lens of an infosec person. But security people tend to deliver these criti…

> This isn't the security community. The security community is pretty much unanimous in supporting Signal over all other secure messengers. Sorry, but I am still yet to see the proclaimed unanimous support for Signal as a messenger. As a protocol – sure, most infosec professionals obviously support Axolotl, but this does not imply your statement in any way. > The entities most harshly critical of Signal are supporter…

I think you misread my comment, which didn't suggest that there is universal support for Signal among everyone, just among security professionals (I adopted the term "security community" from the parent comment, but I agree with the implied criticism that the term "security community" is largely meaningless).

A good way to rebut my claim would be to cite the most high-profile security engineer or security professional or crypto engineer or crypto scientist you can think of who recommends some other system over Signal.

Re: Wrong signal

#53
post #34

I'm repeating myself on many of these points, so I've cut and pasted some of my previous responses: > Signal uses servers controlled by OWS. Other organizations could conceivably operate their own servers because OWS open sources the software, but because OWS strictly opposes federation (meaning the interconnection of independently operated servers which the XMPP protocol (jabber) or e-mail allows), only the users co…

> I do not feel like the FOSS community is a "burden," however I do wish they recognized that many of their desires are unique to a very small minority of Signal users. I wish that they'd take more responsibility for manifesting those desires themselves. > This is the second time in two months that someone from the FOSS scene has written up a list of complaints, but as far as I know, in neither case have the authors ever contributed anything to Signal in an effort to meet their own needs.

I think that the interest in the FOSS community is relatively low given the centralized format in which Signal is offered. I know many people who are deeply into FOSS who would love an alternative to IRC but cannot be found even using Signal. But "their own needs" are completely out of bounds for you, and it seems pretty clear that this isn't something that's going to be fixed in patches and code, so expecting them to come and fix it because you have an open code base is rather disingenuous.

If you started by promoting Signal as a generic protocol or backend to other projects, it would get much more traction in the FOSS community, as they are attracted to components on which other things can be built.

You can claim that this is a reason to ignore the criticism. But, you will always be right in dismissing critiques like this as you've set up the environment in a way which limits the kind of constructive collaboration that is the hallmark of FOSS.

You will probably say this is not true and cite existing public contribution to the project. But what I am saying is that the interest and contribution would be orders of magnitude larger if you really ran the project in a traditionally open way. One hallmark of this would be federation. Whether or not this makes sense practically (the gmail metaphor applies obviously), it is something that people want an need to order to feel they have ownership of their work on a messaging platform. You're simply not going to talk your way out of this.

For human and community reasons, the upside to federation is probably a lot higher than you appreciate. I hope you consider it. You have built a nice platform, but for your work to make a lasting impact you need to share it with others.

Re: Wrong signal

#54
"After Donald Trump’s victory in the US presidential election in particular, many tweets recommended using hard disk encryption and the ostensibly secure messenger app Signal while discouraging the use of competitor apps Threema and Telegram."

Oh FFS. We've seen a continuation of invasive, Bush-era policies under Obama...but now Trump is terrifying?

Spoiler alert: it has been a problem for quite some time, and given the alternative to Trump it was going to still be a problem regardless of who won the election: freedom ponies and rainbows were never an option.

Get a damn grip, people. Can we end the partisan pity party?

Re: Wrong signal

#55

"After Donald Trump’s victory in the US presidential election in particular, many tweets recommended using hard disk encryption and the ostensibly secure messenger app Signal while discouraging the use of competitor apps Threema and Telegram." Oh FFS. We've seen a continuation of invasive, Bush-era policies under Obama...but now Trump is terrifying? Spoiler alert: it has been a problem for quite some time, and given…

> We've seen a continuation of invasive, Bush-era policies IRT the NSA under Obama...but now Trump is terrifying?

Uh, yeah. The Bush/Obama surveillance policies have largely been seen as dangerous not because of actual concrete harms that have materialized, but because if continued they raise the prospect of a much worse (because of the increased scope possible with modern tools) version of the kind of political targeting based on surveillance that was done by Nixon (prompting legal limits, notably the original FISA act.) And perhaps even beyond that, to the kind of retaliation for dissent seen in authoritarian regimes.

Trump is seen as the kind of figure that would be more likely than a more conventional candilate of either party to make those theoretical risks into concrete harms.

Re: Wrong signal

#56

Earlier quoted context omitted.

You probably already know this, but OWS detailed their reasoning for not supporting federation at this time in their blog a while ago: https://whispersystems.org/blog/the-ecosystem-is-moving/

I've seen it, I just disagree with it. IMO it's a dick move to say "no federation" and to also say "no 3rd-party clients." What's the point of GPL if you're completely locked to their official clients & servers anyway?

Code auditing.

Re: Wrong signal

#57

"After Donald Trump’s victory in the US presidential election in particular, many tweets recommended using hard disk encryption and the ostensibly secure messenger app Signal while discouraging the use of competitor apps Threema and Telegram." Oh FFS. We've seen a continuation of invasive, Bush-era policies under Obama...but now Trump is terrifying? Spoiler alert: it has been a problem for quite some time, and given…

> We've seen a continuation of invasive, Bush-era policies IRT the NSA under Obama...but now Trump is terrifying? Uh, yeah. The Bush/Obama surveillance policies have largely been seen as dangerous not because of actual concrete harms that have materialized, but because if continued they raise the prospect of a much worse (because of the increased scope possible with modern tools) version of the kind of political targ…

I'm not buying it.

The house is already on fire, and people are wringing their hands because the new owner might have a can of lighter fluid in his pocket.

Re: Wrong signal

#58
post #3

There are always security trade-offs (especially when it comes to ease of use) but until you can show me a better app, which I can get my non-techy friends to use , Signal remains the best option for the mass market.

Phone-number as identifier is pretty terrible user-experience choice. I am traveling and my phone-number has changed half-a-dozen times in the past year alone, my email has been the same for over a decade. I tend to use Whatsapp because other people already have it but I have absolutely no motivation to use encourage other people to use Signal. Edit: Whoever down-voted this, want to explain how this isn't a huge user…

You also have the reverse problem which is alluded to in the article, that a Phone number for a non-traveller, is pretty static and unlikely to be changed by the user often. However Email is more disposable and I can spin up and shut down email accounts that I could register with Signal et., al. for what I believe to be sensitive communications.

I feel that providers that use number-as-identity know this and use it as a way of assuring they have greater confidence of knowing their user, especially after everyone failed so spectacularly at real names policies.

Re: Wrong signal

#59
post #3

There are always security trade-offs (especially when it comes to ease of use) but until you can show me a better app, which I can get my non-techy friends to use , Signal remains the best option for the mass market.

Phone-number as identifier is pretty terrible user-experience choice. I am traveling and my phone-number has changed half-a-dozen times in the past year alone, my email has been the same for over a decade. I tend to use Whatsapp because other people already have it but I have absolutely no motivation to use encourage other people to use Signal. Edit: Whoever down-voted this, want to explain how this isn't a huge user…

Why does your phone number keep changing?

Re: Wrong signal

#60
post #47
post #39

Earlier quoted context omitted.

This isn't the security community. The security community is pretty much unanimous in supporting Signal over all other secure messengers. That's not to say that security people aren't critical of Signal, which isn't perfect for all the reasons this blog post points out --- Grugq is a pretty good source for these kinds of criticisms through the lens of an infosec person. But security people tend to deliver these criti…

How can you reasonably suggest trusting a mobile device if you have "real adversaries"? If you define your threat model to include any serious governmental interest, you cannot trust a cell phone. They have an always on network connection, remote auto-upgrade capability (at least for the baseband, if not the user software), and built-in microphone, cameras, gps, and other sensors.

Spot on. Many companies pushing "secure" applications conveniently forget to warn users about the false sense of security. The cryptography might be flawless, but everything else...
Post reply on HN