Live data from Hacker News

Wrong signal

it-kollektiv.com

71–80 of 84 posts

Re: Wrong signal

#71
post #64
post #44

Earlier quoted context omitted.

> It sometimes feels like the security community is a bucket of crabs where any time something starts getting traction due to ease of use a lot of others try to pick at it due to it not being perfect even if many of those things are trade offs That's because when it comes to security often theoretical vulnerabilities end up being protocol-destroying vulnerabilities in practice. Security folks are notorious for saying…

> That's because when it comes to security often theoretical vulnerabilities end up being protocol-destroying vulnerabilities in practice. Security folks are notorious for saying, 'that won't work,' being ignored — and then everyone being surprised when indeed it doesn't work. we're not talking about protocol destroying bugs, were talking about things firmly in the realm of trade offs between marginal security gains…

> If there is no central directory of identifiers to public keys, there's no way my mom will use it to send me anything

She'd never use an app where you two bump phones with NFC?

Re: Wrong signal

#72
post #59

Earlier quoted context omitted.

Why does your phone number keep changing?

Because that's how things are, at least in some locations. When you move to another city or state, you either suffer extra roaming costs (and incur some on your peers, as they'll be calling "long-distance" numbers even if you're physically close), or get a new (local) SIM/phone number. At least, that's what my experience is. This must be even more true when moving to another country. (Surely, there also must be some…

At least within the US, you're supposed to be able to port your number anywhere, so you don't have to change your number just because you moved. I don't know how this works in the rest of the world though.

Re: Wrong signal

#73
post #71
post #64

Earlier quoted context omitted.

> That's because when it comes to security often theoretical vulnerabilities end up being protocol-destroying vulnerabilities in practice. Security folks are notorious for saying, 'that won't work,' being ignored — and then everyone being surprised when indeed it doesn't work. we're not talking about protocol destroying bugs, were talking about things firmly in the realm of trade offs between marginal security gains…

> If there is no central directory of identifiers to public keys, there's no way my mom will use it to send me anything She'd never use an app where you two bump phones with NFC?

I don't think her phone has NFC, it might but she wouldn't know if it did. But I don't always see her in person that often, which means we'd have to wait until we were face to face before we could even try to see if she had NFC etc.

Re: Wrong signal

#74

Earlier quoted context omitted.

I've seen it, I just disagree with it. IMO it's a dick move to say "no federation" and to also say "no 3rd-party clients." What's the point of GPL if you're completely locked to their official clients & servers anyway?

Code auditing.

lol no. You could accomplish that with an all-rights-reserved copyright.

Re: Wrong signal

#75
post #52

Earlier quoted context omitted.

> This isn't the security community. The security community is pretty much unanimous in supporting Signal over all other secure messengers. Sorry, but I am still yet to see the proclaimed unanimous support for Signal as a messenger. As a protocol – sure, most infosec professionals obviously support Axolotl, but this does not imply your statement in any way. > The entities most harshly critical of Signal are supporter…

I think you misread my comment, which didn't suggest that there is universal support for Signal among everyone , just among security professionals (I adopted the term "security community" from the parent comment, but I agree with the implied criticism that the term "security community" is largely meaningless). A good way to rebut my claim would be to cite the most high-profile security engineer or security profession…

Unfortunately, and to a large extent why people listen to "open source advocates", the community of security professionals has a surprisingly bad record when it come to things like risk analysis, legal matters, understanding how law enforcement or intelligence agencies work and other ”soft skills”. I trust security professionals when it comes to crypto. Anything else I'm not convinced they aren’t as incompetent as everyone else in software and maybe even more so.

Re: Wrong signal

#76

Earlier quoted context omitted.

Phone-number as identifier is pretty terrible user-experience choice. I am traveling and my phone-number has changed half-a-dozen times in the past year alone, my email has been the same for over a decade. I tend to use Whatsapp because other people already have it but I have absolutely no motivation to use encourage other people to use Signal. Edit: Whoever down-voted this, want to explain how this isn't a huge user…

You also have the reverse problem which is alluded to in the article, that a Phone number for a non-traveller, is pretty static and unlikely to be changed by the user often. However Email is more disposable and I can spin up and shut down email accounts that I could register with Signal et., al. for what I believe to be sensitive communications. I feel that providers that use number-as-identity know this and use it a…

> Phone number for a non-traveller, is pretty static and unlikely to be changed by the user often. However Email is more disposable

I entirely disagree. Even without traveling outside the US - my US phone-number has changed several times (change of carrier etc.); while it is possible to spin-up and shutdown email accounts (e.g. dummy accounts for services requiring registration) -- by this time most individuals should have a single serious account (and a larger percentage in the future): online bank statements, online bills, online shopping -- do you really not have a single primary account?

Re: Wrong signal

#77
post #75
post #52

Earlier quoted context omitted.

I think you misread my comment, which didn't suggest that there is universal support for Signal among everyone , just among security professionals (I adopted the term "security community" from the parent comment, but I agree with the implied criticism that the term "security community" is largely meaningless). A good way to rebut my claim would be to cite the most high-profile security engineer or security profession…

Unfortunately, and to a large extent why people listen to "open source advocates", the community of security professionals has a surprisingly bad record when it come to things like risk analysis, legal matters, understanding how law enforcement or intelligence agencies work and other ”soft skills”. I trust security professionals when it comes to crypto. Anything else I'm not convinced they aren’t as incompetent as ev…

So, I totally agree with this but would like to know more, specifically, about why you believe it, to avoid talking past you. What are your specific concerns?

Re: Wrong signal

#78

Earlier quoted context omitted.

> he will "sing like a canary" if the FEDS ever come calling You mean like when they came a month or so ago and all user data that OWS could hand over for the accounts in question was two timestamps?

Parent had a good point. It shouldn't have been flagged.

He might have a point, but he forgot to mention any evidence for his claims.

Re: Wrong signal

#79
post #68
post #53

Earlier quoted context omitted.

> I do not feel like the FOSS community is a "burden," however I do wish they recognized that many of their desires are unique to a very small minority of Signal users. I wish that they'd take more responsibility for manifesting those desires themselves. > This is the second time in two months that someone from the FOSS scene has written up a list of complaints, but as far as I know, in neither case have the authors…

> But "their own needs" are completely out of bounds for you, and it seems pretty clear that this isn't something that's going to be fixed in patches and code, so expecting them to come and fix it because you have an open code base is rather disingenuous. Many of the things listed in these articles, such as making GCM optional, or supporting distribution outside of Play, are not "completely out of bounds." We've expr…

> Many of the things listed in these articles, such as making GCM optional, or supporting distribution outside of Play, are not "completely out of bounds." We've expressly indicated support for them and enumerated the work required, but nobody has committed to doing the work.

> I don't expect anyone to do the work, but I do think it's strange when someone from the FOSS community complains that we haven't done it for them.

The linked article notes that you have not been so supportive of such developments in the past:

> The community reacted to this by developing a version that does not rely on GCM, however, OWS refused to merge the changes into the Signal code. When the project was forked, they prevented the newly established LibreSignal project [5] from connecting to Signal’s servers and prohibited the use of the term “Signal” in their name.

Reading through the comments that are linked it looks like you mostly had technical concerns about the work. Is that correct?

Clearly the perception of your actions is different than you intend. In your comment here you make it sound like no one had even attempted to do resolve these issues. But that's not what the author of the article believes, and given the public record I'm inclined to agree.

> I'd definitely reconsider if people have a plan for avoiding the problems that we encountered the first time, beyond "federation is good." In the mean time I'm happy to help anyone deploying Signal in their own federated environment.

Your key point is that you're content if people do federation in their own, outside of your domain. That's fair. But what I'm saying is the dream of a federated secure messaging system that's also popular is something which you have the power to chase if you commit to it by making it a core feature of Signal.

Re: Wrong signal

#80
post #63
post #53

Earlier quoted context omitted.

> I do not feel like the FOSS community is a "burden," however I do wish they recognized that many of their desires are unique to a very small minority of Signal users. I wish that they'd take more responsibility for manifesting those desires themselves. > This is the second time in two months that someone from the FOSS scene has written up a list of complaints, but as far as I know, in neither case have the authors…

I think that the interest in the FOSS community is relatively low given the centralized format in which Signal is offered. How is Signal offered in a 'centralized' way? There is a free and open-source implementation that already (according to Moxie) supports federation. And a standing offer from the authors to help anyone doing further work on federation. What more could one reasonably expect, short of demanding OWS…

Do read the linked article. It describes the situation quite a bit better than I can.
Post reply on HN