Live data from Hacker News

Worried About the Privacy of Your Messages? Download Signal

nytimes.com

101–110 of 247 posts

Re: Worried About the Privacy of Your Messages? Download Signal

#101
post #67

Earlier quoted context omitted.

Chaps. I think it's time we just admitted that everything we type/tap/say into any device, regardless of how it's being wrapped up in transit, is absolutely and irrepairably insecure and we're not going to be able to fix that anytime soon. Even with really smart crypto or some slick app; what makes you think that your messages aren't just being read by your os? Would you really notice? Why would you assume that the a…

> I think it's time we just admitted that everything we type/tap/say into any device, regardless of how it's being wrapped up in transit, is absolutely and irrepairably insecure and we're not going to be able to fix that anytime soon. We dont have to set the bar that high. Just lower it slightly and we can achieve great success. Can we make the job of NSA and CIA harder? Not necessarily impossible, just to increase t…

I'm not sure there are many ways to make things harder when the complexity of the systems we have even in our pockets make them so very hard/impossible to even observe let alone protect.

There are too many places, even on a phone, where anything at all can be hiding and we don't really have any way of ever knowing what's there without stepping through the binaries.. That's even more difficult when we've got dalvik and VM's involved. How many people alive do you think could work out exactly what your mobile does in any one second within say, 6 months? ..

For all we know the thompson compiler backdoor really happens, and so how can you even trust the binaries you're producing?

Do you know anyone who built, for instance the openssl.so on their phone personally? Did that person build it on a machine they trust? How can they trust that machine? A single lib with a nefarious function on the few GB of binaries which ship with your phone is enough to completely negate any 'security' these sorts of apps could provide; even if they were trustworthy to begin with which they're obviously not.

It's a charade, assume everything you do is completely observed, regardless of crypto/apps you use.

Even if you have a fully audited and trustworthy (in your view) OS -- then what about IME? Who says that the CA that issued the certs you trust and talk to isn't also feeding them out to the gov or whatever? Who says your HDD isn't talking to the zigbee thermostat in your house and sending your rsa keys to the pentagon? Who says yo home wifi point isn't acting as a decrypting proxy?

We cant tell, and that's the point. There is no way to ever observe these levels complexity and verify security and we don't admit it.

We will never know if the code we are running on our various devices is doing anything extra or not, and so rationally, we should never trust it at all.

Not to say all sec is pointless, you don't want to be low hanging fruit, but above 'insta-pwn' levels of stupid there isn't much more available, even if you're told there is and we keep pretending like we have any control over what's going on anymore...

Re: Worried About the Privacy of Your Messages? Download Signal

#102
post #14

All the privacy solutions on the market are varying degrees of bad (from a privacy/security/freedom perspective), by which I mean they're all flawed in their own ways. Signal requires Google Play Services on Android. That means it's put simply not a privacy messenger. Yes there's crypto, but it's also tied into Whisper Systems' infrastructure, there's no federation. I use Signal reluctantly, and only on IOS. Threema,…

Re: Google Play Services. Here's is the way I understand this to work, so please do correct me if I'm wrong.

Signal uses Google Play Services to notify me that I have an incoming message from Signal. The Signal app is then woken up and the signal app then retrieves my (encrypted) message. So, therefore, the only thing Google knows is that I received a Signal message, what time and if I have location services on, where I was at the time, yes?

On iOS, how is this any different? If I get a notification, iOS knows I got a notification from signal, when and where i was at if Location is turned on.

What am I missing?

Note: I _don't_ like that either system has that much meta data about my conversations available to them, but I don't see how one is better than the other, here.

Re: Worried About the Privacy of Your Messages? Download Signal

#103
post #14

All the privacy solutions on the market are varying degrees of bad (from a privacy/security/freedom perspective), by which I mean they're all flawed in their own ways. Signal requires Google Play Services on Android. That means it's put simply not a privacy messenger. Yes there's crypto, but it's also tied into Whisper Systems' infrastructure, there's no federation. I use Signal reluctantly, and only on IOS. Threema,…

Chaps. I think it's time we just admitted that everything we type/tap/say into any device, regardless of how it's being wrapped up in transit, is absolutely and irrepairably insecure and we're not going to be able to fix that anytime soon. Even with really smart crypto or some slick app; what makes you think that your messages aren't just being read by your os? Would you really notice? Why would you assume that the a…

Maybe hiding our messages from Google is worthwhile even if we can't hide them from the NSA.

Re: Worried About the Privacy of Your Messages? Download Signal

#104

I'm worried about the freedom of dissenting opinion in civil society from surveillance, not the privacy of my messages. Privacy is something I would easily give up for such freedom. Signal seems to me to one tool in a large profile to maintain freedom of information dissemination and information gathering activity. It seems to me that speaking to a large number of people anonymously is not possible with any of the ex…

Can a book (print or electronic) not be published anonymously or under a pseudonym?

Re: Worried About the Privacy of Your Messages? Download Signal

#105

There are a lot of people on this thread crapping on Signal for its various flaws and downsides. It's nice to be smarter and more informed than everyone, but for the rest of us we really need advice about what we SHOULD do if we want a baseline amount of privacy from mass surveillance. I'm honestly asking here--I don't have the knowledge that many in this community do about the exact risk of Signal requiring Google P…

The Tox project is specifically designed to meet your usability requirements. There were also forks of Signal which fixed the privacy issues, however Moxie Marlinspike (the founder of Open Whisper Systems) ordered them to cease and desist.

I think it is important to note that Tox is still considered alpha. From their own wiki's FAQ:

"Tox is by no means complete. You may encounter bugs ranging from simple visual defects to segfaults on file shares. We cannot guarantee what works today will work tomorrow; Tox is an alpha program and code changes daily. Certain commits may break existing APIs, and we strive to give proper advanced warning to all client developers, etc. when such changes will be made. Additionally, Tox has not yet received a full security audit. While we believe Tox is secure against attackers who want to decrypt your messages, you may wish to use a more established solution if you are in a life-or-death situation."

If you're in a life-or-death situation, I think you really ought to be doing some intensive research into secure communications to find the solution that will work best for you.

Re: Worried About the Privacy of Your Messages? Download Signal

#106
post #95

Earlier quoted context omitted.

however Moxie Marlinspike (the founder of Open Whisper Systems) ordered them to cease and desist Would you be kind enough to provide links? I can't find any information about this claim via Google, and Signal is distributed under the GPLv3, which grants rights to fork and modify it: https://github.com/WhisperSystems/Signal-Android

https://github.com/LibreSignal/LibreSignal

Thank you!

tl;dr: You can fork the Signal code if you want, but if you do, Moxie Marlinspike asks you to change the app name and run your own servers. The server source code appears to be available at https://github.com/WhisperSystems/Signal-Server, but I've heard it doesn't include the voice component.

So, for example, if you think that Signal ought to support a feature like iMessage's "Invisible Ink" (https://mic.com/articles/146347/i-os-10-s-invisible-ink-feat...), which Moxie has specifically refused to support (https://github.com/WhisperSystems/Signal-Android/issues/5103), then you can't just fork the client, implement it yourself, and use the new client normally, because you'd no longer be able to talk to regular Signal client if I understand correctly. I mean, even if you figured out a way for two clients to tell each other whether or not the feature was available.

So Signal is open source, but not in a way that's useful if you want to change something.

I don't want to discourage people from using Signal. It's a great app. But I thought this was worth pointing out, assuming the LibreSignal is representative of what will happen if people want to make changes to their client.

Re: Worried About the Privacy of Your Messages? Download Signal

#107
post #8

Earlier quoted context omitted.

This looks like a really good replacement for Skype, which we currently use to manage communication between remote working team members.

Until it's owner decides to sell it to eBay or MS like he did with Skype.

Which is a risk with every service we use...

Re: Worried About the Privacy of Your Messages? Download Signal

#108
post #14

All the privacy solutions on the market are varying degrees of bad (from a privacy/security/freedom perspective), by which I mean they're all flawed in their own ways. Signal requires Google Play Services on Android. That means it's put simply not a privacy messenger. Yes there's crypto, but it's also tied into Whisper Systems' infrastructure, there's no federation. I use Signal reluctantly, and only on IOS. Threema,…

Re: Google Play Services. Here's is the way I understand this to work, so please do correct me if I'm wrong. Signal uses Google Play Services to notify me that I have an incoming message from Signal. The Signal app is then woken up and the signal app then retrieves my (encrypted) message. So, therefore, the only thing Google knows is that I received a Signal message, what time and if I have location services on, wher…

The metadata is considered super important in modern surveillance. Your receipt can be correlated with a sender for example, over the course of many messages. Now they can start on a network analysis, start correlating with other people or events etc...

Re: Worried About the Privacy of Your Messages? Download Signal

#109

I'm worried about the freedom of dissenting opinion in civil society from surveillance, not the privacy of my messages. Privacy is something I would easily give up for such freedom. Signal seems to me to one tool in a large profile to maintain freedom of information dissemination and information gathering activity. It seems to me that speaking to a large number of people anonymously is not possible with any of the ex…

An incomplete sketch of a browser plugin/feature that would allow posts to be signed from an anonymous source. (hiding your IP isn't addressed; use something like Tor)

* Blocks of text that start and end with magic numbers are signed in-band in the style of "gpg --clearsign".

* The pubkey pair is automagically created on first use.

For legacy support with existing infrastructure (such as HN):

* When you submit a form with a , the plugin provides a UI to sign the contents before submitting the form.

* When browsing a page that contains magic number wrapped text, the text is automagically verified and the key pinned.

* The structure of the signed text should allow the plugin to hide the magic numbers, signature, etc, so the text looks normal.

However, newer software would have other options:

* Define a mapping between the in-band data and a tag structure that holds the same data. This needs to be strictly defined, so it is possible to remove the tag structure and verify the original signed text. This gives full presentation control back to the website, while allowing individual posts on the page to be verified.

The big problem - as usual - is key distribution. In the latter case where it is easy to hide metadata with CSS, the public key can simply be included with the post. Unfortunately, in the legacy case I don't think there's a good way to include two pages of public key in each "--clearsign"d post.

Re: Worried About the Privacy of Your Messages? Download Signal

#110
post #108

Earlier quoted context omitted.

Re: Google Play Services. Here's is the way I understand this to work, so please do correct me if I'm wrong. Signal uses Google Play Services to notify me that I have an incoming message from Signal. The Signal app is then woken up and the signal app then retrieves my (encrypted) message. So, therefore, the only thing Google knows is that I received a Signal message, what time and if I have location services on, wher…

The metadata is considered super important in modern surveillance. Your receipt can be correlated with a sender for example, over the course of many messages. Now they can start on a network analysis, start correlating with other people or events etc...

Oh, yes, I understand this. I don't understand how it is different for iOS than Android. Sorry if my initial post was not clear on that.
Post reply on HN