A problem for some people with Signal is that it requires you to use a phone number, and they may not want to disclose theirs. You can set up an SMS gateway number just for this purpose, but you shouldn't need such workarounds.
Worried About the Privacy of Your Messages? Download Signal
191–200 of 247 posts
Re: Worried About the Privacy of Your Messages? Download Signal
#192Earlier quoted context omitted.
In a democracy, dissemination of information to the voters can theoretically affect political change. In countries that are not democracies, I'm uncertain what to do with your complaint. Would you dismiss giving oppressed people access to literature, news, entertainment, or technical and scientific information, on the premise that the information is unlikely to allow them to affect political change? I don't believe t…
Recent events have disproven the cypherpunk-era belief that freely available, secure communications will lead to a better (read: more rational) world. I don't dismiss the desire to give access. I think its utility has been naively overstated; these same tools can be, and have been, used by old guard oligarchs to maintain and extend their political and economic power.
But governments do a pretty good job of keeping their secrets now, so in the end, I think this will balance the scales towards private citizens.
Re: Worried About the Privacy of Your Messages? Download Signal
#193Download Signal? No, thank you. The fact that the guy behind it is hyping it via the New York Times, a generalist publication, instead of validating the thing through professional cryptographers (which he isn't) and recognised privacy champions such as the EFF is very telling. The thing has not been properly validated or verified (for a start, because there is no design document to validate against, and no published…
I'm probably just inviting myself to get trolled by replying to this, but this comment is just ridiculously wrong on so many levels. > The fact that the guy behind it is hyping it via the New York Times, a generalist publication, instead of validating the thing through professional cryptographers (which he isn't) and recognised privacy champions such as the EFF is very telling. Cryptographer Matthew Green on Signal's…
I'm sorry that you get that impression, but I do appreciate your input.
> Cryptographer Matthew Green on Signal's crypto and code quality (it was called RedPhone/TextSecure at the time of this writing)
That's the application that they sold to Twitter, not the one being talked about here. I do not know how different the code bases are.
It is also around that time that the app had a gaping, amateurish hole in that it was simply leaking everything via logcat. And what does the guy do? Instead of addressing the issue like a professional, he goes on a complete tangent rubbishing F-Droid (https://github.com/WhisperSystems/Signal-Android/issues/53) and then making rather poor excuses as to why you should get your application from the Google store and not from anywhere else.
Excuses which by the way, have been evolving over time. I think he eventually admitted that he wants to keep track of how many users are using it (handy to show to your potential buyers).
He also has a history of lying, such as when he used fake WHOIS details to run his "Google anonymiser" thing. And of course, when he was shut down by the registrar, as you do when someone has given you false details, what did he do? He went to the press to whine about the registrar! After he entered a contract in bad faith, something which happens to be a prosecutable offence. That's the sort of person we are talking about here. I hope you will understand if his word does not exactly fill me with confidence.
> https://www.eff.org/node/82654.
That page starts with: "This is version 1.0 of our scorecard; it is out of date, and is preserved here for purely historical reasons."
And continues with: "the results in the scorecard below should not be read as endorsements of individual tools or guarantees of their security"
> Signal has been analyzed, with favorable results, by academic researchers at least twice:
Yes, I am aware of those. And that is not what validation and verification is which, as I said, in the absence of publicly available design documents, is impossible to do independently. The guy is trying to make it look like he's selling a "secure" communication platform, but if you presented that to a defence contractor (which I have some experience with) you would be laughed out of the building. Proper security is not done like this at all. For a start, you actually define your goals, i.e., what you intend to secure, against what threats, etc., etc. If you can show me a paper with that information I would be grateful.
Notably, you may have noticed that those papers, like Green's, are a protocol analysis, not an analysis of the entire solution. In that respect, you're back to the previous situation: the protocol might be ultra-secure, but if you're still leaking your plaintext on a different channel...
> Moxie Marlinspike and [...] probably wouldn't call themselves "cryptographers,"
At the risk of sounding elitist, what is his academic background? (I elided the other person because I do not know who he is).
> but almost anybody in the field would agree that they are experts on applied cryptography.
What do you base that conjecture on?
Re: Worried About the Privacy of Your Messages? Download Signal
#194Earlier quoted context omitted.
> I'm worried about the freedom of dissenting opinion in civil society from surveillance, not the privacy of my messages. Privacy is something I would easily give up for such freedom. I see these two subjects as being inseparable. Before I feel comfortable asserting a dissenting opinion in a public forum, I would much rather discuss the subject among my peers where I don't feel I will be immediately eviscerated for a…
> Before I feel comfortable asserting a dissenting opinion in a public forum, I would much rather discuss the subject among my peers where I don't feel I will be immediately eviscerated for a poorly constructed thought. While I certainly emphasize with the anxiety of publicly expressing an unpopular opinion, I believe it is, especially in times like these, your moral duty to endure in spite of the repercussions and s…
Speaking out matters. So does when, where, and how you speak out. And that is something best discussed privately.
I'd have much more to say on how privacy and anonymity are inextricably linked, but I'll let the EFF say it: https://www.eff.org/deeplinks/2012/01/right-anonymity-matter...
Re: Worried About the Privacy of Your Messages? Download Signal
#195Download Signal? No, thank you. The fact that the guy behind it is hyping it via the New York Times, a generalist publication, instead of validating the thing through professional cryptographers (which he isn't) and recognised privacy champions such as the EFF is very telling. The thing has not been properly validated or verified (for a start, because there is no design document to validate against, and no published…
> it is not open source Huh? https://github.com/WhisperSystems/Signal-Android I'd even argue it's free software - the team has managed to create some confusion about distributing modified binaries - with regards to using the servers Signal operates -- but have clarified that it is indeed ok to build your own binary from the source they provide, and use their servers. I'm not quite convinced about their argument for o…
Terminology. What you call free software I call open source. As you go on to mention, you can see the source but not use it in any meaningful way. In particular:
> but have clarified that it is indeed ok to build your own binary from the source they provide,
Exactly. Your own binary. From their source.
Build your own binary for someone else, and it's "malware", as the guy had the nerve to call F-Droid in that bug report (here: https://github.com/WhisperSystems/Signal-Android/issues/53). That sort of bad faith, coming from a known liar (see my other reply) is what I really cannot condone.
> and use their servers.
Yeah, similarly. Use a source other than theirs or servers other than theirs and they start whingeing.
That is not open source.
> I'm not quite convinced about their argument for official app store distribution and updates,
Possibly because every time it's a different excuse?
> but I can understand the argument.
Yes, so can I: they want to control the platform so that it is their users, so that they can sell it to someone else, like they did last time.
And I would be perfectly fine with that, if it wasn't done via lies, deception, and denigrating third parties, particularly the chaps at F-Droid who at least have the decency of using their real names (not to mention not seeing you as the product).
> Sticking with an app store does require trust in the provider though.
Agreed. How high is Google in your "trusted" list? Yes, I'm picking on Google because it's a bit of an easier target than Apple, but still.
> I think it would be best to avoid FUD.
I agree, and that's precisely why I feel the need to speak up. I challenge the honesty not of their enterprise (which is no different from that of Skype, Whatsapp, or any other player) but of the way they are pursuing their goal. See above.
> It certainly strikes me as one of the better options for pragmatic secure messaging,
I don't know. As mentioned elsewhere, XMPP meets all my requirements and is not vendor-dependent. But the availability of options depends on each user's definition of things like "pragmatic" and "secure" (and even "messaging" for that matter!)
From seeing what's out there though, it appears that modern versions of Whatsapp (which I don't use, I'm FOSS-only) offer essentially the same capabilities as this application though, including end-to-end encryption. And of course, essentially the same disadvantages. I could be mistaken here though.
> that allows for a fairly narrow and reasonable set of threats (Google/Apple/Microsoft (possibly more than one of each, depending on your platform), Whisper Systems themselves, probably most state actors).
I guess it also depends on each user's definition of "fairly narrow and reasonable". :-)
Re: Worried About the Privacy of Your Messages? Download Signal
#196Earlier quoted context omitted.
> A problem for some people with Signal is that it requires you to use a phone number, and they may not want to disclose theirs. That's true, although those of us with unlocked phones can purchase "throwaway" SIM cards with distinct phone-numbers fairly easily with cash, use the number for secure communications only, throw the card away, and then go back to our public lives.
That will expose your IMEI and not really protect you from people that would be tracking you based on metadata. You gotta burn the phone.
So other than full-on burner smartphones (ie: throw away $600 every time you need to do something privately), what's a reasonable heuristic for conducting private business? Maybe collectively owned or rented burner phones so that the metadata collector only ever knows, "Someone rented this device for encrypted communications" rather than who in specific is communicating with whom?
Re: Worried About the Privacy of Your Messages? Download Signal
#197All the privacy solutions on the market are varying degrees of bad (from a privacy/security/freedom perspective), by which I mean they're all flawed in their own ways. Signal requires Google Play Services on Android. That means it's put simply not a privacy messenger. Yes there's crypto, but it's also tied into Whisper Systems' infrastructure, there's no federation. I use Signal reluctantly, and only on IOS. Threema,…
Re: Google Play Services. Here's is the way I understand this to work, so please do correct me if I'm wrong. Signal uses Google Play Services to notify me that I have an incoming message from Signal. The Signal app is then woken up and the signal app then retrieves my (encrypted) message. So, therefore, the only thing Google knows is that I received a Signal message, what time and if I have location services on, wher…
> Signal uses Google Play Services to notify me that I have an incoming message from Signal.
More importantly:
a. That dependency, along with other "restrictions", sets an artificially high barrier to actually using the product independently. This is presumably so that they can maintain the pretence of being "open source".
b. Keep track of application downloads and whatever else Google provides to developers.
Moreover, as the paper that someone has linked elsewhere says, if you are allowing Google services in your app (Google Cloud Messaging, to be exact), you're at the mercy of anyone with control of it. A relatively trivial attack via GCM, as the paper hints, would involve simply replacing your application with a backdoored version, and you'd be none the wiser. It is a massive attack surface that just cannot be ignored.
Re: Worried About the Privacy of Your Messages? Download Signal
#198I continue to be disappointed by headlines like, "Worried About the Privacy of Your Messages? Download Signal" which implies that only some people should be worried about privacy. You'd think that the revelations about the NSA, things like the UK law that requires ISPs to collect and store your Internet browsing history would have more people "worried" but yet it's still pretty much a lost cause to try to explain to…
More concerning is stuff like the US Democratic National Committee emails showing up on Wikileaks. Being blackmailed, ransomed, or leaked is much more of a real threat for most people than some abstract harm that may be posed by the NSA or some ISP logging.
Re: Worried About the Privacy of Your Messages? Download Signal
#199Earlier quoted context omitted.
That will expose your IMEI and not really protect you from people that would be tracking you based on metadata. You gotta burn the phone.
Ah, ok, fair enough. So other than full-on burner smartphones (ie: throw away $600 every time you need to do something privately), what's a reasonable heuristic for conducting private business? Maybe collectively owned or rented burner phones so that the metadata collector only ever knows, "Someone rented this device for encrypted communications" rather than who in specific is communicating with whom?
You need to do a threat analysis.
I did not immediately find any good introductory resources via a quick Google search, but try it yourself. Very very briefly, it involves identifying the threats and their possible consequences, then working on either removing the former or minimising the latter.
Be aware that this is not merely a technological process. It is primarily a social one.
Re: Worried About the Privacy of Your Messages? Download Signal
#200Earlier quoted context omitted.
An incomplete sketch of a browser plugin/feature that would allow posts to be signed from an anonymous source. (hiding your IP isn't addressed; use something like Tor) * Blocks of text that start and end with magic numbers are signed in-band in the style of "gpg --clearsign". * The pubkey pair is automagically created on first use. For legacy support with existing infrastructure (such as HN): * When you submit a form…
I have considered, and even worked on, a Chrome extension for this exact purpose. Some hurdles I discovered: * Websites do weird things with textareas. If it's a plain-ol HTML form, it's pretty easy to intercept and do what you want. It seems most websites intercept button clicks then pass your text around to twenty different JS functions and libraries before doing something useful with it. You wind up writing code t…
I'm probably not going to pick it up, but I'd definitely read the source.