Live data from Hacker News

Worried About the Privacy of Your Messages? Download Signal

nytimes.com

211–220 of 247 posts

Re: Worried About the Privacy of Your Messages? Download Signal

#211
post #14

All the privacy solutions on the market are varying degrees of bad (from a privacy/security/freedom perspective), by which I mean they're all flawed in their own ways. Signal requires Google Play Services on Android. That means it's put simply not a privacy messenger. Yes there's crypto, but it's also tied into Whisper Systems' infrastructure, there's no federation. I use Signal reluctantly, and only on IOS. Threema,…

Chaps. I think it's time we just admitted that everything we type/tap/say into any device, regardless of how it's being wrapped up in transit, is absolutely and irrepairably insecure and we're not going to be able to fix that anytime soon. Even with really smart crypto or some slick app; what makes you think that your messages aren't just being read by your os? Would you really notice? Why would you assume that the a…

Chap (presumably),

> But, HN, I don't know why WE aren't admitting this to ourselves or why we defend such obvious ruses.

What exactly makes Signal an obvious ruse? Many of us don't admit that evading surveillance is impossible because we work full time in commercial surveillance. This is the currently dominant business model of the technology industry. Many of us have also worked in defense / government. At the very least, the fact that we have a non-commercial FOSS alternative to data-collection-traps, which is gaining traction, is fantastic.

> Well, maybe some of you have signal stock I guess.

Signal is run by a non-profit.

You just sound like you're spreading FUD.

Re: Worried About the Privacy of Your Messages? Download Signal

#212
Now gents, a number of you in the comments have wondered about what other alternatives are out there. You may have seen that I specifically advise against Signal, and other users have also expressed concerns about a number other applications, amongst which Wire and Telegram.

One that, to my knowledge has not been mentioned yet, but which would appear to meet some common measure of functionality versus convenience expressed here, is XMPP messaging application Conversations (https://conversations.im/).

I am not going to give it my personal recommendation because having tested it, I did not like a number of design decisions the developers have made, and I did not like their overall vision for the app. With that said, it's horses for courses.

On the end to end encryption front (all the rage these days, eh?), it appears that the Conversations devs have taken Signal's protocol and _done it right_. That means, they actually specced it (https://conversations.im/omemo/) and had it audited (https://conversations.im/omemo/audit.pdf), along with a couple important improvements such as eliminating the requirement for a trusted server or Google Play, which greatly reduces the attack surface.

Again, I personally do not like Conversations and I'm not going to use it myself--that's a personal preference thing, but kudos to the devs for doing a professional job, especially while everyone else are busy selling snake oil.

I say, go give Conversations a try, it may be the thing you were looking for.

Re: Worried About the Privacy of Your Messages? Download Signal

#213
post #14

All the privacy solutions on the market are varying degrees of bad (from a privacy/security/freedom perspective), by which I mean they're all flawed in their own ways. Signal requires Google Play Services on Android. That means it's put simply not a privacy messenger. Yes there's crypto, but it's also tied into Whisper Systems' infrastructure, there's no federation. I use Signal reluctantly, and only on IOS. Threema,…

Check out Matrix/Riot.

Re: Worried About the Privacy of Your Messages? Download Signal

#214
WhatsApp integrated Signal's end-to-end encryption¹ into their communications platform.

Nearly everyone I know uses WhatsApp. This change made the platform much more secure for everyone. It's on by default and works transparently. Since then, at least one government was unable to compel WhatsApp to produce messages² from users under investigation.

I also have Signal installed but nobody I know uses it so its utility is diminished. I told some friends about Signal; they installed the app but won't use it because they can't message anyone except me. The only times people talked to me via Signal was during the temporary WhatsApp blocks ordered by my country's government.

¹ https://whispersystems.org/blog/whatsapp-complete/ ² http://www.forbes.com/sites/parmyolson/2016/05/03/whatsapp-f...

Re: Worried About the Privacy of Your Messages? Download Signal

#215
zkc, zero knowledge communications, was released today. It is just the first release, and a minimal tool with minimal features, but its exactly the solid foundation I have been waiting for.

https://blog.decred.org/2016/12/07/zkc-Secure-Communications...

"zkc is a blending of what we consider to be the best parts of both of these projects, Signal and Pond" "The UI is text-based and emulates the appearance of irssi, in order to keep UI-related complexity low and avoid large GUI toolkits as a dependency." "intended to provide the highest level of communications security balanced with minimal complexity in its code, configuration and usage."

Re: Worried About the Privacy of Your Messages? Download Signal

#216
post #175

Earlier quoted context omitted.

They did in another comment on this page. I do not see any evidence that worries me. Perhaps if you're a famous terrorist, you won't want to use it, because your GIF searches might expose your evil plans. But I only needed a way to talk to family and friends that was more private than Facebook and Google, while not sacrificing features and usability. I think Wire has done an excellent job. I've not found anything els…

Just wondering, but why not just use XMPP? You can choose any server that you like or trust, or run your own (on your own or third party infrastructure, up to you), and use OTR for end-to-end encryption if you feel you need to¹. I have been using XMPP since 2000/2001. My current address is nine years old (and I control the server). I have a choice of clients on every platform that I use. All my contacts have the same…

Is OTR really a practical option? You message seems unclear about it.

Also, how do you get all your contacts to use XMPP and your server?

Re: Worried About the Privacy of Your Messages? Download Signal

#217
post #193

Earlier quoted context omitted.

I'm probably just inviting myself to get trolled by replying to this, but this comment is just ridiculously wrong on so many levels. > The fact that the guy behind it is hyping it via the New York Times, a generalist publication, instead of validating the thing through professional cryptographers (which he isn't) and recognised privacy champions such as the EFF is very telling. Cryptographer Matthew Green on Signal's…

> I'm probably just inviting myself to get trolled by replying to this I'm sorry that you get that impression, but I do appreciate your input. > Cryptographer Matthew Green on Signal's crypto and code quality (it was called RedPhone/TextSecure at the time of this writing) That's the application that they sold to Twitter, not the one being talked about here. I do not know how different the code bases are. It is also a…

>He also has a history of lying, such as when he used fake WHOIS details to run his "Google anonymiser" thing. And of course, when he was shut down by the registrar, as you do when someone has given you false details, what did he do? He went to the press to whine about the registrar! After he entered a contract in bad faith, something which happens to be a prosecutable offence. That's the sort of person we are talking about here. I hope you will understand if his word does not exactly fill me with confidence.

I really don't see why someone should be on my shitlist for lying to godaddy dot com or whatever giant registrar unless you consider fudging identifying details about something that really doesn't matter, especially considering he was very openly associated with the project, some sort of horrible moral offense. I especially find your taking massive umbridge with fudging personal information baffling given how privacy-minded you otherwise seem.

>At the risk of sounding elitist, what is his academic background? (I elided the other person because I do not know who he is).

Combined with the above, the way you're hand-waving away the other of the two original developers of the protocol really just makes it seem like the position you've taken against Signal is mostly predicated on some sort of grudge against Marlinspike himself. Yes, trashing F-Droid was not a great thing to do and you might see him as someone with a strong penchant for self-promotion, but the way you keep on tying your criticisms to Marlinspike personally really muddles your case. For example, you object to him promoting Signal in a New York Times piece saying it is a generalist publication and posit he's just trying to drum up attention so he can find a buyer, which may or may not be true, but isn't one of the most important goals of a secure messaging application to get people to actually use it and to achieve widespread adoption? The main lesson I've learned from GPG mail is that a perfectly private means of communication is worth very little if I can't actually convince anyone to use it with me.

Re: Worried About the Privacy of Your Messages? Download Signal

#218
post #193

Earlier quoted context omitted.

I'm probably just inviting myself to get trolled by replying to this, but this comment is just ridiculously wrong on so many levels. > The fact that the guy behind it is hyping it via the New York Times, a generalist publication, instead of validating the thing through professional cryptographers (which he isn't) and recognised privacy champions such as the EFF is very telling. Cryptographer Matthew Green on Signal's…

> I'm probably just inviting myself to get trolled by replying to this I'm sorry that you get that impression, but I do appreciate your input. > Cryptographer Matthew Green on Signal's crypto and code quality (it was called RedPhone/TextSecure at the time of this writing) That's the application that they sold to Twitter, not the one being talked about here. I do not know how different the code bases are. It is also a…

I think that issue highlights the problem with unofficial repositories. Users remained vulnerable because their upstream provider didn't update quickly enough. It culminated in a user spamming the official issue tracker with an outdated and annoying bug report.

This isn't just unique to Android: there are multiple ongoing efforts at the moment in the Linux world to lessen frustrations with distribution repositories. Snappy, Flatpak, and AppImage intend to unify application deployment and allow users to install applications from anywhere. In most cases, this could mean pulling directly from the application developer themselves. GNOME and KDE will likely encourage this.

I know some Firefox developers who have grouched at the delay between official releases and when distributions finally deploy them, so this problem isn't exclusive to desktop environment developers.

Back to Android: Moxie had a point when he claimed that Android is more privileged to have a system that provides package verification back to the original developer. It doesn't matter where you get an APK from: the developer's website, Google Play, APKMirror, or Bittorrent. If you have the developer's public signing key, you can verify the authenticity of the APK.

F-Droid represented a serious step backwards in Android security, back when they used to self-sign APKs. It wasn't possible any longer to cut out the distributor from the chain of trust. Fortunately, they reacted to Moxie's criticisms, and F-Droid now retains the original package signature when the build can be reproduced.

From a developer perspective however, encouraging or even tolerating unofficial installation channels for secure communication software is bad. If vulnerable users are in-contact with non-vulnerable users, they unknowingly put both parties at risk. If the ecosystem evolves to the point where this is common, the whole system is insecure.

What Android desperately needs is a high-quality, non-profit, privacy-friendly, charity- and grant-driven app store. It must entice open-source app developers. It cannot do self-builds, except for reproducibility. It needs crash-reporting, analytics, usage metrics, device-specific builds, localization options, and more. It requires dead-simple tools for command-line deploying.

Until then, in my opinion, F-Droid will never be accepted by app developers. F-Droid is for users only. Not for the same purposes, either: for the cautious user, F-Droid mainly shines as a locally-setup repo for self-deployed apps.

P.S.: Perrin & Moxie recently began documenting Signal Protocol: https://whispersystems.org/docs/

Re: Worried About the Privacy of Your Messages? Download Signal

#219
post #209

Earlier quoted context omitted.

> Can I run a client from the Git repo and still use all of their infrastructure? Yes. You can. They describe how in the very repo I linked. Your ardent unwillingness to spend the 30-45 seconds it would take to find this out before spouting unwarranted false criticism is quite strange. Do you have some personal issue with OWS? I really didn't mean to be defending OWS here - I'd much rather see Signal leveraging non-G…

>> Can I run a client from the Git repo and still use all of their infrastructure? > Yes. You can. The thing is, lucideer, the "restrictions" on the use of the source code are engineered to raise the barrier to independent use, notably by preventing or discouraging redistribution. This means that only those who are able and willing to compile Android source can run their own binaries. Everyone else has to go with the…

> Everyone else has to go with the binaries they distribute which, as the other poster has correctly argued, cannot be independently verified.

Do you have reverse engineering experience on Android?

APK uses the zip format. Extract its contents and compare those, minus the META-INF directory, which contains digests and a detached PKCS#7 signature.

Apps whose code output isn't reproducible can still be compared with a varying amount of IDA analysis.

Re: Worried About the Privacy of Your Messages? Download Signal

#220
post #204

Earlier quoted context omitted.

The mere act of using Signal is suspicious. But if usage is universal then that suspicion can not be acted on. The suggestion that the motivation for this article is profit for the NYT or Moxie is quite destructive.

> The suggestion that the motivation for this article is profit for the NYT or Moxie is quite destructive. No, that's literally how it works. Media need to sell copy (clicks these days) and companies need to get coverage. And that's perfectly OK if companies are acting ethically and journalists and editors are doing due diligence. The person that you mention has good connections in the media and uses them to self-pro…

>...tat he sells...

It's free.

And normally one would associate such vehement and repetitive insistence on counter-factuals with trolling

Post reply on HN