Live data from Hacker News

Worried About the Privacy of Your Messages? Download Signal

nytimes.com

231–240 of 247 posts

Re: Worried About the Privacy of Your Messages? Download Signal

#231
post #193

Earlier quoted context omitted.

> I'm probably just inviting myself to get trolled by replying to this I'm sorry that you get that impression, but I do appreciate your input. > Cryptographer Matthew Green on Signal's crypto and code quality (it was called RedPhone/TextSecure at the time of this writing) That's the application that they sold to Twitter, not the one being talked about here. I do not know how different the code bases are. It is also a…

>He also has a history of lying, such as when he used fake WHOIS details to run his "Google anonymiser" thing. And of course, when he was shut down by the registrar, as you do when someone has given you false details, what did he do? He went to the press to whine about the registrar! After he entered a contract in bad faith, something which happens to be a prosecutable offence. That's the sort of person we are talkin…

> I really don't see why someone should be on my shitlist for lying to godaddy dot com or whatever giant registrar unless you consider fudging identifying details about something that really doesn't matter,

I think I can see where you are coming from. You seem to compare this with, say, opening a GMail account under an alias, if I understand correctly.

However, holding domain names and, at the time, SSL certificates requires a different sort of accountability. I can elaborate on that if you wish, but I trust it won't be necessary.

> especially considering he was very openly associated with the project,

In the same way that Mr platinumrad or Ms at612 are associated with this discussion? By the use of an alias?

> some sort of horrible moral offense.

Yes. And please note he did not just lie to the registrar. When he got caught, he went and whined to some journo who published a piece criticising the registrar without bothering to contrast the information first. It all being presented as if it was the registrar in the wrong, when they were following the rules, which are there to protect the public in the first place. This coming from some bloke who was saying "don't trust Google, trust me. Because."

> I especially find your taking massive umbridge with fudging personal information baffling given how privacy-minded you otherwise seem.

I value my privacy. At the same time, when I enter a contract, I do so in good faith and of course part of it is letting the other party know who I am.

> really just makes it seem like the position you've taken against Signal is mostly predicated on some sort of grudge against Marlinspike himself.

Yes, you are correct. My apologies if that wasn't clear. I question the ethics, motivation, and competence of this one individual, who happens to be closely associated with said project.

> Yes, trashing F-Droid was not a great thing to do

To put it mildly. On an incidental note and more generally, have you ever seen him do a mea culpa?

> [but] isn't one of the most important goals of a secure messaging application to get people to actually use it and to achieve widespread adoption?

I do not know. I would guess not (based on defence experience). But the main point is that him saying "oh sure, it's secure" does not make it secure. He seems to be taking advantage of the public's inherent credulity and lack of awareness of what "security" actually means and involves. We have gone through this discussion already, so for an example of what I consider a better developed and correctly presented security solution, please see the Conversations IM application.

> The main lesson I've learned from GPG mail is that a perfectly private means of communication is worth very little if I can't actually convince anyone to use it with me.

This is a different, and long discussion, but it is probable that the reason why you are seeing that is the other party having mentally (or formally) done a cost/benefit analysis and deciding that their information is not of such value to justify the extra effort to protect it. Rightly or wrongly.

Re: Worried About the Privacy of Your Messages? Download Signal

#232
post #218
post #193

Earlier quoted context omitted.

> I'm probably just inviting myself to get trolled by replying to this I'm sorry that you get that impression, but I do appreciate your input. > Cryptographer Matthew Green on Signal's crypto and code quality (it was called RedPhone/TextSecure at the time of this writing) That's the application that they sold to Twitter, not the one being talked about here. I do not know how different the code bases are. It is also a…

I think that issue highlights the problem with unofficial repositories. Users remained vulnerable because their upstream provider didn't update quickly enough. It culminated in a user spamming the official issue tracker with an outdated and annoying bug report. This isn't just unique to Android: there are multiple ongoing efforts at the moment in the Linux world to lessen frustrations with distribution repositories.…

> From a developer perspective however, encouraging or even tolerating unofficial installation channels for secure communication software is bad.

What is your threat model?

Re: Worried About the Privacy of Your Messages? Download Signal

#233
post #195
post #174

Earlier quoted context omitted.

> it is not open source Huh? https://github.com/WhisperSystems/Signal-Android I'd even argue it's free software - the team has managed to create some confusion about distributing modified binaries - with regards to using the servers Signal operates -- but have clarified that it is indeed ok to build your own binary from the source they provide, and use their servers. I'm not quite convinced about their argument for o…

> I'd even argue it's free software Terminology. What you call free software I call open source. As you go on to mention, you can see the source but not use it in any meaningful way. In particular: > but have clarified that it is indeed ok to build your own binary from the source they provide, Exactly. Your own binary. From their source. Build your own binary for someone else, and it's "malware", as the guy had the n…

While you might claim that running an ASOP derivative you need to trust Google less (and in turn trust something like f-droid more, perhaps) -- if you want a chat/im client on an Android device it's hard to see how Google isn't already one entity you need to trust (along with a list of hardware manufacturers).

As for your other comments - you may run your own server infrastructure from same or derived sourced, your own derived clients, distribute binaries etc - but you can't dilute the brand. Similar with Debian cloud images for example.

I'm not sure how that's "not FOSS".

Re: Worried About the Privacy of Your Messages? Download Signal

#234
post #44

Earlier quoted context omitted.

What about WhatsApp, Telegram? I don't use them, but saying that there are no options today for secure, encrypted communication raises my eyebrow.

Telegram is a farce. They don't have end-to-end encryption by default, and their encryption protocol(MTProto) is home-made and basically a secret. They haven't opened it up to testing or open sourced it, so it's pretty useless at ensuring 'privacy'. Plus recently 15 million phone numbers linked to Telegram accounts were hacked because of an SMS verification loophole. WhatsApp at least has end to end encryption- thoug…

>They haven't opened it up to testing or open sourced it

https://core.telegram.org/mtproto https://telegram.org/apps#source-code

Re: Worried About the Privacy of Your Messages? Download Signal

#235
post #175

Earlier quoted context omitted.

They did in another comment on this page. I do not see any evidence that worries me. Perhaps if you're a famous terrorist, you won't want to use it, because your GIF searches might expose your evil plans. But I only needed a way to talk to family and friends that was more private than Facebook and Google, while not sacrificing features and usability. I think Wire has done an excellent job. I've not found anything els…

Just wondering, but why not just use XMPP? You can choose any server that you like or trust, or run your own (on your own or third party infrastructure, up to you), and use OTR for end-to-end encryption if you feel you need to¹. I have been using XMPP since 2000/2001. My current address is nine years old (and I control the server). I have a choice of clients on every platform that I use. All my contacts have the same…

For one thing, XMPP does not have the same features. Try Wire and see for yourself. There's audio, video, voice messages, multiple device encryption. Maybe XMPP has improved, but it didn't work as well for mobile use.

Re: Worried About the Privacy of Your Messages? Download Signal

#236

I continue to be disappointed by headlines like, "Worried About the Privacy of Your Messages? Download Signal" which implies that only some people should be worried about privacy. You'd think that the revelations about the NSA, things like the UK law that requires ISPs to collect and store your Internet browsing history would have more people "worried" but yet it's still pretty much a lost cause to try to explain to…

I've had success in framing it from the perspective of "Want to use an app that can help activists/journalists be able to do their work more safely and securely while also protecting yourself from criminals/those you wouldn't want to own your data."

It seems to resonate much more with the millennial demo, as we can empathize with the struggles of journalists/activists/state-dissidents even though we may see our own data/life as in less need of securing, especially in light of the "Facebook/Google already have it so why bother?" sentiment that gets thrown around.

Re: Worried About the Privacy of Your Messages? Download Signal

#237

Earlier quoted context omitted.

This criticism applies equally to every piece of software you haven't written yourself. You have to trust someone at some point. OWS has demonstrated that they are more trustworthy than their competitors.

Sure, but the ease of someone abusing this is far greater than what we've been using before. Can you honestly say that you trust signal over locally or even airgapped pgp'd text?

Nope! But they solve two completely different problems. And the metadata with Signal is actually much better than PGP+email. Have you looked at email headers recently?

Re: Worried About the Privacy of Your Messages? Download Signal

#238
post #219
post #209

Earlier quoted context omitted.

>> Can I run a client from the Git repo and still use all of their infrastructure? > Yes. You can. The thing is, lucideer, the "restrictions" on the use of the source code are engineered to raise the barrier to independent use, notably by preventing or discouraging redistribution. This means that only those who are able and willing to compile Android source can run their own binaries. Everyone else has to go with the…

> Everyone else has to go with the binaries they distribute which, as the other poster has correctly argued, cannot be independently verified. Do you have reverse engineering experience on Android? APK uses the zip format. Extract its contents and compare those, minus the META-INF directory, which contains digests and a detached PKCS#7 signature. Apps whose code output isn't reproducible can still be compared with a…

Re-reading this post, I'm not sure why I typed IDA -- I meant baksmali. IDA is still useful for bundled ELF dependencies.

Re: Worried About the Privacy of Your Messages? Download Signal

#239
One thing I'm very worried about with Signal is the high levels of permissions the app requires when you first install it.

It seems very counter intuitive,. Worried about privacy & security of your messages? Oh firstly you need to trust all your personal contact info to us. Yes they say they don't use it off of the phone, but it's asked for and that's based on trust.

On iPhone it requires access to your contact list. Surely it could run without this? Snapchat for example makes it easy to add friends in person, by scanning a code on one phone from another. How is sending unencrypted text messages announcing your social graph the only way to use the app.

Why is the app asking for so much permissions trust itself?

Re: Worried About the Privacy of Your Messages? Download Signal

#240
post #39

Earlier quoted context omitted.

You call that a temper tantrum? I thought he was being very reasonable.

We'll agree to disagree. If he said "Please don't use our servers with your custom client, shit might break. You could run your own infra and keep it up to date with us and we'll federate", this would be reasonable. Instead, if you read that thread a bit more he throws up his hands and says federation is a thing of the past because he had a bad experience with CM. Yeah, because we don't still use federated standards…

Federated standards have problems with spam and rolling out encryption-by-default. This applies to both examples you mentioned.
Post reply on HN