Live data from Hacker News

Another flaw in Signal desktop app leaks chats in plaintext

thehackernews.com

71–80 of 232 posts

Re: Another flaw in Signal desktop app leaks chats in plaintext

#73

Earlier quoted context omitted.

This may or may not be true, but in a lot of cases where you need encryption, you also need not to have a GPS tracker on you while you're using it. You have (at least slightly) more chance of being anonymous with a dedicated laptop computer than you have with any smartphone.

Ignoring the recent LocationSmart revelations, if you disable location access you should basically have the same level of geospatial anonymity.

> Ignoring the recent LocationSmart revelations

You can't, though; that's kind of the point.

Re: Another flaw in Signal desktop app leaks chats in plaintext

#76

In security less is more. The more we try to make encryption mainstream, the more difficult it gets because the mainstream interacts with computers predominately via browsers. The mainstream won't adopt something that isn't highly similar to what a browser has to offer in terms of media richness (photos, videos, html), so you see Signal choosing technologies like Electron, a browser, to develop their native applicati…

In general less is more, with proper abstraction, not just in security.

Re: Another flaw in Signal desktop app leaks chats in plaintext

#77
post #24

Honestly, and none of you are going to like hearing this, and the Signal people aren't going to appreciate me saying it: if you're serious about messaging securely, don't use Signal Desktop; don't use desktop secure messengers at all. Desktop applications are incredibly risky, far more so than iOS mobile apps are.

> don't use desktop secure messengers at all. Desktop applications are incredibly risky, far more so than iOS mobile apps are. It's risky to use an open source OS. If you are serious about security, use Android or iOS. Instead of direct ssl connection to XMPP server, it's much safer to send all your data with Google Cloud Messaging. /s Desktop computers are currently the most open sourced, least opaque, least spyware…

You have my upvote, but I imagine that tptacek means that iOS is very very well sandboxed, and has an extremely tight and well authenticated download and update system which is extremely difficult for a third party to monkey with.

This is security via centralization and trusting a benevolent capitalist dictator. As long as your personal interests are aligned with interests of the benevolent capitalist's shareholders, you should be fine.

It is my least favorite security model. But, in the case of iOS it seems to be working well (for now). My long-term hope is for a decentralized FOSS model, but for the time being, in the USA, on a multipurpose machine, the benevolent capitalist dictator beats it, especially on sandboxing and package/app authentication.

Re: Another flaw in Signal desktop app leaks chats in plaintext

#78
post #20

Earlier quoted context omitted.

Ah, so don't use the now secured opensource client using Signal's protocol. We should use PGP with all the weak yet-to-be-patched clients. Cause it's not PGP which got hacked it was the client. Very different from how the Signal client got hacked not their protocol. /s

No, I'm saying use just PGP - manually - and don't use any client interface to it. Control the encryption yourself. Your sarcasm is misplaced.

Given the absent security of desktop Linux, and the dreadful opsec of its users, as revealed by many cryptocurrency wallet thefts, I wouldn't place much trust in persistent PGP secrecy unless all participants used Heads, and renewed keys regularly, and ran nothing except gpg. How many people do that, in the entire world, do you think? A hundred, at best?

Re: Another flaw in Signal desktop app leaks chats in plaintext

#80
post #24

Honestly, and none of you are going to like hearing this, and the Signal people aren't going to appreciate me saying it: if you're serious about messaging securely, don't use Signal Desktop; don't use desktop secure messengers at all. Desktop applications are incredibly risky, far more so than iOS mobile apps are.

> don't use desktop secure messengers at all. Desktop applications are incredibly risky, far more so than iOS mobile apps are. It's risky to use an open source OS. If you are serious about security, use Android or iOS. Instead of direct ssl connection to XMPP server, it's much safer to send all your data with Google Cloud Messaging. /s Desktop computers are currently the most open sourced, least opaque, least spyware…

You should be far more worried that desktop apps don't require permission before eavesdropping on your conversations using the microphone (including 3rd level sub-dependencies of that NPM module you installed), than that Android or iOS is secretly recording your conversations under the guise of "ok Google" or "Hello Siri".

Regardless of the device form factor, if you don't want the OS to have access to the microphone then you have to physically disable the microphone (but if you are that paranoid you should probably live in the woods away from all electronic devices).

Post reply on HN