Live data from Hacker News

I don't trust Signal

drewdevault.com

291–300 of 473 posts

Re: I don't trust Signal

#291
post #193

Earlier quoted context omitted.

> Moxie forbids you from distributing branded builds of the Signal app ... Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction. > ... and if you rebrand he forbids you from using the official Open Whisper servers. This seems pretty fair to me. Not only could you abuse their resources, it would greatly hinder their ability to make changes and respon…

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play. The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't. This alone is enough for me to lose trust in Signal.

Maybe Moxie doesnt see it as his problem to address concerns of non-contributing critics.

Are there any identified, non-state-level actor threats here, or is this just an ideological rant against proprietary software? If state-level actors are your concern, using android means you have already lost.

Re: I don't trust Signal

#292
post #261
post #239

Earlier quoted context omitted.

They acknowledge that in literally the next paragraph, and the entire post is about how they improved on that old state of things. How is that "smoke and mirrors"?

Right, my bad. This does look like a sensible solution

Is this solution deployed in production? The source code says "beta".

Re: I don't trust Signal

#293
post #91

Earlier quoted context omitted.

I am happy to see I am not the only person in the world that feels like this about Signal. The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.) I admire Wire for a n…

> that's the unique instant messaging that has FOSS'ed both the server and the clients. Signal's server code is open source as well: https://github.com/signalapp/Signal-Server And apparently the client can verify that the server is running that code: https://signal.org/blog/private-contact-discovery/#trust-but...

Server and the contact directory service are two different things. The remote attestation is just for a small part of the code (SGX code have a lot of constraints, including size). Also, I don't know if it changed but the new contact discovery service was not in production last time I checked.

Re: I don't trust Signal

#294

Earlier quoted context omitted.

Checksummed but not signed.

SSL provides integrity guarantees.

Only a bit of transport level integrity. But it doesn't make your average hosting provider into a high assurance one or its servers, OSes, software stacks, etc. Quite known problem since the cryptocurrency era.

Re: I don't trust Signal

#295
> This is a strong accusation, I know. The thing which convinced me of its truth is Signal’s centralized design and hostile attitude towards forks.

The thing that convinced you that Moxie feels a certain way is that Signal has a 'centralized design'.

Please, if you're going to accuse someone of acting in bad faith with no evidence the least you can do is be honest about it. You have nothing but your feelings for proof of anything.

Re: I don't trust Signal

#296

Earlier quoted context omitted.

The server might as well be closed source. We have no guarantees that Moxie is actually running this in production and he refuses to federate with third-party servers.

This is addressed in https://signal.org/blog/private-contact-discovery/ – using Intel SGX, it's possible for the clients to verify that the server is running the code it should be running. I'm not sure whether this is already deployed, but it refutes any claim that Signal isn't serious about your concern. I don't see how federation is related to this at all . We know you're bummed about it, you don't need to inject i…

> This is addressed in https://signal.org/blog/private-contact-discovery/ – using Intel SGX, it's possible for the clients to verify that the server is running the code it should be running

Just the code inside the enclave and that's a very small amount of code, definitely not the entire server.

Re: I don't trust Signal

#297
post #220
post #177

Earlier quoted context omitted.

Isn't the whole point of Signal that it's e2e encrypted and therefore can't really read and share your messages? Whereas Facebook's system is centralized? So yeah you're safe from outside attacks but not internal ones? I mean if you're asking me if I know for certain that Signal is better than Facebook, there's no way for me to know for sure. But at some point there is a level of trust required and I trust a company…

> Isn't the whole point of Signal that it's e2e encrypted and therefore can't really read and share your messages? Maybe. They have an awkward, compromised design, because fundamentally you can only the key exchange stuff that's necessary for forward secrecy if you're both online at the same time, but of course they want to support offline messaging, so they have a protocol that's mostly-e2e but the server also parti…

> Combine that with Signal keeping the server not-quite-open and being weirdly insistent on not having federation, and I'm suspicious.

I'm not exactly sure what not-quite-open means (I thought the code was available, do you mean the server won't accept modified clients?), but Signal was federated once, with Cyanogen, and they opted not to continue the federated model. I don't think it's weird to not want to coordinate upgrades across servers in multiple organizations. Looking at existing federation models that mostly work, we have things like email, where there's no coordination and some servers never get upgraded, leading to a very low lowest common denominator; there's also IRC, where servers in a network really need to run the same software and are upgraded in lockstep -- that's fine enough if everyone is on board, but it doesn't look that much different than one organization running the servers.

Re: I don't trust Signal

#299
post #193

Earlier quoted context omitted.

> Moxie forbids you from distributing branded builds of the Signal app ... Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction. > ... and if you rebrand he forbids you from using the official Open Whisper servers. This seems pretty fair to me. Not only could you abuse their resources, it would greatly hinder their ability to make changes and respon…

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play. The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't. This alone is enough for me to lose trust in Signal.

It seems pretty odd to me to distrust someone because they aren't using the platform that you'd like them to use. Aren't there other issues with f-droid? You have to root your device to run it, allow third party code. Those are all security concerns too.

It was posted elsewhere but here's Moxie's take: https://github.com/signalapp/Signal-Android/issues/127#issue...

Re: I don't trust Signal

#300
+1 I agree wholeheartedly wiht the concerns and complaints in this post. Even if you were to have the most trustworthy person leading a system like this, who is to say that this person's mind won't change. Or worse, a different successor could redefine the goals - this is created under a company after all. What's the solution? Trust in design.
Post reply on HN