I know Signal is secure and all — and I use it myself — but I can’t help but think how can we trusted that the central servers aren’t wiretapped? It would be the ultimate proof of security if one could transparently verify that the middle man is running the actual code it claims to be running.
EU Commission to staff: Switch to Signal messaging app
71–80 of 289 posts
Re: EU Commission to staff: Switch to Signal messaging app
#72Re: EU Commission to staff: Switch to Signal messaging app
#73But what should I use if I am a politician and fundamentally believe that the government should be able to read my communications?
Interestingly, the EU's position on this looks really confused. SMS messages should (in theory) only transit their own local telcos. The USA doesn't get a look-in unless it hacks the telcos themselves.
What the EU is doing here is routing all Commission traffic through US based server farms and roots of trust. The phones are controlled from the USA, the comms services are too. So their own local firms can no longer see the traffic but US firms can (Signal claim this isn't the case but people are wising up to the fact that this can't be true until more infrastructure is in place).
What actual threat are they trying to block here?
Re: EU Commission to staff: Switch to Signal messaging app
#74I know Signal is secure and all — and I use it myself — but I can’t help but think how can we trusted that the central servers aren’t wiretapped? It would be the ultimate proof of security if one could transparently verify that the middle man is running the actual code it claims to be running.
Signal uses Intel SGX to give you some assurances about this, at least for parts of their serving stack. You can run the remote attestation tools and get a report back from Intel that says, in effect, "you connected to a genuine CPU and it's running software with this hash". Then you reproduce the build of the open source code and check the hashes match. I'd be surprised if anyone has ever actually done this. It's a…
Assuming that the sgx environment hasn't been tampered with. There have been several flaws in sgx, e.g. https://www.theregister.co.uk/2019/02/12/intel_sgx_hacked/
Re: EU Commission to staff: Switch to Signal messaging app
#75Earlier quoted context omitted.
Can one really trust they don't store more if they physicaly have the information at one point in time ? Or possibly their upstream connectivity provider could do that metadata scrapping.
I will link to this each and every time this comes up: https://signal.org/bigbrother/eastern-virginia-grand-jury/ Signal turned over everything they had on this user (which was two time stamps: user creation and last access), and fought the gag order to be able to publish the subpoena and the response. Signal would have to be pretty stupid to lie to a federal court. Think what you want, but Signal doesn’t have any me…
Even if I couldn't break the encryption I'd have timing and connectivity data.
So, if I were a user, I would always operate on the assumption that info would leak.
Re: EU Commission to staff: Switch to Signal messaging app
#76How is something that's tied to your phone number "secure"? The communications are encrypted, but my identity is public.
Re: EU Commission to staff: Switch to Signal messaging app
#77This is a mistake. They should at least compile their own version and not something that comes from an US based app store under US law. At any point the US can force a change. This is as secure as purchasing a machine from Crypto AG. [1] [1] https://en.wikipedia.org/wiki/Crypto_AG
Perhaps a better idea would be to fund an audit of the Signal app. (Or has that been done already?)
Re: EU Commission to staff: Switch to Signal messaging app
#78This is a mistake. They should at least compile their own version and not something that comes from an US based app store under US law. At any point the US can force a change. This is as secure as purchasing a machine from Crypto AG. [1] [1] https://en.wikipedia.org/wiki/Crypto_AG
Perhaps a better idea would be to fund an audit of the Signal app. (Or has that been done already?)
Re: EU Commission to staff: Switch to Signal messaging app
#79Earlier quoted context omitted.
Perhaps a better idea would be to fund an audit of the Signal app. (Or has that been done already?)
Doesn't help figure out if the signal update of the day that comes from the store is any good.
Re: EU Commission to staff: Switch to Signal messaging app
#80Earlier quoted context omitted.
Is there no open source or European alternative? Just keep relying on some Californian dude that insist i give him my and my friends phone numbers? And harass me so i give him more info to “personalize my profile” !?
wire.com is a good option. Open source, chats, calls, video calls, web app, phone app, etc.