Live data from Hacker News

EU Commission to staff: Switch to Signal messaging app

politico.eu

71–80 of 289 posts

Re: EU Commission to staff: Switch to Signal messaging app

#71

I know Signal is secure and all — and I use it myself — but I can’t help but think how can we trusted that the central servers aren’t wiretapped? It would be the ultimate proof of security if one could transparently verify that the middle man is running the actual code it claims to be running.

They use the Intel sgx (secure enclave) to do exactly this. Although for message contents, it doesn't matter anyway because they are end to end encrypted and cannot be read except by the receiving party.

Re: EU Commission to staff: Switch to Signal messaging app

#72
That's a tad unfortunate. Signal was just low profile enough that my wife and I could use it in China. This raises the profile of it just a bit higher than I'd like. Further, with the likes of https://news.ycombinator.com/item?id=22202110 having a higher profile makes the organisation more vulnerable to harassment from the government.

Re: EU Commission to staff: Switch to Signal messaging app

#73
post #2

But what should I use if I am a politician and fundamentally believe that the government should be able to read my communications?

SMS and phone calls. The infrastructure is all there already.

Interestingly, the EU's position on this looks really confused. SMS messages should (in theory) only transit their own local telcos. The USA doesn't get a look-in unless it hacks the telcos themselves.

What the EU is doing here is routing all Commission traffic through US based server farms and roots of trust. The phones are controlled from the USA, the comms services are too. So their own local firms can no longer see the traffic but US firms can (Signal claim this isn't the case but people are wising up to the fact that this can't be true until more infrastructure is in place).

What actual threat are they trying to block here?

Re: EU Commission to staff: Switch to Signal messaging app

#74
post #68

I know Signal is secure and all — and I use it myself — but I can’t help but think how can we trusted that the central servers aren’t wiretapped? It would be the ultimate proof of security if one could transparently verify that the middle man is running the actual code it claims to be running.

Signal uses Intel SGX to give you some assurances about this, at least for parts of their serving stack. You can run the remote attestation tools and get a report back from Intel that says, in effect, "you connected to a genuine CPU and it's running software with this hash". Then you reproduce the build of the open source code and check the hashes match. I'd be surprised if anyone has ever actually done this. It's a…

> Then you reproduce the build of the open source code and check the hashes match.

Assuming that the sgx environment hasn't been tampered with. There have been several flaws in sgx, e.g. https://www.theregister.co.uk/2019/02/12/intel_sgx_hacked/

Re: EU Commission to staff: Switch to Signal messaging app

#75
post #32

Earlier quoted context omitted.

Can one really trust they don't store more if they physicaly have the information at one point in time ? Or possibly their upstream connectivity provider could do that metadata scrapping.

I will link to this each and every time this comes up: https://signal.org/bigbrother/eastern-virginia-grand-jury/ Signal turned over everything they had on this user (which was two time stamps: user creation and last access), and fought the gag order to be able to publish the subpoena and the response. Signal would have to be pretty stupid to lie to a federal court. Think what you want, but Signal doesn’t have any me…

If I worked for the intelligence agencies I would be capturing all the info going in and out of the signal servers at the infrastructure level.

Even if I couldn't break the encryption I'd have timing and connectivity data.

So, if I were a user, I would always operate on the assumption that info would leak.

Re: EU Commission to staff: Switch to Signal messaging app

#76
post #59

How is something that's tied to your phone number "secure"? The communications are encrypted, but my identity is public.

Security is not the same thing as anonymity. Maybe Signal's design goals just don't align with your requirements, and that's okay. But that doesn't mean that it can't be the right tool for people with a different set of requirements.

Re: EU Commission to staff: Switch to Signal messaging app

#77
post #66

This is a mistake. They should at least compile their own version and not something that comes from an US based app store under US law. At any point the US can force a change. This is as secure as purchasing a machine from Crypto AG. [1] [1] https://en.wikipedia.org/wiki/Crypto_AG

Perhaps a better idea would be to fund an audit of the Signal app. (Or has that been done already?)

Doesn't help figure out if the signal update of the day that comes from the store is any good.

Re: EU Commission to staff: Switch to Signal messaging app

#78
post #66

This is a mistake. They should at least compile their own version and not something that comes from an US based app store under US law. At any point the US can force a change. This is as secure as purchasing a machine from Crypto AG. [1] [1] https://en.wikipedia.org/wiki/Crypto_AG

Perhaps a better idea would be to fund an audit of the Signal app. (Or has that been done already?)

An audit would only prove that the current code is secure.

Re: EU Commission to staff: Switch to Signal messaging app

#79
post #77
post #66

Earlier quoted context omitted.

Perhaps a better idea would be to fund an audit of the Signal app. (Or has that been done already?)

Doesn't help figure out if the signal update of the day that comes from the store is any good.

That is true. But given how much interest there is to find vulnerabilities in the Signal app, I would be very surprised if anyone would succeed in putting up a compromised Signal app on the App store and also be able to fly under the radar.

Re: EU Commission to staff: Switch to Signal messaging app

#80
post #18

Earlier quoted context omitted.

Is there no open source or European alternative? Just keep relying on some Californian dude that insist i give him my and my friends phone numbers? And harass me so i give him more info to “personalize my profile” !?

wire.com is a good option. Open source, chats, calls, video calls, web app, phone app, etc.

wire.com moved HQ to US and “Individual consumers are no longer part of Wire’s strategy.”
Post reply on HN