Live data from Hacker News

EU Commission to staff: Switch to Signal messaging app

politico.eu

171–180 of 289 posts

Re: EU Commission to staff: Switch to Signal messaging app

#171
post #119

Earlier quoted context omitted.

But for an entity like the EU they could have complete control over the lot, with relative ease. The client, server and protocol are all open.

Is the server really open? I was under the impression that it was not. That's my only issue with Signal honestly, you can't rehost/fork easily if you're unhappy with the way the project is going.

https://github.com/signalapp/Signal-Server

Re: EU Commission to staff: Switch to Signal messaging app

#172

This is a mistake. They should at least compile their own version and not something that comes from an US based app store under US law. At any point the US can force a change. This is as secure as purchasing a machine from Crypto AG. [1] [1] https://en.wikipedia.org/wiki/Crypto_AG

Crypto AG was an intel op the entire time. Where is your proof Signal works for and is owned by the American government?

Re: EU Commission to staff: Switch to Signal messaging app

#173
post #36
post #28

The EU budget is 148 Billion Euros. Surely, if they have a requirement for a secure communication app, they have the wherewithal to build one for their needs, that EU citizens and others could then use if they so chose? Essential knowledge is definitely public. This is not about 'Signal' it's about why governments can't/won't deliver on so many issues they themselves deem to be very materially important to them, part…

EU projects are often a bit of a mess; design by committee taken to the extreme, with each committee member being a nation.

That is not how the EU works, at least not the parts which I have some insight into. There is indeed a lot of design by committee but the countries have little to no say in the day to day work of the EU agencies.

Re: EU Commission to staff: Switch to Signal messaging app

#174

This is a mistake. They should at least compile their own version and not something that comes from an US based app store under US law. At any point the US can force a change. This is as secure as purchasing a machine from Crypto AG. [1] [1] https://en.wikipedia.org/wiki/Crypto_AG

The OS is US based too and they could easily keylog everything. Even if you wipe out the OS for a self-compiled one, there are blobs running full blown OS in the hardware and it has access to every single hardware resource, good luck getting rid of that one without building your own hardware and drivers from scratch.

> good luck getting rid of that one without building your own hardware and drivers from scratch.

For an individual that is obviously infeasible. For the continent of Europe as a whole, it obviously isn't. Why shouldn't they put some money into developing cellphone hardware with open source drivers?

Re: EU Commission to staff: Switch to Signal messaging app

#175

Earlier quoted context omitted.

Giving this advice has almost no cost and, at least arguably, it is better for staff to use Signal than other messengers. So, IMHO, this is good advice.

Not if the staff is lured by all the E2EE promises and all the lock icons to overestimate the security of the app and share more information than they would otherwise.

Not using something that actually improves security because people might think that it actually improves security is a crappy argument. If your phone is insecure for two separate reasons you should fix both of them instead of using each as an excuse not to fix the other.

Re: EU Commission to staff: Switch to Signal messaging app

#176

Earlier quoted context omitted.

I will link to this each and every time this comes up: https://signal.org/bigbrother/eastern-virginia-grand-jury/ Signal turned over everything they had on this user (which was two time stamps: user creation and last access), and fought the gag order to be able to publish the subpoena and the response. Signal would have to be pretty stupid to lie to a federal court. Think what you want, but Signal doesn’t have any me…

If I worked for the intelligence agencies I would be capturing all the info going in and out of the signal servers at the infrastructure level. Even if I couldn't break the encryption I'd have timing and connectivity data. So, if I were a user, I would always operate on the assumption that info would leak.

In this threat model, the only defense you would have would be an overlay network resistant to correlation attacks where all nodes are involved in routing traffic (like I2P), or a mixnet like Katzenpost.

Getting people to use Tor for everything is hard enough, good luck getting people to use stuff even more obscure.

Re: EU Commission to staff: Switch to Signal messaging app

#177
post #43

Earlier quoted context omitted.

Why reinvent the wheel? Signal does the job, doesn't store data, not even metadata, and can be used immediately.

> doesn't store data, not even metadata Isn't that just a promise? Also, even then, it is based on your contacts, which are seen by google.

Signal's source code is published so you can go look for yourself. If you believe that despite precautions the source code won't match what actually runs on your phone then realistically you've no real option to use any technological artefact and will be obliged to resort to maybe whispering coded messages to close confidants. As a large technocracy this is not a practical option for the EU.

Your phone number is sent to Signal's servers during sign-up and it uses the conventional SMS service to "close the loop" and prove this number is under your control. Having signed up you can use a PIN to lock the number to you so that anyone without that PIN can't do the "new phone" dance (this expires if you stop answering PIN questions correctly)

If you choose to do so a digest of your contact's phone numbers can be sent to Signal for them to match against the set of (also digested) numbers of Signal users so they can tell you who has Signal enabled.

Whether you choose to give your contacts to Google, to Facebook, to Apple or whoever is up to you and outside Signal's control.

Signal does let you create an encrypted profile, and then your device can tell other people's devices the keys to look at the profile if you want to allow that. You don't have to use a profile or trust anybody else if you don't want to. Signal doesn't learn the keys (unless I guess you deliberately sent them those keys) so they can't read the profile.

Unlike many of its competitors Signal's messages can't be read by Signal, in most cases this includes who sent them (Signal's "Sealed Sender" means in most cases if you correspond with someone the indication of who sent them a message will be encrypted such that they can tell you sent it but Signal only knows it was someone they authorised to send them messages). When you attach images Signal avoids learning how large the images are exactly, and if you use a service like GIPHY to add typical meme images like Stephen Colbert eating popcorn Signal double-proxies this so that they don't learn which GIF you used, and GIPHY doesn't learn who used it.

Edit: Fixed name of GIPHY. Huh.

Re: EU Commission to staff: Switch to Signal messaging app

#178
post #119

Earlier quoted context omitted.

But for an entity like the EU they could have complete control over the lot, with relative ease. The client, server and protocol are all open.

Is the server really open? I was under the impression that it was not. That's my only issue with Signal honestly, you can't rehost/fork easily if you're unhappy with the way the project is going.

Forking Signal isn't practical for the same reason Forking the UN wouldn't be practical. Network effect.

But the code is right there for you to read it and re-use it, you just won't get far building your own network with one user and demanding everybody else switch over.

Re: EU Commission to staff: Switch to Signal messaging app

#179

why is there no european company the size of whatsapp, facebook, apple and so on?

good luck competing with 0% tax state-sponsored companies without venture capital. The same reason there is no european huawei. There are some medium sized companies, but they don't have the same advantages as those in the US or China

I thought all the competitors to Huawei were European. They keep telling us that's the problem. (Apparently we need to be more closely aligned to America than Europe.)
Post reply on HN