Live data from Hacker News

EU Commission to staff: Switch to Signal messaging app

politico.eu

211–220 of 289 posts

Re: EU Commission to staff: Switch to Signal messaging app

#211
post #202

One thing I found quite surprising about Signal is that you lose your messages if you move to a new phone - there is no backup on iOS. https://support.signal.org/hc/en-us/articles/360007059752-Ba...

This is the tradeoff. Being backed up somewhere is more convenient but less secure. If it is only on that one device, it requires physical control of the hardware. If it is in iCloud or somewhere else, it is an attack vector and one that can be exploited remotely and at scale.

That does not make much sense since you can backup all your data on an Android phone.

Re: EU Commission to staff: Switch to Signal messaging app

#212

This is a mistake. They should at least compile their own version and not something that comes from an US based app store under US law. At any point the US can force a change. This is as secure as purchasing a machine from Crypto AG. [1] [1] https://en.wikipedia.org/wiki/Crypto_AG

Does F-Droid support signed releases, and does Signal sign their APKs? In fact, aren't all APKs signed?

Signal is not on F-Droid, because m0xie does not want that[1].

Some forks of Signal are, though[2].

[1] https://community.signalusers.org/t/how-to-get-signal-apks-o... [2] https://forum.f-droid.org/t/signal-in-f-droid-in-2018/2847

Re: EU Commission to staff: Switch to Signal messaging app

#213

Earlier quoted context omitted.

Yes, selection should happen after the fact. Build at least an MVP with all critical functionality implemented in working stages. Then use that for the competition to get the contract. Preselection is hot garbage, as proven time and time again. Of course mechanism to mitigate the upfront cost of participating in such a competition should be implemented but in the end it should turn out cheaper/more worthwhile since a…

I’m as certain as I can be that few if any companies will be willing to invest (hundreds of) millions into projects to build some custom solution just to risk losing the bid in the end. And in top of that they would have a product that may have 0 demand elsewhere. Imagine if your employer told you they’ll hire you after you successfully deliver a project to test your worth. You’d think it’s a joke. And anyway most co…

This is true. What I see in my country is that initial product is maybe expensive, but still somehow acceptable. Problem is that, for some reason unknown to me, government does not gain rights to modify implemented solution and can't bring in another vendor to implement either next phase or do maintenance of the solution. And this introduces many years long vendor lock-in that pays off.

Re: EU Commission to staff: Switch to Signal messaging app

#214

Earlier quoted context omitted.

Thats why it should be done like darpa, choosing the best in the end.

Yes, selection should happen after the fact. Build at least an MVP with all critical functionality implemented in working stages. Then use that for the competition to get the contract. Preselection is hot garbage, as proven time and time again. Of course mechanism to mitigate the upfront cost of participating in such a competition should be implemented but in the end it should turn out cheaper/more worthwhile since a…

> Preselection is hot garbage, as proven time and time again.

Oh come on bro you don’t like the f35? ;)

Re: EU Commission to staff: Switch to Signal messaging app

#215

Earlier quoted context omitted.

Lasers, electron microscopes and x-ray scanners used for testing and verification in the semiconductor manufacturing industry plus loads of custom and open source tools.

Can it really be economically viable to have these scanned rather than just toss them out? I would imagine that anyone high enough in the EU to be a target is only using drives provided to them

It's not so much about being able to use a free USB drive; more about knowing if someone is distributing malware.

Re: EU Commission to staff: Switch to Signal messaging app

#216
post #190

Earlier quoted context omitted.

What kind of tools do you use for that? Would they catch BadUSB-like malware?

Lasers, electron microscopes and x-ray scanners used for testing and verification in the semiconductor manufacturing industry plus loads of custom and open source tools.

Yes, x-ray scanners seem to of made big inroads and only recently I learned that companies use them to verify phones as in the past they would visual check them - but copies have gotten so good that xray is the only real way now.

Though even then, you have to have something to compare it with and also know what you are looking at and able to eliminate what should and shouldn't be there.

Though when you have multilayer flash, the possibility to have a nefarious layer, sandwiched between good layers, makes things way harder.

All that said, as a rule, I'd just downright ban any non-company/entity USB drive or any tech. Keyboards and Mice, more so.

Re: EU Commission to staff: Switch to Signal messaging app

#217
post #164
post #79

Earlier quoted context omitted.

That is true. But given how much interest there is to find vulnerabilities in the Signal app, I would be very surprised if anyone would succeed in putting up a compromised Signal app on the App store and also be able to fly under the radar.

With cooperation, you could literally target just certain devices with the compromised version.

IMHO, the cost of that attack is pretty darn high.

Re: EU Commission to staff: Switch to Signal messaging app

#218

I once worked in the Commission, briefly. Technical security seemed to be non-existent as far as I could tell (in an admittedly very junior role). Once all of the interns got invited to the U.S. embassy to meet the Ambassador (some guy who literally said he got the job because he was friends with Obama). On the way out the nice embassy staff gave us goodie-bags, complete with handy pen drives... Basically everyone wa…

> some guy who literally said he got the job because he was friends with Obama There are two kinds of U.S. ambassadors: 1) Career foreign service people 2) Friends of the presidential administration at the time Examples of the latter aren't hard to find. Off the top of my head I'm familiar with William Timken, a US businessman who was appointed Ambassador to Germany by George W. Bush because he was a huge supporter […

Or, to put that another way—there are two kinds of ambassadors/diplomats:

1. People the administration is paying to go out and brown-nose foreign leaders, or those leaders’ own ambassadors/diplomats, in a combination “outbound sales” and “customer service” sort of way;

2. People who presumably have the ear of the administration, where foreign leaders want to pay to impress them in order to access the administration through them.

Whether or not you call someone who’s a friend of the president an “ambassador”, foreign leaders are going to want to treat them as an ambassador, so you may as well give them the protections that playing that role requires—even if they never normally leave the country—on the off-chance that a foreign leader either runs into them or intentionally pursues and {hires through a proxy, seduces, coerces, etc.} them.

In this second sense, “ambassador” is short for “a person a state leader is worried about the welfare and mental sanctity of, in the face of global political machinery trying to manipulate the leader by any means necessary.”

Re: EU Commission to staff: Switch to Signal messaging app

#219

It seems like nothing is secure anymore these days. Not even Signal. Let‘s go back to sending ravens.

RFC1149, IP over Avians[1] is not in any way protected against e.g. MITM. Nor is sending the verbatim message by Avians. Sending a micro-SD by raven does not solve it either.

All you need is a bow-and-arrow, a practiced hand, and your own raven to MITM the message.

[1] https://tools.ietf.org/html/rfc1149

Re: EU Commission to staff: Switch to Signal messaging app

#220
post #212

Earlier quoted context omitted.

Does F-Droid support signed releases, and does Signal sign their APKs? In fact, aren't all APKs signed?

Signal is not on F-Droid, because m0xie does not want that[1]. Some forks of Signal are, though[2]. [1] https://community.signalusers.org/t/how-to-get-signal-apks-o... [2] https://forum.f-droid.org/t/signal-in-f-droid-in-2018/2847

Ah, yes, I forgot about that. Too bad they don't even publish the APK on signal.org.
Post reply on HN