Live data from Hacker News

EU Commission to staff: Switch to Signal messaging app

politico.eu

251–260 of 289 posts

Re: EU Commission to staff: Switch to Signal messaging app

#251
post #168

Earlier quoted context omitted.

It's a promise that got taken to court and survived. https://signal.org/bigbrother/eastern-virginia-grand-jury/ You can use a different contacts app, you don't have to give all your information to Google. My contacts are managed by a Nextcloud instance.

> You can use a different contacts app, you don't have to give all your information to Google As far as I know OWS does not mention this anywhere on their site nor on their program -- aren't the issues with usability of other programs and lack of sane defaults (such as with gpg) often given as an argument by signal supporters on why you should prefer it? That being said, is that even possible? I admit that I am not t…

Google Play Services and your contacts are completely different things. I'm confused on what information you think is being sent. As far as I'm aware, all FCM does is provide a push that tells the app to check in with Signal's server. No contact information is in play.

Signal also released a WebRTC version that doesn't depend on Google Play Services if that floats your boat.

Re: EU Commission to staff: Switch to Signal messaging app

#252

Earlier quoted context omitted.

I've read it requires a phone number so that it does not need to collect or store any (other) data on users.

It also very shadily holds that number hostage, meaning you are forced to wait seven days after uninstalling the app in order to be able to unregister your number from signal. If you don't you'll just not get messages from people on Signal. My opinion of them is quite low thanks to the iMessage-tier bullshit.

This certainly isn't the case with any version I've used. It's just Settings -> Delete Account, and its a large, red, very visible button.

Re: EU Commission to staff: Switch to Signal messaging app

#253
post #43
post #11

I'm supprised they have not developed their own or at least, bankrolled the development of one via grants. Though it would be good if there was an open source communications platform that would allow the public to engage with politicians in a formal and constructive way. Alas, so much disparity in solutions that it often irks me. https://ec.europa.eu/digital-single-market/en/projects Be great if the interface was bet…

Why reinvent the wheel? Signal does the job, doesn't store data, not even metadata, and can be used immediately.

Because only a fool would needlessly rely on a foreign private entity accountable to no one. And while a private entity might trust a foreign government more than their own (or assume that the foreign government doesn't care about them), this doesn't apply to the EC.

Re: EU Commission to staff: Switch to Signal messaging app

#254
Our top political campaigns use Wickr (it's pushed down from on high) but I have a hard time believing it adds any more security than simply mandating 2fa security keys w/ google advanced protection.

Given the problems ive experiences with the wickr app and lack of basic phone security ive seen this feels LESS secure to me.

Google put out research saying they had 0 successful phishing after mandated fobs. I guess there's a concern about forwards and that Wickr shows when someone screenshots but that doesnt stop anything...

I have seen lots of campaign staff that dont have passwords on their phone, or weak 4 digit ones. I use a password manager to store a long wickr pass but I think most just use a simple pass or re-use a password...

Wickr on my phone has render problems all the time and it has shown messages without me logging in at least twice.

It's also super inconvenient. if they really care about E2E - which doesnt even feel like the actual problem they are trying to fix (phishing/ability to read past messages when an account is compromised) - I'd rather have some enthusiastic outsiders develop an open source basic PGP chrome extension to sit on top of gmail or something (maybe that already exists)

Re: EU Commission to staff: Switch to Signal messaging app

#255
post #52

Earlier quoted context omitted.

To be fair, the vulnerability was fixed quickly. And in the end it improved the security of Matrix and the governement application. I prefer this to a closed-source application developed internally, without communication on security vulnerabilities.

Yes, does cover that in the link and from my perspective - ruddy good response time upon that and well handled. I can think of many comparable situations in other countries (some EU ones as well) in which the person finding the issue would of very easily been locked up.

To be clear, the vulnerability was with the specific server configuration for the French Matrix deployment (authing people based on email domain), and not a flaw in Matrix itself. We're not aware of anyone else running in that config. https://matrix.org/blog/2019/04/18/security-update-sydent-1-... had the details.

The actual bug was thanks to a long-standing bug in python's standard email.utils library, which finally got fixed: https://bugs.python.org/issue34155, combined with insufficiently-defensive coding and testing on my side. (I wrote the auth code in question).

Re: EU Commission to staff: Switch to Signal messaging app

#256

They should use Threema [1] which is based in Switzerland. Even though Switzerland is not in the EU it's not as bad as the US (from an EU standpoint) and since Switzerland is heavily dependent on the EU the likelihood of them spying on the EU is pretty small. Apart from that Threema publishes a transparency report [2] where they list all requests from governmental authorities. [1]: https://threema.ch/en [2]: https://…

1. The last time people bought non-transparent crypto from Switzerland it turned out decades later the company was secretly owned by the CIA. https://www.theguardian.com/us-news/2020/feb/11/crypto-ag-ci...

2. Threema is proprietary around open source library. It's trivial to add a backoor after any audit, and it's trivial to lie in your transparency report. Open source stuff is _obvious_ choice. There's no reason to open entire source for Threema (no ~one's making a profit copying other messengers) unless they're hiding something.

Re: EU Commission to staff: Switch to Signal messaging app

#257

The staff will be using Whatsapp. Signal has its issues but it's more secure than Whatsapp.

The benefit is, once you've got to have Signal installed, you'll probably want to talk to your friends over it as well to save time switching between the apps.

Re: EU Commission to staff: Switch to Signal messaging app

#258

That's a tad unfortunate. Signal was just low profile enough that my wife and I could use it in China. This raises the profile of it just a bit higher than I'd like. Further, with the likes of https://news.ycombinator.com/item?id=22202110 having a higher profile makes the organisation more vulnerable to harassment from the government.

My understanding is that US Senators already use it. At least there was a headline on HN ages back. The main issue with apps like Signal in my opinion comes from apps that snoop on your screen. I wouldnt be surprised if there are rogue custom keyboards that do this. I would be more worried if only communist / socialist nations (you all know the ones I am talking about, not sure of a better name so calling them what t…

[deleted]

Re: EU Commission to staff: Switch to Signal messaging app

#259
post #211

Earlier quoted context omitted.

This is the tradeoff. Being backed up somewhere is more convenient but less secure. If it is only on that one device, it requires physical control of the hardware. If it is in iCloud or somewhere else, it is an attack vector and one that can be exploited remotely and at scale.

That does not make much sense since you can backup all your data on an Android phone.

It's all going to change over time. What matters here is the direction the app is going towards.

Are we going to get more features? Yes.

Are we confident the devs can deliver those features actually secure? Yes, these guys are the ones leading the industry at the moment.

Do we need to worry about long term future of the app being sold? No, the project is a non-profit, it's backed by a foundation, and it's an ideological app, not a for-profit app or con (startup)

Re: EU Commission to staff: Switch to Signal messaging app

#260
post #59

How is something that's tied to your phone number "secure"? The communications are encrypted, but my identity is public.

This is about official communications in an organization with public lists of work phone numbers, not our underground cypherpunk community where we have no names maan we are nameless.

There's no requirement to be anonymous in this context. Metadata can be reduced via tech but it's not the top-priority -- quick fix to confidentiality problems OTOH is.

Post reply on HN