Live data from Hacker News

EU Commission to staff: Switch to Signal messaging app

politico.eu

281–289 of 289 posts

Re: EU Commission to staff: Switch to Signal messaging app

#281
post #112

In previous discussion here on HN, Wire was claimed to be more secure than Signal (something related to initial key sharing?) I don't understand why there's so much publicity behind Signal, and Wire is never mentioned. I've been using Wire for years, and it doesn't require a phone number to setup.

One reason I stopped using was it turned from delightfully light to painfully bulky. Also its deliberate transition (I’m sure they had reasons for that) from a simple chat app to more Slack like.

Re: EU Commission to staff: Switch to Signal messaging app

#282
post #68

Earlier quoted context omitted.

Signal uses Intel SGX to give you some assurances about this, at least for parts of their serving stack. You can run the remote attestation tools and get a report back from Intel that says, in effect, "you connected to a genuine CPU and it's running software with this hash". Then you reproduce the build of the open source code and check the hashes match. I'd be surprised if anyone has ever actually done this. It's a…

Very interesting, thanks for sharing. I had one idea of extreme transparency. What if the Signal server used a per-user-thread model where each thread was isolated in a sandbox, which only the user has access to. The user can log in with read only access via ssh and certify that nothing is logged, nothing is tampered with etc. A kind of extreme transparency.

You're heading in the right direction but traditional UNIX tools don't work here. That's why Signal needs to use SGX.

Consider: how do you know the SSH server isn't tampered with? It could be feeding you an entirely fake session.

You might say, the sandbox. How do you know the sandbox isn't tampered with?

How do you know the hard disk or the RAM isn't tampered with? The third party owns the machine itself.

SGX is based on the insight that it's very, very difficult to tamper with a physical circuit as small as a CPU. The CPU is the root of trust in any machine. If a CPU can produce a report that says the moral equivalent of "I'm running an OpenSSH server version X" and the CPU itself is preventing the server owner from tampering with the software, then you have the ability to reason about what the server is doing with your data.

Re: EU Commission to staff: Switch to Signal messaging app

#283

Earlier quoted context omitted.

The phone number deregister flow is such a dark pattern it's incredible. Not something a chat app should ever do to be reputable.

How so?

If you uninstall the app it has a seven day forced delay for releasing your phone number, it isn't disclosed anywhere and the form just silently errors out when seven days haven't passed.

Re: EU Commission to staff: Switch to Signal messaging app

#284

Earlier quoted context omitted.

I don't know about you, but I as a 'techie in the east-west' have a bunch of people who ask me or follow my choices wrt tech stuff. I might recommend Signal to them if they specifically ask for something encrypted, but if they just follow what I use they'll see no Signal.

Sure. But the fact that the huge majority of messaging users use their phones is not exactly controversial. Heck, whatsapp has gotten several orders of magnitude more people to use encrypted messaging than any other software, and techies hate it.

You are absolutely right. People on here love to crap on good solutions in search for the perfect solution, whether or not that actually solves users' problems. Case in point: your comment being greyed out. WhatsApp adopting Signal protocol probably accomplished several orders of magnitude more than anything else the Signal team has done. Of course Signal remains better for privacy, and yes, there are other messengers that don't require you to use a phone number. But for most people, using phone numbers solves so many more problems than it causes. Use the most secure messenger that works for you.

Re: EU Commission to staff: Switch to Signal messaging app

#285
post #110

Earlier quoted context omitted.

at least the Dutch sites work. try a post communist country gov site and you'll start appreciating it right away.

Have you ever used Estonia's?

The EU should just give the keys to the server room to Estonia and let them handle our IT.

Re: EU Commission to staff: Switch to Signal messaging app

#286

Earlier quoted context omitted.

Have you ever used Estonia's?

If anybody wishes to explore, here's an example: https://www.eesti.ee/en/

I like how in "eesti.ee/en/" more than 50% of the letters are "e". So that how I picture an Estonian keyboard now.

Re: EU Commission to staff: Switch to Signal messaging app

#288
post #21

Earlier quoted context omitted.

Personally I believe that if you become an elected representative of the public you should become a public person where all your in-person meetings and all your phone calls and messages are public for the period you are elected. If you meet someone without disclosing it, it should be a criminal offence. I know this will never happen in real life but I think this is the only way to solve the problem of corrupt officia…

Also: The Circle by Dave Eggers.

Thank you, I haven't read that one. It's going to be read within the next few weeks :)

Re: EU Commission to staff: Switch to Signal messaging app

#289
post #260
post #59

How is something that's tied to your phone number "secure"? The communications are encrypted, but my identity is public.

This is about official communications in an organization with public lists of work phone numbers, not our underground cypherpunk community where we have no names maan we are nameless. There's no requirement to be anonymous in this context. Metadata can be reduced via tech but it's not the top-priority -- quick fix to confidentiality problems OTOH is.

Right, and how do I communicate when my phone battery is dead? Or the phone breaks?
Post reply on HN