Live data from Hacker News

Abusing WebRTC to reveal coarse location data in Signal

medium.com

61–64 of 64 posts

Re: Abusing WebRTC to reveal coarse location data in Signal

#61

> if a Signal user wishes to hide their private/public IP addresses even from contacts who call, then it has an option “Always Relay Calls” in its privacy options I thought Signal was all about privacy by default ? :D Signal fans love to dunk on Telegram for secret chats not being the only kind of chat.. well turns out on Signal, private is not the only kind of call, and your IP address is exposed by default.

Signal fans like to selectively forget that the server-side is proprietary software - therefore, the whole platform can't quite be proven to be reliable.

Essentially, they are not much better than Whatsapp stans.

Re: Abusing WebRTC to reveal coarse location data in Signal

#62

Earlier quoted context omitted.

I order to get a device that is not explicitly compromised with custom targeted malware one could: take a walk, enter a random shop, buy a device. Now you only have the standard malware that everyone gets preinstalled on their devices. How to keep it free of custom targeted malware? That is another question!

With a target like Snowden who is under constant surveillance and lives at the whim of his host country, he could expect that any off the shelf hardware he bought would be immediately compromised. His hosts would just make up some bullshit reason to part him from the device for several minutes and do an evil maid attack. Or from afar his hosts or another country's actors could exploit undisclosed vulnerabilities in h…

I agree I cover that in my OP.

Re: Abusing WebRTC to reveal coarse location data in Signal

#63

> if a Signal user wishes to hide their private/public IP addresses even from contacts who call, then it has an option “Always Relay Calls” in its privacy options I thought Signal was all about privacy by default ? :D Signal fans love to dunk on Telegram for secret chats not being the only kind of chat.. well turns out on Signal, private is not the only kind of call, and your IP address is exposed by default.

Signal fans like to selectively forget that the server-side is proprietary software - therefore, the whole platform can't quite be proven to be reliable. Essentially, they are not much better than Whatsapp stans.

I don't need the source code for Facebook.com to know what information my open-source browser sends to it. Same concept with Signal, you can read the client source code to know what the protocol sends to the server.

Re: Abusing WebRTC to reveal coarse location data in Signal

#64

> if a Signal user wishes to hide their private/public IP addresses even from contacts who call, then it has an option “Always Relay Calls” in its privacy options I thought Signal was all about privacy by default ? :D Signal fans love to dunk on Telegram for secret chats not being the only kind of chat.. well turns out on Signal, private is not the only kind of call, and your IP address is exposed by default.

Signal fans like to selectively forget that the server-side is proprietary software - therefore, the whole platform can't quite be proven to be reliable. Essentially, they are not much better than Whatsapp stans.

That’s hilariously wrong, the server source code is at https://github.com/signalapp/Signal-Server. How can you make such a claim in good faith when it’s so absolutely trivial to refute?
Post reply on HN