Live data from Hacker News

Signal app downloads spike as US protesters seek message encryption

qz.com

141–150 of 367 posts

Re: Signal app downloads spike as US protesters seek message encryption

#141

Earlier quoted context omitted.

Key management is still centralized and controlled by Apple, so they can still MITM communications by messing with the key exchange. iCloud backups (enabled by default) are not end-to-end encrypted. So while it's technically E2E, in practice you get very little protection from it because it's broken by design. I still use iMessage because of the user experience, but let's not be fooled by their misleading E2E claims;…

If both parties disable iCloud on their phones, does Apple have any way to read messages sent via iMessage?

Yes, if they add a wiretapping key to one or both of your key lists, which is silent/invisible to the sender.

Re: Signal app downloads spike as US protesters seek message encryption

#142
post #92

The biggest drawback with Signal for protesters is that it exposes the user's phone number to everyone else in groups (just like WhatsApp does). There is no way to even hide the fact that you have an account on Signal. I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it. If the authorities don't use tactics like they did in Hong Kong, the protesters may be safe…

This tradeoff is arguably a good thing. By using phone numbers as IDs signal can rely on your phone's local contacts (meaning they don't have to send your social graph to their servers). This way they can keep very little metadata on you. There's pretty much nothing for them to turn over except the fact that your phone number has the signal app. Most of the other secure apps could turn over your entire contact list (…

> Most of the other secure apps could turn over your entire contact list (which could be damaging for people in a protest that are being targeted).

But that doesn't help much if the entire contact list is a list of trash mail adresses (in the case of Wire) or a list of random IDs (in the case of Threema). And at least Threema does not store any information about your contacts on their servers.

Can you obtain a phone number without any ID in the US? Because you can't in large parts of Europe.

Re: Signal app downloads spike as US protesters seek message encryption

#143
post #132
post #104

Earlier quoted context omitted.

Absolutely agree. I really wish Telegram would get off the phone number system, especially after the embarrassing hack in Brazil. It's not explicitly Telegram's fault, but if your primary authentication method is insecure it's at least a little bit your fault. Phone numbers are NOT safe. I don't know why SMS MFA is even a thing, they're worse than passwords. When you use phone numbers or SMS for security, you are put…

Telegram should maybe just use proper encryption first.

And by default.

Re: Signal app downloads spike as US protesters seek message encryption

#144
post #99
post #92

The biggest drawback with Signal for protesters is that it exposes the user's phone number to everyone else in groups (just like WhatsApp does). There is no way to even hide the fact that you have an account on Signal. I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it. If the authorities don't use tactics like they did in Hong Kong, the protesters may be safe…

Signal is not only used by protesters[0][1] so discovering that a phone number is connected to a Signal account by no means implies that the phone is used by a protester. [0]: https://www.militarytimes.com/flashpoints/2020/01/23/deploye... [1]: https://www.theguardian.com/politics/2019/dec/17/tories-swit...

That doesn't change the fact that all phone numbers are visible to all group members. All it takes is one rogue participant to reveal the identities of all members. If that actor has access to triangulation data they now have identity, location history, words and possibly images/video.

Re: Signal app downloads spike as US protesters seek message encryption

#145

Long-time Signal user but I'm on the verge of moving I think. There are several UX shortcomings but the new PIN nag is a bridge too far. What are my options for alternatives? I imagine Telegram is the next best bet but very open to suggestions.

Same. The UI is just atrocious. It’s fundamentally a better product but just doesn’t come through as a whole. Evidently they learned nothing from Gimp/Photoshop.

Re: Signal app downloads spike as US protesters seek message encryption

#147
post #92

The biggest drawback with Signal for protesters is that it exposes the user's phone number to everyone else in groups (just like WhatsApp does). There is no way to even hide the fact that you have an account on Signal. I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it. If the authorities don't use tactics like they did in Hong Kong, the protesters may be safe…

If that helps, there is a rate limit for checking whether a number is in Signal: with a single account, you can only check 4320 phone numbers a day. This makes mass user enumeration attacks somewhat less practical.

isn’t getting your hands on lots of sims/phone numbers, and thus Signal accounts, pretty trivial, though?

Re: Signal app downloads spike as US protesters seek message encryption

#148

Long-time Signal user but I'm on the verge of moving I think. There are several UX shortcomings but the new PIN nag is a bridge too far. What are my options for alternatives? I imagine Telegram is the next best bet but very open to suggestions.

I like Threema. You don't have to provide a phone number to create an ID with them. You can create a backup of your private key in a completely offline way but there is also an online backup for convenience.

Telegram is great for public things like huge groups or newsletters. But no encryption by default is a no go for me.

Post reply on HN