Live data from Hacker News

Signal app downloads spike as US protesters seek message encryption

qz.com

211–220 of 367 posts

Re: Signal app downloads spike as US protesters seek message encryption

#211
post #128

Signal exposes the user's phone number, better alternative is to use burner phones or Telegram.

Telegram doesn't have encryption for groups though.

Actually they do: https://telegram.org/faq#q-so-how-do-you-encrypt-data , but since group chats are using Telegram's servers the encryption is not client-to-client. Here is the actual specification of how does their srever-client encryption work: https://core.telegram.org/mtproto

Re: Signal app downloads spike as US protesters seek message encryption

#212
post #157

Earlier quoted context omitted.

That doesn't change the fact that all phone numbers are visible to all group members. All it takes is one rogue participant to reveal the identities of all members. If that actor has access to triangulation data they now have identity, location history, words and possibly images/video.

Yeah, it's optimized for communication between trusted parties (e.g. Snowden and a journalist) - as such the focus is on verifying the identity of the other person, not hiding it. It'd be cool if they figured out a group chat setting that was optimized for groups like protesters trying to coordinate - show your identity only to users you are directly connected with/have verified/whitelisted, but hide your identity to…

Except the whole point of OTR-like messaging was that you can communicate with someone who you can't be entirely sure you trust in perpetuity (that's why messages in Signal and similar systems don't have non-repudiation -- neither party can prove to a third party that a message really was sent by the other party). Now, obviously the metadata worry is separate to how the message cryptography is implemented but it does seem odd to have a threat model which is somewhat confused on this question.

Re: Signal app downloads spike as US protesters seek message encryption

#213

Earlier quoted context omitted.

Using phone number as ID has been proven idiotic since forever now. As much as I like Signal this is such a design flaw that it makes their software not only untrustable but often unusable too. What's wrong with email logins?

I'm no expert on the subject, but probably the use of phone numbers (and confirmation by SMS) is helpful to limit the number of bots.

Signal could still validate the phone number via SMS and immediately discard it afterwards.

Personally I liked the way ICQ did it back in the day, they used a uniq ID just for their service decoupling it from a phone number.

If Signal wanted to avoid long numbers, they could use a CorrectBatteryHorseStaple approach which is what Xbox does for their usernames if you don't pick one.

Easier to remember,

Re: Signal app downloads spike as US protesters seek message encryption

#214
post #137
post #128

Signal exposes the user's phone number, better alternative is to use burner phones or Telegram.

Or an open standard like Matrix

First time hearing about Matrix standard. But in case the clients are maintained by some individuals - why should we trust them that there are no backdoors in their compiled binaries? Seems like a nice project! But probably it will take it's small niche, probably for now it is not wide spreaded, haven't heard any noise about the standard.

Re: Signal app downloads spike as US protesters seek message encryption

#215
post #200
post #187

Earlier quoted context omitted.

> Signal DOES NOT get your full contact list The full contact list is uploaded to Signal servers by the phones. The only protection layer that users have is the questionable security of Intel's SGX. It's still much better than what WhatsApp is doing, just not a black and white situation. To add a point to your list: Signal does not have automatic cloud backup of messages, unlike WhatsApp. On WhatsApp, 30% of users ha…

Do you have a reference for the claim that your full contact list is uploaded to servers? That seems important since their privacy policy says that they only use hashes, and it can’t be dependent on SGX since it runs on non-Intel hardware: https://signal.org/legal/#privacy-policy

SGX is for the servers not the clients. Their enclave is open source so you can theoretically audit it using RA.

I say theoretically because these schemes all have a core problem when they're not federated - you have no idea what your client is really doing and it's the client performing remote attestation with the enclave. You have no control over it. It could update tomorrow and switch every last bit of encryption off. Or it could do RA but not pin the enclave hash to anything audited (i.e. it accepts any enclave signed by Signal).

It's not a theoretical problem. Facebook say that WhatsApp is end to end encrypted, in the same way as Signal. That didn't stop them blocking people from forwarding links related to coronavirus. The literal and entire point of E2E cryptography is to stop them monitoring and interfering with people's communications, Facebook have been assuring governments for years they're powerless to do that, but of course the moment Facebook wanted to fight "misinformation" it all went out the window.

Fundamentally Signal and WhatsApp can never provide meaningful encryption or privacy. They don't allow alternative clients, so regardless of how much code they throw into the mix they control the entire pipe end to end and can just as easily switch it off again. And the moment their employees feel they have a sufficiently good motivation, it'll happen again.

Re: Signal app downloads spike as US protesters seek message encryption

#216
post #210
post #206

Earlier quoted context omitted.

The method is explained here: https://signal.org/blog/private-contact-discovery/ Yes, it's hashes of phone numbers instead of the phone numbers themselves, but that's a detail. Phone numbers are easy to brute-force especially for people the protesters are worried about, as well as easy to build rainbow tables for.

I think you might want a better way of phrasing that: it’s not the “full contact list” - most people would assume that includes names and all of the other metadata - and since it’s rate-limited there’s an interesting trade off where it’s not easy to brute-force but it is targetable if you are trying to track specific known people.

The name, profile pic, etc. is less relevant than the social graph itself. State actors already have phone number name mappings at least about their own residents. If you are just curious about who's visa applications to deny because according to data collected by your IMSI-catcher many of their contacts have participated in an anti-government protest, then the name etc. isn't really relevant.

Re: Signal app downloads spike as US protesters seek message encryption

#218

Has anyone here successfully convinced their non-techie friends to switch to Signal? How have you done it? I've been trying on and off with my closest friends, but no luck.

Yesterday my non-technical colleagues a whatsapp group just said "I'm switching to signal, see you there" and suddenly a few people switched.

Re: Signal app downloads spike as US protesters seek message encryption

#219

Has anyone here successfully convinced their non-techie friends to switch to Signal? How have you done it? I've been trying on and off with my closest friends, but no luck.

I got my family group chat setup in Signal. The biggest problem was how long it takes signal to sync your contacts. WhatsApp can do it in seconds but signal was taking an hour or more (this was on Xmas day).

Re: Signal app downloads spike as US protesters seek message encryption

#220
post #99

Earlier quoted context omitted.

Signal is not only used by protesters[0][1] so discovering that a phone number is connected to a Signal account by no means implies that the phone is used by a protester. [0]: https://www.militarytimes.com/flashpoints/2020/01/23/deploye... [1]: https://www.theguardian.com/politics/2019/dec/17/tories-swit...

The point made by the parent commenter was that you can join any group (if you get someone to invite you) related to a certain topic and get the phone numbers of everyone in that group. I am not sure about the situation in the US, but in Europe almost all phone numbers are directly linked to a certain person and address by the provider.

> The point

One of the points which, yes, I agree with, but I mainly responded to this:

> I can add phone numbers by enumeration into my contacts and Signal will show who among my contacts is on it.\

> I am not sure about the situation in the US, but in Europe almost all phone numbers are directly linked to a certain person and address by the provider.

Or you can go to a corner shop and buy a Lyca or Lebara SIM with cash. No need to give them your address. You can buy top ups in cash as well. At least in Western Europe this is available everywhere, pretty much.

(I'd still prefer if Signal didn't require phone number to sign up though.)

Post reply on HN