Live data from Hacker News

Looking back at how Signal works

signal.org

61–70 of 301 posts

Re: Looking back at how Signal works

#61
post #6
post #2

> how we think about concepts like privacy, security, and trust I was disappointed to see that a mobile number is needed and that this number is shown by default in groups. Mobile numbers are much more trackable then email addresses in my opinion. And I do not understand at all why others should be able to see them so easily. So I now prefer Telegram because at least it hides numbers in groups by default.

Burner sim to setup and throw away addresses this concern. Telegram, messages in plaintext on the server? Encryption that isn't open? Yeah telegram is a bit of a non-starter if you have these kinds of concerns as far as I'm aware.

Both of these rhetorical claims are misinformation. Please don't do this.

Telegram messages are encrypted at rest on Telegram's servers with the keys held by Telegram the company. [1]

MTProto is fully open-source. [2]

Here's a FAQ of Telegram's most frequent criticisms. [3]

[1] https://telegram.org/faq#q-do-you-process-data-requests

[2] https://core.telegram.org/mtproto

[3] https://telegra.ph/How-really-secure-and-private-is-Telegram...

Re: Looking back at how Signal works

#62

Signal is a walled garden. They refuse to allow federation and even prohibit any modified client to use their servers. It's the least open "open source" model, and once (if) they gain significant market share they can easily close down the app and lock-in the users. Please use and spread federated alternatives. Donate and contribute.

What alternative would you recommend?

Re: Looking back at how Signal works

#63
post #59
post #32

Earlier quoted context omitted.

PIN only stops registration for a fixed amount of time, believe 7-days, then the entity controlling the number would be able to reclaim the account. If the “attacker” maintained control, new devices that add the number from their contact list would get no alert; that is, the users would have to figure out the number is controlled by someone else.

That’s 7 days since last use. So if you continue to use the app at least once every 7 days, it will remain registration locked. Also, anyone who had communicated with you before the switch would see a “safety number changed” notification if the number became affiliated with a new device.

Curious, where’s the “last use” in the documentation or code? Ask because I have seen other issues with the PIN vs docs and haven’t gotten to testing the recovery mode.

EDIT: Found the related docs, appears they had been edited since I lasted looked at them; for example, you can now disable PIN reminders:

https://support.signal.org/hc/en-us/articles/360007059792-Si...

And yes, “anyone who had communicated with you before the switch would see a ‘safety number changed’ notification if the number became affiliated with a new device” is correct, though so is my statement about new numbers adding the number. To be honest, I have caused the alerts to happen before, the other user had no idea what they meant, didn’t say anything, just clicked okay.

Re: Looking back at how Signal works

#64

I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…

> I'm thinking of switching to Matrix solely because the desktop client is pretty bad.

Oooooh, I've got some bad news for you.

Re: Looking back at how Signal works

#65
post #6

Earlier quoted context omitted.

Burner sim to setup and throw away addresses this concern. Telegram, messages in plaintext on the server? Encryption that isn't open? Yeah telegram is a bit of a non-starter if you have these kinds of concerns as far as I'm aware.

In most European countries you need to submit your ID to get any sort of working SIM card.

That wouldn't be a problem in phones where the radio part is screened from the system (Pinephone?) so that implementing encryption can be effective. The SIM might be tied with my me, but any eavesdropper would see only noise because the outgoing data is encrypted by the system before entering the radio hardware and is decrypted by the system after leaving it. They can know I generated some traffic at a certain moment, which is the same information they could get from the carrier operator, but that's about it.

Re: Looking back at how Signal works

#66
post #64

I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…

> I'm thinking of switching to Matrix solely because the desktop client is pretty bad. Oooooh, I've got some bad news for you.

What is it? Riot works beautifully.

Re: Looking back at how Signal works

#67

Signal is a walled garden. They refuse to allow federation and even prohibit any modified client to use their servers. It's the least open "open source" model, and once (if) they gain significant market share they can easily close down the app and lock-in the users. Please use and spread federated alternatives. Donate and contribute.

What alternative would you recommend?

XMPP with OMEMO

Re: Looking back at how Signal works

#68

Earlier quoted context omitted.

at least on Android you can sideload it

I recall reading something recently about how in a coming release, Android will disable sideloading. The sole permitted way to sideload will be to enable ADB and then install the app with adb install. Some techies will continue to do that, just like some people unlock the bootloader and install LineageOS on their device, but removing Signal from the Play Store would make it as good as dead for the general public. (Ev…

Some googling leads to this [1]. From what I read it seems to be an opt-in program (for now). Was initially very concerned when I read your post, especially because Google recently broke Magisk (likely forever).

[1]: https://www.xda-developers.com/google-advanced-protection-pl...

Re: Looking back at how Signal works

#69
post #28

Earlier quoted context omitted.

Signal’s official statement on the EARN It Act is here: https://signal.org/blog/earn-it/

Thanks for the link. There's a subtle threat in there, that they'll move out of the country if they have issues which I think a lot of tech companies would. This bill is so stupid in that tech companies can relatively easily move.

The legal entities can move to other jurisdictions, sure, but it doesn't matter because app distribution still occurs primarily through USA-based Google Play and USA-based Apple App Store—both of which can easily geofence apps as they please (or as they're required).

This is one of the reasons I've started to appreciate Matrix a lot more lately.

https://matrix.org/blog/2020/01/02/on-privacy-versus-freedom

Re: Looking back at how Signal works

#70

Earlier quoted context omitted.

If that’s the case doesn’t it matter even less that signal requires it since it’s already known anyway? Signal’s use of phone numbers as IDs means they don’t have to have any of your contacts sent to their servers. As shown in the article they have no metadata and nothing to reveal beyond your phone number and when you signed up. These other apps send your social graph to their servers, track and store metadata, don’…

Assuming you’re using Signal for organizing something the government doesn’t want you organizing, if one member of the group gets rubber-hosed into unlocking their phone, the govt instantly gets a list of verifiably correct names of people involved. In contrast, with a service that lets you use usernames that maneuver would reveal nothing but those usernames (which are as pseudonymous as it gets).

One of the other problems with using phone numbers, is that it provides an opening for adversaries. Now they know your phone number, which can be used for social-engineering attacks to attempt to bypass 2FA for any other online services tied to your phone number. Either for 2FA or for account-recovery/i-forgot-my-password functionality. 2FA by SMS is wrong and broken and nobody should use it, but they do.

Adversaries will attempt to social engineer customer service for your phone carrier into issuing them a new SIM or porting out the number, so they can receive verification SMS and phone calls.

Post reply on HN