Live data from Hacker News

Looking back at how Signal works

signal.org

171–180 of 301 posts

Re: Looking back at how Signal works

#172
post #115

Been a big fan of whisper systems since the redphone project. Great to see them maturing. However, given the topic title it would have been nice to see some actual documentation on how signal actually works rather than just claims that it doesnt work like the others.

Does this help? https://signal.org/docs/

It seems to be about the clients rather than the server.

A level deeper than "how signal works" and more "how signal is made"

For example, I'd expect a "how signal works" article to explain why they even need when an account was registered and when it was last used.

"this phone number is using signal" is still a pretty large metadata leak.

Especially when state actors and probably a fair few non state actors can remotely compromise devices via the stuff in the baseband processor.

Re: Looking back at how Signal works

#173

Earlier quoted context omitted.

I'm talking about the discourse sorroundig privacy, not literally specifically about my phone. I hate to see it marketed as a tool of revolution instead of just common sense practices. Your use of "ideologically driven" is confusing. Of course they should be driven, by their ideology on how a messaging app should be. But how could their opinion on the protest drive them? Just some weeks ago a whole different crew was…

> how could their opinion on protest drive them? Some people believe in first and fourth amendment rights. Moxie, one of the original developers of the Signal protocol: Tracking everyone is no longer inconceivable, and is in fact happening all the time. We know that Sprint alone responded to 8 million law enforcement requests for real time customer location just in 2008. They got so many requests that they built an a…

But I am not upset in the least about the rioters or anyone else, I can assure you.

Guarding people's privacy and rights to a voice (during protests or otherwise) is a good use of the first and fourth amendments. But let's not confuse form and content. The protests are not advocating privacy, and I'm not even going to voice my opinions about them. There's a difference between backing the content of the protests, and defending the rights that incidentally enable them. The blogpost in question ended with "it’s your powerful voices that are out there organizing and advocating for change". I can only construe that as either explicitly siding with whatever ongoing protest there is, or an empty general statement (I assume it's the former though, but makes little difference to me).

I think my point got side-tracked by fault of my own. I don't require every single thing I use not to have ideologies attached, because it's simply impossible. And everyone has every right to voice their idiotic opinions, God knows I'm doing that. But it saddens me that more often than not people who could choose to be content-agnostic instead leverage their position to fight the good cause. And there's a thousand conflicting good causes.

Thanks for the links, btw.

Re: Looking back at how Signal works

#174

Earlier quoted context omitted.

The Signal team has always been open about the reason why they reject third-party clients: they claim that XMPP adoption was hindered by the inability of a user’s software to know if the software on the other end supports the same feature set. XMPP had grown into a large set of features that some clients supported and others did not. If Signal introduces a new feature, it knows that all users’ devices will support th…

Backwards compatibility against a previous set of features isn't easy but it's certainly not impossible and graceful degradation is a thing.

You can always define backwards compatibility that only goes to a certain lowest common denominator feature set, and no lower. For instance I have a number of httpd that support TLS1.2+ and specifically disallow SSLv3, TLS1.0 and TLS1.1. The population of browser user agents that don't understand TLS1.2 is infinitesimal at this point.

Re: Looking back at how Signal works

#175

Earlier quoted context omitted.

The Signal team has always been open about the reason why they reject third-party clients: they claim that XMPP adoption was hindered by the inability of a user’s software to know if the software on the other end supports the same feature set. XMPP had grown into a large set of features that some clients supported and others did not. If Signal introduces a new feature, it knows that all users’ devices will support th…

Backwards compatibility against a previous set of features isn't easy but it's certainly not impossible and graceful degradation is a thing.

It isn't clear if graceful degradation is possible in a security app.

Re: Looking back at how Signal works

#176

I love Signal and use it as much as I can, but I'm thinking of switching to Matrix solely because the desktop client is pretty bad. It won't show me messages until it syncs everything (so I can't even see old messages while things sync), and, what's worse, it skips messages, and multi-device just doesn't work. My laptop just shows "Message could not be decrypted" until I delete everything and reset. I'm not sure why…

I, for one, have a bigger problem with it forcing the use of phone numbers as a sign-in method. They're an arbitrary identifier from a legacy system that there's not really a point in continuing to extend, because if your device is capable of anything more advanced than SMS it's also capable of... well, this. Also KaiOS and the like are making chat feasible even on feature phones. Don't get me wrong, RCS will be a fi…

> Don't get me wrong, RCS will be a fine enough fallback (once it's E2E), but standardized chat is the dream.

Is there a plan for RCS to be E2E? Given that RCS went under the GSMA umbrella in 2008, and it's 2020 and adoption is minimal, I don't have any hopes for a future update that supports E2E to come out any time sooner than 2040, with handsets supporting it in 2050, and all endpoints supporting it in 2065; Google will have released about 30 more messangers by then, of course.

Re: Looking back at how Signal works

#177
post #176

Earlier quoted context omitted.

I, for one, have a bigger problem with it forcing the use of phone numbers as a sign-in method. They're an arbitrary identifier from a legacy system that there's not really a point in continuing to extend, because if your device is capable of anything more advanced than SMS it's also capable of... well, this. Also KaiOS and the like are making chat feasible even on feature phones. Don't get me wrong, RCS will be a fi…

> Don't get me wrong, RCS will be a fine enough fallback (once it's E2E), but standardized chat is the dream. Is there a plan for RCS to be E2E? Given that RCS went under the GSMA umbrella in 2008, and it's 2020 and adoption is minimal, I don't have any hopes for a future update that supports E2E to come out any time sooner than 2040, with handsets supporting it in 2050, and all endpoints supporting it in 2065; Googl…

Google's working on it, apparently.

Re: Looking back at how Signal works

#178

Earlier quoted context omitted.

I just opened my Signal desktop app that I had synced previously. It asked me to resync again with my mobile device, which needs camera permissions to take a picture of a QR code. I had previously removed Signal from my mobile device. Low and behold, my account no longer existed and I had to sign back up with a phone number. I then clicked sync and most of my messages on my desktop are gone. I don't see how this is e…

If I understand your description, you reset your account. They delete the messages for safety when you reset. An attacker could reset by getting ahold of your phone number by sim jacking or the govt getting your text. It's a safety method so no one can take you texts. Of course many people want to carry their texts along, but this is a safety risk if you lost control over your number. So that's what signal is doing.…

No, I had removed the app from my mobile previously, not deleted my account. When I resynced, they had removed my account and the messages saved on my desktop disappeared.

Re: Looking back at how Signal works

#179
Or use something that you (or someone you trust) can self-host, so then even the company/CEO/TLA-with-subpoenas are out of the picture.

Not only do I get to get Moxie out of the picture, I also get my phone and the phone companies out of it.

Re: Looking back at how Signal works

#180

All encryption is broken wrt a quantum cracker. How will, say, the future look at these Signal uses?

You are wrong that all encryption is broken with a quantum cracker. But as far as I know Signal is not quantum resistant. It's certainly something to keep in mind - that whatever you say might resurface later.
Post reply on HN