Live data from Hacker News

I don't trust Signal (2018)

drewdevault.com

21–30 of 115 posts

Re: I don't trust Signal (2018)

#21
post #19

I reacted to previous posts about this by installing Element (was Riot.im; search for both words) matrix client, setting up a periodic donation to privacytools.io, and making accounts with that as homeserver (chat.privacytools.io) for me and for the rest of the family. (Previously, I had a Librem.one account, but they don't maintain their server, so I dropped it.) It works... Still waiting for anyone else I know to c…

Matrix does pretty well in terms of privacy these days.

As for privacytools.io, I can't really agree. They have made a number of suggestions which are less about actual privacy and more about a trend I've come to think of as "privacy roleplaying" - trendy software & services which use privacy and security as a selling point but whose implementation doesn't back it up. An example is Protonmail. When it comes to the privacy vs usability debate I come down hard on the side of privacy. Doesn't matter how pretty it is if it's going to get you rubber hosed.

Re: I don't trust Signal (2018)

#22
post #8
post #4

After the PIN/Intel SGX debacle, I trust Signal even less.

Seems like I missed this a month ago. I'm now catching up from Matthew Green's blog post. [1] [1]: https://blog.cryptographyengineering.com/2020/07/10/a-few-th...

Thanks for posting this! I had been waiting for Matthew Green's reaction.

Re: I don't trust Signal (2018)

#23
post #9

Earlier quoted context omitted.

There is no alternative that provides the ease of use and privacy guarantees. I think the OWS/Moxie hate is misplaced. They’re competing with iMessage and WhatsApp and Instagram and Facebook, and Signal is a much better option than all of those. Let’s be honest: the alternative is that Facebook gets all of our chats in cleartext.

I don't buy it. I've been running my own Matrix homeserver and giving access to non-techy members of my family for years already. Setting up e2e is not automatic, but nothing that my mother couldn't do after 5 minutes of hand-holding. It is on us with tech skills to help others to get out of any centralized alternative. Ease of use will come with the less technical user base.

It's on us as tech users to create solutions that don't require 5 minutes of hand holding with every user of software and call it an achievement.

Re: I don't trust Signal (2018)

#24
Signal falls into an uncomfortable place for me.

I like pre-paid cellphone plans which give me a small number of text messages, a small amount of airtime. Using these I can communicate with people when I am not near a WiFi AP. I do not want to pay for data and would prefer to use my and my friends' access points and the free wifi in the small number of commercial locations that I visit.

In Canada all of the major carriers disable WiFi Calling² on pre-paid plans. They essentially only enable it as crutch to leach off public infrastructure to take up the slack on their insufficient private infrastructure.

So I infrequently (but enough to be annoyed) find myself in the situation that I am not near a WiFi access point and wish to communicate with someone else. Currently Signal will only allow me to do this via insecure SMS messages.

I read their original explanation in 2015 for disabling this functionality. Namely SMS leaks too much metadata¹ and we are only catering to needs of real-activists in real-dictatorships, and anyway SMS is too expensive there so this is a 1st World Problem.

As an explanation it leaves me wondering why I would bother with Signal: if I bite the bullet and sign up for a circa CA$50/month plan with data I may as well just use Element Matrix over WiFi. Signal brings nothing to the table except the possibility of accidentally sending an insecure SMS message and incurring a 30c charge for it.

1. https://signal.org/blog/goodbye-encrypted-sms/ 2. https://support.signal.org/hc/en-us/articles/360007321171-Ca...

Re: I don't trust Signal (2018)

#25
post #20

I only use phone calls (sync) and e-mail (async) nowadays.There's no other communication channel I would need. I'd only be willing to substitute them with their encrypted, P2P, and open-source counterparts, if they ever come into existence. Texting, on the other hand, used to be the bane of my existence, as--especially in its current form (free, nested layout, etcetera)--it's one of the most distracting, inefficient,…

You could have substituted email for its encrypted, P2P, open-source counterpart for almost 30 years now. It's called PGP / GnuPG. What more do we really need? It actually has more legal protection and formality, and way more clarity, than any centrally managed "E2EE" chat platform.

We just need a really good app that uses SMTP as the underlying protocol to send messages that aren't MIME / HTML email, but rather are a simple new format for chat, and then start using email as a chat mechanism. There's no real reason why it can't be fast enough.

Re: I don't trust Signal (2018)

#26
I trust Signal's end-to-end encryption promise, but I have a problem with the application not offering anonymity or privacy. By demanding users to provide a cell phone number to enable their accounts, they are connecting actual people to the Signal accounts and consequently also allowing them (or someone else) to visualize social networks; in intelligence gathering, data such as who speaks to whom, at what hours, with what message frequency etc. is highly valuable. It's also important that users ask themselves how Signal manages to finance all the SMS costs and the infrastructure when the application is gratis and free from ads.

Re: I don't trust Signal (2018)

#27

I trust Signal's end-to-end encryption promise, but I have a problem with the application not offering anonymity or privacy. By demanding users to provide a cell phone number to enable their accounts, they are connecting actual people to the Signal accounts and consequently also allowing them (or someone else) to visualize social networks; in intelligence gathering, data such as who speaks to whom, at what hours, wit…

Just to add... yes, I know it's possible to register a Signal account with a disposable VLN, but how many Signal users can be expected to be "tech literate" to this level? Practically none.

Re: I don't trust Signal (2018)

#29
post #4

After the PIN/Intel SGX debacle, I trust Signal even less.

For anyone who doesn't know what this is about:

https://community.signalusers.org/t/dont-want-pin-dont-want-...

https://community.signalusers.org/t/mandatory-pin-without-cl...

TL;DR:

- Signal introduced mandatory PINs to store certain user information (profile, contact list) on their servers in an encrypted fashion (protected by the user's PIN and, if the user chooses a short PIN, Intel SGX enclaves that Signal uses)

- PIN UI was/is exceptionally bad, didn't explain what PIN was for and came with annoying Do-you-still-remember-your-PIN popups which made zero sense when user chooses long passphrase.

- Most importantly: If user chooses a short PIN, protection of their information will hinge purely on Intel SGX enclaves. But: The PIN UI didn't recommend choosing a long passphrase and also didn't explain this point.

- Lots of users didn't want any of their information on Signal servers to begin with, were annoyed by popups and/or didn't trust SGX and ran amok (see the above two links)

- It seems PINs can now be disabled[0]

[0]: https://support.signal.org/hc/en-us/articles/360007059792-Si...

For more details, see the post by Matthew Green that was posted in a sibling comment.

Re: I don't trust Signal (2018)

#30

Earlier quoted context omitted.

I don't buy it. I've been running my own Matrix homeserver and giving access to non-techy members of my family for years already. Setting up e2e is not automatic, but nothing that my mother couldn't do after 5 minutes of hand-holding. It is on us with tech skills to help others to get out of any centralized alternative. Ease of use will come with the less technical user base.

It's on us as tech users to create solutions that don't require 5 minutes of hand holding with every user of software and call it an achievement.

Yes, you are absolutely right. No, it does not invalidate what I am saying.

If we keep expecting underfunded and under-resourced parties to come up with software ready and with absolute feature-parity over what is being pushed by the companies that have time, money and marketing teams, we are never going to make a dent on mindshare of the general public.

If on the other hand are diligent in refusing for centralized alternatives while willing to learn and emulate what they do right, then we will at the very least be in a state of steady progress. Matrix and Synapse from two years ago where way worse than they are today. I am confident that in two years from now it will be even better and easier than it is today. Facebook/Google Meet/MS Teams/Skype from two years ago was centralized and closed, just as I expect them to be closed two years from now.

Post reply on HN