Live data from Hacker News

I don't trust Signal (2018)

drewdevault.com

31–40 of 115 posts

Re: I don't trust Signal (2018)

#31

I trust Signal's end-to-end encryption promise, but I have a problem with the application not offering anonymity or privacy. By demanding users to provide a cell phone number to enable their accounts, they are connecting actual people to the Signal accounts and consequently also allowing them (or someone else) to visualize social networks; in intelligence gathering, data such as who speaks to whom, at what hours, wit…

Just to add... yes, I know it's possible to register a Signal account with a disposable VLN, but how many Signal users can be expected to be "tech literate" to this level? Practically none.

Given the demographic Signal attracts that seems like an unsafe assumption.

Re: I don't trust Signal (2018)

#32
I love Mr. DeVault's work, and think he consistently shows integrity in his work, to say nothing of his incredible productivity and engineering.

That said, in my time following his blog and Mastodon toots, he's prone to making these hot-takes that take down successful projects that do a lot of public good, but don't tick every check. His repeated criticism of Mozilla is a good example of this.

It often feels like cutting off ones nose to spite the face. Without the Mozillas and OpenWhispers of this world, we've no hope for the DeVaults which create incredible feats of engineering that tick all the ideal boxes but lack some of the creature comforts (e.g. sr.ht, wayland, etc..)

I'm optimistic for the future, and the projects started by Moxie and DeVault are a large part of it.

Re: I don't trust Signal (2018)

#33
This post has been on Hacker News several times. For instance: https://news.ycombinator.com/item?id=17723973.

When it was first published, it included an emphatic recommendation to use Matrix, and, later, Tox --- in fact, the post even included a changelog at the bottom recording the inclusion of Tox. After it was pointed out to the author that Matrix didn't even do E2E by default, the recommendations (and the changelog) were ghost-edited out of the post, but you can still see them on Archive.org.

I don't understand why people take this post seriously.

Re: I don't trust Signal (2018)

#34
post #19

I reacted to previous posts about this by installing Element (was Riot.im; search for both words) matrix client, setting up a periodic donation to privacytools.io, and making accounts with that as homeserver (chat.privacytools.io) for me and for the rest of the family. (Previously, I had a Librem.one account, but they don't maintain their server, so I dropped it.) It works... Still waiting for anyone else I know to c…

Matrix does pretty well in terms of privacy these days. As for privacytools.io, I can't really agree. They have made a number of suggestions which are less about actual privacy and more about a trend I've come to think of as "privacy roleplaying" - trendy software & services which use privacy and security as a selling point but whose implementation doesn't back it up. An example is Protonmail. When it comes to the pr…

This is useful information. So, not librem.one, not privacytools.io, then... Maybe that leaves a homeserver of my own? I guess I am glad no one has picked up my current address. But it doesn't bode well for adoption.

I had thought that parking on a homeserver was not trusting them.

Re: I don't trust Signal (2018)

#35
I'm so proud that a family member managed to get all of my extended family on Signal. My grandparents are even on Signal.

I wouldn't trust such an app for anything actually secret due to the mentioned issues (and phone number req), but I think it's great that we're using high grade encryption to talk about what we had for dinner.

Encrypted and private should be the default no matter what!

Re: I don't trust Signal (2018)

#36

What's the alternative to Signal then? For iOS users?

Considering the first few pages of text of this guys problems with signal is it heavily encourages (but does not require) the google app store to install and update the app, I'm guessing he would really freak out on an apple device, where there is no tools that really let you bypass the apple store, and services.

Re: I don't trust Signal (2018)

#37
Trust it to what?

I use Signal because I think it protects my SMS messages from:

a) being harvested and read by other apps on my phone

b) being read by someone who unlocks my phone

c) being passively intercepted and stored by carriers and their snoopy employees

d) opposition researchers or private investigators targeting my friends, acquaintances, and business associates.

For anything targeted and state level, all bets are off anyway, so it's not a solution for people who have that problem. What am I missing?

Re: I don't trust Signal (2018)

#38
post #33

This post has been on Hacker News several times. For instance: https://news.ycombinator.com/item?id=17723973 . When it was first published, it included an emphatic recommendation to use Matrix, and, later, Tox --- in fact, the post even included a changelog at the bottom recording the inclusion of Tox. After it was pointed out to the author that Matrix didn't even do E2E by default, the recommendations (and the chang…

Ah, once again with the insubtantive rebuttal of the last point in the article, the point which has the least relevance to the meat of the article. And this time, your rebuttal is out of date, because Matrix does have end-to-end encryption by default for all chats! Always lovely having you around on HN, tptacek.

Re: I don't trust Signal (2018)

#39

I love Mr. DeVault's work, and think he consistently shows integrity in his work, to say nothing of his incredible productivity and engineering. That said, in my time following his blog and Mastodon toots, he's prone to making these hot-takes that take down successful projects that do a lot of public good, but don't tick every check. His repeated criticism of Mozilla is a good example of this. It often feels like cut…

I appreciate your feedback, and I try to be more balanced with this kind of article these days, and publish them less often. However, I'd like to point out that I've always strived to find other resolutions to these problems first - I spoke with Moxie and others involved in Signal at length before writing this article, and only wrote this as a last resort. With organizations like Mozilla, I have also spoken directly to some of those responsible, though it's more difficult with a larger organization, and waited until a long-term pattern of bad behavior had been established. I make these criticisms because I want them to live up to the ideals they proclaim - it's with the hope that they'll change for the better.
Post reply on HN