Live data from Hacker News

I don't trust Signal (2018)

drewdevault.com

41–50 of 115 posts

Re: I don't trust Signal (2018)

#41

Trust it to what? I use Signal because I think it protects my SMS messages from: a) being harvested and read by other apps on my phone b) being read by someone who unlocks my phone c) being passively intercepted and stored by carriers and their snoopy employees d) opposition researchers or private investigators targeting my friends, acquaintances, and business associates. For anything targeted and state level, all be…

I use Signal because I think it protects my SMS messages

It depends. I think calling them simply SMS messages instead of being more precise is misleading because: Text messages sent through your mobile SMS/MMS plan are insecure and need your phone to be connected to your mobile network.

and

Signal Desktop does not send or receive SMS/MMS messages. Only Signal messages will be sent or received. The desktop app is an independent client that works whether or not your mobile device is present or online. We also want to encourage users to move away from insecure legacy protocols.

https://support.signal.org/hc/en-us/articles/360007321171-Ca...

I find it very confusing.

Re: I don't trust Signal (2018)

#42
post #33

This post has been on Hacker News several times. For instance: https://news.ycombinator.com/item?id=17723973 . When it was first published, it included an emphatic recommendation to use Matrix, and, later, Tox --- in fact, the post even included a changelog at the bottom recording the inclusion of Tox. After it was pointed out to the author that Matrix didn't even do E2E by default, the recommendations (and the chang…

Ah, once again with the insubtantive rebuttal of the last point in the article, the point which has the least relevance to the meat of the article. And this time, your rebuttal is out of date, because Matrix does have end-to-end encryption by default for all chats! Always lovely having you around on HN, tptacek.

Recommending a tool that wasn't even end-to-end encrypted over Signal because you didn't like the way Signal's leadership responded to your demand to support F-Droid is the most relevant thing you wrote. Just because it was malpractice doesn't make it out of bounds.

Re: I don't trust Signal (2018)

#43
post #14

Original from 2018, 467 comments https://news.ycombinator.com/item?id=17723973 . Not commenting as snark (reposts are ok after all) more to save Dang digging out the link and also to see how many more or less duplicate sentiment comments are made and / or how perceptions have changed.

I thought that first comment had some inappropriately personal things to say about ddvault and his article. It also seemed like they didn't really respond with substance to the what the article said.

What substance in the article did I miss? Unlike the author, I stand by what I wrote originally.

I'll note the irony of calling my critique overly personalized, when the original article is based on the logic that Moxie's disagreement with DeVault's opinion about F-Droid --- a controversy that is meaningful to less than 1% of Signal's Android user base --- implies inexorably that Moxie is untrustworthy and disingenuous.

Re: I don't trust Signal (2018)

#44

Earlier quoted context omitted.

It's on us as tech users to create solutions that don't require 5 minutes of hand holding with every user of software and call it an achievement.

Yes, you are absolutely right. No, it does not invalidate what I am saying. If we keep expecting underfunded and under-resourced parties to come up with software ready and with absolute feature-parity over what is being pushed by the companies that have time, money and marketing teams, we are never going to make a dent on mindshare of the general public. If on the other hand are diligent in refusing for centralized a…

> absolute feature-parity over what is being pushed by the companies that have time, money and marketing teams

Signal started as any other startup. And yet ;)

> while willing to learn and emulate what they do right, then we will at the very least be in a state of steady progress

In total agreement with you

Re: I don't trust Signal (2018)

#45
post #41

Trust it to what? I use Signal because I think it protects my SMS messages from: a) being harvested and read by other apps on my phone b) being read by someone who unlocks my phone c) being passively intercepted and stored by carriers and their snoopy employees d) opposition researchers or private investigators targeting my friends, acquaintances, and business associates. For anything targeted and state level, all be…

I use Signal because I think it protects my SMS messages It depends. I think calling them simply SMS messages instead of being more precise is misleading because: Text messages sent through your mobile SMS/MMS plan are insecure and need your phone to be connected to your mobile network. and Signal Desktop does not send or receive SMS/MMS messages. Only Signal messages will be sent or received. The desktop app is an i…

It has other features, but the main point of using Signal is to send encrypted messages to people using the PSTN directory service (e.g. phone numbers). You are still in that sandbox.

The secondary feature it it ostensibly encrypts messages at rest on your device so they cannot be decrypted and read by other apps. (Assuming that's true.)

If you want a more secure messenger, use Wickr, Riot/Matrix/whatever it's called now, or protonmail or something similar, as these don't depend on the phone directory for identity and so they resist some traffic analysis and contact tracing as well.

The threat model is both the business model and use case for security products, so talking about the features or implementations outside the context of the threat model is going to just add uncertainty, imo.

Re: I don't trust Signal (2018)

#46
post #17

As to the interjection that Signal is lacking a FBI canary - Moxie was clear on the subject: https://web.archive.org/web/20141027143819/https://github.co...

The EFF reference at the bottom of that link provides a useful alternative position:

> What’s the legal theory behind warrant canaries?

> The First Amendment protects against compelled speech. For example, a court held that the New Hampshire state government could not require its citizens to have “Live Free or Die” on their license plates. While the government may be able to compel silence through a gag order, it may not be able to compel an ISP to lie by falsely stating that it has not received legal process when in fact it has.

> Have courts upheld compelled speech?

> Rarely. In a few instances, the courts have upheld compelled speech in the commercial context, where the government shows that the compelled statements convey important truthful information to consumers. For example, warnings on cigarette packs are a form of compelled commercial speech that have sometimes been upheld, and sometimes struck down, depending on whether the government shows there is a rational basis for the warning.

> Have courts upheld compelled false speech?

> No, and the cases on compelled speech have tended to rely on truth as a minimum requirement. For example, Planned Parenthood challenged a requirement that physicians tell patients seeking abortions of an increased risk of suicidal ideation. The court found that Planned Parenthood did not meet its burden of showing that the disclosure was untruthful, misleading, or not relevant to the patent’s decision to have an abortion.

> Are there any cases upholding warrant canaries?

> Not yet. EFF believes that warrant canaries are legal, and the government should not be able to compel a lie. To borrow a phrase from Winston Churchill, no one can guarantee success in litigation, but only deserve it.

Re: I don't trust Signal (2018)

#47
post #9

Earlier quoted context omitted.

There is no alternative that provides the ease of use and privacy guarantees. I think the OWS/Moxie hate is misplaced. They’re competing with iMessage and WhatsApp and Instagram and Facebook, and Signal is a much better option than all of those. Let’s be honest: the alternative is that Facebook gets all of our chats in cleartext.

I don't buy it. I've been running my own Matrix homeserver and giving access to non-techy members of my family for years already. Setting up e2e is not automatic, but nothing that my mother couldn't do after 5 minutes of hand-holding. It is on us with tech skills to help others to get out of any centralized alternative. Ease of use will come with the less technical user base.

e2e, with pfs, is entirely automatic on Signal, and doesn’t require weird client configurations like self-hosted Matrix.

Re: I don't trust Signal (2018)

#48

I love Mr. DeVault's work, and think he consistently shows integrity in his work, to say nothing of his incredible productivity and engineering. That said, in my time following his blog and Mastodon toots, he's prone to making these hot-takes that take down successful projects that do a lot of public good, but don't tick every check. His repeated criticism of Mozilla is a good example of this. It often feels like cut…

I appreciate your feedback, and I try to be more balanced with this kind of article these days, and publish them less often. However, I'd like to point out that I've always strived to find other resolutions to these problems first - I spoke with Moxie and others involved in Signal at length before writing this article, and only wrote this as a last resort. With organizations like Mozilla, I have also spoken directly…

> I make these criticisms because I want them to live up to the ideals they proclaim - it's with the hope that they'll change for the better.

Thanks. It's important that projects are held to high standards, even if they're hard to achieve. Otherwise there'd be no pushback against pure pragmatism.

Re: I don't trust Signal (2018)

#49

I trust Signal's end-to-end encryption promise, but I have a problem with the application not offering anonymity or privacy. By demanding users to provide a cell phone number to enable their accounts, they are connecting actual people to the Signal accounts and consequently also allowing them (or someone else) to visualize social networks; in intelligence gathering, data such as who speaks to whom, at what hours, wit…

The exact opposite privacy thing is happening with Signal. They use your phone number because your phone links it to your contacts, which Signal uses as its "buddy list". By repurposing your contacts as a buddy list, Signal avoids storing any of that information itself. Virtually every other competing service stores a plaintext buddy list serverside, where it can be subpoena'd and NSL'd. The data in that buddy list is of equal value to state-level adversaries as the contents of the messages themselves.

I think --- I have no special knowledge here --- that nobody wants to do away with phone numbers more than Signal itself. That's what the "secure value storage" drama is about: using SGX to optionally vouchsafe an encrypted contact database, which would allow Signal to operate with opaque identifiers rather than contacts.

Re: I don't trust Signal (2018)

#50
post #11
post #9

Earlier quoted context omitted.

There is no alternative that provides the ease of use and privacy guarantees. I think the OWS/Moxie hate is misplaced. They’re competing with iMessage and WhatsApp and Instagram and Facebook, and Signal is a much better option than all of those. Let’s be honest: the alternative is that Facebook gets all of our chats in cleartext.

I think Drew responded to that. I thought this was a key quote: > Off the bat, let me explain that I expect a tool which claims to be secure to actually be secure. I don’t view “but that makes it harder for the average person” as an acceptable excuse. If Edward Snowden and Bruce Schneier are going to spout the virtues of the app, I expect it to actually be secure when it matters - when vulnerable people using it to e…

Which is pretty rich, because in the post where that quote originally appeared, the author recommended as an alternative to Signal a tool that wasn't even end-to-end encrypted by default.
Post reply on HN