I love Mr. DeVault's work, and think he consistently shows integrity in his work, to say nothing of his incredible productivity and engineering. That said, in my time following his blog and Mastodon toots, he's prone to making these hot-takes that take down successful projects that do a lot of public good, but don't tick every check. His repeated criticism of Mozilla is a good example of this. It often feels like cut…
I appreciate your feedback, and I try to be more balanced with this kind of article these days, and publish them less often. However, I'd like to point out that I've always strived to find other resolutions to these problems first - I spoke with Moxie and others involved in Signal at length before writing this article, and only wrote this as a last resort. With organizations like Mozilla, I have also spoken directly…
I don't trust Signal (2018)
51–60 of 115 posts
Re: I don't trust Signal (2018)
#52I trust Signal's end-to-end encryption promise, but I have a problem with the application not offering anonymity or privacy. By demanding users to provide a cell phone number to enable their accounts, they are connecting actual people to the Signal accounts and consequently also allowing them (or someone else) to visualize social networks; in intelligence gathering, data such as who speaks to whom, at what hours, wit…
The exact opposite privacy thing is happening with Signal. They use your phone number because your phone links it to your contacts, which Signal uses as its "buddy list". By repurposing your contacts as a buddy list, Signal avoids storing any of that information itself. Virtually every other competing service stores a plaintext buddy list serverside, where it can be subpoena'd and NSL'd. The data in that buddy list i…
Re: I don't trust Signal (2018)
#53I really don’t think OWS has the authority to stop forks from using the Signal servers, any more than YC has the authority to dictate that I use Chrome to view HN. There is, of course, the vague language of the CFAA, so I’m not sure I’d want to test this theory, but his demands that forks not use the main centralized servers are, in my opinion, unenforceable bluster.
This doesn't have much value without federation , which would require active support from OWS.
Re: I don't trust Signal (2018)
#54Earlier quoted context omitted.
The exact opposite privacy thing is happening with Signal. They use your phone number because your phone links it to your contacts, which Signal uses as its "buddy list". By repurposing your contacts as a buddy list, Signal avoids storing any of that information itself. Virtually every other competing service stores a plaintext buddy list serverside, where it can be subpoena'd and NSL'd. The data in that buddy list i…
Ah, yes, because it's impossible to store a contact list client-side. Or to encrypt arbitrary data like that to store server-side! Glad Moxie's looking out for us.
Re: I don't trust Signal (2018)
#55Earlier quoted context omitted.
Just to add... yes, I know it's possible to register a Signal account with a disposable VLN, but how many Signal users can be expected to be "tech literate" to this level? Practically none.
Given the demographic Signal attracts that seems like an unsafe assumption.
I would still guess that none is a bad assumption, however.
Edit: Spelling
Re: I don't trust Signal (2018)
#56Earlier quoted context omitted.
Ah, yes, because it's impossible to store a contact list client-side. Or to encrypt arbitrary data like that to store server-side! Glad Moxie's looking out for us.
Please point to the mainstream secure messenger other than Signal that doesn't store a database of contacts serverside.
Re: I don't trust Signal (2018)
#57Earlier quoted context omitted.
I appreciate your feedback, and I try to be more balanced with this kind of article these days, and publish them less often. However, I'd like to point out that I've always strived to find other resolutions to these problems first - I spoke with Moxie and others involved in Signal at length before writing this article, and only wrote this as a last resort. With organizations like Mozilla, I have also spoken directly…
I'm sorry you're getting downvoted. Though I disagree with some of your stances on OWS and Mozilla, your articles are always thoughtful and there is never a doubt you're earnestly fighting for a better world w.r.t software.
Re: I don't trust Signal (2018)
#58Earlier quoted context omitted.
I think Drew responded to that. I thought this was a key quote: > Off the bat, let me explain that I expect a tool which claims to be secure to actually be secure. I don’t view “but that makes it harder for the average person” as an acceptable excuse. If Edward Snowden and Bruce Schneier are going to spout the virtues of the app, I expect it to actually be secure when it matters - when vulnerable people using it to e…
Which is pretty rich, because in the post where that quote originally appeared, the author recommended as an alternative to Signal a tool that wasn't even end-to-end encrypted by default.
B) Matrix has always been very easy to set up E2E
C) Matrix is now E2E by default, at least with the client non-technical users will be using. I think it is for the other clients as well, but I do not know for sure.
Re: I don't trust Signal (2018)
#59Earlier quoted context omitted.
I use Signal because I think it protects my SMS messages It depends. I think calling them simply SMS messages instead of being more precise is misleading because: Text messages sent through your mobile SMS/MMS plan are insecure and need your phone to be connected to your mobile network. and Signal Desktop does not send or receive SMS/MMS messages. Only Signal messages will be sent or received. The desktop app is an i…
It has other features, but the main point of using Signal is to send encrypted messages to people using the PSTN directory service (e.g. phone numbers). You are still in that sandbox. The secondary feature it it ostensibly encrypts messages at rest on your device so they cannot be decrypted and read by other apps. (Assuming that's true.) If you want a more secure messenger, use Wickr, Riot/Matrix/whatever it's called…
You can't.
I think this is a common misconception.
Re: I don't trust Signal (2018)
#60Earlier quoted context omitted.
Which is pretty rich, because in the post where that quote originally appeared, the author recommended as an alternative to Signal a tool that wasn't even end-to-end encrypted by default.
A) I see that nowhere in this post, so the author must have retracted it when he found that out. B) Matrix has always been very easy to set up E2E C) Matrix is now E2E by default, at least with the client non-technical users will be using. I think it is for the other clients as well, but I do not know for sure.
Matrix was years from being E2E by default when this post, and that recommendation, was written.