Live data from Hacker News

I don't trust Signal (2018)

drewdevault.com

71–80 of 115 posts

Re: I don't trust Signal (2018)

#71
post #69

Earlier quoted context omitted.

You've got to be kidding me. The ability to store data on your device is a basic requirement of a software environment which is provided by all platforms. I'd forgive someone for not understanding that arbitrary data can be encrypted, but you claim to have some expertise in cryptography so you don't get a pass there. Someone like OWS, the developers of a privacy app, certainly don't get a pass. It is possible, and it…

Support your claim with evidence, like I asked earlier. Not axiomatically; with an example of a mainstream messenger other than Signal that doesn't store a database of contacts serverside. For example: do either of the two messengers you formerly recommended manage to avoid this problem? After all, it's apparently super simple to solve this. Look at where this left Tox.

>Not axiomatically; with an example of a mainstream messenger

I don't have to provide the specific sort of evidence you're asking for in order to be right. I could write up a small script demonstrating the approach I'm talking about here, but it's rather obvious and based on simple, well-understood axioms. Unless you reject the axioms that (1) contact lists are representible as data, (2) applications can store data on your device, and (3) that data can be encrypted?

If you're just going to argue in bad faith then you can take it elsewhere, I'm not interested. Based on my past experiences with you, I don't have high hopes.

>do either of the two messengers you formerly recommended

Recommandations which have been retracted; I decline to answer.

Re: I don't trust Signal (2018)

#72
post #53

Earlier quoted context omitted.

This doesn't have much value without federation , which would require active support from OWS.

You can literally just look at Matrix, the tool you recommended, to see the problem with federation, fragmentation, and market demands to support lowest-common-denominator security. It took years after your recommendation for Matrix to have universal default E2E, the table-stakes feature of a secure messenger.

Are you going to back this up with evidence, or is it okay when you use axiomatic arguments?

"It took a while" is not actually an argument that the procedure is wrong or less correct, in case you were unsure.

Re: I don't trust Signal (2018)

#73
post #53

Earlier quoted context omitted.

You can literally just look at Matrix, the tool you recommended, to see the problem with federation, fragmentation, and market demands to support lowest-common-denominator security. It took years after your recommendation for Matrix to have universal default E2E, the table-stakes feature of a secure messenger.

Are you going to back this up with evidence, or is it okay when you use axiomatic arguments? "It took a while" is not actually an argument that the procedure is wrong or less correct, in case you were unsure.

In fact, it is an argument that you were wrong, and the evidence for that is that when you made the argument, and for two whole years afterwards, your recommendation would have put vulnerable users on a platform that was for many users default-plaintext.

Re: I don't trust Signal (2018)

#74
post #46
post #17

As to the interjection that Signal is lacking a FBI canary - Moxie was clear on the subject: https://web.archive.org/web/20141027143819/https://github.co...

The EFF reference at the bottom of that link provides a useful alternative position: > What’s the legal theory behind warrant canaries? > The First Amendment protects against compelled speech. For example, a court held that the New Hampshire state government could not require its citizens to have “Live Free or Die” on their license plates. While the government may be able to compel silence through a gag order, it may…

As counterpoint, the US Supreme Court held that Idahoans are obliged to advertise "famous potatoes" on their license tags. But potatoes really are famous (at least by Idaho standards) so it is just a fact and not an opinion. I guess.

Re: I don't trust Signal (2018)

#75
post #42

Earlier quoted context omitted.

Ah, once again with the insubtantive rebuttal of the last point in the article, the point which has the least relevance to the meat of the article. And this time, your rebuttal is out of date, because Matrix does have end-to-end encryption by default for all chats! Always lovely having you around on HN, tptacek.

Recommending a tool that wasn't even end-to-end encrypted over Signal because you didn't like the way Signal's leadership responded to your demand to support F-Droid is the most relevant thing you wrote. Just because it was malpractice doesn't make it out of bounds.

Look at this guy, he was wrong! Wrong wrong wrong WRONG! Look, he retracted his statement, that's how WRONG he was!

Re: I don't trust Signal (2018)

#76
post #69

Earlier quoted context omitted.

Support your claim with evidence, like I asked earlier. Not axiomatically; with an example of a mainstream messenger other than Signal that doesn't store a database of contacts serverside. For example: do either of the two messengers you formerly recommended manage to avoid this problem? After all, it's apparently super simple to solve this. Look at where this left Tox.

>Not axiomatically; with an example of a mainstream messenger I don't have to provide the specific sort of evidence you're asking for in order to be right. I could write up a small script demonstrating the approach I'm talking about here, but it's rather obvious and based on simple, well-understood axioms. Unless you reject the axioms that (1) contact lists are representible as data, (2) applications can store data o…

You did not retract them. You ghost edited them out of your post to save face. A retraction would be useful, and you should add one.

Re: I don't trust Signal (2018)

#77
post #76

Earlier quoted context omitted.

>Not axiomatically; with an example of a mainstream messenger I don't have to provide the specific sort of evidence you're asking for in order to be right. I could write up a small script demonstrating the approach I'm talking about here, but it's rather obvious and based on simple, well-understood axioms. Unless you reject the axioms that (1) contact lists are representible as data, (2) applications can store data o…

You did not retract them. You ghost edited them out of your post to save face. A retraction would be useful, and you should add one.

You might have preferred it if I had written up a retraction in the article itself, but nevertheless, the statement was removed over 2 years ago and has no bearing on the present-day discussion. Stop being a bully and leave me alone! I am tired of your harassment.

Re: I don't trust Signal (2018)

#78
post #42

Earlier quoted context omitted.

Recommending a tool that wasn't even end-to-end encrypted over Signal because you didn't like the way Signal's leadership responded to your demand to support F-Droid is the most relevant thing you wrote. Just because it was malpractice doesn't make it out of bounds.

Look at this guy, he was wrong! Wrong wrong wrong WRONG! Look, he retracted his statement, that's how WRONG he was!

Once again: you did not retract your statement. You ghost-edited it out of your post. The purpose of a retraction is to inform your readers of your mistake, and a retraction would be a good thing to add to your post.

The distinction is especially germane in a thread on a post that purports to discern how trustworthy someone else is. You set the bar, now clear it.

Re: I don't trust Signal (2018)

#79
post #78

Earlier quoted context omitted.

Look at this guy, he was wrong! Wrong wrong wrong WRONG! Look, he retracted his statement, that's how WRONG he was!

Once again: you did not retract your statement. You ghost-edited it out of your post. The purpose of a retraction is to inform your readers of your mistake, and a retraction would be a good thing to add to your post. The distinction is especially germane in a thread on a post that purports to discern how trustworthy someone else is. You set the bar, now clear it.

I refuse. I did my part a long time ago, and you're just an asshole who doesn't know when to quit.

Re: I don't trust Signal (2018)

#80
post #59

Earlier quoted context omitted.

It has other features, but the main point of using Signal is to send encrypted messages to people using the PSTN directory service (e.g. phone numbers). You are still in that sandbox. The secondary feature it it ostensibly encrypts messages at rest on your device so they cannot be decrypted and read by other apps. (Assuming that's true.) If you want a more secure messenger, use Wickr, Riot/Matrix/whatever it's called…

Sure. Agreed. I was responding to your statement that you can send encrypted SMS messages using that handy PSTN directory access provided by Signal. You can't. I think this is a common misconception.

Open loop criticisms are why I often can't stand other security and crypto people.

To be clear, if someone is a Signal user, you use their phone number for directory discovery and initializing identity, then Signal messages themselves are encrypted and transported via Signal servers using WebRTC as a transport protocol?

I think without a sequence diagram, most discussion of security protocols is pointless.

Post reply on HN