Live data from Hacker News

I don't trust Signal (2018)

drewdevault.com

81–90 of 115 posts

Re: I don't trust Signal (2018)

#81
post #69

Earlier quoted context omitted.

You've got to be kidding me. The ability to store data on your device is a basic requirement of a software environment which is provided by all platforms. I'd forgive someone for not understanding that arbitrary data can be encrypted, but you claim to have some expertise in cryptography so you don't get a pass there. Someone like OWS, the developers of a privacy app, certainly don't get a pass. It is possible, and it…

Support your claim with evidence, like I asked earlier. Not axiomatically; with an example of a mainstream messenger other than Signal that doesn't store a database of contacts serverside. For example: do either of the two messengers you formerly recommended manage to avoid this problem? After all, it's apparently super simple to solve this. Look at where this left Tox.

> Support your claim with evidence, like I asked earlier.

You asked for specifically mainstream messengers.

Cutting out mainstream, I can think of Tox and Jami off the top of my head.

Update 0: remove Tox, as you mention it in your comment.

Update 1: add Tox back in because your reply is about it, and I made edit 0 before seeing your reply.

Re: I don't trust Signal (2018)

#82
post #59

Earlier quoted context omitted.

Sure. Agreed. I was responding to your statement that you can send encrypted SMS messages using that handy PSTN directory access provided by Signal. You can't. I think this is a common misconception.

Open loop criticisms are why I often can't stand other security and crypto people. To be clear, if someone is a Signal user, you use their phone number for directory discovery and initializing identity, then Signal messages themselves are encrypted and transported via Signal servers using WebRTC as a transport protocol? I think without a sequence diagram, most discussion of security protocols is pointless.

Signal does not send encrypted SMS messages. Period. It can send encrypted messages but they are not SMS.

I think that without using the same words that other "security professionals" (which I would not class myself as) use most discussion becomes absolutely pointless.

Re: I don't trust Signal (2018)

#83
post #69

Earlier quoted context omitted.

Support your claim with evidence, like I asked earlier. Not axiomatically; with an example of a mainstream messenger other than Signal that doesn't store a database of contacts serverside. For example: do either of the two messengers you formerly recommended manage to avoid this problem? After all, it's apparently super simple to solve this. Look at where this left Tox.

> Support your claim with evidence, like I asked earlier. You asked for specifically mainstream messengers. Cutting out mainstream, I can think of Tox and Jami off the top of my head. Update 0: remove Tox, as you mention it in your comment. Update 1: add Tox back in because your reply is about it, and I made edit 0 before seeing your reply.

Until a couple years ago, Tox worked with sidecar services that existed solely to store this information serverside. That, and the fact that Tox is not a mainstream messenger, illustrates the point I'm trying to make --- which is about messengers, not about this post, which thankfully doesn't make this bogus but popular argument.

Re: I don't trust Signal (2018)

#84
post #70

Earlier quoted context omitted.

In Canada, Fido has $10/m + tax "Tablet Plan" which can be used on phones and gives you 4GB/m data

I appreciate the suggestion but had already experienced the issue that WiFi Calling did not work with my unlocked Nexus5, similar to this: https://forums.fido.ca/t5/General-Support/Wifi-Calling-worke... As noted on this article, your compatible device must have been purchased from Fido. If you have a non-Fido device and no conflicting services, Wi-Fi Calling may work, but we can’t assure that the feature will work pr…

No experience in Wifi Calling but I use the 2ndLine app for (very rare) calls and SMS. It gives you a local number. Data-only is the most cost effective imo

Re: I don't trust Signal (2018)

#85
post #49

I trust Signal's end-to-end encryption promise, but I have a problem with the application not offering anonymity or privacy. By demanding users to provide a cell phone number to enable their accounts, they are connecting actual people to the Signal accounts and consequently also allowing them (or someone else) to visualize social networks; in intelligence gathering, data such as who speaks to whom, at what hours, wit…

The exact opposite privacy thing is happening with Signal. They use your phone number because your phone links it to your contacts, which Signal uses as its "buddy list". By repurposing your contacts as a buddy list, Signal avoids storing any of that information itself. Virtually every other competing service stores a plaintext buddy list serverside, where it can be subpoena'd and NSL'd. The data in that buddy list i…

Applications can request access to the contact list at any time. They don't need to incorporate some sort of "ask for a phone number to send an SMS to" functionality to enable this. Additionally, there's nothing preventing them letting users confirm accounts by e-mail instead of SMS.

Re: I don't trust Signal (2018)

#86
post #78

Earlier quoted context omitted.

Once again: you did not retract your statement. You ghost-edited it out of your post. The purpose of a retraction is to inform your readers of your mistake, and a retraction would be a good thing to add to your post. The distinction is especially germane in a thread on a post that purports to discern how trustworthy someone else is. You set the bar, now clear it.

I refuse. I did my part a long time ago, and you're just an asshole who doesn't know when to quit.

I can't compel you to do anything, including things that would strengthen your rhetorical position.

Re: I don't trust Signal (2018)

#87
post #49

Earlier quoted context omitted.

The exact opposite privacy thing is happening with Signal. They use your phone number because your phone links it to your contacts, which Signal uses as its "buddy list". By repurposing your contacts as a buddy list, Signal avoids storing any of that information itself. Virtually every other competing service stores a plaintext buddy list serverside, where it can be subpoena'd and NSL'd. The data in that buddy list i…

Applications can request access to the contact list at any time. They don't need to incorporate some sort of "ask for a phone number to send an SMS to" functionality to enable this. Additionally, there's nothing preventing them letting users confirm accounts by e-mail instead of SMS.

The Signal project itself has repeatedly explained why they use phone number identifiers, which are the most controversial feature of the platform. I'm not misunderstanding them.

Re: I don't trust Signal (2018)

#88
post #70

Earlier quoted context omitted.

I appreciate the suggestion but had already experienced the issue that WiFi Calling did not work with my unlocked Nexus5, similar to this: https://forums.fido.ca/t5/General-Support/Wifi-Calling-worke... As noted on this article, your compatible device must have been purchased from Fido. If you have a non-Fido device and no conflicting services, Wi-Fi Calling may work, but we can’t assure that the feature will work pr…

No experience in Wifi Calling but I use the 2ndLine app for (very rare) calls and SMS. It gives you a local number. Data-only is the most cost effective imo

Thanks for the response. One more question: when I look at those plans on Fido¹ they seem to suggest that I need to be an existing postpaid customer. The plan seems like an add-on to other plans. Is this accurate or did you sign up from scratch with no other commercial relationship with Fido?

Make sure that you are an eligible Fido customer. You must be an existing, postpaid, mobile customer.

1. https://www.fido.ca/consumer/tablets

Re: I don't trust Signal (2018)

#89
post #31

Earlier quoted context omitted.

Given the demographic Signal attracts that seems like an unsafe assumption.

I would guess that a significant portion of Signal's users are non-technical people dragged there by their technical friends that couldn't get them onto Matrix. I would still guess that none is a bad assumption, however. Edit: Spelling

Practically none. I think it's safe to assume it's not even 1 in 1000 who have registered with a VLN, or even know what one is.

Re: I don't trust Signal (2018)

#90
post #83

Earlier quoted context omitted.

> Support your claim with evidence, like I asked earlier. You asked for specifically mainstream messengers. Cutting out mainstream, I can think of Tox and Jami off the top of my head. Update 0: remove Tox, as you mention it in your comment. Update 1: add Tox back in because your reply is about it, and I made edit 0 before seeing your reply.

Until a couple years ago, Tox worked with sidecar services that existed solely to store this information serverside. That, and the fact that Tox is not a mainstream messenger, illustrates the point I'm trying to make --- which is about messengers, not about this post, which thankfully doesn't make this bogus but popular argument.

> Tox worked with sidecar services that existed solely to store this information serverside.

So Tox is out. No contest.

> That, and the fact that Tox is not a mainstream messenger, illustrates the point I'm trying to make --- which is about messengers

This doesn't make sense to me. @ddevault stated that a messenger could store contacts client side. Jami clearly demonstrates this. What does it being mainstream or not have to do with this?

> thankfully doesn't make this bogus but popular argument.

What does this add, except a personal attack? We can see that you think this is a bad argument from the fact that you're contesting it.

Post reply on HN