I was vouching for Signal for all my friends for years, supported them with donations, and was really rooting for them. However, I regrettably can't trust in moxie having the best intentions with Signal anymore. Lost count of the number of times this has been recycled on HN so I'm not taking the time to formulate this extremely well but: * For the longest time, requires phone number as identifier. When asked to remov…
Moxie Marlinspike has a plan to reclaim our privacy
61–70 of 237 posts
Re: Moxie Marlinspike has a plan to reclaim our privacy
#62Earlier quoted context omitted.
I’m not a Matrix user, but it seems like Matrix does in fact handle contact metadata: https://matrix.org/faq/#what-is-an-identity-server%3F I think there’s a difference between what you’re saying, which seems to be that you personally don’t upload your contact metadata to Matrix, and what I asked / the previous commenter was describing, which is the idea that there are messaging platforms which have decided to not su…
You can optionally add your public identifiers to Matrix (phone, email, etc), which lets people search for you via identity providers. What Signal does is 1) require your phone number, 2) automatically upload every phone number in your contacts, and 3) send a push notification to people on Signal that have uploaded your number in the past that you have joined. It's a world of difference. And a huge breach of implied…
But again, the point I made originally, and which you replied to, isn’t about what users may or may not do. It’s whether any messaging platforms have resolved to not store metadata, rather than attempting (as Signal has) to only store it securely.
We can debate whether people agree with Signal’s approach to the tech or the UX, but Matrix doesn’t bother; if you give them your metadata, they’re just storing it without any attempt at E2E encryption.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#63It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…
However, their decision to force PINs broke Signal for one of my non-technical contacts, to this day (despite them supposedly offering an opt-out now). This person opens Signal, gets some weird confusing modal dialog, and is now stuck.
There is supposed to be a way to opt out without having to set and remember a PIN now, but I was unable to guide this person to find it, and I can't exactly travel there to see what's on the screen and find the damn button (or figure out why it isn't showing up). So this person can no longer use Signal, and we had to fall back to WhatsApp. Which leaks more information, but has a killer feature that Signal now lacks: it allows me to communicate with this person!
(For those unaware: Signal made a really boneheaded decision a couple months ago, against all specific criticism that they were receiving - they introduced PINs that would then be used to back up at least metadata to the server, protected under a questionable scheme whose security assumptions only work if SGX is unbreakable. To force users into this, they blocked access to the messenger and your messages, so you had to set a PIN and upload your data if you wanted to talk to your friends and didn't have a contact for them on a different messenger.)
Intentionally breaking a product like this also breaks trust. I can no longer rely on Signal for "just wanting a video chat with Grandma and Grandpa". I can no longer trust that Moxie will make reasonable decisions, and not e.g. tomorrow break my ability to communicate with people unless I agree to upload my message history.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#64Earlier quoted context omitted.
> When tech nerds nit pick Signal's implementation, they ignore that the unfederated nature of Signal limits the damage these decisions can cause. It limits the damage that some decisions can cause, but exacerbates others. Signal only allows the first-party client to connect to its network; if the developers were legally compelled to add a backdoor into that client, users would have few options. Its security depends…
Signal is OSS and you can start your own fork & network if you want to. App publishing platforms not having a good binary signature verification system is the orthogonal issue that you're bringing up, that would in many ways apply to matrix for most users too. Most will never bother to sideload it.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#65Earlier quoted context omitted.
Matrix lets people host their own servers and in doing so put the metadata anywhere they are comfortable. One can have metadata for sensitive internal corporate channels stay on a network they own in whatever country they want while still being able to chat with outside parties on matrix.org or other servers. Several friends host their own servers and more recently matrix p2p is rapidly maturing to dump the need for…
not the _identity_ servers currently though.
This is, granted, not as easy as it should be, but it is an issue the matrix team is working on improving.
You also don't need to use the identity service at all. It is totally optional for user discovery.
Third party implementations of the identity server already exist too.
Someone could even write their own replacement that uses SGX if they really wanted ;)
Re: Moxie Marlinspike has a plan to reclaim our privacy
#66Earlier quoted context omitted.
You can't coherently be alarmed by Signal's use of SGX while at the same time endorsing systems that use no cryptography whatsoever to protect the metadata Signal uses SGX for.
Matrix lets people host their own servers and in doing so put the metadata anywhere they are comfortable. One can have metadata for sensitive internal corporate channels stay on a network they own in whatever country they want while still being able to chat with outside parties on matrix.org or other servers. Several friends host their own servers and more recently matrix p2p is rapidly maturing to dump the need for…
With a centralized approach like Signal, I have to trust one single provider, i.e. the Signal Foundation running the servers, with my (meta)data. Sure, in an ideal world I'd rather not trust anyone. Fair enough. With a federated network, however, I generally have to trust every single host that any of my contacts has decided to sign up with, as my metadata will necessarily leak to those hosts when I'm communicating with those contacts in question. And while I personally put in a lot of time and effort into making sure I only use software and internet platforms that protect my privacy as best as possible, most of my contacts don't. The NSA would have an easy time setting up a rogue host.
Now imagine that, in addition, there weren't just one single version of the Signal app, but dozens of forks by dozens of developers. The security risks would get even greater and I would now also have to make sure that my friends use the right (secure) version.
Am I the exception here? Does everyone here only have friends who are IT security experts and know how to tell apart trustworthy hosts and app developers from non-trustworthy ones?
On a side note, another reason why I no longer strongly believe in the idea of decentralization is the following: There was a CompSci paper a few years ago that argued that in any human-made (initially) decentralized network/graph (whether digital or analog; whether a graph of company relationships or mankind's social graph) there will eventually appear "supernodes" which have a disproportionally high number of edges/connections to other nodes. (In the same vain, even in federated networks like email, some hosts will become bigger than others and will eventually take over most of the users and traffic.) In short: There is no such thing as full decentralization. Nodes will necessarily "accumulate" and gather around local centers. (If anyone finds/knows that paper: Please let me know!)
Re: Moxie Marlinspike has a plan to reclaim our privacy
#67I was vouching for Signal for all my friends for years, supported them with donations, and was really rooting for them. However, I regrettably can't trust in moxie having the best intentions with Signal anymore. Lost count of the number of times this has been recycled on HN so I'm not taking the time to formulate this extremely well but: * For the longest time, requires phone number as identifier. When asked to remov…
I've also heard that Signal on android leaks message text because of google's keyboard auto-prediction feature. They should implement their own keyboard or find a way to disable text prediction - and educate their users.
On Apple this is less true, but it is also a centralized black box that grants you no freedom, and apps can be banned at any time with little recourse.
You could use something other than Android like PostmarketOS or Librem5 however odds are Signal won't create clients for those platforms considering Moxie has stated publicly he prefers distribution through proprietary channels in order to collect usage stats. Moxie has also stated he will actively fight any third party clients that try to join his network, so we won't likely see many of those attempted for alternative platforms either.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#68I have my own kibbitz about stuff down in the weeds, I think the decision to make a cellphone/SMS identity key in the recruitment and to have one device per identity is a design issue for me and my use case, but I understand this is not a black/white thing, and there were noises made in 2019 about moving to a different model of identity, I an content to wait, but there is the vague meta-question if the ranking of this kind of idea gets exposure too: How do we know the thinking around identity and recruitment?
Re: Moxie Marlinspike has a plan to reclaim our privacy
#69I was vouching for Signal for all my friends for years, supported them with donations, and was really rooting for them. However, I regrettably can't trust in moxie having the best intentions with Signal anymore. Lost count of the number of times this has been recycled on HN so I'm not taking the time to formulate this extremely well but: * For the longest time, requires phone number as identifier. When asked to remov…
I've also heard that Signal on android leaks message text because of google's keyboard auto-prediction feature. They should implement their own keyboard or find a way to disable text prediction - and educate their users.
Whether or not Google respects it is not clear, but it does show a little incognito mode icon on the keyboard.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#70Why is it, whenever Signal is brought up on Hacker News, we get inundated with the people who object to the core decisions of the Signal Project? Would Signal really be better if, instead of having a secure messenger available to the masses, it spent massive amounts of time implementing the things these people want? No. I would be comfortable recommending Signal (or WhatsApp) to a nontechnical friend and communicatin…
A great deal of human communication is dedicated to signalling high rank/superiority, or demonstrating familiarity/intimacy.[1] In the case of HN, very few people know much about Moxie, so the only useful signal they can convey is expertise. Many people come here because of their technical or product development background/interests, and the way they show expertise is by second-guessing technical, user interface, and…