Live data from Hacker News

Signal is having technical difficulties

status.signal.org

371–380 of 750 posts

Re: Signal is having technical difficulties

#371
post #126
post #71

I just donated to Signal after seeing the error banner in the app. I realised I was more than happy to pay WhatsApp's yearly charge back in the pre-Facebook days (think it was 70p or so?). Figured I could give Signal a few quid every now and then, maybe keep a server up for a few seconds :) Donation link should anyone be interested: https://signal.org/donate/

Signal is being used by at least 10 well-paid medical professionals (group chat) that I know of, and one of them proclaimed today that Signal is owned by Elon Musk (probably because he tweeted about it). I did not care to educate them. And this is in a first world country with a rather wealthy population. Why am I saying this? Users don't give a damn, they expect free things, and they expect things which work. They h…

What happens when a whistleblower or dissident wants to use Signal? Should they be forced to cough up a payment with a traceable credit card or app store account in order to use it?

For that reason alone I think it's important for the service to be free. Though I would perhaps support some reasonable free usage limits if needed to prevent abuse.

Re: Signal is having technical difficulties

#372
post #316

Earlier quoted context omitted.

I set up an monthly donation just now, thanks for the reminder. Remember: regular donations are better because they help with long term planning.

Although monthly donations presumably get more siphoned off in processing fees than an equivalently large donation annually.

I dont know if Paypal allows for monthly donations but they dont have any processing fees

https://www.paypal.com/fundraiser/charity/3675786

Re: Signal is having technical difficulties

#373
post #84

Earlier quoted context omitted.

Or that you can use that money for a Matrix server instead of supporting centralization. Element is less polished than Signal app but they've been catching up quite fast. If you and your friends aren't locked into the Signal ecosystem yet, might be worth considering, especially if you're techies.

Matrix comes up a lot but even Signal is often called not polished enough. And for matrix onboarding is hard for techies and I've had zero chance for the general public. Fine to push it towards techies, but my grandma can't figure it out but she can Signal. Push matrix when it's more polished but right now it just feels silly to push it.

Exactly. I'm for decentralization, but the reality is that if "we" (we techies) tried to push Element on everyone today they would just fall back to WhatsApp. So better to go for Signal today and then switch everyone over to a Matrix (or similar) client in a couple of years. As the past week demonstrated, it's possible to switch masses out of a closed, network-effect-dominated system.

Re: Signal is having technical difficulties

#374
post #71

I just donated to Signal after seeing the error banner in the app. I realised I was more than happy to pay WhatsApp's yearly charge back in the pre-Facebook days (think it was 70p or so?). Figured I could give Signal a few quid every now and then, maybe keep a server up for a few seconds :) Donation link should anyone be interested: https://signal.org/donate/

me too. just donated. please comment below if you also donated. let's keep this thing running! Its personal interest now, because I moved bunch of groups from whatsapp and its not working now! but at the same I love these guys for what they do.

I donated

Re: Signal is having technical difficulties

#376
post #341

Earlier quoted context omitted.

we’ve been working a lot on onboarding on Element, just as Signal have. it’s not perfect, but empirically it’s good enough for many non-technical users. comments like this are likely based on stale data (eg from when we forced e2ee setup during registration).

Well if you think about sending this to your aunt: https://wiki.mozilla.org/Matrix Compared to installing the Signal app and verifying your phone number over SMS, the difference is quite remarkable. Signal has had smooth and frictionless onboarding as part of the design. But also, comparing Matrix to Signal is a bit like comparing apples to oranges IMO.

Why would I send my aunt to a page about how to join the mozilla community? Over half of that wiki page is mozilla specific information, and even most of the matrix info is irrelevant to most users if they just want to do a basic registration.

The real apples to oranges comparison is you thinking that this wiki page is somehow comparable to registering a signal account.

Re: Signal is having technical difficulties

#377

This is not good. I've moved so many people over in the last week. For purposes of getting them invested, this is a truly inopportune moment for an extended outage.

Thousands of people are joining Signal after hearing about the Whatsapp privacy policy changes, but the irony is that a significant portion of these people (if not the majority) still use Facebook, upload photos and stuff, chat on messenger, with that app, installed on their phones alongside Signal. Most people don't actually realize why should they be worried about corporations collecting their data. I wonder what fraction of these people will stick to Signal. Signal is adding new servers, lets hope they dont need to retire these in the coming days.

Re: Signal is having technical difficulties

#378
post #302

Earlier quoted context omitted.

>I really wish the EU would put up funds for open source software, like signal, it seems to be something they could get behind for the greater good. They do https://hexus.net/tech/news/software/125747-14-open-source-p...

I just wonder about the process and the results. I mean, it doesn't look to me, as if there is a management behind this, that actually has a goal. It looks more like they are giving funds to projects who apply for them. IMO, they should state 3 clear goals and sponsor specific projects which reach those goals. To give some example how those could look like: - create a decentralized, federated instant messaging platfo…

I disagree. I believe the governments should fund existing open source software that are considered to be "critical" infrastructure (as in lots and lots of people rely on it) instead of chasing some random goals and adding bureaucracy on top that would slow down lead developers.

Just give them money and trust them that they'll do whatever it is they've done so far that many people recognised and started relying on their solution to the problem.

Without looking them up, there's exactly three pieces of software in the list above your comment that I don't recognize: FLUX TL, WSO2, midPoint. I'm happy to see all the other names on it, and I'm pretty sure I'll feel the same way about these three after I look them up.

Re: Signal is having technical difficulties

#379
post #305

Earlier quoted context omitted.

You connect to AWS when you connect to Signal. That means the USA is the government with the most influence on Amazon to have taps placed or connection logs handed over. They can do sealed sender stuff all they like, but when 10.0.1.1 sends a 17-byte message and the server then sends a 17-byte message to 10.0.2.1, and a minute later 10.0.2.1 submits something to the server of 48 bytes and then 48 bytes are forwarded…

> You connect to AWS when you connect to Signal. That means the USA is the government with the most influence on Amazon to have taps placed or connection logs handed over. I'm not an networking guy but can you explain this more? I'm actually curious and what better place to get actual info than HN? If you have a sealed sender then shouldn't this be impossible? Shouldn't the size of the message be sealed as well and w…

Agreed about being optimistic about usernames. I'm hoping it'll be what we expect, I hear different things from different people but frankly I also have been too lazy to actually look into it (I feel like I'm always the one doing the digging).

> Shouldn't the size of the message be sealed as well

To hide the volume of data being sent, you need to limit how much data you can send. How would you hide from the relaying server how much data you're sending without adding dummy data? And if you add 0-500 bytes of dummy data every 5 minutes, then whenever you send >500 bytes or send a message more often than once per 5 minutes, the server still knows that it was an actual message and its size, and you can start to do traffic analysis.

> Shouldn't this also apply to any app because traffic is going to bounce through some US based (or US company owned) server?

Um, when I message my friend whose Matrix homeserver I'm using, the traffic involved is:

1. DNS lookup of a .de domain (does not reveal message size or anything else, even if I were to use Google DNS and reveal my home server to a USA company)

2. TCP connection to a German server

3. More traffic to his German server

And same on the receiving side. Unless one of us travels to the Americas, it's not likely to ever pass through the USA. That isn't to say that American agencies might not collaborate with European agencies or even tap European land-based connections, but it's harder and would not be an option available to criminal (or civil, for that matter) investigations due to the disproportionality of the method.

> can you explain this more?

I'm not quite sure what's unclear about it, but I'll give it another general shot. Imagine you see this traffic log, where A/B/C/D are different IP addresses. You see various people sending data of various sizes (you don't know who's who, but everyone connects from their own IP address, or in networking terms, a TCP tuple). Since the server is just pushing messages from one contact to another, like if Alice messages Bob, it will always forward a message as soon as possible.

    00:00 A -> server: [17 encrypted bytes]
    00:00 C -> server: [29 encrypted bytes]
    00:00 server -> D: [17 encrypted bytes]
    00:00 server -> B: [29 encrypted bytes]
    00:01 D -> server: [48 encrypted bytes]
    00:01 server -> A: [48 encrypted bytes]
From this, I would assume (without knowing any contents or anything else) that the subscriber behind IP address "A" is talking to the subscriber behind IP address "D", and that "C" is talking to "B". Now you can start building a social graph, which according to a paper I recently read (I could maybe dig it up again) needs only a few nodes before they can tell who you are, or they just ask the ISP (or in the case of the Netherlands, query the CIOT database[1]).

If you think that a "sealed sender" might hide your IP address, the answer is no because the packets somehow need to make it across the network to the right devices (or to the server for that matter) and then the receiver decrypts it.

[1] https://nl.wikipedia.org/wiki/CIOT only available in Dutch. TL;DR central mapping system of IP addr -> subscriber info, available at the police's discretion, updated daily.

Re: Signal is having technical difficulties

#380
post #126

Earlier quoted context omitted.

Signal is being used by at least 10 well-paid medical professionals (group chat) that I know of, and one of them proclaimed today that Signal is owned by Elon Musk (probably because he tweeted about it). I did not care to educate them. And this is in a first world country with a rather wealthy population. Why am I saying this? Users don't give a damn, they expect free things, and they expect things which work. They h…

What happens when a whistleblower or dissident wants to use Signal? Should they be forced to cough up a payment with a traceable credit card or app store account in order to use it? For that reason alone I think it's important for the service to be free. Though I would perhaps support some reasonable free usage limits if needed to prevent abuse.

How sympathetic are the Signal developers to the concerns of dissidents, really? Signal has had a policy of many years to require a phone number – buying a SIM card now requires providing government ID in so many countries – and only now have they promised progress on this front someday. They also recommend that users install through the Play Store, and they only grudgingly provide a standalone APK. Anyone with the Play Store installed presumably has the full Google software suite that leaks location data, what one enters into the keyboard, etc. that the state can exploit. (And also Signal is based in the US where they are vulnerable to NSLs.)

This all makes me assume that Signal’s security is meant to shield phone owners against advertisers and ordinary criminals, not the state.

Post reply on HN