Live data from Hacker News

Help users in Iran reconnect to Signal

signal.org

271–280 of 417 posts

Re: Help users in Iran reconnect to Signal

#271
post #190

Earlier quoted context omitted.

They could literally have a hidden function in WhatsApp that scoops up all your chat history and sends it to Facebook if the government ask them to. It’s closed source. No one has a clue what it’s doing. To be clear I’m not suggesting this is absolutely happening. I’m merely pointing out it’s entirely possible from a technological perspective given it’s closed source software owned by Facebook. That’s not a recipe fo…

To be clear about the threat vector, there's also nothing stopping signal from doing the same if they wanted to. Its impossible to tell if the version of signal you download from the app store is unmodified from the code you can find on github. I trust signal more than I trust facebook, but if you use signal, even though its opensource you still have to trust them not to put anything funky in the binary they upload t…

This is very true. Reproducible builds for mobile apps would be far superior. You can build Signal from source for Android if you wish, although obviously this is a massive pain to do for each update, there’s absolutely nothing stopping you from doing it.

On iOS it's a lot more difficult to get the required certificates from Apple but you can run your own build in Xcode and deploy it to your personal device if you are a registered Apple developer.

While reproducible builds are obviously the gold standard, for apps you install from the Play Store or the App Store, developers sign the apps that get distributed with their own private keys. As Google and Apple don’t have access to these it should be verifiable that the apps are not tampered with.

There is an exception here with the Play Store, where there is an opt-in option for Google to sign the app on your behalf [1], but I think we can safely assume Signal are manually signing with their own private keys.

In any case it's easy to just grab an APK from an Android device and check signatures for yourself.

For iOS though, no surprises here it’s locked down. Although from what I gather reading Apple’s security documentation, it confirms that apps must be signed by developers with their private keys. [2] But unlike Android there’s sadly no way I can tell for the user to independently verify this without jailbreaking.

But ultimately, short of building each version yourself, all this is moot if you distrust the developers.

[1] https://developer.android.com/studio/publish/app-signing [2] https://manuals.info.apple.com/MANUALS/1000/MA1902/en_US/app...

Re: Help users in Iran reconnect to Signal

#272
post #188

I would keep in mind that the US has weird antiterror laws about assisting enemies and also laws which construe bypassing system designs as hacking. For instance, Virgil Griffith is being held and charged for giving a high level description of bitcoin transactions at an academic conference in North Korea. This is incredibly more specific and more technical of an act. https://www.coindesk.com/usa-v-virgil-griffith-wha…

Virgil Griffith was told not to enter North Korea by the US government, and snuck in through China anyway. He admitted to specifically talking about how to use cryptocurrencies to avoid sanctions, and admitted he knew at the time that that was illegal.

https://www.nytimes.com/2019/12/02/nyregion/north-korea-virg...

Re: Help users in Iran reconnect to Signal

#273
post #188

I would keep in mind that the US has weird antiterror laws about assisting enemies and also laws which construe bypassing system designs as hacking. For instance, Virgil Griffith is being held and charged for giving a high level description of bitcoin transactions at an academic conference in North Korea. This is incredibly more specific and more technical of an act. https://www.coindesk.com/usa-v-virgil-griffith-wha…

Can someone who is a lawyer comment on this, please? edit: further.. how is Signal shielded (if at all) from providing services to anyone in Iran? Wouldn't they be a target in such a case? The blog post is an explicit call for assistance specifically to do so.

> Executive order 13722, signed by President Donald Trump in 2016, prohibits U.S. persons from exporting services to *North Korea*.

Edit: You might find GitHub's description of how they handle this interesting: https://github.blog/2021-01-05-advancing-developer-freedom-g...

Re: Help users in Iran reconnect to Signal

#274
post #188

I would keep in mind that the US has weird antiterror laws about assisting enemies and also laws which construe bypassing system designs as hacking. For instance, Virgil Griffith is being held and charged for giving a high level description of bitcoin transactions at an academic conference in North Korea. This is incredibly more specific and more technical of an act. https://www.coindesk.com/usa-v-virgil-griffith-wha…

Can someone who is a lawyer comment on this, please? edit: further.. how is Signal shielded (if at all) from providing services to anyone in Iran? Wouldn't they be a target in such a case? The blog post is an explicit call for assistance specifically to do so.

Not a lawyer, but details of the sanctions are public[1], including Iran General License D-1 which covers services, software, and hardware incident to personal communications. The license has details for fee based and generally public free-of-charge services. We want Iranians to be free to communicate.[2]

[1]: https://home.treasury.gov/policy-issues/financial-sanctions/...

[2]: https://home.treasury.gov/news/press-releases/sm0322

Re: Help users in Iran reconnect to Signal

#275
post #95

Signal could learn a lot from Telegram in this regard. Russian govt had tried to block Telegram but telegram servers just keep jumping over various cidrs and users got the ip addresses for connecting over push updates and the only thing the govt succeeded in was blocking a wide range of subnets including AWS ranges and GCP ranges thus disrupting a whole lot of businesses and even some government services. They gave u…

While it worked in that case, it is not an invincible method.

Re: Help users in Iran reconnect to Signal

#276

Earlier quoted context omitted.

Not at all true. Try http://www.president.ir/en

That does not resolve for me. Neither do any of the news sites. I even tried government ministries, such as en.mop.ir. simple$ ping president.ir/en ping: cannot resolve president.ir/en: Unknown host simple$ ping en.mop.ir ping: cannot resolve en.mop.ir: Unknown host simple$ ping tehrantimes.com ping: cannot resolve tehrantimes.com: Unknown host simple$ ping presstv.com ping: cannot resolve presstv.com: Unknown host

That might be something your ISP is doing. Try

  dig www.president.ir @8.8.8.8

Re: Help users in Iran reconnect to Signal

#277
post #226
post #185

Earlier quoted context omitted.

I just set up one of these Signal proxies. Hope it helps you and others in your country communicate freely and safely. [1] Regarding Tor: if you want a Signal-like app that uses an onion router look at Session. [2] It uses the same encryption protocol and very similar UI to Signal but routes all traffic through the Loki network so your traffic passes through three nodes. It is an onion network like Tor. One other ben…

Session has: 1. An associated crypto-currency (not outright bad but weird smell IMO) [1] 2. Abandoned perfect forward secrecy and deniability [2] 3. Never completed an audit (though supposedly one is in progress) [3] There are a million and one encrypted chat programs out there. Why should I use this one? [1]: https://github.com/oxen-io/oxen-mobile-wallet [2]: https://getsession.org/session-protocol-technical-informa…

My only annoyance with the crypto currency is that it doesn’t have a good UX yet. They have stated before though that Session will always remain free for everyone. I think compensating node operators in some capacity makes sense but if it’s not implemented well, node operators feel a bit screwed over.

Regarding your footnote #2 about PFS, it said this (among other things).

> In some theoretical scenarios, these properties do protect users; however the utility of these protections in real-world scenarios is often more limited in scope than might be expected. We must also consider that these safeguards are offered at the expense of additional complexity, decreased account portability, and multi-device limitations. These protocols were simply not designed to be run over a decentralised network.

I have to say, I’ve considered the utility of it myself. It seems to me that I’m far, far more likely to have my chats compromised through my chats being stored in plain text on my devices than in a technical scenario that PFS could have prevented. What do you think?

Re: Help users in Iran reconnect to Signal

#278
post #228

Earlier quoted context omitted.

Whoa whoa whoa… there can be legal consequences for spinning-up a proxy in countries sanctioning Iran. This is a case where action can in fact be way worse for someone than inaction. I still can't find any discussion about that and it's worth investigating.

I imagine that you're right, but it feels like a really weird case to choose to prosecute.

Sure.

But then one day they come and "ask" you to backdoor your employers platform. And when you say "WTF???" they start talking about terrorism charges for the VPS/proxy you ran back in 2021 in violation of Iranian sanctions.

Chilling effects are real. Laws they can "choose to prosecute" or not, just means they have more ways to coerce you if they want...

Re: Help users in Iran reconnect to Signal

#279

Signal should be federated. This censorship problem would not exist, or would be organically routed around, were the service federated. Without federation, Signal is just another stepping stone in the long path of eventually abandoned instant messengers, all the way back from ICQ. We will get to an SMTP-like protocol, and email-like service, at some point. If not Signal, some other one.

Signal was federated at one point: https://lwn.net/Articles/687294/ Moxie, one of the original authors of the Signal protocol, said federation severely restricted flexibility and so they had to move on: https://news.ycombinator.com/item?id=11668912

They "federated" with only one other server run by the Cyanogenmod team.

Agreeing on and keeping some spec up to date is a solved problem. Just ask any web standards committee.

Re: Help users in Iran reconnect to Signal

#280
post #247
post #226

Earlier quoted context omitted.

Session has: 1. An associated crypto-currency (not outright bad but weird smell IMO) [1] 2. Abandoned perfect forward secrecy and deniability [2] 3. Never completed an audit (though supposedly one is in progress) [3] There are a million and one encrypted chat programs out there. Why should I use this one? [1]: https://github.com/oxen-io/oxen-mobile-wallet [2]: https://getsession.org/session-protocol-technical-informa…

I mentioned it because it has a seamlessly built in onion routing protocol. I read further down the thread that Tor is blocked in Iran, but I’m guessing the same is unlikely to be true of Loki/Oxen simply because it isn’t nearly as well known. The lack of metadata is also quite a unique selling point in my eyes. There’s a million encrypted messengers now sure. How many automatically connect through an onion router wi…

Session protocol is currently running on session now[1]. It’s actually the reason that they were able to allow up to 100 people in closed groups now.

[1]: https://getsession.org/session-release-roundup-10/

Post reply on HN