Live data from Hacker News

Signal's TLS Proxy Failed to Be Probing Resistant

github.com

11–20 of 46 posts

Re: Signal's TLS Proxy Failed to Be Probing Resistant

#11
post #9
post #6

For people curious, it looks like they are discussing it in the community but only the mod is involved and I don't think they (Herohtar) are an employee. While the block was unintentional this doesn't seem like the right way to handle the situation and Moxie should have been clearer and that would have avoided the issue. It is easy to interpret the response given as being brushed off. TLDR: DuckSoft got autobanned be…

People who run the project get to pick the bug tracker. Its really next level entitlement to not let maintainers choose the place they track bugs.

That's fine. I'm not sure why that means they shouldn't be more clear. The GH comment was a preference. The problem here is that the message Signal sent sounds generic and can easily be interpreted as brushing the person off. They clearly interpreted it that way.

Re: Signal's TLS Proxy Failed to Be Probing Resistant

#12
post #3

How long did he wait for the signal forum to approve his account? The guy, or girl, seems rather aggressive. It's mentioned they've not slept in a while...

It got approved fairly quickly. It was a false positive (see my link in main thread) with their spam detection (DuckSoft copy pasted the post so flagged as "type too fast").

Re: Signal's TLS Proxy Failed to Be Probing Resistant

#13
post #9

Earlier quoted context omitted.

People who run the project get to pick the bug tracker. Its really next level entitlement to not let maintainers choose the place they track bugs.

That's fine. I'm not sure why that means they shouldn't be more clear. The GH comment was a preference. The problem here is that the message Signal sent sounds generic and can easily be interpreted as brushing the person off. They clearly interpreted it that way.

Why shouldn't people who post in the wrong place get a generic message?

Afaict, its not like they are reporting a drop everything issue. Did anyone actually think that a determined adversary would not be able to distinguish between one of their proxies and a generic TLS server, given sufficient resources?

Re: Signal's TLS Proxy Failed to Be Probing Resistant

#15
post #13

Earlier quoted context omitted.

That's fine. I'm not sure why that means they shouldn't be more clear. The GH comment was a preference. The problem here is that the message Signal sent sounds generic and can easily be interpreted as brushing the person off. They clearly interpreted it that way.

Why shouldn't people who post in the wrong place get a generic message? Afaict, its not like they are reporting a drop everything issue. Did anyone actually think that a determined adversary would not be able to distinguish between one of their proxies and a generic TLS server, given sufficient resources?

> Why shouldn't people who post in the wrong place get a generic message?

Because people aren't clairvoyant and it is reasonable to assume that people that post stuff on GitHub accept issues, just like the main Signal account does. The generic message, without original clarity in how to note an issue, is easy to interpret as being ignored. Especially as they had a false positive ban being flagged as spam. I understand Signal's pov and I understand DuckSoft's. I think Signal has the higher responsibility in clarity than some random person trying to note a flaw they found.

Look, you can like Signal and still think they made the wrong move. I've used it every day for years and converted the majority of my friends. No one expects Signal to be perfect.

Re: Signal's TLS Proxy Failed to Be Probing Resistant

#16
While the authors of this definitely didn't handle this well, I'd argue it's a pretty severe weakness and the tool shouldn't have been released in this state. Active probing has been observed in the wild [1] and pretty much all tooling in the space handles it in their threat model [2], so its naive to not consider it.

I get why the signal team wanted something to use HTTPS, even networks with completely insane firewalls accept it and they get to reuse existing domain fronting code, but existing tools continues to viable in Iran and would have made much more sense in the circumstances.

[1] https://blog.torproject.org/learning-more-about-gfws-active-...

[2] https://github.com/Yawning/obfs4/blob/master/doc/obfs4-spec....

Re: Signal's TLS Proxy Failed to Be Probing Resistant

#17
post #13

Earlier quoted context omitted.

Why shouldn't people who post in the wrong place get a generic message? Afaict, its not like they are reporting a drop everything issue. Did anyone actually think that a determined adversary would not be able to distinguish between one of their proxies and a generic TLS server, given sufficient resources?

> Why shouldn't people who post in the wrong place get a generic message? Because people aren't clairvoyant and it is reasonable to assume that people that post stuff on GitHub accept issues, just like the main Signal account does. The generic message, without original clarity in how to note an issue, is easy to interpret as being ignored. Especially as they had a false positive ban being flagged as spam. I understan…

> Because people aren't clairvoyant

Luckily they have a generic message to read. No clairvoyancey required.

I'm not defending signal here because i just like signal. Almost any other open source project would have responded the same way. Many would probably have been less polite about it. If you send a personalized note to everyone who reports a bug incorretly, you won't have any time to actually fix bugs.

Edit: i agree though that the false positive spam ban is a bit unfortunate. Shit happens sometimes. I maintain the generic message was totally reasonable and they should not do anything different in that regard if they could do it over again. The spam ban however was understandable but obviously should not have happened.

Re: Signal's TLS Proxy Failed to Be Probing Resistant

#18

Moxie deserves an ACM award for his contributions to crypto but he shouldn't be leading the project. Maybe posting on the Discourse forum was the right thing to do here. I just see a lot of hostility between Signal employees and those wishing to make the project a little bit better.

They have been ignoring or brushed off the importance of reported privacy related issues for years. Doesn't built trust to use Signal for me personally

Re: Signal's TLS Proxy Failed to Be Probing Resistant

#19
post #9

Earlier quoted context omitted.

People who run the project get to pick the bug tracker. Its really next level entitlement to not let maintainers choose the place they track bugs.

That's fine. I'm not sure why that means they shouldn't be more clear. The GH comment was a preference. The problem here is that the message Signal sent sounds generic and can easily be interpreted as brushing the person off. They clearly interpreted it that way.

The GH issue poster was overreacting in multiple steps: first by getting the generic reply, then thinking that making issues was disabled to "get rid of him" (or what not). He/she should get some sleep.

Re: Signal's TLS Proxy Failed to Be Probing Resistant

#20
post #7

Moxie deserves an ACM award for his contributions to crypto but he shouldn't be leading the project. Maybe posting on the Discourse forum was the right thing to do here. I just see a lot of hostility between Signal employees and those wishing to make the project a little bit better.

That so-called hostility seems to be pretty one-sided IMO. The response from the Signal dev seemed pretty calm and reasonable, but OP seemed to take it as a personal insult for no reason. Some projects don't want to discuss issues on GitHub and prefer a forum they have control over; that's totally understandable.

That's those projects I don't report issues to and rather maintain local patches for.

I'm not gonna sign up to the fivetrillionth forum or bug tracker for your special snowflake software. If you don't allow bug reports via github issues, you won't get mine.

Post reply on HN