Live data from Hacker News

Help users in Iran reconnect to Signal

signal.org

351–360 of 417 posts

Re: Help users in Iran reconnect to Signal

#351

This is only popular and presented as altruistic because toppling the Iranian regime aligns with the foreign policy of Western states. Now that's fine if you support the expansion of global liberal democracy (which happens to be neither liberal or democratic) but just don't be deluded into believing this is some good guy vs bad guy scenario. As we speak, U.S media is advocating for the removal of Signal because Ameri…

I am not in the US and this is popular to me because I'm happy to be able to help people out who are suppressed by their government. Not everything is a US conspiracy in geopolitics...

That nation states do things to advance their interests globally is not a conspiracy. Foreign policy 101.

Who is to say that the Western technocratic system of government replacing the current Iranian regime would not also be oppressive? I personally believe it would be vastly more oppressive.

Re: Help users in Iran reconnect to Signal

#352
post #339
post #331

Earlier quoted context omitted.

I see that Signal no longer depends on Google Play Services specifically. However it's still the case that it depends on proprietary Google code (it just includes that code in its own APK now) and still can't practically be installed without auto-update (again, it just includes that in its APK).

The "proprietary Google code" is a library with a well defined API, you can see what it has access to. I agree that Signal should take it out, but it's not an especially big deal from a security perspective. The auto update functionality just tells you that an update is available, you can choose not to install it. You can also independently verify that the sha256 sum matches the one given on the website, and that the…

> you can choose not to install it

There is a time bomb in there and servers will kick you out regularly unless you have updated.

If you get a patched client running you could probably change whatever string is required but some sort of action is required on the client side.

Re: Help users in Iran reconnect to Signal

#353
post #231

Earlier quoted context omitted.

And it seems they've fixed the issue, without any kind of public comment.... still not great: https://github.com/signalapp/Signal-TLS-Proxy/commit/39a97da...

I (partially) fixed this issue, and I'm not affiliated in any way with Signal. It's public ( https://github.com/signalapp/Signal-TLS-Proxy/pull/2 ), and it looks like they welcome contributions, because they merged mine.

Sorry for not noticing your PR before filing the bug.

I still find the way they (partially) dealt with this a bit worrisome.

Re: Help users in Iran reconnect to Signal

#354
post #3

I'm a big fan of the idea of independently-run proxy servers. Caddy has a secure forward proxy plugin born out of a research project at Google that does something similar, but works with any clients that let you configure HTTP proxies, and doesn't terminate TLS: instead it tunnels it over TLS. The proxy server itself can also be probe-resistant, i.e. difficult to detect that a website is acting as a proxy. I'm hoping…

White people are so naive that they believe the research sponsored by a giant advertisement company is net positive for the people of the world. Meanwhile Q lives in their closet

Re: Help users in Iran reconnect to Signal

#355

Earlier quoted context omitted.

I wonder how many First Amendment lawyers would be champing at the bit to take a case where a prosecutor was dumb enough to charge someone with a crime for assisting dissidents to communicate.

Problem is that to many from the other side of the Atlantic "dissidents" look an awful lot like "terrorists".

Calling everybody "terrorists" is for politicians and pundits. Judges spend all day seeing through hyperbole like that.

Re: Help users in Iran reconnect to Signal

#356

Earlier quoted context omitted.

> Hackers usually are not in favor of censorship or information restriction. So who do you mean, with "you"? There are many comments on previous HN threads defending censorship and information restriction, precisely as the GP has described it. https://news.ycombinator.com/item?id=25693742 https://news.ycombinator.com/item?id=25691631 https://news.ycombinator.com/item?id=25706993 https://news.ycombinator.com/item?id=2…

What you call “defending censorship” is perhaps better described as “defending free speech”. Forced speech is not free speech.

Stong disagree. When a handful of tech companies that form an Oligarchy on modern communication decide to systemically oppress members of one political party, that's the antithesis of free speech.

Re: Help users in Iran reconnect to Signal

#357

Damn, I've read the code. This won't work against an active probe. Censors just use signal domains and non-signal domains to test your proxy. If signal domains get passed and non-signal domains got denied, you are fucked. Besides, TLS in TLS is highly identifiable by simple packet length dpi. I'd hope there's better plan.

TLS 1.3 supports (encrypted) padding bytes for Application Data; which could be used to normalize the packet lengths. Probably not accessibly via normal system TLS libraries though.

Although, if only Signal is making nice sized packets, that could be suspicous.

Re: Help users in Iran reconnect to Signal

#358
post #277
post #226

Earlier quoted context omitted.

Session has: 1. An associated crypto-currency (not outright bad but weird smell IMO) [1] 2. Abandoned perfect forward secrecy and deniability [2] 3. Never completed an audit (though supposedly one is in progress) [3] There are a million and one encrypted chat programs out there. Why should I use this one? [1]: https://github.com/oxen-io/oxen-mobile-wallet [2]: https://getsession.org/session-protocol-technical-informa…

My only annoyance with the crypto currency is that it doesn’t have a good UX yet. They have stated before though that Session will always remain free for everyone. I think compensating node operators in some capacity makes sense but if it’s not implemented well, node operators feel a bit screwed over. Regarding your footnote #2 about PFS, it said this (among other things). > In some theoretical scenarios, these prope…

> My only annoyance with the crypto currency is that it doesn’t have a good UX yet. They have stated before though that Session will always remain free for everyone. I think compensating node operators in some capacity makes sense but if it’s not implemented well, node operators feel a bit screwed over.

Preface: i've been in it since 2011, but I entirely agree. It's still too complicated for most users, but we as community have gone a long way from where we were 10 years ago, so we certainly have blinders as to where to improve upon.

Could you specify what it is specifically that makes the overall UX so disappointing? I ask because I think we are now entering a phase of on-boarding a lot of non-tech people onto BTC network as payment settlement networks and other misc financial services, something I already have personal experience with, but having a tech person lime these out would be a tremendous help.

Thanks!

Re: Help users in Iran reconnect to Signal

#359

Hi, from Iran with love! First of all, thank you moxie and signal team for this proxy. Until 2018, many Iranians used telegram but Iran's regime after Russia blocked this messenger. telegram released mtproxy and this proxy was helpful. Russia lifted the ban on telegram but this app is still blocked on my country. but with VPNs, many iranians still use this app. after 2018, second most popular messaging app in iran wa…

I'm surprised Tor isn't blocked, since it's pretty easy to block it, but if it's not, you can always tunnel your entire phone through Tor, which would include Signal. Do keep in mind, that depending on your threat model, you might want to separate your apps across multiple devices or at least accounts (I mean like Android user accounts), so only some go through Tor (see the Silk Road case for why), but that also equally applies to VPNs.

I don't remember what it's called, but I think the app is official by the Tor devs and basically makes a local VPN that your phone connects to and then forwards all traffic through Tor. It was on F-Droid last time I checked.

Re: Help users in Iran reconnect to Signal

#360

Earlier quoted context omitted.

"I would like to see your supportive reaction if an Iranian company offers hosting to Parler. " This is a hacker forum and not a US foreign ministry praise board, even though it is mainly US based. In other words, I doubt the reaction here would be rage, if a iranian company would do that. Hackers usually are not in favor of censorship or information restriction. So who do you mean, with "you"?

Fair enough, you have a good point. By, "you" I mean a tech person who is supportive of Signal action and is willing to setup a proxy without realizing that this is circumventing another country's law. I agree I could have said it more clearly and less emotionally.

I think you expressed it really well. Double standards and hypocrisy seem to be one trait that Americans inherited from their British founders.
Post reply on HN