Live data from Hacker News

Help users in Iran reconnect to Signal

signal.org

371–380 of 417 posts

Re: Help users in Iran reconnect to Signal

#371

Earlier quoted context omitted.

I'm surprised Tor isn't blocked, since it's pretty easy to block it, but if it's not, you can always tunnel your entire phone through Tor, which would include Signal. Do keep in mind, that depending on your threat model, you might want to separate your apps across multiple devices or at least accounts (I mean like Android user accounts), so only some go through Tor (see the Silk Road case for why), but that also equa…

> so only some go through Tor (see the Silk Road case for why), but that also equally applies to VPNs. Can you explain this?

I looked into the Silk Road story again and it looks like I was misremembering how they caught DPR, but splitting your "personally identifiable" and other browsing is still a good idea.

Let's say you use the Tor browser to browse some regular (non-Tor) site that is illegal in your country for whatever reason. But let's say you then remember you still haven't paid your taxes so you open a new tab and quickly go do that. But you're still in the Tor browser, so your e-banking traffic is going out the same exit node as your "illegal" traffic. Now, anyone that saw both of those things come out of the same node can conclude that it's somewhat likely both were done by the same person. If that someone is the government, they can get access logs from your bank and see which account was accessed by the exit node's IP. The more times you do this, the stronger the link between you personally and the illegal site is.

Of course, doing your taxes through the same Tor session is something most people would know to not do, but if your entire device is tunneled through Tor, you no longer have a say in what data it leaks. Your banking app probably sends requests periodically in the background to check for updates or whatever, your email client syncs your emails, etc. If any one of those services can be coerced by your government (and chances are they can) then whatever illegal things you do in that session can be loosely linked to you. I say loosely, because there are many people on one exit node, but the data points start adding up after a while (and depending on the insanity of your leaders, just being on the list of candidates might be enough to disappear you).

As for how they would get that metadata in the first place, there are a few ways. The exit node might be under their jurisdiction, but since we're talking about bypassing censorship, it certainly isn't. They could also have compromised the "illegal" server (hacked/coerced/honeypot...), in which case it's just a matter of cross-referencing the site's logs with anything they can get their hands on (and if the government is authoritarian enough, they probably already have access to a lot). The last option is compromising the exit node, which is also not impossible. There's nothing stopping your government from setting up a thousand Tor exit nodes and logging all the metadata. If you're constantly running Tor, chances are you land on one of their exit nodes eventually.

DISCLAIMER: the above was probably a bit too paranoid, but as I have zero experience hiding from an authoritarian government, I'm not in a position to judge how much paranoia is justified. It's entirely possible that none of this applies because your specific adversary doesn't employ these specific de-anonymization tactics, but that is something you need to know for your specific situation. I assumed an "everything is fucked" threat model here, but yours might not be as severe and other types of mitigations might be more appropriate.

Re: Help users in Iran reconnect to Signal

#372
post #226
post #185

Earlier quoted context omitted.

I just set up one of these Signal proxies. Hope it helps you and others in your country communicate freely and safely. [1] Regarding Tor: if you want a Signal-like app that uses an onion router look at Session. [2] It uses the same encryption protocol and very similar UI to Signal but routes all traffic through the Loki network so your traffic passes through three nodes. It is an onion network like Tor. One other ben…

Session has: 1. An associated crypto-currency (not outright bad but weird smell IMO) [1] 2. Abandoned perfect forward secrecy and deniability [2] 3. Never completed an audit (though supposedly one is in progress) [3] There are a million and one encrypted chat programs out there. Why should I use this one? [1]: https://github.com/oxen-io/oxen-mobile-wallet [2]: https://getsession.org/session-protocol-technical-informa…

>Abandoned perfect forward secrecy and deniability...

I suspect that is the future for encrypted messaging. Pretty much everyone ends up keeping their old messages around thus negating the value of forward secrecy[1]. Deniability ends up being just some forgability scheme in most cases[2].

So the benefit of those features turned out to not be worth the extra risk of the added complexity.

[1]: https://articles.59.ca/doku.php?id=pgpfan:forward_secrecy

[2]: https://articles.59.ca/doku.php?id=pgpfan:repudiability

Re: Help users in Iran reconnect to Signal

#373

It's an irony how American companies try circumvents another country's law (regardless of whether you call it censorship or not, it is still a law) and boast about it. Yet, in the US these companies help the mainstream narrative to enforce censorship by banning (Google and Apple App market) or simply not offering other point of views basic hosting services (AWS). I am an Iranian and don't agree with all of our govern…

> I would like to see your supportive reaction if an Iranian company offers hosting to Parler. I imagine you would call it foreign intervention! It's fine with me if an Iranian company offers to host Parler. Having said that, I'm also in favor of prosecuting US companies that violate any sanctions we have against Iran.

Why are you in favor of sanctions on Iran? I've never really heard a good argument. It mostly tends to be "Well they say things I don't like that scare me, like Death to America" so very anti free speech type arguments.

Re: Help users in Iran reconnect to Signal

#374
post #238

So their government is blocking Facebook, Twitter, Youtube, Telegram, Signal, BBC, CNN, Netflix, and probably many other social and media platforms. Meanwhile we are blocking Iranians to access Docker, Slack, Gitlab, Google Code, Github(Github until recently), Paypal, Apple Store, Play Store, AWS, Coursera, Adobe, Nvidia, AVG, Avast, Symantec, McAfee, Matlab!!, Oracle and many more. It should be really fun to use Int…

I use all the websites and products US seems to block (except the antiviruses), but none of the ones the Iranian govt seems to block (except YouTube for fun).

The ones blocked by Iran aren't important in my opinion whereas the ones the US blocks all seem very important.

Re: Help users in Iran reconnect to Signal

#375

Earlier quoted context omitted.

Are there any instructions to build the app yourself for signal?

Yes, they have some docs on GitHub for how to do it: https://github.com/signalapp/Signal-Android/wiki/How-to-buil... You can build the iOS version too for development: https://github.com/signalapp/Signal-iOS/blob/master/BUILDING... I haven't done it before but you should even be able to deploy that build to your phone in theory: https://codewithchris.com/deploy-your-app-on-an-iphone/ It's unclear to me if there are a…

I think you will have a problem when it comes to push notifications. I doubt a local build would be able to receive push notifications addressed to App Store builds.

Re: Help users in Iran reconnect to Signal

#376
post #240

Hi, from Iran with love! First of all, thank you moxie and signal team for this proxy. Until 2018, many Iranians used telegram but Iran's regime after Russia blocked this messenger. telegram released mtproxy and this proxy was helpful. Russia lifted the ban on telegram but this app is still blocked on my country. but with VPNs, many iranians still use this app. after 2018, second most popular messaging app in iran wa…

Thx Sherwin! Just out of curiosity: is iMessage working ok in Iran?

Not the OP but, I can confirm that iMessage works perfectly in Iran; However, because of both economical situation (inflation and the higher price of iPhone comparing to average Android phones) and the fact that local companies cannot release their apps on the AppStore, only a small portion of people use iPhone or in this case iMessage.

Re: Help users in Iran reconnect to Signal

#377
This is why the mindset that no body will leave whatsapp or social media is very detrimental and erroneous. Even if a few 1000 tech savy users use distributed communication that looks like regular traffic all the time, then when an event like this where governement shuts down all main stream social media happens, people will be forced to learn about distributed communication and mass transformation will happen.

Re: Help users in Iran reconnect to Signal

#379
post #185

Hi, from Iran with love! First of all, thank you moxie and signal team for this proxy. Until 2018, many Iranians used telegram but Iran's regime after Russia blocked this messenger. telegram released mtproxy and this proxy was helpful. Russia lifted the ban on telegram but this app is still blocked on my country. but with VPNs, many iranians still use this app. after 2018, second most popular messaging app in iran wa…

I just set up one of these Signal proxies. Hope it helps you and others in your country communicate freely and safely. [1] Regarding Tor: if you want a Signal-like app that uses an onion router look at Session. [2] It uses the same encryption protocol and very similar UI to Signal but routes all traffic through the Loki network so your traffic passes through three nodes. It is an onion network like Tor. One other ben…

I don't understand the point of reinventing many wheels. Why not build a friendly chat app on top of established onion routing protocols (Tor/I2P), or add your own onion routing backend (proxy) to established federated chat apps like Conversations, which already has perfect Tor integration for Jabber/XMPP over .onion servers?

Also, Session is promoted as a non-profit project, but following links around about LokiNet and Oxen you find out about a blockchain-based cryptocurrency, which is known to be an anti-pattern on many levels (though they use Proof-of-Service not Proof-of-Work which is slightly less worse).

Finally, Session appears to be free-software (good), but is not distributed on F-Droid, the only privacy/security-friendly app store for Android. They encourage you to download random APKs from Google Play (which requires Google Play Services malware and a google account) or Github (owned by Microsoft, though i note they sign checksums with PGP on Github so it's safer to download from there than Google Play, even though they don't provide instructions on how to verify signatures). On F-Droid, they could either have F-Droid build/distribute the package with Fdroid's PGP key, or open their own F-Droid repo with their own PGP key (like Newpipe did), or both.

I really appreciate their communication around dissent and the need to protect communications to help the people against their governments. However these three points i just noted are really shady to say the least. I understand they need to please investors to put money in their fridges, however trying to mix for-profit incentives with non-profit services to the communities is always a dead-end.

Re: Help users in Iran reconnect to Signal

#380
post #20

Earlier quoted context omitted.

if they block can block tor what makes you think they can't block these proxies? furthermore if you use tor you can use the existing network of bridges/relays as well as their pluggable transports protocol to avoid DPI/traffic analysis.

Tor is very easy to block, and relies on very similar proxies to circumvent that.

You probably haven't followed Tor development in the past years. obfs4 and snowflake a really cool circumvention methods that are orders of magnitude harder to detect and block than these "signal" TLS proxies.

The TLS proxy signal just advertised uses plaintext TLS SNI header to determine where to route the packets, which makes it really trivial to detect and/or block. The same cannot be said about tor.

Post reply on HN