Moxie deserves an ACM award for his contributions to crypto but he shouldn't be leading the project. Maybe posting on the Discourse forum was the right thing to do here. I just see a lot of hostility between Signal employees and those wishing to make the project a little bit better.
They have been ignoring or brushed off the importance of reported privacy related issues for years. Doesn't built trust to use Signal for me personally
Signal's TLS Proxy Failed to Be Probing Resistant
21–30 of 46 posts
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#22Earlier quoted context omitted.
They have been ignoring or brushed off the importance of reported privacy related issues for years. Doesn't built trust to use Signal for me personally
Could you be more specific about the issues they’ve been ignoring or brushing off?
If you are serious about privacy and secure messenger, you just can't brush off such issues.
[1] https://twitter.com/realsexycyborg/status/119769536810582425... [2] https://community.signalusers.org/t/signal-should-warn-users... [2] https://www.theverge.com/22249391/signal-app-abuse-messaging...
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#23Earlier quoted context omitted.
That so-called hostility seems to be pretty one-sided IMO. The response from the Signal dev seemed pretty calm and reasonable, but OP seemed to take it as a personal insult for no reason. Some projects don't want to discuss issues on GitHub and prefer a forum they have control over; that's totally understandable.
That's those projects I don't report issues to and rather maintain local patches for. I'm not gonna sign up to the fivetrillionth forum or bug tracker for your special snowflake software. If you don't allow bug reports via github issues, you won't get mine.
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#24They're generally dismissive, especially so about design problems that cause a big amount of bugs that are strewn throughout Signal, like their handling of message timestamps/sync and dismissal of the IME concerns.
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#25Earlier quoted context omitted.
Could you be more specific about the issues they’ve been ignoring or brushing off?
For a year, they have been reporting reports of the issue wit the IME keyboards. See: https://community.signalusers.org/t/signal-should-warn-users... If you are serious about privacy and secure messenger, you just can't brush off such issues. [1] https://twitter.com/realsexycyborg/status/119769536810582425... [2] https://community.signalusers.org/t/signal-should-warn-users... [2] https://www.theverge.com/22249391/sig…
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#26Earlier quoted context omitted.
Could you be more specific about the issues they’ve been ignoring or brushing off?
For a year, they have been reporting reports of the issue wit the IME keyboards. See: https://community.signalusers.org/t/signal-should-warn-users... If you are serious about privacy and secure messenger, you just can't brush off such issues. [1] https://twitter.com/realsexycyborg/status/119769536810582425... [2] https://community.signalusers.org/t/signal-should-warn-users... [2] https://www.theverge.com/22249391/sig…
Signal should focus on problems they can realistically solve.
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#27Earlier quoted context omitted.
That's those projects I don't report issues to and rather maintain local patches for. I'm not gonna sign up to the fivetrillionth forum or bug tracker for your special snowflake software. If you don't allow bug reports via github issues, you won't get mine.
From pure interpretation of your answer, i would say you are the snowflake human here.
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#28Re: Signal's TLS Proxy Failed to Be Probing Resistant
#29Re: Signal's TLS Proxy Failed to Be Probing Resistant
#30How long did he wait for the signal forum to approve his account? The guy, or girl, seems rather aggressive. It's mentioned they've not slept in a while...
It got approved fairly quickly. It was a false positive (see my link in main thread) with their spam detection (DuckSoft copy pasted the post so flagged as "type too fast").
I am DuckSoft on GitHub and I prove my identity by GPG signing this message.
I am not typing too fast, nor pasting all my stuffs into the comment area. I just put a link to the GitHub issue. The discussion board even automatically extracted title and abstract for me, where I thought, 'pretty cool huh'.
Then I got banned. -----BEGIN PGP SIGNATURE-----
iQEzBAEBCAAdFiEE2H0QtOEy/6QN7CMrejqfpuT9So0FAmAdx9IACgkQejqfpuT9 So1KrQf+M8VzJBj4FgNZB/KZZ/suxNBF9DEkcfR66mwf/YzGGK9Gf2QDBqNoHUJs jJGvRai4ygqtZE3oX3GZmkjRT8LzEiNgmOM+B39SehL7F9rhMGz4lHMrRV5ZnSxp w5ALHSs3L6Gyg5hwNOQV73+STg9Vc2TsWSCS+Xr+BuNYbbLwiKWV9M1pxOynaWx0 J5+JswXaZkEONcKyGKbwc2FrgH1EXRgv+TipHucAkz+1HVMRd9NZ5W38vjASWEwO dEXXmCWyH8rQ69rLU+M7lXiKY0IBVrvVirzC97TpS22A74FDTdEG4xpGHSzPaDFp 3DRJvymGOlHDqhlotR8ox1ndFPzR9A== =ib+f -----END PGP SIGNATURE-----