Live data from Hacker News

Help users in Iran reconnect to Signal

signal.org

381–390 of 417 posts

Re: Help users in Iran reconnect to Signal

#381
WTF Signal?! You claim to help users from Iran, however you encourage them to circumvent a government ban by using proxy which redirect trafic based on TLS SNI header, in plaintext?! Maybe you think the Iranian government doesn't have the resources (yet) to log/drop packets based on SNI, however it may well be the case already or soon because that's really not hard to do.

You are actively encouraging people to use technology that will reveal to their ISP/government they use Signal despite a government ban. You also force them to use phone numbers, which are uniquely-identifiable and are also advertised publicly in multi-user chats. ARE YOU TRYING TO GET PEOPLE JAILED OR KILLED?

If you were really fighting for freedom and the right to legitimate dissent against unfair governments, then you would federate your services so you don't become a central authority who can ban users (SPOF), abandon phone numbers entirely (because they're a security nightmare and publishing them facilitates harassment, a known problem on your platform you have refused to address so far), and use established proxying mechanisms which are less detectable than a plaintext header containing "signal.org" (like Tor).

Re: Help users in Iran reconnect to Signal

#382

WTF Signal?! You claim to help users from Iran, however you encourage them to circumvent a government ban by using proxy which redirect trafic based on TLS SNI header, in plaintext?! Maybe you think the Iranian government doesn't have the resources (yet) to log/drop packets based on SNI, however it may well be the case already or soon because that's really not hard to do. You are actively encouraging people to use te…

The SNI is encapsulated in an outer layer of TLS, which is removed before forwarding traffic to Signal. That's what nginx-terminate is doing.

Re: Help users in Iran reconnect to Signal

#383

WTF Signal?! You claim to help users from Iran, however you encourage them to circumvent a government ban by using proxy which redirect trafic based on TLS SNI header, in plaintext?! Maybe you think the Iranian government doesn't have the resources (yet) to log/drop packets based on SNI, however it may well be the case already or soon because that's really not hard to do. You are actively encouraging people to use te…

The SNI is encapsulated in an outer layer of TLS, which is removed before forwarding traffic to Signal. That's what nginx-terminate is doing.

The header will appear in plaintext between the user and the proxy (easy to detect/log/drop for their ISP/government), and still appear in plaintext between the proxy and Signal (which is less of a problem).

The SNI header is not dropped to upstream because it's used whether the reverse proxy is operated by the intended recipient (Signal) or not (the proxy). That's precisely the reason why people have been promoting Encrypted SNI for some time now.

Re: Help users in Iran reconnect to Signal

#384

Earlier quoted context omitted.

> I would like to see your supportive reaction if an Iranian company offers hosting to Parler. I imagine you would call it foreign intervention! It's fine with me if an Iranian company offers to host Parler. Having said that, I'm also in favor of prosecuting US companies that violate any sanctions we have against Iran.

Why are you in favor of sanctions on Iran? I've never really heard a good argument. It mostly tends to be "Well they say things I don't like that scare me, like Death to America" so very anti free speech type arguments.

I vouched for this post but you appear to be shadow-banned.

> Why are you in favor of sanctions on Iran?

My position isn't that Iranian sanctions are a good idea - I don't yet have an informed opinion about them.

We have laws against US companies trading with Iran and I believe in the rule of law as a general principle.

Re: Help users in Iran reconnect to Signal

#385

Earlier quoted context omitted.

The SNI is encapsulated in an outer layer of TLS, which is removed before forwarding traffic to Signal. That's what nginx-terminate is doing.

The header will appear in plaintext between the user and the proxy (easy to detect/log/drop for their ISP/government), and still appear in plaintext between the proxy and Signal (which is less of a problem). The SNI header is not dropped to upstream because it's used whether the reverse proxy is operated by the intended recipient (Signal) or not (the proxy). That's precisely the reason why people have been promoting…

It is not true that Signal domains are visible in plaintext on the wire between the user and the proxy.

You can spin up the proxy and check yourself.

Alternatively, you can ask yourself "why go through the trouble of setting up a legitimate ca-signed certificate if Signal domains are already leaking in plaintext"? The whole point of the ca-signed cert is to make the traffic blend in. Why go through that trouble when a simple regular expression could identify it?

Re: Help users in Iran reconnect to Signal

#386
post #364

Earlier quoted context omitted.

Hi there, Signal Android dev here. We have reproducible build steps, so you actually can verify the code is the same :) https://github.com/signalapp/Signal-Android/tree/master/repr...

Reproducible builds do not help to determine if the version you download via the Play Store (or, for those on enterprise devices, any pre-installed corporate stores) is the same as you build - Play Store presents no real means to verify that. This includes any auto-updates if they are enabled. It's an issue with Play Store as a delivery channel, the individual app in question can't do much about that. Reproducible bu…

The instructions posted by the dev directly include instructions for pulling the APK from your phone which was installed through the Play Store.

https://github.com/signalapp/Signal-Android/tree/master/repr...

Re: Help users in Iran reconnect to Signal

#387

Earlier quoted context omitted.

Tor is very easy to block, and relies on very similar proxies to circumvent that.

You probably haven't followed Tor development in the past years. obfs4 and snowflake a really cool circumvention methods that are orders of magnitude harder to detect and block than these "signal" TLS proxies. The TLS proxy signal just advertised uses plaintext TLS SNI header to determine where to route the packets, which makes it really trivial to detect and/or block. The same cannot be said about tor.

I’m familiar with obfs4 and snowflake.

Signals TLS proxy is naive compared to obfs4, but at it’s core it’s a similar solution.

Re: Help users in Iran reconnect to Signal

#388

Hi, from Iran with love! First of all, thank you moxie and signal team for this proxy. Until 2018, many Iranians used telegram but Iran's regime after Russia blocked this messenger. telegram released mtproxy and this proxy was helpful. Russia lifted the ban on telegram but this app is still blocked on my country. but with VPNs, many iranians still use this app. after 2018, second most popular messaging app in iran wa…

Honest question: Is using Tor not a risk by itself in Iran? I wonder if this doesn't pop up under surveillance mechanisms as conspirative behavior and may trigger focussed surveillance, which is hard to get out of.

But maybe so many people in Iran use Tor that it's not very outstanding to use it? I remember there were stats on that published on the Tor Project Website...

Edit: To answer myself after 5 minutes of thinking: Of course there are bridges, too. I guess they don't appear as suspicous as regular entry nodes?

Re: Help users in Iran reconnect to Signal

#389
post #233

Earlier quoted context omitted.

Using innocent sounding CNAMEs on abandoned domains is definitely a smart idea. I’ve definitely got some old domains kicking about, I’ll see how far off they are from expiration and do something similar if they have at least a few months left in them. The proxies themselves can also be hosted at normal sounding domains and subdomains like cdn.technology.memes or whatever. And when you point other domains to them as C…

If your scheme for conveying innocent sounding proxy domains requires it's own innocent sounding domains what have you added?

To my thinking, it creates a chain of "it's really hard to block them all" - as soon as I saw (via the link) that you submit your new proxy to https://signal.tube I thought "...so the Iranian gov't just has to block any and all access - DNS, HTTP - to that domain" and people can't even see what proxies are out there. So if my friendly domain name is "learned as a Signal proxy" they just block my domain (personally, I'd use two domains to double-blind it).

My conceptual idea is that how you get the person the name of the proxy to use has to hide as signal amongst the noise and not get trapped in DNS/domain blocking filters - and if it's keyword blocked by the Great Firewall, you just start asking other random domains for their MX records etc. I believe it's generally referred to as steganography: https://en.wikipedia.org/wiki/Steganography

Re: Help users in Iran reconnect to Signal

#390

Earlier quoted context omitted.

Not exactly the same. Signal is banned by Iranian government, parler was banned by US companies.

Accurate but a disingenuous concept (not you) because U.S companies are approaching nation state power, i.e Google, Amazon etc.

Yes. Exactly. How do we as outsiders know the us govt isnt doing backchannel deals with faang, even with one is enough to get the ball rolling.

Even if thats not the case, my question still stands. If American companies banned parler, why dodgy govt intervene like how it tries to potray a sense of high handedness when it comes to Iran. If the can sanction companies to not serve Iran, cant they force them to serve parler in the first place? If not then they are silently agreeing with faang decision, against free speech

Post reply on HN