Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

1–10 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#3
As I wrote in a comment[1] in their other attention-seeking post[2], they keep talking about "risks" and "vulnerability".

There's no exploit or vulnerability here (despite their use of the "PoC" and "responsible disclosure" terms that apply to such things). The fact that you can detect a Signal proxy as a Signal proxy isn't a vulnerability; if it gets censored you're no worse off than you were if that proxy didn't exist: the main Signal servers are censored in Iran already. Indeed, this is the Signal circumvention proxy working precisely as designed.

As I understand it, these people got banned from the Signal forum for spreading this FUD there, too. Predictably, they started accusing Signal of some coverup. They managed to get an interview to further publicize their FUD, but eventually reason prevailed and that was pulled by the author, too.

Sometimes I really wonder the motives and identities behind the people causing such massive and unnecessary drama and fear in the community surrounding the only mainstream, reliable, end-to-end encrypted messenger out there. iMessage and WhatsApp both got their end-to-end crypto backdoored en masse via plaintext backup/escrow systems, but Signal remains generally safe and secure (provided general endpoint security practices are followed). These sorts of FUD attacks make me wonder about why they're happening, and the motives and incentives of the people causing them.

One of the people harassing Moxie about it on Twitter has 1: https://github.com/net4people/bbs/issues/60#issuecomment-775...

2: https://github.com/net4people/bbs/issues/60

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#5
post #4

Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!

PGP means it's serious!

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#6
post #4

Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!

No, they're cosplaying security/encryption experts, in an effort to have their attempt at seeking attention seem less like the farce that it is.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#7
post #4

Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!

This is a community with a strong focus on security - they're proving their identity when they post to add their agreement.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#8
It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1].

The above post is their reaction, which feels more like them lashing out rather than attempting to uphold the greater values of the anti-censorship community. I feel that it doesn't benefit anyone that they behaved this way, choosing to attack the Signal team and the reporter of the article below, rather than resolving the issue productively while allowing the community to continue focusing on their mission.

[1] https://www.bleepingcomputer.com/news/security/removal-notic...

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#9
post #4

Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!

This is a community with a strong focus on security - they're proving their identity when they post to add their agreement.

I don't mean to argue, but I believe github's account system with 2FA should be more than secure enough. If it's not, then why even start a bbs there? Why not just use a signed & encrypted email chain? Seems trivial, especially for what wants to appear to be security professionals.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#10
post #4

Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!

This is a community with a strong focus on security - they're proving their identity when they post to add their agreement.

It's a LARP, not about a strong focus on security. These people do not normally sign their comments.
Post reply on HN