Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

11–20 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#11
post #6
post #4

Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!

No, they're cosplaying security/encryption experts, in an effort to have their attempt at seeking attention seem less like the farce that it is.

My first reaction was that surely this must be satire, because the last thing I ask myself reading that post is "but how do I know these 2FA GitHub accounts are not hacked?!" ...

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#12
Censorship and privacy are important issues. So is civilised online debate, and communities learning to work together in a nice way.

I admire the people that put in time and energy to create a safer future for us all.

Hope that this is not going to be taken the wrong way, but whenever I read such threads (and again - I respect all the people involved, their efforts and the importance of this issues) - I can't help but being reminded with this: https://www.youtube.com/watch?v=a0BpfwazhUA

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#13
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

What could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#14
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

They even talk about their own inappropriate behaviour in this statement:

>2021-02-06 12:00 @DuckSoft sended a pull request that adds the PoC to Signal TLS proxy's repository. It has since been deleted and both @DuckSoft and @studentmain were banned by the Signal organization on GitHub in the afternoon. A repost by @U-v-U was later closed and locked.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#15
post #9

Earlier quoted context omitted.

This is a community with a strong focus on security - they're proving their identity when they post to add their agreement.

I don't mean to argue, but I believe github's account system with 2FA should be more than secure enough. If it's not, then why even start a bbs there? Why not just use a signed & encrypted email chain? Seems trivial, especially for what wants to appear to be security professionals.

I work in account security, not for GH, but another platform.

Account security with 2FA is a long way from foolproof. Accounts get compromised all the time, especially by phishing or malware.

That's why my company's internal emails are all PGP encrypted and signed, even with managed accounts and YubiKey authentication.

When it really, really matters, you need more than 2FA.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#16
post #13
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

What could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.

>If their issues are closed (and Signal does not seem interested in discussing this)

Signal merely asked that they post on community.signalusers.org instead of Github.

>they feel like this is actively putting peoples lives in danger

That's obviously bullshit though, this can't possibly put peoples lives in more danger than using signal without a proxy a week ago would've.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#17
post #15
post #9

Earlier quoted context omitted.

I don't mean to argue, but I believe github's account system with 2FA should be more than secure enough. If it's not, then why even start a bbs there? Why not just use a signed & encrypted email chain? Seems trivial, especially for what wants to appear to be security professionals.

I work in account security, not for GH, but another platform. Account security with 2FA is a long way from foolproof. Accounts get compromised all the time, especially by phishing or malware. That's why my company's internal emails are all PGP encrypted and signed, even with managed accounts and YubiKey authentication. When it really, really matters, you need more than 2FA.

Yes, of course, I agree! Where I disagree is the notion that putting some PGP keys in a github issues comment is going to prevent anything :/

Edit: Like, if I had hacked one of their accounts, what's keeping me from commenting there and just copy-pasting the key they used before, or generating a new one? Are they going to check?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#18
post #16
post #13

Earlier quoted context omitted.

What could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.

>If their issues are closed (and Signal does not seem interested in discussing this) Signal merely asked that they post on community.signalusers.org instead of Github. >they feel like this is actively putting peoples lives in danger That's obviously bullshit though, this can't possibly put peoples lives in more danger than using signal without a proxy a week ago would've.

> this can't possibly put peoples lives in more danger than using signal without a proxy a week ago would've.

I see one reason it could, it filters out people who do "need" to use it. It could even be people who did not use it before, but think it's undetectable now. Signal implies it can't be detected, at least to non-technical readers.

>Unlike a standard HTTP proxy, connections to the Signal TLS Proxy look just like regular encrypted web traffic. There’s no CONNECT method in a plaintext request to reveal to censors that a proxy is being used.

https://signal.org/blog/help-iran-reconnect/

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#19
post #13
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

What could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.

This isn't putting anybody's life in danger - to my rough understanding the only thing detection of a proxy allows for is its takedown. I doubt the Iranian government has the resources or will to trawl their entire net for these proxies and trace their physical locations. What I meant by resolving the situation in a more productive way entails taking a step back and considering the situation outside this Twitter and Github row.

Both the Signal team and this anti-censorship BBS strive towards the same values, and the only thing drama and indignation does is to crack and weaken the effect of the community as a whole. The public sparring should stop and longer-term dialogues should be held to consider everyone's points and come to a conclusion that reasonably satisfies all sides. Depending on emotional investment this may be tough to do at the moment, but down the line it will do wonders for increasing cohesion and productivity.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#20
post #17
post #15

Earlier quoted context omitted.

I work in account security, not for GH, but another platform. Account security with 2FA is a long way from foolproof. Accounts get compromised all the time, especially by phishing or malware. That's why my company's internal emails are all PGP encrypted and signed, even with managed accounts and YubiKey authentication. When it really, really matters, you need more than 2FA.

Yes, of course, I agree! Where I disagree is the notion that putting some PGP keys in a github issues comment is going to prevent anything :/ Edit: Like, if I had hacked one of their accounts, what's keeping me from commenting there and just copy-pasting the key they used before, or generating a new one? Are they going to check?

It's proof that it IS them who posted that comment.
Post reply on HN