Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!
No, they're cosplaying security/encryption experts, in an effort to have their attempt at seeking attention seem less like the farce that it is.
A Statement on Recent Events Between Signal and the Anti-Censorship Community
11–20 of 290 posts
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#12I admire the people that put in time and energy to create a safer future for us all.
Hope that this is not going to be taken the wrong way, but whenever I read such threads (and again - I respect all the people involved, their efforts and the importance of this issues) - I can't help but being reminded with this: https://www.youtube.com/watch?v=a0BpfwazhUA
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#13It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#14It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…
>2021-02-06 12:00 @DuckSoft sended a pull request that adds the PoC to Signal TLS proxy's repository. It has since been deleted and both @DuckSoft and @studentmain were banned by the Signal organization on GitHub in the afternoon. A repost by @U-v-U was later closed and locked.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#15Earlier quoted context omitted.
This is a community with a strong focus on security - they're proving their identity when they post to add their agreement.
I don't mean to argue, but I believe github's account system with 2FA should be more than secure enough. If it's not, then why even start a bbs there? Why not just use a signed & encrypted email chain? Seems trivial, especially for what wants to appear to be security professionals.
Account security with 2FA is a long way from foolproof. Accounts get compromised all the time, especially by phishing or malware.
That's why my company's internal emails are all PGP encrypted and signed, even with managed accounts and YubiKey authentication.
When it really, really matters, you need more than 2FA.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#16It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…
What could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.
Signal merely asked that they post on community.signalusers.org instead of Github.
>they feel like this is actively putting peoples lives in danger
That's obviously bullshit though, this can't possibly put peoples lives in more danger than using signal without a proxy a week ago would've.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#17Earlier quoted context omitted.
I don't mean to argue, but I believe github's account system with 2FA should be more than secure enough. If it's not, then why even start a bbs there? Why not just use a signed & encrypted email chain? Seems trivial, especially for what wants to appear to be security professionals.
I work in account security, not for GH, but another platform. Account security with 2FA is a long way from foolproof. Accounts get compromised all the time, especially by phishing or malware. That's why my company's internal emails are all PGP encrypted and signed, even with managed accounts and YubiKey authentication. When it really, really matters, you need more than 2FA.
Edit: Like, if I had hacked one of their accounts, what's keeping me from commenting there and just copy-pasting the key they used before, or generating a new one? Are they going to check?
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#18Earlier quoted context omitted.
What could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.
>If their issues are closed (and Signal does not seem interested in discussing this) Signal merely asked that they post on community.signalusers.org instead of Github. >they feel like this is actively putting peoples lives in danger That's obviously bullshit though, this can't possibly put peoples lives in more danger than using signal without a proxy a week ago would've.
I see one reason it could, it filters out people who do "need" to use it. It could even be people who did not use it before, but think it's undetectable now. Signal implies it can't be detected, at least to non-technical readers.
>Unlike a standard HTTP proxy, connections to the Signal TLS Proxy look just like regular encrypted web traffic. There’s no CONNECT method in a plaintext request to reveal to censors that a proxy is being used.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#19It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…
What could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.
Both the Signal team and this anti-censorship BBS strive towards the same values, and the only thing drama and indignation does is to crack and weaken the effect of the community as a whole. The public sparring should stop and longer-term dialogues should be held to consider everyone's points and come to a conclusion that reasonably satisfies all sides. Depending on emotional investment this may be tough to do at the moment, but down the line it will do wonders for increasing cohesion and productivity.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#20Earlier quoted context omitted.
I work in account security, not for GH, but another platform. Account security with 2FA is a long way from foolproof. Accounts get compromised all the time, especially by phishing or malware. That's why my company's internal emails are all PGP encrypted and signed, even with managed accounts and YubiKey authentication. When it really, really matters, you need more than 2FA.
Yes, of course, I agree! Where I disagree is the notion that putting some PGP keys in a github issues comment is going to prevent anything :/ Edit: Like, if I had hacked one of their accounts, what's keeping me from commenting there and just copy-pasting the key they used before, or generating a new one? Are they going to check?