Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

21–30 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#21
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations.

Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama.

The tone is not more important than the facts. It never is.

Im not suggesting you have some alternative motive to deflect the facts. Any one could have written this reaction.

The top comment on a thread like this is always the same. Talking about tone. But I don't mean this offensively, I'm sure I've done it myself as well at times, but it feels like theater. Like a journalist asking a question they know they won't get an answer to. Talking about drama is the same participating in it.

So what should we use instead of signal?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#23
post #13

Earlier quoted context omitted.

What could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.

This isn't putting anybody's life in danger - to my rough understanding the only thing detection of a proxy allows for is its takedown. I doubt the Iranian government has the resources or will to trawl their entire net for these proxies and trace their physical locations. What I meant by resolving the situation in a more productive way entails taking a step back and considering the situation outside this Twitter and…

> I doubt the Iranian government has the resources or will to trawl their entire net for these proxies and trace their physical locations.

The proxies are necessarily run outside of Iran, as Signal is blocked inside of Iran. I think the (tenuous) argument is that the government could see that user X is connecting to proxy host Y (outside of Iran), and then themselves connect to proxy host Y to verify it's a Signal proxy, and then take action (including potential violence) against user X for connecting to it (and presumably block further connections from within Iran to proxy host Y).

It's overblown, I think.

> Both the Signal team and this anti-censorship BBS strive towards the same values, and the only thing drama and indignation does is to crack and weaken the effect of the community as a whole.

This is precisely why I'm so curious about why this happened. It's easy to dismiss it as simple douchebaggery, but at least one of the accounts harassing Moxie on twitter about it have the classic hallmarks of sockpuppets, and the whole over-the-top PGP signing thing (and opening of multiple issues, and seeking press) makes me think this is a bit more of a coordinated smear campaign.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#24
post #20
post #17

Earlier quoted context omitted.

Yes, of course, I agree! Where I disagree is the notion that putting some PGP keys in a github issues comment is going to prevent anything :/ Edit: Like, if I had hacked one of their accounts, what's keeping me from commenting there and just copy-pasting the key they used before, or generating a new one? Are they going to check?

It's proof that it IS them who posted that comment.

It is proof that someone with a copy of the private key posted that comment. Also this https://xkcd.com/1181/

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#25
post #3

As I wrote in a comment[1] in their other attention-seeking post[2], they keep talking about "risks" and "vulnerability". There's no exploit or vulnerability here (despite their use of the "PoC" and "responsible disclosure" terms that apply to such things). The fact that you can detect a Signal proxy as a Signal proxy isn't a vulnerability; if it gets censored you're no worse off than you were if that proxy didn't ex…

> Sometimes I really wonder the motives and identities behind the people causing such massive and unnecessary drama

In this case, it's pretty boring. They are just a group of "your average power users" or "wannabe programmers" in their highschool or junior years who happened to be born in China so had some exposure to anti-censorship. Being in their overconfident period of life, they pass by various myth they don't really understand as truth. The community is quite toxic but usually they don't cause trouble outside of their own circle, but when it happens, I don't know how to deal with them either.

They also misuses words like "vulnerability" or "responsible disclosure" because some of them have read a lot of news about security research, thought it is extremely cool but have no idea what it actually means.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#26
Yes, indeed, I'm baffled that the people from Signal who dismiss these critics think that the only people possibly "endangered" are the proxy owners.

It does not cross their mind that the users are immediately endangered too.

They don't understand that it is very easy to identify the proxy users once the Signal proxies themselves are detected?

I'm here replying on the top level to this comment, because I think this is very important: https://news.ycombinator.com/item?id=26076113

Edit:

Actually it is because it is a different problem they are trying to solve.

What Signal is solving by these additional proxies is to avoid being blocked. So this is orthogonal to avoiding the detection of users.

The real way to avoid detection of users is going through something like Tor.

Edit 2:

The real problem is that, in countries where Signal is blocked, it is ALSO forbidden and illegal.

If it was just blocked and not forbidden, nothing wrong in working around the blocking.

But actually permitting users to work around the blocking when it is illegal is not helping them, unless there is also a way to hide them. Else it helps them commit (overtly) the crime for which they risk many troubles.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#27
post #23

Earlier quoted context omitted.

This isn't putting anybody's life in danger - to my rough understanding the only thing detection of a proxy allows for is its takedown. I doubt the Iranian government has the resources or will to trawl their entire net for these proxies and trace their physical locations. What I meant by resolving the situation in a more productive way entails taking a step back and considering the situation outside this Twitter and…

> I doubt the Iranian government has the resources or will to trawl their entire net for these proxies and trace their physical locations. The proxies are necessarily run outside of Iran, as Signal is blocked inside of Iran. I think the (tenuous) argument is that the government could see that user X is connecting to proxy host Y (outside of Iran), and then themselves connect to proxy host Y to verify it's a Signal pr…

>It's overblown, I think.

https://freedomhouse.org/country/iran/freedom-net/2019

>Several harsh prison sentences were handed down during the reporting period in retaliation for online activities. Mostafa Abdi, an editor of the news site Majzooban Noor, was sentenced to 26 years in prison and 74 lashes in August 2018. Five other journalists at the outlet received sentences ranging from 7 to 12 years (see C3).

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#28
post #25
post #3

As I wrote in a comment[1] in their other attention-seeking post[2], they keep talking about "risks" and "vulnerability". There's no exploit or vulnerability here (despite their use of the "PoC" and "responsible disclosure" terms that apply to such things). The fact that you can detect a Signal proxy as a Signal proxy isn't a vulnerability; if it gets censored you're no worse off than you were if that proxy didn't ex…

> Sometimes I really wonder the motives and identities behind the people causing such massive and unnecessary drama In this case, it's pretty boring. They are just a group of "your average power users" or "wannabe programmers" in their highschool or junior years who happened to be born in China so had some exposure to anti-censorship. Being in their overconfident period of life, they pass by various myth they don't r…

I've seen a growing number of anti-Signal posts and activism lately, mostly surrounding the (well-documented) design tradeoffs that Signal makes for usability and privacy (such as opting to use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers), or their famous decision not to federate/interoperate.

Perhaps it's just criticism growing in lockstep with Signal's overall growth and notoriety, and there aren't any concerted efforts to discredit Signal and sow doubt about using it because it's harder for the intelligence agencies to surveil. I'd like to live in that world.

I'm not sure that I do.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#29
post #27
post #23

Earlier quoted context omitted.

> I doubt the Iranian government has the resources or will to trawl their entire net for these proxies and trace their physical locations. The proxies are necessarily run outside of Iran, as Signal is blocked inside of Iran. I think the (tenuous) argument is that the government could see that user X is connecting to proxy host Y (outside of Iran), and then themselves connect to proxy host Y to verify it's a Signal pr…

>It's overblown, I think. https://freedomhouse.org/country/iran/freedom-net/2019 >Several harsh prison sentences were handed down during the reporting period in retaliation for online activities. Mostafa Abdi, an editor of the news site Majzooban Noor, was sentenced to 26 years in prison and 74 lashes in August 2018. Five other journalists at the outlet received sentences ranging from 7 to 12 years (see C3).

Signal is end-to-end encrypted. The only thing the network surveillance would be able to determine is that you were connecting to Signal via an open Signal proxy, not the people you were talking to, or the content of your messages.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#30

Yes, indeed, I'm baffled that the people from Signal who dismiss these critics think that the only people possibly "endangered" are the proxy owners. It does not cross their mind that the users are immediately endangered too. They don't understand that it is very easy to identify the proxy users once the Signal proxies themselves are detected? I'm here replying on the top level to this comment, because I think this i…

Exactly, according to NGO's people get lashed and jailed for online activities. After Signal has been blocked being detected could actually endanger peoples life.

https://freedomhouse.org/country/iran/freedom-net/2019 https://freedomhouse.org/country/iran/freedom-net/2020

Post reply on HN