Moxie - and the Signal team - seems to have a real issue taking feedback from outside experts. See the way he has been completely dismissive of the IME vulnerability highlighted by Naomi Wu and others. I remember back when it was TextSecure - I tried to raise some usability and security issues. First I was ignored, then dismissed, then - a few years later - they implemented some of the changes. I still use Signal. Bu…
Maybe, but I think that the way these researchers reacted when their criticism wasn't heard doesn't benefit anybody. By ratcheting up the tension and participating in an internet catfight against the Signal team, a net loss occurs for the anti-censorship community. If the Signal team does indeed have a real problem with taking feedback and criticism, a better approach might've been to gather support and enter into lo…
A Statement on Recent Events Between Signal and the Anti-Censorship Community
41–50 of 290 posts
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#42Earlier quoted context omitted.
> Sometimes I really wonder the motives and identities behind the people causing such massive and unnecessary drama In this case, it's pretty boring. They are just a group of "your average power users" or "wannabe programmers" in their highschool or junior years who happened to be born in China so had some exposure to anti-censorship. Being in their overconfident period of life, they pass by various myth they don't r…
I've seen a growing number of anti-Signal posts and activism lately, mostly surrounding the (well-documented) design tradeoffs that Signal makes for usability and privacy (such as opting to use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers), or their famous decision not to federate/interoperate. Perhaps it's just criticism growing in lockstep with Signal's overall…
https://www.opentech.fund/results/supported-projects/open-wh...
https://pando.com/2015/03/01/internet-privacy-funded-by-spoo...
Now if I were an Iranian dissident, I would be reasonably confident Signal is designed to withstand the Iranian regime’s interception efforts (but not necessarily traffic analysis). If I were someone on the US government’s shitlist like Edward Snowden or Julian Assange, my calculus would be entirely different. (Yes, I know Snowden has endorsed Signal)
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#43Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#44Earlier quoted context omitted.
>It's overblown, I think. https://freedomhouse.org/country/iran/freedom-net/2019 >Several harsh prison sentences were handed down during the reporting period in retaliation for online activities. Mostafa Abdi, an editor of the news site Majzooban Noor, was sentenced to 26 years in prison and 74 lashes in August 2018. Five other journalists at the outlet received sentences ranging from 7 to 12 years (see C3).
Did they draw the government's attention because they were connecting to banned websites or because they were running a high-profile news outlet? It's seems unlikely to me that the Iranian government would be able to prosecute even a small fraction of instances of the former, whereas there's only a small number of high-profile news outlets at any given time.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#45It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…
What could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.
The fork option is there and always has been.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#46What interests me more, is Signal's principal stance about censorship. If non-tech people ever come to Signal in numbers, the moderation problem will inevitably arise. Would they censor things that we currently have public consensus about? Like CP, terrorism etc.
Let's hope it will remain just a messaging/videocall app.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#47Earlier quoted context omitted.
What could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.
This isn't putting anybody's life in danger - to my rough understanding the only thing detection of a proxy allows for is its takedown. I doubt the Iranian government has the resources or will to trawl their entire net for these proxies and trace their physical locations. What I meant by resolving the situation in a more productive way entails taking a step back and considering the situation outside this Twitter and…
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#48This ‘statement’ is quite weird. Is it normal to declare oneself an oppressed minority over a github issue?
I feel like we should be a bit more charitable to people who make things. Otherwise nobody will make anything anymore...
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#49Earlier quoted context omitted.
I work in account security, not for GH, but another platform. Account security with 2FA is a long way from foolproof. Accounts get compromised all the time, especially by phishing or malware. That's why my company's internal emails are all PGP encrypted and signed, even with managed accounts and YubiKey authentication. When it really, really matters, you need more than 2FA.
Yes, of course, I agree! Where I disagree is the notion that putting some PGP keys in a github issues comment is going to prevent anything :/ Edit: Like, if I had hacked one of their accounts, what's keeping me from commenting there and just copy-pasting the key they used before, or generating a new one? Are they going to check?
If at any point in the future, someone wanted to say, "Well, so-and-so may not really have been the one who posted it," or, on the other hand, one of the signers later wanted to renege and say they didn't really sign it, it's going to be a lot harder for anyone to buy that the account credentials and PGP privkey were stolen and used than just that someone somehow spoofed a post from an account.
It's like the difference between posting a +1 retweet and having a signed document notarized. One of those is a lot harder to claim was faked/unauthorized later.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#50It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…
Unfortunately it's not possible to productively resolve issues with the Signal team, something you can find documented again and again.
(My own experience: I had to justify the the user impact of 30+sec freezes on every sent message, confirmed by multiple people. Bug was closed wontfix.)
This is a known thing with Moxie and the culture he's created at Signal and it's unfortunate that he's still starting drama with everyone instead of doing any self-reflection.