Earlier quoted context omitted.
It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…
Tone can often be more important than facts. At one point in my career I had a somewhat public facing role. I made a tough decision that aggravated a user, who decided to send me several death threats. Suddenly that tough decision wasn’t so tough anymore. Any possible resolution was gone. These situations involve people. We aren’t fact machines.
A Statement on Recent Events Between Signal and the Anti-Censorship Community
71–80 of 290 posts
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#72Earlier quoted context omitted.
It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…
> So what should we use instead of signal? Threema is one alternative.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#73I think that says it all.
I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it's not ideal even to circumvent censorship. But they're apparently working on something better, and all this distraction is not helping.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#74Moxie - and the Signal team - seems to have a real issue taking feedback from outside experts. See the way he has been completely dismissive of the IME vulnerability highlighted by Naomi Wu and others. I remember back when it was TextSecure - I tried to raise some usability and security issues. First I was ignored, then dismissed, then - a few years later - they implemented some of the changes. I still use Signal. Bu…
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#75Earlier quoted context omitted.
> this can't possibly put peoples lives in more danger than using signal without a proxy a week ago would've. I see one reason it could, it filters out people who do "need" to use it. It could even be people who did not use it before, but think it's undetectable now. Signal implies it can't be detected, at least to non-technical readers. >Unlike a standard HTTP proxy, connections to the Signal TLS Proxy look just lik…
If the mere use of Signal is banned, traffic analysis tools an DPI can be used to identify users and bring them the unwelcome attention of the regime’s well-staffed secret police. I’m sure the Chinese are selling them surveillance tech, and if not Iranians are quite capable of developing it themselves. It’s not a simple issue to resolve. WireGuard is better in that it only establishes a flow if authenticated, but UDP…
Actually it seems more likely that it's US-built censorship tools -- specifically BlueCoat, which was detected in 2013[1]. BlueCoat claimed they didn't sell the hardware to Iran because it would violate sanctions but that's not much consolation for the people who are being surveilled using their tools.
[1]: https://www.washingtonpost.com/world/national-security/repor...
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#76Earlier quoted context omitted.
One major reason for the push back against Signal promotion is that it does not represent any sort of federated protocol. It is a complete silo. So if it did become popular it would eventually be a serious problem and would need to be fought against.
> It is a complete silo. So if it did become popular it would eventually be a serious problem and would need to be fought against. This is an explicit design decision. It used to federate, and they found that to be terrible, so they stopped, and now it's better. Maybe you should find something else to fight against. https://signal.org/blog/the-ecosystem-is-moving/ Worth noting: Google Talk used to federate, via XMPP.…
Compared to the number of GTalk users, a bunch of self-hosted users probably didn't count for much.
> and something like 99%+ of the federation traffic was inbound spam
I heard this too, not sure if it was the only reason.
Too bad Google doesn't know how to manage spam. Good thing they don't have any other federated communication products. /s
> Federated protocols aren't very good, and don't evolve.
What makes you say this? XMPP has come a long way since 1999 and is still evolving to this day. Even email is slowly evolving. Is Matrix not evolving? HTTP isn't really federated, but Moxie also mentions the web being stuck on HTTP/1.1, because HTTP/2 and HTTP/3 don't exist.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#77Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#78Even if I agree with the principles of the anti-censorship people, to be an activist to apply pressure on Signal for features instead of forking and building solutions is suspicious to me. Signal does a great job of frustrating mass interception, which I think was its original point. Inventing new criteria and re-framing their product as inadequate for this scope change as an activism play seems insincere. We can exp…
What would you fork? The signal server code that hasn’t been updated in almost a year[1]?
If that is truly the same code that we use with signal today, would your fork work with this same network? Or would it be it’s own 1-server network all alone?
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#79Earlier quoted context omitted.
I've seen a growing number of anti-Signal posts and activism lately, mostly surrounding the (well-documented) design tradeoffs that Signal makes for usability and privacy (such as opting to use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers), or their famous decision not to federate/interoperate. Perhaps it's just criticism growing in lockstep with Signal's overall…
Did you know Signal, like Tor, was financed by an offshoot of the CIA? https://www.opentech.fund/results/supported-projects/open-wh... https://pando.com/2015/03/01/internet-privacy-funded-by-spoo... Now if I were an Iranian dissident, I would be reasonably confident Signal is designed to withstand the Iranian regime’s interception efforts (but not necessarily traffic analysis). If I were someone on the US government’…
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#80Earlier quoted context omitted.
> Why can't the user just be expected to deal with their contact list? They are; they let the user maintain their own list of phone numbers for their contacts, precisely like the phone company in your example. > They require the phone number as an anti-spam/moderation measure and hide behind privacy. This is (inaccurate) speculation from ignorance. Signal, unlike almost every other phone-number-using-service on the p…
Then why not let users sign up with a random unique ID number that they can share with their contacts?