Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

81–90 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#81
post #28

Earlier quoted context omitted.

I've seen a growing number of anti-Signal posts and activism lately, mostly surrounding the (well-documented) design tradeoffs that Signal makes for usability and privacy (such as opting to use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers), or their famous decision not to federate/interoperate. Perhaps it's just criticism growing in lockstep with Signal's overall…

One major reason for the push back against Signal promotion is that it does not represent any sort of federated protocol. It is a complete silo. So if it did become popular it would eventually be a serious problem and would need to be fought against.

>So if it did become popular it would eventually be a serious problem and would need to be fought against.

It already is.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#82
post #74
post #31

Moxie - and the Signal team - seems to have a real issue taking feedback from outside experts. See the way he has been completely dismissive of the IME vulnerability highlighted by Naomi Wu and others. I remember back when it was TextSecure - I tried to raise some usability and security issues. First I was ignored, then dismissed, then - a few years later - they implemented some of the changes. I still use Signal. Bu…

[flagged]

Why does her view on something completely unrelated matter to the facts? Why are you even comping through her Twitter history? This is clearly a personal attack "just because". Disgusting.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#83
post #9

Earlier quoted context omitted.

This is a community with a strong focus on security - they're proving their identity when they post to add their agreement.

I don't mean to argue, but I believe github's account system with 2FA should be more than secure enough. If it's not, then why even start a bbs there? Why not just use a signed & encrypted email chain? Seems trivial, especially for what wants to appear to be security professionals.

But that's exactly the point isn't it? I mean, using pgp because you don't trust the communication channel. And you would still have the same issue with a mailing list.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#84

why is instant messaging so important? why can't people use eg an encrypted tor bridge to send and receive encrypted emails? or is a mobile phone cheaper/more practical than a laptop in such a situation?

PGP lacks forward secrecy. E.g. the Iranian government can collect every PGP-message you ever send, and if and when they compromise your private key, they can retrospectively

a) decrypt your entire message history, even if you've deleted it from your endpoint

b) prove that you're the author of every message, because only your private key can be used to craft the digital signatures.

Signal solves both problems. For dissidents' communication, PGP is hard to use and incredibly dangerous even when used correctly. It needs to be killed with fire and buried next to nuclear waste in a container made of Beskar or something.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#85
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

Seems to me it was Moxie attacking, not them.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#86
post #21

Earlier quoted context omitted.

It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…

> So what should we use instead of signal? Threema is one alternative.

Or Session

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#87
post #48

Signal seems to get a lot of unfair criticism. I think this is at least partly because they made something a lot of people actually do use. This would otherwise be quite a rarity in cryptography. This ‘statement’ is quite weird. Is it normal to declare oneself an oppressed minority over a github issue? I feel like we should be a bit more charitable to people who make things. Otherwise nobody will make anything anymor…

I agree. If you don't like it, create a fork? It is open source.

A fork won't tell people that doesn't use it that the original project they forked is dangerous to use. The proxy shouldn't be there in the first place unless it actually worked. I'm not saying i agree (or disagree) with the current issue's writers but this isn't the first time Signal have put their head in the sand when a problem was pointed out to them. It has become a well-known pattern of Moxie's.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#88
post #60
post #52

Earlier quoted context omitted.

What should Signal do about "the IME vulnerability"? They can't possibly defend against compromised phones. Why call it "the IME vulnerability" anyway? This isn't about a vulnerability, we're discussing compromised phones. "IME vulnerability" seems designed to make this sound like a Signal issue, which it isn't.

There are two practical options. 1. Bundle an Open source IME to be used when in incognito mode. 2. Warn users when they switch to incognito that their IME may still be recording the words they type. This isn't just about compromised phones. A 3rd party keyboard doesn't have to respect the incognito flag.

"Important: Keyboards and IME’s can ignore Android’s Incognito Keyboard flag. This Android system flag is a best effort, not a guarantee. It’s important to use a keyboard or IME that you trust. Signal cannot detect or prevent malware on your device."

https://support.signal.org/hc/en-us/articles/360055276112-In...

Sure, the app should say that too, not sure if it does.

Also, the small team of developers can only fix so many things at a time. There's ~50M more users today than a month ago, there's bound to be more work wrt. maintenance which will slow down implementing new features.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#89

Even if I agree with the principles of the anti-censorship people, to be an activist to apply pressure on Signal for features instead of forking and building solutions is suspicious to me. Signal does a great job of frustrating mass interception, which I think was its original point. Inventing new criteria and re-framing their product as inadequate for this scope change as an activism play seems insincere. We can exp…

Signal is open source in the same way pfsense is: it is impossible to actually build everything current from publicly available source.
Post reply on HN