Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

91–100 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#91
post #71

Earlier quoted context omitted.

Tone can often be more important than facts. At one point in my career I had a somewhat public facing role. I made a tough decision that aggravated a user, who decided to send me several death threats. Suddenly that tough decision wasn’t so tough anymore. Any possible resolution was gone. These situations involve people. We aren’t fact machines.

> Tone can often be more important than facts. Exactly: https://www.edge.org/response-detail/27181

Good read. Formalizes what Fox News etc. do to everything they spout out.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#92
post #4

Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!

Here's how moxie feels about people using PGP. https://moxie.org/2015/02/24/gpg-and-me.html

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#93
post #60
post #52

Earlier quoted context omitted.

What should Signal do about "the IME vulnerability"? They can't possibly defend against compromised phones. Why call it "the IME vulnerability" anyway? This isn't about a vulnerability, we're discussing compromised phones. "IME vulnerability" seems designed to make this sound like a Signal issue, which it isn't.

There are two practical options. 1. Bundle an Open source IME to be used when in incognito mode. 2. Warn users when they switch to incognito that their IME may still be recording the words they type. This isn't just about compromised phones. A 3rd party keyboard doesn't have to respect the incognito flag.

>Bundle an Open source IME to be used when in incognito mode

Is there a good open source IME? I thought Apple/Google/Microsoft haven't been able to ship a decent one and most people use Baidu's.

> 2. Warn users when they switch to incognito that their IME may still be recording the words they type.

Is a blanket "Your phone might be compromised, we can't help you if it is." warning actually useful? This doesn't really provide the user with any actionable information.

>This isn't just about compromised phones.

This is 100% about compromised phones running malicious keyboard apps.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#94
Signal seems like a magnet for toxic avengers. It's really unfortunate because every negative interaction has a cost. It doesn't matter how valid what "net4people" is claiming because how they're saying it is unacceptable. The Signal team has its reasons for not adopting their recommendations. That's enough.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#95
post #54
post #3

As I wrote in a comment[1] in their other attention-seeking post[2], they keep talking about "risks" and "vulnerability". There's no exploit or vulnerability here (despite their use of the "PoC" and "responsible disclosure" terms that apply to such things). The fact that you can detect a Signal proxy as a Signal proxy isn't a vulnerability; if it gets censored you're no worse off than you were if that proxy didn't ex…

> The fact that you can detect a Signal proxy as a Signal proxy isn't a vulnerability; if it gets censored you're no worse off than you were if that proxy didn't exist: the main Signal servers are censored in Iran already. Indeed, this is the Signal circumvention proxy working precisely as designed. There is more risk than just "if it gets censored". If the proxy can be detected, so can users of that proxy. If users…

> What is clear, is that this is a vulnerability. Circumventing blocks tends to be illegal. If we want to help people circumvent such blocks, we need to help them from being caught as well.

Nah, circumventing a block doesn't imply obfuscation of any kind. Signal's normal server connections are not obfuscated, there is no reasonable expectation that a connection to it via a proxy would be, either.

It seems like people are considering this a vulnerability because accessing Signal (via a proxy or otherwise) in Iran is illegal (as I understand it).

It doesn't seem like people would view this as a vulnerability if that weren't legally the case, so I don't think that points to this being a vulnerability in the software.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#96
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

I'm in the process of re-reading the book, How To Win Friends and Influence People. It's an older book but the discussion on human behavior and utilizing that to influence people is still useful.

I found the behavior and statements around this to be the kind that make the situation worse rather than make it better. They appear to be working against their own goal and may not realize it.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#97
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

[deleted]

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#98
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

> Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol.

I don't understand. How would you circumvent censorship of the protocol without obfuscating the protocol?

It seems to me that signal has never claimed to be able to hide that it was being used... until now?

But thanks for posting the thing from Moxie, it does sound quite reasonable.

What would be useful to me and presumably other HN readers is a clear summary of the tech involved, readable by an audience who is technical but not security/circumention experts. Like, the people complaining could be spending time on that, to educate users and developers, instead of doing... whatever they are doing. That seems to have turned into a much less interesting argument about etiquette or something.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#99
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

Look at this statement, it says it all:

"We are the underdogs, doing the real work, and yet unappreciated by many people."

This is the number one reason why people's tone gets sharper and sharper in online "communities", and often they are 100% right.

Most online "communities" devolve into cliques, where the powerful gang up on dissenters. Often the dissenters indeed do a lot of real work behind the scenes, while 80% of the powerful are well spoken parasites.

The powerful then resort to censorship, which escalates the situation.

In this case, who cares about resolving issues "productively" if people's lives are at stake?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#100
post #41

Earlier quoted context omitted.

Maybe, but I think that the way these researchers reacted when their criticism wasn't heard doesn't benefit anybody. By ratcheting up the tension and participating in an internet catfight against the Signal team, a net loss occurs for the anti-censorship community. If the Signal team does indeed have a real problem with taking feedback and criticism, a better approach might've been to gather support and enter into lo…

The owners and maintainers of the product get to decide on how to handle issues like this one. But I’m not convinced that an “internet catfight” is a good enough reason for shutting down the conversation completely as it was done. I am aware that it’s totally unfair that signal owners should have to deal with this kind of behavior and not take strong measure like they did... I don’t really know what a good resolution…

> You were blocked because you know that we don't use GH for discussion, but came here anyway and started opening fake PRs so that you could post and harass other people on GH.

> …If you want to discuss anything about circumvention or any other aspects of Signal in a way that is respectful to the rest of the community, please join in on the forums.

https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec...

That does not to me seem like "shutting down the conversation completely".

(As if there is even a way to do that on the internet if you were to try!)

Post reply on HN