Earlier quoted context omitted.
Tone can often be more important than facts. At one point in my career I had a somewhat public facing role. I made a tough decision that aggravated a user, who decided to send me several death threats. Suddenly that tough decision wasn’t so tough anymore. Any possible resolution was gone. These situations involve people. We aren’t fact machines.
> Tone can often be more important than facts. Exactly: https://www.edge.org/response-detail/27181
A Statement on Recent Events Between Signal and the Anti-Censorship Community
91–100 of 290 posts
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#92Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#93Earlier quoted context omitted.
What should Signal do about "the IME vulnerability"? They can't possibly defend against compromised phones. Why call it "the IME vulnerability" anyway? This isn't about a vulnerability, we're discussing compromised phones. "IME vulnerability" seems designed to make this sound like a Signal issue, which it isn't.
There are two practical options. 1. Bundle an Open source IME to be used when in incognito mode. 2. Warn users when they switch to incognito that their IME may still be recording the words they type. This isn't just about compromised phones. A 3rd party keyboard doesn't have to respect the incognito flag.
Is there a good open source IME? I thought Apple/Google/Microsoft haven't been able to ship a decent one and most people use Baidu's.
> 2. Warn users when they switch to incognito that their IME may still be recording the words they type.
Is a blanket "Your phone might be compromised, we can't help you if it is." warning actually useful? This doesn't really provide the user with any actionable information.
>This isn't just about compromised phones.
This is 100% about compromised phones running malicious keyboard apps.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#94Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#95As I wrote in a comment[1] in their other attention-seeking post[2], they keep talking about "risks" and "vulnerability". There's no exploit or vulnerability here (despite their use of the "PoC" and "responsible disclosure" terms that apply to such things). The fact that you can detect a Signal proxy as a Signal proxy isn't a vulnerability; if it gets censored you're no worse off than you were if that proxy didn't ex…
> The fact that you can detect a Signal proxy as a Signal proxy isn't a vulnerability; if it gets censored you're no worse off than you were if that proxy didn't exist: the main Signal servers are censored in Iran already. Indeed, this is the Signal circumvention proxy working precisely as designed. There is more risk than just "if it gets censored". If the proxy can be detected, so can users of that proxy. If users…
Nah, circumventing a block doesn't imply obfuscation of any kind. Signal's normal server connections are not obfuscated, there is no reasonable expectation that a connection to it via a proxy would be, either.
It seems like people are considering this a vulnerability because accessing Signal (via a proxy or otherwise) in Iran is illegal (as I understand it).
It doesn't seem like people would view this as a vulnerability if that weren't legally the case, so I don't think that points to this being a vulnerability in the software.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#96It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…
I found the behavior and statements around this to be the kind that make the situation worse rather than make it better. They appear to be working against their own goal and may not realize it.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#97The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#98The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…
I don't understand. How would you circumvent censorship of the protocol without obfuscating the protocol?
It seems to me that signal has never claimed to be able to hide that it was being used... until now?
But thanks for posting the thing from Moxie, it does sound quite reasonable.
What would be useful to me and presumably other HN readers is a clear summary of the tech involved, readable by an audience who is technical but not security/circumention experts. Like, the people complaining could be spending time on that, to educate users and developers, instead of doing... whatever they are doing. That seems to have turned into a much less interesting argument about etiquette or something.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#99It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…
"We are the underdogs, doing the real work, and yet unappreciated by many people."
This is the number one reason why people's tone gets sharper and sharper in online "communities", and often they are 100% right.
Most online "communities" devolve into cliques, where the powerful gang up on dissenters. Often the dissenters indeed do a lot of real work behind the scenes, while 80% of the powerful are well spoken parasites.
The powerful then resort to censorship, which escalates the situation.
In this case, who cares about resolving issues "productively" if people's lives are at stake?
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#100Earlier quoted context omitted.
Maybe, but I think that the way these researchers reacted when their criticism wasn't heard doesn't benefit anybody. By ratcheting up the tension and participating in an internet catfight against the Signal team, a net loss occurs for the anti-censorship community. If the Signal team does indeed have a real problem with taking feedback and criticism, a better approach might've been to gather support and enter into lo…
The owners and maintainers of the product get to decide on how to handle issues like this one. But I’m not convinced that an “internet catfight” is a good enough reason for shutting down the conversation completely as it was done. I am aware that it’s totally unfair that signal owners should have to deal with this kind of behavior and not take strong measure like they did... I don’t really know what a good resolution…
> …If you want to discuss anything about circumvention or any other aspects of Signal in a way that is respectful to the rest of the community, please join in on the forums.
https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec...
That does not to me seem like "shutting down the conversation completely".
(As if there is even a way to do that on the internet if you were to try!)