Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

101–110 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#101
Sorry, where's the vulnerability in _signal_ here?

The TLS proxy is not sufficient. Marlinspike addressed this in their incredibly childish PR [0]:

>As we said in the blog post, it is nothing more than a simple TLS proxy as an interim solution to help people while we're working on something more scalable and more robust

I'm not so sure they made it clear they were working on another solution in that blog post [1], but it's a known problem that proxies can be fingered. I don't see the value add here and I can't read this as anything other than "boo hoo, we weren't listened to" (which is not surprising, given their behavior)

[0]: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec...

[1]: https://signal.org/blog/help-iran-reconnect/

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#102
post #93
post #60

Earlier quoted context omitted.

There are two practical options. 1. Bundle an Open source IME to be used when in incognito mode. 2. Warn users when they switch to incognito that their IME may still be recording the words they type. This isn't just about compromised phones. A 3rd party keyboard doesn't have to respect the incognito flag.

>Bundle an Open source IME to be used when in incognito mode Is there a good open source IME? I thought Apple/Google/Microsoft haven't been able to ship a decent one and most people use Baidu's. > 2. Warn users when they switch to incognito that their IME may still be recording the words they type. Is a blanket "Your phone might be compromised, we can't help you if it is." warning actually useful? This doesn't really…

I use AnySoft for English and used to use Trime for Chinese. I now use SwiftKey (not open source) for Pinyin.

What activists have been saying - and you should speak to them, not me - is that a warning is better than lulling people into a false sense of security.

Again, your phone may not be compromised but your IME could still be malicious.

The fact that Moxie and his team won't even engage with the people who originally brought this up is somewhat vexing.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#103
post #31

Moxie - and the Signal team - seems to have a real issue taking feedback from outside experts. See the way he has been completely dismissive of the IME vulnerability highlighted by Naomi Wu and others. I remember back when it was TextSecure - I tried to raise some usability and security issues. First I was ignored, then dismissed, then - a few years later - they implemented some of the changes. I still use Signal. Bu…

[deleted]

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#104
post #59

Elon Musk should tweet about Matrix. Signal team seems completely irresponsible here. Censorship in countries where this app could help puts opponents lives at risk and already led to executions.

+1 for Matrix. Signal is a honeypot.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#107
post #91
post #71

Earlier quoted context omitted.

> Tone can often be more important than facts. Exactly: https://www.edge.org/response-detail/27181

Good read. Formalizes what Fox News etc. do to everything they spout out.

the entire mainstream media no longer just reports on the facts, but now has to in the reporters opinions and feelings too...

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#108
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

> Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. I don't understand. How would you circumvent censorship of the protocol without obfuscating the protocol? It seems to me that signal has never claimed to be able to hide that it was being used... until now? But thanks for posting the thing from Moxie, it does sou…

Reading the config in the TLS repo, it seems to me that the censorship is at the domain level.

So I guess they're trying to pop up as many endpoints as possible to circumvent that.

I don't know the details about the network block though, so I might be mistaken. But the nginx config in that repo is purely a TLS proxy. Nothing magical happening there at all, just an entrance node to the main signal network

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#109
post #88
post #60

Earlier quoted context omitted.

There are two practical options. 1. Bundle an Open source IME to be used when in incognito mode. 2. Warn users when they switch to incognito that their IME may still be recording the words they type. This isn't just about compromised phones. A 3rd party keyboard doesn't have to respect the incognito flag.

"Important: Keyboards and IME’s can ignore Android’s Incognito Keyboard flag. This Android system flag is a best effort, not a guarantee. It’s important to use a keyboard or IME that you trust. Signal cannot detect or prevent malware on your device." https://support.signal.org/hc/en-us/articles/360055276112-In... Sure, the app should say that too, not sure if it does. Also, the small team of developers can only fix s…

That was only added 19 days ago - after months of people (politely) asking for it to be acknowledged as a serious concern.

https://github.com/signalapp/Signal-Android/commit/0a29ffcf4...

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#110
post #30

Yes, indeed, I'm baffled that the people from Signal who dismiss these critics think that the only people possibly "endangered" are the proxy owners. It does not cross their mind that the users are immediately endangered too. They don't understand that it is very easy to identify the proxy users once the Signal proxies themselves are detected? I'm here replying on the top level to this comment, because I think this i…

Exactly, according to NGO's people get lashed and jailed for online activities. After Signal has been blocked being detected could actually endanger peoples life. https://freedomhouse.org/country/iran/freedom-net/2019 https://freedomhouse.org/country/iran/freedom-net/2020

Was the better solution here that signal does nothing?
Post reply on HN