Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

111–120 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#111
post #78

Even if I agree with the principles of the anti-censorship people, to be an activist to apply pressure on Signal for features instead of forking and building solutions is suspicious to me. Signal does a great job of frustrating mass interception, which I think was its original point. Inventing new criteria and re-framing their product as inadequate for this scope change as an activism play seems insincere. We can exp…

> instead of forking and building solutions What would you fork? The signal server code that hasn’t been updated in almost a year[1]? If that is truly the same code that we use with signal today, would your fork work with this same network? Or would it be it’s own 1-server network all alone? [1]: https://github.com/signalapp/Signal-Server

I think we should ask this guy how he build it ?

https://www.reddit.com/r/signal/comments/l5dug8/signal_serve...

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#112
post #71

Earlier quoted context omitted.

Tone can often be more important than facts. At one point in my career I had a somewhat public facing role. I made a tough decision that aggravated a user, who decided to send me several death threats. Suddenly that tough decision wasn’t so tough anymore. Any possible resolution was gone. These situations involve people. We aren’t fact machines.

> Tone can often be more important than facts. Exactly: https://www.edge.org/response-detail/27181

this was very helpful. Never heard of 'Russell conjugation' before.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#113
post #4

Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!

This threw me off too. PGP in these contexts isn't a proof of any meaningful properties, and reads mostly as theater/additional drama.

Using a non-repudiatable signing system to promote claims about how a proxy is easy to detect comes off as very hinky to me, to use a technical term.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#114
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

> rather than resolving the issue productively Unfortunately it's not possible to productively resolve issues with the Signal team, something you can find documented again and again. (My own experience: I had to justify the the user impact of 30+sec freezes on every sent message, confirmed by multiple people. Bug was closed wontfix.) This is a known thing with Moxie and the culture he's created at Signal and it's unf…

But even then, there's really no point in trolling the PR section of Github besides griefing. Just fork the thing and make a better Signal if you believe so harshly that there's no hope with Moxie at the helm.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#115
post #41

Earlier quoted context omitted.

The owners and maintainers of the product get to decide on how to handle issues like this one. But I’m not convinced that an “internet catfight” is a good enough reason for shutting down the conversation completely as it was done. I am aware that it’s totally unfair that signal owners should have to deal with this kind of behavior and not take strong measure like they did... I don’t really know what a good resolution…

> You were blocked because you know that we don't use GH for discussion, but came here anyway and started opening fake PRs so that you could post and harass other people on GH. > …If you want to discuss anything about circumvention or any other aspects of Signal in a way that is respectful to the rest of the community, please join in on the forums. https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... That…

Like I said, it’s totally upto the project owners to decide how they want to interface with the community. But the concrete result of that decision was just to move the discussion to a GitHub issue on another repo.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#116
post #65

Earlier quoted context omitted.

I think we are both talking about tone. While you are saying that expressing emotions and the drama is important in a discussion over Signals' future, I believe that such conduct only drives a wedge into it. These issues are emotional and affect important freedoms, but while expressing them is important doing it in such a high-profile, damaging way can only bruise egos and create even more tension. Instead, both part…

How exactly do both parties sit down to discuss their grievances when the incumbent party is clearly banning the party with a different perspective?

They're banning the other party for their abusive language and behaviour, for their unsubstantiated, bad-faith claims of suppression and for misusing project resources. On top of the fact that they're not listening to why their assertions are incorrect.

Any party acting in such a belligerent, infantile manner is going to be banned since they have proven they cannot act like grown-ups in a grown-up setting.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#117
post #30

Earlier quoted context omitted.

Exactly, according to NGO's people get lashed and jailed for online activities. After Signal has been blocked being detected could actually endanger peoples life. https://freedomhouse.org/country/iran/freedom-net/2019 https://freedomhouse.org/country/iran/freedom-net/2020

Was the better solution here that signal does nothing?

They could have prioritized the dev (or scheduled the release/deployment):

1/ integrate some Tor-like system, and 2/ the amateur proxies feature

Actually they can still do it, by deactivating and putting the amateur proxies feature in standby temporarily while the Tor-like system is being implemented.

The very least they can do is not denying that, now they have already deployed 2/, developing 1/ is becoming an emergency.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#118
I think both Moxie and Signal have to be more open to criticism instead of hiding behind either a CoC or a reactive/elitist mindset.

They can't eat their cake and have it. If they advise vulnerable groups to use their technology, then they're morally obligated to explore and mitigate any and all issues brought to the table.

Signal has lots of funding, so getting "insulted" is not an option — in my view that only applies to FOSS maintainers who work for free.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#119
post #102
post #93

Earlier quoted context omitted.

>Bundle an Open source IME to be used when in incognito mode Is there a good open source IME? I thought Apple/Google/Microsoft haven't been able to ship a decent one and most people use Baidu's. > 2. Warn users when they switch to incognito that their IME may still be recording the words they type. Is a blanket "Your phone might be compromised, we can't help you if it is." warning actually useful? This doesn't really…

I use AnySoft for English and used to use Trime for Chinese. I now use SwiftKey (not open source) for Pinyin. What activists have been saying - and you should speak to them, not me - is that a warning is better than lulling people into a false sense of security. Again, your phone may not be compromised but your IME could still be malicious. The fact that Moxie and his team won't even engage with the people who origin…

>is that a warning is better than lulling people into a false sense of security.

But in the end any such warning is meaningless as it can't possibly be acted upon.

>Again, your phone may not be compromised but your IME could still be malicious.

If you're using a malicious keyboard app I think it's fair to say that your phone is compromised.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#120
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

> Signal has never claimed to be able to hide that it was being used.

From their blog post some days ago, I thought it did just that:

> Unlike a standard HTTP proxy, connections to the Signal TLS Proxy look just like regular encrypted web traffic. There’s no CONNECT method in a plaintext request to reveal to censors that a proxy is being used. Valid TLS certificates are provisioned for every proxy server, making it more difficult for censors to fingerprint the traffic than it would be if static self-signed certificates were used instead. In short, everything is designed to blend into the background as much as possible.

They should probably make that post less reassuring and list the exact risks.

https://signal.org/blog/help-iran-reconnect/

Post reply on HN