why is instant messaging so important? why can't people use eg an encrypted tor bridge to send and receive encrypted emails? or is a mobile phone cheaper/more practical than a laptop in such a situation?
PGP lacks forward secrecy. E.g. the Iranian government can collect every PGP-message you ever send, and if and when they compromise your private key, they can retrospectively a) decrypt your entire message history, even if you've deleted it from your endpoint b) prove that you're the author of every message, because only your private key can be used to craft the digital signatures. Signal solves both problems. For di…
A Statement on Recent Events Between Signal and the Anti-Censorship Community
151–160 of 290 posts
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#152Offtopic, but what's with all the PGP signatures? One message is literally just "this message is signed with my key", followed by a key and a previous key. Is this a meta joke, automated signing (like signed emails), or am I tripping?!
This is a community with a strong focus on security - they're proving their identity when they post to add their agreement.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#153I think both Moxie and Signal have to be more open to criticism instead of hiding behind either a CoC or a reactive/elitist mindset. They can't eat their cake and have it. If they advise vulnerable groups to use their technology, then they're morally obligated to explore and mitigate any and all issues brought to the table. Signal has lots of funding, so getting "insulted" is not an option — in my view that only appl…
And, of course, someone who is a bit more diplomatic may have better luck getting some of these issues across to the development team in an impartial manner.
Why is the lead Signal developer responding to the public on GitHub and Twitter? It is really helping the project? At this point I'd argue that it's actually hurting the project as we see more of these pointless and public flame wars. Others have pointed out the similarity between this situation and the IME keyboard kerfuffle a couple weeks back.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#154It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…
> rather than resolving the issue productively Unfortunately it's not possible to productively resolve issues with the Signal team, something you can find documented again and again. (My own experience: I had to justify the the user impact of 30+sec freezes on every sent message, confirmed by multiple people. Bug was closed wontfix.) This is a known thing with Moxie and the culture he's created at Signal and it's unf…
They hide behind the shield of being volunteers to justify not addressing or communicating about any user concerns, but they also want to play in the big leagues and have hundreds of millions of users who would otherwise be using other chat platforms.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#155Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#156Earlier quoted context omitted.
> You were blocked because you know that we don't use GH for discussion, but came here anyway and started opening fake PRs so that you could post and harass other people on GH. > …If you want to discuss anything about circumvention or any other aspects of Signal in a way that is respectful to the rest of the community, please join in on the forums. https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... That…
he was banned on the forums too
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#157* Publish the exploit before vendor know it
* Publish the exploit before vendor delivered the patch
* Send their own opinion to every media possible (including ycombinator) without mentioning the full event, and using new account to looks more neutral
* Disrespect other people
* And also have their own "secure" software (v2fly, v2ray, ...)
Okay, looks like we need to have a new definition of "security researcher".
I think Signal did what they should do when communicate with those "trick or treat" guys: treat me with fame, or I'll trick you with a PoC. Is there a better word to shorten this review...? Oh there is: robber.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#158The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…
> Signal has never claimed to be able to hide that it was being used. From their blog post some days ago, I thought it did just that: > Unlike a standard HTTP proxy, connections to the Signal TLS Proxy look just like regular encrypted web traffic. There’s no CONNECT method in a plaintext request to reveal to censors that a proxy is being used. Valid TLS certificates are provisioned for every proxy server, making it m…
Given its broad user base, it wouldn't hurt for Signal to clearly state "we can't keep the fact of the communication private, only the contents".
That would short-circuit attempts to gain notoriety by pointing out obvious facts and calling them vulnerabilities. It's also common sense for anyone who knows their way around a puter, but that's not Signal's median user.
"Privacy" products are a market for lemons, and Signal's public messaging should strive to insulate its users from FUD.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#159Earlier quoted context omitted.
I use AnySoft for English and used to use Trime for Chinese. I now use SwiftKey (not open source) for Pinyin. What activists have been saying - and you should speak to them, not me - is that a warning is better than lulling people into a false sense of security. Again, your phone may not be compromised but your IME could still be malicious. The fact that Moxie and his team won't even engage with the people who origin…
>is that a warning is better than lulling people into a false sense of security. But in the end any such warning is meaningless as it can't possibly be acted upon. >Again, your phone may not be compromised but your IME could still be malicious. If you're using a malicious keyboard app I think it's fair to say that your phone is compromised.
Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community
#160It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…
It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…