Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

181–190 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#181

Earlier quoted context omitted.

They're banning the other party for their abusive language and behaviour, for their unsubstantiated, bad-faith claims of suppression and for misusing project resources. On top of the fact that they're not listening to why their assertions are incorrect. Any party acting in such a belligerent, infantile manner is going to be banned since they have proven they cannot act like grown-ups in a grown-up setting.

That's a fair point and I agree with you. Something I've been wondering as of lately, what can we (as a society) do to move off the edge of high emotions? I feel as if it's a common theme anywhere I look.

We must start reading the rules of the online places we visit, as a start, and obeying them. If we don't agree with the rules, don't like "codes of conduct"? Fine, we do not participate there at all.

It's their house and we abide by their rules.

If we break a rule and it's pointed out, then we apologise and goto 10: read and follow the rules. We do not throw tantrums, we do not cry "censorship! suppression!".

We act in good faith: if we post a thread, open an issue, submit a PR, and it is closed, then we do not simply repeat our action. Whether we agree with the closure or not, repeating is an attempt at evasion and a smack in the face of those running the place. Either of these two behaviours then invite us to be banned, because we have acted in bad faith.

We do not immediately and vocally assume that an act we don't like is a personal attack against ourselves or our values. If our post is "hidden by the community", this does does not mean "the leadership of the project is orchestrating an agenda against us". It means our peers have found our conduct distasteful and is a very loud alarm that we must heed: that we have behaved outside of the expected conduct and our peers found it distasteful, unhelpful, insulting. If a web site algorithm has prevented us from posting a link, an image because our account is new or it has triggered anti-spam measures, we do not post elsewhere about how we're being persecuted.

We invite like-minded people to join the discussion when they have innovative ideas, when they can add material to a discussion that has not yet been supplied, an angle that has not been addressed, or a concept that has been misunderstood. We never ping our friends to jump on our bandwagon, shouting the same things over and over again. Perhaps if a concern is dismissed as an outside, then more voices can be constructive, but they must conduct themselves with civility and be particularly aware that they need to add to the discussion, not to add pressure.

If a counterpoint is given to something we passionately believe in, then to discuss is to use logic and data to refute it. In the ideal, we ask ourselves to fight for this counterpoint: perhaps it is entirely valid? What we must refrain from is reading a fair and polite counterpoint and immediately treating it as an attack, a dismissal. This prompts a counter-attack and we are no longer discussing - we are now detracting from the point. When we make our issue or improvement a negative it reflects back upon us. Who wishes to discuss with a party that cannot cope with rational disagreement? In addition, we must resist the urge to simply exaggerate our cause: to state an incorrect point more loudly does not make it correct, it just antagonises those who disagree. Those who we are trying to see our reasons, our solutions, or problems.

Once we have broken the rules, assumed and publicised bad faith, breached expected conduct, ignored the ire of our peers, evaded bans, repeated actions which were turned down, called on our friends to flame and troll, replied to constructive criticism with louder voices, manipulated the conversation with hyperbole and outright refused to listen to the possibility we may be wrong...then we hold a beacon above our heads, advertising that we are incapable of joining a rational debate and seek not to improve anything but only be told we are right and righteous.

I say this not to you, but to answer your question: if anyone reads what has transpired in this matter, and then asks your question, they need to very deeply analyse their behaviour because it is unacceptable in any civilised society.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#182
post #21

Earlier quoted context omitted.

It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…

> The tone is not more important than the facts. It never is. This is an error software engineers sometimes make. When working with human beings, tone matters. Tone always matters. "Nature cannot be fooled," but presenting facts with the wrong tone can lead to them being discarded, harming the project and/or people involved. You get better outcomes recognizing that people make better decisions when they aren't emotio…

The thing about Mother Nature is her dependability, not only can she not be fooled, she's the firmest conceivable foundation upon which to build. When you're depending upon tone that's never more than a subtle shift of tone from disaster. "Four legs good, Two legs bad" becomes "Four legs good, Two legs better" so easily.

I agree with you that tone matters, but I think that's a bad thing, a weakness or vulnerability. We should take "tone matters" into consideration the same way we'd take "OCSP without stapling results in a query to the CA for each leaf certificate examined, thereby harming privacy" into consideration. Can we prevent it? Can we mitigate the resulting harms? We definitely shouldn't celebrate it.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#183
post #84

why is instant messaging so important? why can't people use eg an encrypted tor bridge to send and receive encrypted emails? or is a mobile phone cheaper/more practical than a laptop in such a situation?

PGP lacks forward secrecy. E.g. the Iranian government can collect every PGP-message you ever send, and if and when they compromise your private key, they can retrospectively a) decrypt your entire message history, even if you've deleted it from your endpoint b) prove that you're the author of every message, because only your private key can be used to craft the digital signatures. Signal solves both problems. For di…

>decrypt your entire message history, even if you've deleted it from your endpoint

But how many people actually delete their old messages? If they don't then forward secrecy doesn't help. They get your messages when they get you key material.

Encrypted instant messaging is inherently less secure than something that can be performed offline like encrypted email because the key information is exposed all the time. So it is much less likely that you will have your key information exposed in the first place with encrypted email. An instant messenger on a phone can normally be defeated simply by grabbing your unlocked phone from your hand and scrolling though your old messages.

>prove that you're the author of every message, because only your private key can be used to craft the digital signatures.

A private key that in the case of, say, PGP does not have to be associated with any particular identity at all. Also, PGP offers actual deniability by simply not signing the message in the first place while, say, Signal only offers a particularly weak version of forgeability[1] which is problematic in general.

[1] https://articles.59.ca/doku.php?id=pgpfan:repudiability#forg... (see Forgeablity Light)

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#184
post #177

Earlier quoted context omitted.

This has nothing to do with my post.

Of course it does, unless you were replying to the wrong comment in the first place. What was it you did not see any evidence of?

I think that it was you who replied to the wrong comment. I did not see any evidence of them talking about any inappropriate behavior of their own nor did I see them saying anything inappropriate in the quote that you posted.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#185
post #177

Earlier quoted context omitted.

Of course it does, unless you were replying to the wrong comment in the first place. What was it you did not see any evidence of?

I think that it was you who replied to the wrong comment. I did not see any evidence of them talking about any inappropriate behavior of their own nor did I see them saying anything inappropriate in the quote that you posted.

You have to be pretty thick if you can’t understand how those pull requests were inappropriate.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#186
post #109

Earlier quoted context omitted.

That was only added 19 days ago - after months of people (politely) asking for it to be acknowledged as a serious concern. https://github.com/signalapp/Signal-Android/commit/0a29ffcf4...

Shouldn't Signal then also warn or refuse to work on Android versions with known vulnerabilities? Or if there are apps installed on the device with the accessibility permission? Where would you say the line should be drawn?

There's some missing nuance here. Naomi Wu documented this much better than my summary, but the short version is that you need an IME keyboard for Chinese text entry, and the only one that's any good (and so, has a huge install base) is an application created and owned by a corporation with strong ties to the Chinese government.

When there's a security rake-in-a-darkened-shed that a large fraction of your users will step on, with a demonstrable risk to their life and liberty, I think reasonable people can agree that we're standing on the "hey, maybe we should at least pop a dialog about this" side of the line.

It took Moxie well over a year to come to the same conclusion, and then in a really lazy way as documented by the commit upthread. I'm starting to see him as a particularly unreasonable person.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#187
post #14

Earlier quoted context omitted.

They even talk about their own inappropriate behaviour in this statement: >2021-02-06 12:00 @DuckSoft sended a pull request that adds the PoC to Signal TLS proxy's repository. It has since been deleted and both @DuckSoft and @studentmain were banned by the Signal organization on GitHub in the afternoon. A repost by @U-v-U was later closed and locked.

I do not see any evidence of this in said quote.

>2021-02-06 12:00 @DuckSoft sended a pull request that adds the PoC to Signal TLS proxy's repository.

This is inappropriate. Pulling in a random PoC to the repo is not how you’re supposed to use PRs. Issues exist for this purpose, but theirs had already been removed.

>It has since been deleted [...] A repost by @U-v-U was later closed and locked.

Reposting the inappropriate PR is also inappropriate.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#188

Earlier quoted context omitted.

Maybe, but I think that the way these researchers reacted when their criticism wasn't heard doesn't benefit anybody. By ratcheting up the tension and participating in an internet catfight against the Signal team, a net loss occurs for the anti-censorship community. If the Signal team does indeed have a real problem with taking feedback and criticism, a better approach might've been to gather support and enter into lo…

At this point, a clear demonstration of how Signal's current design fails to keep users safe forwarded to the New York Times, WaPo, and Fox News would be a lot more valuable than shitposting via the Github PR system.

The New York Times published an article just a week ago claiming Signal was "problematic" for affording anonymity. I would assume WaPo feels the same way. No benefit in forwarding to either institution.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#189
post #109

Earlier quoted context omitted.

That was only added 19 days ago - after months of people (politely) asking for it to be acknowledged as a serious concern. https://github.com/signalapp/Signal-Android/commit/0a29ffcf4...

Shouldn't Signal then also warn or refuse to work on Android versions with known vulnerabilities? Or if there are apps installed on the device with the accessibility permission? Where would you say the line should be drawn?

I feel like this is somewhat disingenuous.

IME keylogging is a known, serious, and frequently exploited issue that affects a substantial portion of Signal users. Signal's "Incognito Keyboard" setting didn't mention that the flag can be ignored, which was misleading and dangerous.

But yes, warning about accessibility settings if there's evidence of that being an attack vector seems like a good idea. I don't know about unsupported Android versions.

https://twitter.com/RealSexyCyborg/status/134995902394088652...

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#190
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

A lot of people get confused about this with p2p type stuff. At ZeroTier we constantly have to explain to people that it is not Tor, and we get bug reports about how "people can see my IP!" Of course they can see your IP. You are communicating directly with them.

End-to-end encryption means content privacy but not necessarily meta-data privacy or anonymity.

Post reply on HN