Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

191–200 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#191

Earlier quoted context omitted.

Shouldn't Signal then also warn or refuse to work on Android versions with known vulnerabilities? Or if there are apps installed on the device with the accessibility permission? Where would you say the line should be drawn?

I feel like this is somewhat disingenuous. IME keylogging is a known, serious, and frequently exploited issue that affects a substantial portion of Signal users. Signal's "Incognito Keyboard" setting didn't mention that the flag can be ignored, which was misleading and dangerous. But yes, warning about accessibility settings if there's evidence of that being an attack vector seems like a good idea. I don't know about…

> frequently exploited

Do you happen to have a source for this? There’s lots of speculation out there, but I’ve never seen anyone claiming to have proof of this being frequently exploited.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#192

Do I have it correct that the anti-censorship team refused to take the trivial step just to copy/paste their original issue on a forum as suggested by the project?

If you see their timeline and screenshots here [0], it says they weren't allowed to post in the forum.

[0] https://github.com/net4people/bbs/issues/60

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#193
post #109

Earlier quoted context omitted.

That was only added 19 days ago - after months of people (politely) asking for it to be acknowledged as a serious concern. https://github.com/signalapp/Signal-Android/commit/0a29ffcf4...

Shouldn't Signal then also warn or refuse to work on Android versions with known vulnerabilities? Or if there are apps installed on the device with the accessibility permission? Where would you say the line should be drawn?

In fact it might not be such a bad idea to warn about those things, and perhaps a short list of other possibly privacy-compromising settings

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#194

Earlier quoted context omitted.

I think that it was you who replied to the wrong comment. I did not see any evidence of them talking about any inappropriate behavior of their own nor did I see them saying anything inappropriate in the quote that you posted.

You have to be pretty thick if you can’t understand how those pull requests were inappropriate.

You have to be pretty thick if you can’t understand what my post was about.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#195

Earlier quoted context omitted.

I do not see any evidence of this in said quote.

>2021-02-06 12:00 @DuckSoft sended a pull request that adds the PoC to Signal TLS proxy's repository. This is inappropriate. Pulling in a random PoC to the repo is not how you’re supposed to use PRs. Issues exist for this purpose, but theirs had already been removed. >It has since been deleted [...] A repost by @U-v-U was later closed and locked. Reposting the inappropriate PR is also inappropriate.

I do not find either of these to be inappropriate.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#196
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

[deleted]

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#197

Do I have it correct that the anti-censorship team refused to take the trivial step just to copy/paste their original issue on a forum as suggested by the project?

I'm not 100% sure I'm right, but I think that at some point they were denied access to the forum because of spam protections or moderation.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#198

Earlier quoted context omitted.

That's a fair point and I agree with you. Something I've been wondering as of lately, what can we (as a society) do to move off the edge of high emotions? I feel as if it's a common theme anywhere I look.

We must start reading the rules of the online places we visit, as a start, and obeying them. If we don't agree with the rules, don't like "codes of conduct"? Fine, we do not participate there at all. It's their house and we abide by their rules. If we break a rule and it's pointed out, then we apologise and goto 10: read and follow the rules. We do not throw tantrums, we do not cry "censorship! suppression!". We act…

I'm sorry, but we don't read replies longer than 140 characters or that use the word "persecuted". Please create a new account and re-submit your argument in the form of a haiku.

Having made rules is not sufficient for those rules to be just. Rules are not themselves authority bearing - nor can one side be upset when they make obnoxious rules and get push back. When you respond to criticism of those rules by deleting the criticisms... well it's clear you are no longer hosting an open forum and instead trying to shut down speech you don't like.

The posters did not use insults, they did not attack the people behind signal - they pointed out that the statement regarding the proxies was false (which it factually was) and that the circumvention that Signal gave was likely insufficient for most users. Shutting down a potentially serious security bug because it's in the wrong spot or because you don't like the tone is bullshit - it tell me you as a person care more about tone policing then keeping your users safe. When you're doing battle against nation-states who like to jail their dissidents, you don't get to reap half-successes.

This isn't a child's baseball game, this is a situation where lives are at risk. "Sorry, we really tried to put out the fire, but your yard sign made me upset and I had to go write in my journal instead of doing my job."

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#199
post #21

Earlier quoted context omitted.

It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…

> there isn't a currently easily available obvious way to have private secure conversations. Ricochet[1] works really well. It uses Tor hidden services to communicate. Your Ricochet ID is your onion address. To add a contact, you input their Ricochet ID and a short message, and Ricochet connects to their onion address and sends a contact request. If the contact request is accepted then you'll each show up as a contac…

Doesn't the security of Tor depend on the proposition "Surely my opponent would never operate a bunch of exit nodes"? That has always been my impression, and it seems like a problem when your opponent is a state actor.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#200

Earlier quoted context omitted.

>2021-02-06 12:00 @DuckSoft sended a pull request that adds the PoC to Signal TLS proxy's repository. This is inappropriate. Pulling in a random PoC to the repo is not how you’re supposed to use PRs. Issues exist for this purpose, but theirs had already been removed. >It has since been deleted [...] A repost by @U-v-U was later closed and locked. Reposting the inappropriate PR is also inappropriate.

I do not find either of these to be inappropriate.

How is reposting content that was previously removed by maintainers not inappropriate? Signal made it very clear that this stuff should be posted on their community forums, not github.
Post reply on HN