Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

201–210 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#201

Earlier quoted context omitted.

> The tone is not more important than the facts. It never is. This is an error software engineers sometimes make. When working with human beings, tone matters. Tone always matters. "Nature cannot be fooled," but presenting facts with the wrong tone can lead to them being discarded, harming the project and/or people involved. You get better outcomes recognizing that people make better decisions when they aren't emotio…

The thing about Mother Nature is her dependability, not only can she not be fooled, she's the firmest conceivable foundation upon which to build. When you're depending upon tone that's never more than a subtle shift of tone from disaster. "Four legs good, Two legs bad" becomes "Four legs good, Two legs better" so easily. I agree with you that tone matters, but I think that's a bad thing, a weakness or vulnerability.…

> not only can she not be fooled, she's the firmest conceivable foundation upon which to build

I agree.

What do we do with that observation when we then observe that human beings care so deeply about how they're being interacted with by other human beings? We are products of nature, after all.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#202

Earlier quoted context omitted.

We must start reading the rules of the online places we visit, as a start, and obeying them. If we don't agree with the rules, don't like "codes of conduct"? Fine, we do not participate there at all. It's their house and we abide by their rules. If we break a rule and it's pointed out, then we apologise and goto 10: read and follow the rules. We do not throw tantrums, we do not cry "censorship! suppression!". We act…

I'm sorry, but we don't read replies longer than 140 characters or that use the word "persecuted". Please create a new account and re-submit your argument in the form of a haiku. Having made rules is not sufficient for those rules to be just. Rules are not themselves authority bearing - nor can one side be upset when they make obnoxious rules and get push back. When you respond to criticism of those rules by deleting…

> Having made rules is not sufficient for those rules to be just

Quite. And if one doesn't think the rules are just, then simply don't play the game. However, rules such as "don't spam an issue", "don't spam a PR", "don't insult others", "please use the forum for this discussion" strike me as being simple, sensible and just rules. Which rules are unjust, in this context?

> Rules are not themselves authority bearing - nor can one side be upset when they make obnoxious rules and get push back.

In a dictatorship - such as a web site forum - the rules are, in fact, authority bearing. Since a user or their content can be removed at the whim of an operator, that authority is proven. This entire dramatic performance has been because the entirety of one "side" is upset when they've been subjected to pushback because they have broken the rules, and the authority of those rules has been effected.

> When you respond to criticism of those rules by deleting the criticisms... well it's clear you are no longer hosting an open forum and instead trying to shut down speech you don't like.

You are conflating what happened here. A user committed malconduct (of the sort that most projects would react badly to) and their offending material was deleted because it was an unhelpful duplicate placed in the wrong forum. Such content can only be deleted because it is...unhelpful, duplicate and in the wrong forum. All that was needed was the discussion moved to where it was expected. GitHub projects are not open forums and the PR was not speech.

> The posters did not use insults, they did not attack the people behind signal

I refute this statement with the following: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... https://community.signalusers.org/t/why-signal-blocked-me-fr... (more a threat than insult, I guess) https://community.signalusers.org/t/why-signal-blocked-me-fr... https://community.signalusers.org/t/why-signal-blocked-me-fr...

> Shutting down a potentially serious security bug

They were not shut down to begin with - they were simply asked to post in the correct forum. Once they started their abusive behaviour they had to be shut down because they couldn't behave themselves.

> This isn't a child's baseball game, this is a situation where lives are at risk. "Sorry, we really tried to put out the fire, but your yard sign made me upset and I had to go write in my journal instead of doing my job."

I'm not sure what you're trying to achieve here, other than proving one of my latter points.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#203
post #159
post #119

Earlier quoted context omitted.

>is that a warning is better than lulling people into a false sense of security. But in the end any such warning is meaningless as it can't possibly be acted upon. >Again, your phone may not be compromised but your IME could still be malicious. If you're using a malicious keyboard app I think it's fair to say that your phone is compromised.

It can be acted on: you can realize that you probably shouldn't talk about everything using Signal despite the person urging you to install it swearing that it's secure. (which was the exact event that was given as a reason to add this: some journalist telling Chinese students(?) to use Signal to talk to them freely)

If your keyboard sends everything you type to the state, and there are no usable alternative keyboards, what realistic actions can you take?

a) type nothing anywhere on your phone: send only emojis, 'gifs', and voice notes?

b) learn to read and write a language with keyboards that don't phone home; or transcribe your written language to an alphabet with a keyboard that doesn't phone home

c) buy an expensive phone with an OS supplied keyboard that doesn't phone home (assuming such phones exist?)

d) learn Android development and input method theory and build a new keyboard for yourself

Are any of these actions actually feasible for the general population?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#204
post #199

Earlier quoted context omitted.

> there isn't a currently easily available obvious way to have private secure conversations. Ricochet[1] works really well. It uses Tor hidden services to communicate. Your Ricochet ID is your onion address. To add a contact, you input their Ricochet ID and a short message, and Ricochet connects to their onion address and sends a contact request. If the contact request is accepted then you'll each show up as a contac…

Doesn't the security of Tor depend on the proposition "Surely my opponent would never operate a bunch of exit nodes"? That has always been my impression, and it seems like a problem when your opponent is a state actor.

Hidden services don't use exit nodes.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#205

Earlier quoted context omitted.

> rather than resolving the issue productively Unfortunately it's not possible to productively resolve issues with the Signal team, something you can find documented again and again. (My own experience: I had to justify the the user impact of 30+sec freezes on every sent message, confirmed by multiple people. Bug was closed wontfix.) This is a known thing with Moxie and the culture he's created at Signal and it's unf…

FWIW, my experience with Signal sadly confirms this. There’s a critical issue for years with the iOS app that there’s no way to backup or otherwise extract your chat logs (contrary to the usual behavior of iOS apps which automatically backup to your computer or iCloud), no warning of this when you first install, and almost no communication from developers on the subject for years despite huge numbers of complaints. T…

> They hide behind the shield of being volunteers to justify not addressing or communicating about any user concerns

I agree this lacking feature is an important matter, but the Signal team have explained why the iOS app doesn't have a backup facility. Saying there's "no communication" is not true.

I'm not sure what the purpose of saying "hiding behind the shield of being volunteers" is. Are you inferring they're lying and that they simply don't care? Perhaps that they're raking in their paycheck whilst leaving the volunteers to martyr themselves against complaining users? Neither are helpful accusations.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#206
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

Why does it need your phone number? Seems pretty weird for a “secure” program. And why does it use AWS? Isn’t that subject to all kinds of privacy risks including National Security Letters?

Why isn’t Signal just a Free and open source, infrastructure-less p2p solution? Maybe the goal isn’t really security or privacy after all...

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#207

Sorry, where's the vulnerability in _signal_ here? The TLS proxy is not sufficient. Marlinspike addressed this in their incredibly childish PR [0]: >As we said in the blog post, it is nothing more than a simple TLS proxy as an interim solution to help people while we're working on something more scalable and more robust I'm not so sure they made it clear they were working on another solution in that blog post [1], bu…

Why is Signal positioning itself as a solution when Rosenfeld admits it’s not ready?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#208
post #21
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…

Telegram?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#209

Earlier quoted context omitted.

>2021-02-06 12:00 @DuckSoft sended a pull request that adds the PoC to Signal TLS proxy's repository. This is inappropriate. Pulling in a random PoC to the repo is not how you’re supposed to use PRs. Issues exist for this purpose, but theirs had already been removed. >It has since been deleted [...] A repost by @U-v-U was later closed and locked. Reposting the inappropriate PR is also inappropriate.

I do not find either of these to be inappropriate.

They are, along with all of the misbehaviour this group is perpetrating. Acting in this way well result in nothing but derision and bans from any organisation (and prospective employer, for that matter) because it is childish and unproductive.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#210

What interests me more, is Signal's principal stance about censorship. If non-tech people ever come to Signal in numbers, the moderation problem will inevitably arise. Would they censor things that we currently have public consensus about? Like CP, terrorism etc.

I doubt that this will ever be an issue, because Signal is a messaging application, on which censoring/moderation is thus irrelevant. It's not a social network (contrary to e.g. Telegram which has tons of SNS features). Let's hope it will remain just a messaging/videocall app.

This ignores demonstrated harm* from the combination of human behavior and low-effort large-scale communications.

* https://en.wikipedia.org/wiki/Indian_WhatsApp_lynchings

Post reply on HN