Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

211–220 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#211

Earlier quoted context omitted.

I agree. If you don't like it, create a fork? It is open source.

Signal discourages third-party clients. https://community.signalusers.org/t/how-to-get-signal-apks-o...

Fork the client and the server then. Yes, I've seen from other comments that the server repo is apparently rarely updated. If that's significant to getting a working client, probably fork the client from earlier; most likely, it you get a significant number of users, you're going to need to get really familiar with the server environment anyway.

Running a server environment is probably time consuming ane expensive, but that's kind of why the people running the servers get to set the rules.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#212
post #206
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

Why does it need your phone number? Seems pretty weird for a “secure” program. And why does it use AWS? Isn’t that subject to all kinds of privacy risks including National Security Letters? Why isn’t Signal just a Free and open source, infrastructure-less p2p solution? Maybe the goal isn’t really security or privacy after all...

It seems like the phone number is used mainly for matching you up to your contacts, and secondarily used for a first level of authentication. Signal has always encouraged independent verification of folks' public keys for sensitive communication.

Whether or not AWS is risky, I don't think signal has any increased risk hosting their infrastructure on it vs. any other service. The whole point is that comms are end-to-end encrypted from handset to handset, and so any data in Amazon's hands is encrypted.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#213
post #199

Earlier quoted context omitted.

Doesn't the security of Tor depend on the proposition "Surely my opponent would never operate a bunch of exit nodes"? That has always been my impression, and it seems like a problem when your opponent is a state actor.

Hidden services don't use exit nodes.

You could first charitably strengthen their argument by silently correcting “exit nodes” to “nodes”. The core point stands.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#214
post #82

Earlier quoted context omitted.

Why does her view on something completely unrelated matter to the facts? Why are you even comping through her Twitter history? This is clearly a personal attack "just because". Disgusting.

[flagged]

We've banned this account for using HN primarily for political and nationalistic battle and ignoring our many requests to stop. This is standard HN policy. Regardless of which sides you're battling for or against, it nukes this site for the curious conversation it's supposed to exist for.

If you don't want to be banned, you're welcome to email hn@ycombinator.com and give us reason to believe that you'll follow the rules in the future.

https://news.ycombinator.com/newsguidelines.html

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#215
post #203
post #159

Earlier quoted context omitted.

It can be acted on: you can realize that you probably shouldn't talk about everything using Signal despite the person urging you to install it swearing that it's secure. (which was the exact event that was given as a reason to add this: some journalist telling Chinese students(?) to use Signal to talk to them freely)

If your keyboard sends everything you type to the state, and there are no usable alternative keyboards, what realistic actions can you take? a) type nothing anywhere on your phone: send only emojis, 'gifs', and voice notes? b) learn to read and write a language with keyboards that don't phone home; or transcribe your written language to an alphabet with a keyboard that doesn't phone home c) buy an expensive phone wit…

Knowing what you can't do safely is important. How is "don't send 'incriminating' messages to that journalist through a phone, or if you do be aware you might be monitored and there might be consequences" not a realistic action in the scenario?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#216
post #206

Earlier quoted context omitted.

Why does it need your phone number? Seems pretty weird for a “secure” program. And why does it use AWS? Isn’t that subject to all kinds of privacy risks including National Security Letters? Why isn’t Signal just a Free and open source, infrastructure-less p2p solution? Maybe the goal isn’t really security or privacy after all...

It seems like the phone number is used mainly for matching you up to your contacts, and secondarily used for a first level of authentication. Signal has always encouraged independent verification of folks' public keys for sensitive communication. Whether or not AWS is risky, I don't think signal has any increased risk hosting their infrastructure on it vs. any other service. The whole point is that comms are end-to-e…

Seems like using a phone number as an account identifier is a huge risk to privacy. Has Rosenfeld admitted this? It’s just weird to require a phone number unless you’re talking about some big tech botnet like Facebook or Google.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#217
post #206
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

Why does it need your phone number? Seems pretty weird for a “secure” program. And why does it use AWS? Isn’t that subject to all kinds of privacy risks including National Security Letters? Why isn’t Signal just a Free and open source, infrastructure-less p2p solution? Maybe the goal isn’t really security or privacy after all...

> Why does it need your phone number?

Great question! It's a good way to make it easy for general-purpose users with limited technical expertise to adopt, use, and find one another.

> Seems pretty weird for a “secure” program.

You're right! It's definitely weird, but it's also understandable as a tradeoff in favor of less technically adept users. It's not one I'm in love with, but I think it makes sense.

> And why does it use AWS? Isn’t that subject to all kinds of privacy risks including National Security Letters?

The risk from NSLs depends a lot on what is hosted. If it's opaquely encrypted blobs, there's minimal risk. And where could things be hosted that wouldn't be subject to privacy risks from a government of some sort?

> Why isn’t Signal just a Free and open source, infrastructure-less p2p solution?

That's such a good idea that Signal is already a Free and open source solution!

That said, nothing is ever actually infrastructure-less, just like no data store is actually schema-less. There's just explicit infrastructure and implicit infrastructure. Implicit p2p infrastructure is not immune to governments or NSLs, and is often subject to more by virtue of being in more countries.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#218

Earlier quoted context omitted.

FWIW, my experience with Signal sadly confirms this. There’s a critical issue for years with the iOS app that there’s no way to backup or otherwise extract your chat logs (contrary to the usual behavior of iOS apps which automatically backup to your computer or iCloud), no warning of this when you first install, and almost no communication from developers on the subject for years despite huge numbers of complaints. T…

> They hide behind the shield of being volunteers to justify not addressing or communicating about any user concerns I agree this lacking feature is an important matter, but the Signal team have explained why the iOS app doesn't have a backup facility. Saying there's "no communication" is not true. I'm not sure what the purpose of saying "hiding behind the shield of being volunteers" is. Are you inferring they're lyi…

Not no communication. Almost no communication. They have occasionally given explanations for why the feature is difficult to implement, and occasionally given explanations for why they think the feature shouldn’t exist at all even if it could be implemented (despite it existing for Android users). They have never clearly communicated what their intent is: Will they implement it? If so, when? And they have never clearly warned users of this sharp edge in advance of installing software which will hurt them if they care about not losing control over their own data.

By “hiding behind the shield of being volunteers”, I’m not implying anything about them lying about anything. I’m saying that they have explicitly, on multiple occasions, indicated that it’s bad form for users to feel entitled to certain dealbreaker issues being fixed, or even to feel entitled to communication about whether those issues will be fixed and on what schedule. And their reason for believing users are not entitled to anything from them is that they are just volunteers.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#219

Earlier quoted context omitted.

Hidden services don't use exit nodes.

You could first charitably strengthen their argument by silently correcting “exit nodes” to “nodes”. The core point stands.

I don't think the core point does stand.

1. To deanonymise a hidden service connection you need to observe the traffic of all of the nodes in the circuit.

2. OK, let's say your adversary controls all of the nodes in the circuit and deanonymises the endpoints. Now what? You're no worse off than you would be if you weren't using Tor in the first place, so it's not an argument against Tor at all. All it's saying is "the absolute worst case of using Tor is no worse than the best case of not using Tor".

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#220

Earlier quoted context omitted.

But even then, there's really no point in trolling the PR section of Github besides griefing. Just fork the thing and make a better Signal if you believe so harshly that there's no hope with Moxie at the helm.

Even if one thought that this would help the people that need help on this matter, you can't really fork signal as it is today, I think. Or at least whatever it is that signal is using on its servers because that is very unlikely to be the software in its public repo, which hasn't been updated in almost a year. And even for a while before then, most of the commits were version bumps with no visible changes on the cod…

Not only that, but Signal has indicated that third-party clients are not welcome to use their servers. So even if you contented yourself with forking the client, you can't use it.

https://github.com/LibreSignal/LibreSignal/issues/37#issueco...

Post reply on HN