Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

231–240 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#231
post #206
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

Why does it need your phone number? Seems pretty weird for a “secure” program. And why does it use AWS? Isn’t that subject to all kinds of privacy risks including National Security Letters? Why isn’t Signal just a Free and open source, infrastructure-less p2p solution? Maybe the goal isn’t really security or privacy after all...

Using phone numbers as identifiers for encrypted messages is the core feature of Signal. It was marketed from day one as a drop in SMS replacement. Initially it even used SMS as the transport for encrypted messages. It was literally called "TextSecure".

You can find any number of infrastructure-less p2p solutions. The number of users they have compared to Signal might be illuminating.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#232

Earlier quoted context omitted.

> They hide behind the shield of being volunteers to justify not addressing or communicating about any user concerns I agree this lacking feature is an important matter, but the Signal team have explained why the iOS app doesn't have a backup facility. Saying there's "no communication" is not true. I'm not sure what the purpose of saying "hiding behind the shield of being volunteers" is. Are you inferring they're lyi…

Not no communication. Almost no communication. They have occasionally given explanations for why the feature is difficult to implement, and occasionally given explanations for why they think the feature shouldn’t exist at all even if it could be implemented (despite it existing for Android users). They have never clearly communicated what their intent is: Will they implement it? If so, when? And they have never clear…

But where are they supposed to do the more communication? Surely they can't go reading and responding to every thread online that discusses Signal - there's just so many of them. In GitHub, too, issues often get duplicated or drowned in comments.

(Although I strongly disagree that they should be saying when they are going to implement it, as that's only setting themselves up for failure: unless it's almost ready, there's just too many things that can influence your roadmap.)

For what it's worth, they did provide another update on this one month ago saying that they do intend to implement it and thus think it can and should be, I think: https://www.reddit.com/r/technology/comments/kt91qk/signal_p...

> Thanks, we know this is a big deal and think about it a lot. We're working on ways to do it that would be privacy preserving, and in the mean time we've got the p2p device transfer you mention.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#233
post #229
post #226

Earlier quoted context omitted.

The major group Signal wants to market to is normal people, and they've stated repeatedly that they optimize for that over maximum security with what they consider worse usability. And even though I disagree with the focus on phone numbers and wish they'd prioritized a model that makes them optional, I do understand the network effect argument for including it. Kind of annoying that the alternatives that do it better…

Normal people have no issues creating user handles on Reddit and Discord and Twitter. Again, the only reason to require a phone number is because Rosenfeld wants it.

No, because using phone numbers gives you contact discovery through the phone book "for free" (with further privacy implications Signal has discussed at length). And an entire argument around it providing a social graph independent of service infrastructure that is important for some aspects of user freedom - again something that has been discussed publicly at length, both from Moxie and from other players in the wider messenger ecosystem (many of which at least partially disagree and have made different tradeoffs - but generally acknowledge the tradeoff exists).

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#234
post #109
post #88

Earlier quoted context omitted.

"Important: Keyboards and IME’s can ignore Android’s Incognito Keyboard flag. This Android system flag is a best effort, not a guarantee. It’s important to use a keyboard or IME that you trust. Signal cannot detect or prevent malware on your device." https://support.signal.org/hc/en-us/articles/360055276112-In... Sure, the app should say that too, not sure if it does. Also, the small team of developers can only fix s…

That was only added 19 days ago - after months of people (politely) asking for it to be acknowledged as a serious concern. https://github.com/signalapp/Signal-Android/commit/0a29ffcf4...

That... Sounds exactly like taking external feedback?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#235
post #21
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…

I think the point is that these people just sound like they are barking up the wrong tree. They're bitching at a non-profit org who gives away their services for free for not doing things exactly the way they want. And then getting self-righteously upset when said non-profit bans them for acting in an abusive manner.

> The tone is not more important than the facts. It never is.

This is 100% wrong. Tone does matter. If you want someone to do something for you, acting entitled and insulting them usually isn't going to get you where you want to go. Unfortunately straight facts don't sway hearts and minds. That is just how human psychology works. I wish it were different, but wishing does not make it so (speaking of facts!).

The Signal team does not owe these people a way to conduct private secure conversations. Yet they are working on it anyway, because they believe it's the right thing to do. And I bet it's pretty demotivating for a bunch of people to come and tell them that they're doing it wrong and their current interim efforts are useless. No one is owed an explanation or dialogue from the Signal team, and behaving aggressively in order to demand one is about the most unproductive thing they could do.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#236
post #224
post #223

Earlier quoted context omitted.

Discoverability, familiarity, and usability are good reasons that many find convincing. I understand that some people might disagree. Personal insults aren't called for. Please stop.

There's no reason to post in the fashion of a glib marketing department person if you're not. And I don't think ANYBODY finds requiring a phone number "because it's discoverable, familiar, usable" is convincing especially when considering that dissidents are apparently one of the major groups this is marketed to. The whole thing smells funny, there's no reason to require a phone number other than Rosendfeld WANTS it.

How many casual users have you personally convinced to switch to some E2E-encrypted messaging app?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#237

Earlier quoted context omitted.

They're banning the other party for their abusive language and behaviour, for their unsubstantiated, bad-faith claims of suppression and for misusing project resources. On top of the fact that they're not listening to why their assertions are incorrect. Any party acting in such a belligerent, infantile manner is going to be banned since they have proven they cannot act like grown-ups in a grown-up setting.

That's a fair point and I agree with you. Something I've been wondering as of lately, what can we (as a society) do to move off the edge of high emotions? I feel as if it's a common theme anywhere I look.

It's a very tough problem to solve, especially given how social media algorithms stir outrage and throw civility away for higher engagement numbers.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#238
post #109
post #88

Earlier quoted context omitted.

"Important: Keyboards and IME’s can ignore Android’s Incognito Keyboard flag. This Android system flag is a best effort, not a guarantee. It’s important to use a keyboard or IME that you trust. Signal cannot detect or prevent malware on your device." https://support.signal.org/hc/en-us/articles/360055276112-In... Sure, the app should say that too, not sure if it does. Also, the small team of developers can only fix s…

That was only added 19 days ago - after months of people (politely) asking for it to be acknowledged as a serious concern. https://github.com/signalapp/Signal-Android/commit/0a29ffcf4...

What would you consider to be an acceptable length of time for a feedback cycle for an understaffed organization who gives away their services for free? I think "months" can be entirely reasonable.

At this point you're not complaining about the end result -- they did actually implement something as a result of the feedback -- you're just complaining about the time it took them to do so. Which is IMO pretty silly, as the Signal folks make their own decisions about prioritization, and they're not at all beholden to the people who don't pay them for their service for any kind of schedule guarantees.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#239
post #178

Earlier quoted context omitted.

Should Signal then come with a blanket warning “Do not trust Signal!”?

A brief explanation of the threat model (i.e. what it aims to protect against and what it doesn't) would probably be more useful. "Do not trust people that tell you Signal is perfectly secure" is true but probably doesn't lead to the right user behavior. I'm not claiming communicating these things well is easy. (and obviously a bunch of the blame lies with people that do uncritically push Signal, if you are journalis…

Why is it the responsibility of the Signal developers to do people's threat modeling for them?

If your situation is that you need to communicate things that could get you killed or imprisoned, you should be using a burner phone that has pretty much nothing installed on it but Signal (or whatever app you choose to use for secure comms). You should also be using a third-party OS/ROM that you can be pretty sure hasn't been backdoored by a local telco or government, or a device that you've managed to import from abroad that likely doesn't have local modifications.

I would assume that most people do not do this, and yet somehow expect Signal to magically make the entire stack below it secure, which is a ridiculous expectation.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#240
post #232

Earlier quoted context omitted.

Not no communication. Almost no communication. They have occasionally given explanations for why the feature is difficult to implement, and occasionally given explanations for why they think the feature shouldn’t exist at all even if it could be implemented (despite it existing for Android users). They have never clearly communicated what their intent is: Will they implement it? If so, when? And they have never clear…

But where are they supposed to do the more communication? Surely they can't go reading and responding to every thread online that discusses Signal - there's just so many of them. In GitHub, too, issues often get duplicated or drowned in comments. (Although I strongly disagree that they should be saying when they are going to implement it, as that's only setting themselves up for failure: unless it's almost ready, the…

> But where are they supposed to do the more communication? Surely they can't go reading and responding to every thread online that discusses Signal - there's just so many of them.

They could put out an official statement on their web site about the matter that everyone can reference. "We intend to do this and here's the way we intend for it to work, and we expect it to take roughly 1 year ±6 months to implement. Here's the GitHub issue to track our progress."

Or they could post something on this thread on their official forums which has 18.7k views, 731 likes, and 384 replies: https://whispersystems.discoursehosting.net/t/ios-backup-kee...

This isn't rocket science; plenty of other organizations have ways of disseminating information to millions of people so that everyone knows what's up. I don't expect the White House Press Secretary to speak to me personally, but I do expect her to answer questions from reporters and make official statements about matters that huge numbers of people care about.

Either way, there needs to be some acknowledgment that this is not just a nice-to-have feature request, but that things are actively, terribly broken for certain users at the moment. They should not be working on aesthetic features like Stickers when something is so fundamentally broken. They should be acknowledging their users' pain, apologizing for having screwed up, and emphasizing that they appreciate the priority of this matter.

And until the issue is fixed, it would also take approximately 0 effort for them to warn users about this prior to installing or using the app, so that users can opt out in the meantime if they want control over their data.

>> Thanks, we know this is a big deal and think about it a lot. We're working on ways to do it that would be privacy preserving

Thanks, that's a small step in the right direction which I hadn't seen. Still, it comes after years of being almost entirely mum on the subject, and "think[ing] about it a lot" isn't terribly great comfort to users who have been stuck in the lurch for literally years. How long are they going to be thinking about it? When do they start taking action? What does "privacy preserving" mean?

Post reply on HN