Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

281–290 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#281
post #258
post #156

Earlier quoted context omitted.

He wasn't. Why lie about this? https://community.signalusers.org/u/DuckSoft/summary

im just quoting the parent article. can yall read it before commenting and making accusations?

The timeline is incorrect.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#282

Earlier quoted context omitted.

> frequently exploited Do you happen to have a source for this? There’s lots of speculation out there, but I’ve never seen anyone claiming to have proof of this being frequently exploited.

Yes, I linked it above.

You did not. Realsexycyborg has no idea if this is being exploited or not, she’s only speculating.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#283
post #256

Earlier quoted context omitted.

What is stopping someone from running signal on a dedicated burner if they're worried about it? Different people have different threat models and I think asking for a phone number for the reasons posted above is acceptable for most people.

There really is no such thing as a dedicated burner. you don't even need NSA level threat vectors for most phone sim purchases in western countries to exfiltrate tons of user data. Wifi is even worse, not better..

I think the best way to get a burner account is to use the free services to receive text messages online. These are enough to create an account, and you can then set a pin to prevent any takeover, assuming you synchronize your account every week.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#284
post #95
post #54

Earlier quoted context omitted.

> The fact that you can detect a Signal proxy as a Signal proxy isn't a vulnerability; if it gets censored you're no worse off than you were if that proxy didn't exist: the main Signal servers are censored in Iran already. Indeed, this is the Signal circumvention proxy working precisely as designed. There is more risk than just "if it gets censored". If the proxy can be detected, so can users of that proxy. If users…

> What is clear, is that this is a vulnerability. Circumventing blocks tends to be illegal. If we want to help people circumvent such blocks, we need to help them from being caught as well. Nah, circumventing a block doesn't imply obfuscation of any kind. Signal's normal server connections are not obfuscated, there is no reasonable expectation that a connection to it via a proxy would be, either. It seems like people…

Signal put forward the TLS-proxy as a way to circumvent specifically the block on signal. This suggests they want people to be able to access signal despite it being illegal.

The feature is 'use access in Iran despite it being illegal'. If that is your pitch, then 'being detectable as doing the illegal thing we want to enable' counts as a vulnerability for that feature.

Whether software has a vulnerability or not cannot be determined without knowing how that software is meant to be used.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#285
post #71

Earlier quoted context omitted.

> Tone can often be more important than facts. Exactly: https://www.edge.org/response-detail/27181

That is really useful: > Russell Conjugation (or “emotive conjugation”) is a presently obscure construction from linguistics, psychology and rhetoric which demonstrates how our rational minds are shielded from understanding the junior role factual information generally plays relative to empathy in our formation of opinions. > Years later, the data-driven pollster Frank Luntz stumbled on much the same concept unaware…

And the last sentence:

> (Humans) fear (that) authentic emotions will get us into trouble with our social group, and so continue to look to others to tell us what is safe to feel.

By e.g. paying attention to if the speaker said "whistle blower" or "snitch"

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#286
post #31

Moxie - and the Signal team - seems to have a real issue taking feedback from outside experts. See the way he has been completely dismissive of the IME vulnerability highlighted by Naomi Wu and others. I remember back when it was TextSecure - I tried to raise some usability and security issues. First I was ignored, then dismissed, then - a few years later - they implemented some of the changes. I still use Signal. Bu…

This is exactly why I moved away from signal. A combination of ignoring user's concerns and confusing/inaccurate communication about the security and the privacy of their users. That's absolutely not what you want to have for a service people depend on for privacy. If you're promoting your service to people who risk their lives and freedom by using it you need to make it 100% clear to them what their risks are. Today…

> Signal still haven't updated their privacy policy to reflect it either (it still states "Signal is designed to never collect or store any sensitive information.")

They don't need to update their privacy policy because they never have access to the profil information.

Technically, the encrypted profile information and your messages (when they are in transit to your contacts) are being stored on their servers in the exact same way. The only difference is that messages are deleted afterwards whereas your profile is stored permanently until you decide to change it. That doesn't make the profile information any less secure, though. Yes, maybe in 20 years someone will be able to break AES-256 (or whatever symmetric encryption algorithm they use) and then the stored cyphertext version of your profile information might be valuable. Personally, I doubt it. But even if I turn out to be wrong: The possible attack vector against your profile information is the same as for messages: After all, tomorrow Signal could get convinced by an intelligence agency to permanently store all your encrypted messages from now on and then the exact same risks of AES-256 getting broken would apply.

Conclusion: When Signal says they're not collecting any sensitive information, they mean that they themselves don't have access to any such information because it gets encrypted. This is the promise of end-to-end encryption. They're not promising anything beyond that.

In particular, they can't promise that the encryption will never get broken. No one knows. And no one in their right mind would promise anything like that. But at least they do everything to mitigate that risk by openly publishing all their cryptography algorithms for peer review and actively participating in scientific research surrounding that topic.

> I still run into people who have no idea that Signal is storing their profile information and their contacts on signal's servers

The precise meaning of the phrase "Signal is storing their profile information on [their] servers" vs. what the average person will actually understand here, are two entirely different things here: Most people will think that Signal stores that profile information in cleartext on their servers – because that is the current status quo with almost all popular online platforms – when in reality this is not the case.

Normally, I would be saying at this point: Please stop spreading FUD. But I do agree with your statement that

> If you're promoting your service to people who risk their lives and freedom by using it you need to make it 100% clear to them what their risks are.

Signal could indeed do a better job here. In view of the above, however, I'm having the feeling the risks weren't really clear to you, either? (No offense)

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#287
post #277

Earlier quoted context omitted.

That then means you can't communicate with others running the normal Signal client. Signal is not a federated protocol.

> That then means you can't communicate with others running the normal Signal client. Signal is not a federated protocol. You also can't communicate with WhatsApp users directly either. If your fork of Signal in better, then you should have no difficulty it convincing people to switch to it. Just because the software is open source, you're not entitled to connect to and use someone else's service in any way you like.

Right, but the idea and comment I'm addressing is "If you don't like it, create a fork".

This "do it yourself" mantra doesn't apply to Signal, and they have a history of rejecting community work. It's much more valuable to advocate for changes and fixes to the main app.

> If your fork of Signal in better, then you should have no difficulty it convincing people to switch to it.

This isn't true. Signal has a marketing budget and millions of downloads of inertia.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#288
post #273

Earlier quoted context omitted.

There's some missing nuance here. Naomi Wu documented this much better than my summary, but the short version is that you need an IME keyboard for Chinese text entry, and the only one that's any good (and so, has a huge install base) is an application created and owned by a corporation with strong ties to the Chinese government. When there's a security rake-in-a-darkened-shed that a large fraction of your users will…

First, I speak Chinese, I understand what the IME thing is about. I agree that the "Incognito Keyboard" flag is a miscommunication, it should say "Politely tell my IME don't use my input to make smart suggestions", but IMO it is more of an OS issue instead of application issue. Android decided this should be called "IME Incognito Mode", but in reality it is not enforced and merely a hint to the IME. Maybe in addition…

"But what's next" is a slippery slope argument that isn't interesting. This particular issue is unique, and it makes sense to warn about it, and there's no really good reason not to when doing so is so trivially accomplished.

Hemming and hawing whether a line warning about a vulnerability that compromises a secure messaging app for over a year for any reason, but especially because of a shitty, arguably sexist tone argument not behavior I want to see from people who make security tools.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#289

Earlier quoted context omitted.

This is exactly why I moved away from signal. A combination of ignoring user's concerns and confusing/inaccurate communication about the security and the privacy of their users. That's absolutely not what you want to have for a service people depend on for privacy. If you're promoting your service to people who risk their lives and freedom by using it you need to make it 100% clear to them what their risks are. Today…

> Signal still haven't updated their privacy policy to reflect it either (it still states "Signal is designed to never collect or store any sensitive information.") They don't need to update their privacy policy because they never have access to the profil information. Technically, the encrypted profile information and your messages (when they are in transit to your contacts) are being stored on their servers in the…

>> They don't need to update their privacy policy because they never have access to the profil information.

irrelevant. Their policy states that their software is "designed to never collect or store any sensitive information." when in fact, it does. Where and how they store the sensitive information they are collecting is entirely beside the point. Assumptions about what people may or may not think that means don't really matter. As written it's a very straightforward and 100% false statement.

> The only difference is that messages are deleted afterwards whereas your profile is stored permanently until you decide to change it. That doesn't make the profile information any less secure, though.

Yes it does. Regardless of the fact that it's encrypted, it isn't as secure as you might think. See this thread for details: https://community.signalusers.org/t/proper-secure-value-secu...

> After all, tomorrow Signal could get convinced by an intelligence agency to permanently store all your encrypted messages from now on and then the exact same risks of AES-256 getting broken would apply.

Funny you should mention that because it turns out the Signal was handed a subpoena back in 2016 demanding that they hand over subscriber's names, phone numbers, and contacts. At the time, they were very proud to say they told them "Too bad, we don't have any of that data". In their own words:

"We’ve designed the Signal service to minimize the data we retain about Signal users, so the only information we can produce in response to a request like this is the date and time a user registered with Signal and the last date of a user’s connectivity to the Signal service."

"Notably, things we don’t have stored include anything about a user’s contacts (such as the contacts themselves, a hash of the contacts, any other derivative contact information), anything about a user’s groups (such as how many groups a user is in, which groups a user is in, the membership lists of a user’s groups), or any records of who a user has been communicating with."

Today, they are collecting and storing exactly that data. User's names, photos, numbers, and contacts. Yes, it's encrypted, but that's when they pull out something like this: https://community.signalusers.org/t/sgx-cacheout-sgaxe-attac... assuming they haven't forced Intel to leave a backdoor for them already or they don't want to take the time to brute force a pin.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#290

Earlier quoted context omitted.

> Signal still haven't updated their privacy policy to reflect it either (it still states "Signal is designed to never collect or store any sensitive information.") They don't need to update their privacy policy because they never have access to the profil information. Technically, the encrypted profile information and your messages (when they are in transit to your contacts) are being stored on their servers in the…

>> They don't need to update their privacy policy because they never have access to the profil information. irrelevant. Their policy states that their software is "designed to never collect or store any sensitive information." when in fact, it does. Where and how they store the sensitive information they are collecting is entirely beside the point. Assumptions about what people may or may not think that means don't r…

I see where you're coming from. Ultimately, it comes down to a question of terminology. You say that a service storing the ciphertext of sensitive information is "collecting" this information. I, in turn, maintain it's at least not that clear, given that "collecting personal information" has a completely different meaning in the context of online platforms that don't offer end-to-end encryption.

This is why I think that your original statement that

> Today I still run into people who have no idea that Signal is storing their profile information and their contacts on signal's servers

is at least highly misleading and you're doing those people a disfavor by being similarly vague as the Signal website (albeit in the opposite way).

In any case, I agree that the statement you're quoting from their website,

> Signal is designed to never collect or store any sensitive information.

should be worded much more carefully (as should a lot more information on their website). Nevertheless, it should be noted that that particular statement is not part of their ToS / Privacy Policy and rather just an introductory statement.

> Regardless of the fact that [the profile information is] encrypted, it isn't as secure as you might think. See this thread for details: […]

Like you, I've been very concerned about Signal relying on SGX enclaves and I'm still extremely disappointed by the way they have been handling this topic. In fact, I've sent them multiple messages over the past year, asking them how come they trust SGX so much and what they've taken away from the Signal PIN UI/UX debacle. (I still think it's very poor UX to name a passphrase which should be as long as possible a "PIN".) Unfortunately, time and again they chose not to respond.

Nevertheless, the questionable security of SGX enclaves only comes into play if you choose to activate the Signal PIN feature and choose an insecure PIN. Obviously, this is still a huge red flag as the majority of users will do just that. But at least if you don't use Signal PINs you're good – in the sense that the app chooses a random lengthy passphrase for you. So yes, the encrypted profile still gets stored on their servers but, again, the attack vector is the same as in the case of messages getting stored during transmission.

Overall, you might think I'm contradicting myself – arguing both in favor and against Signal at the same time. And you would be right. Unfortunately, Signal is still by far the best tool we have for secure communication these days. (Where "best" is defined as "striking the best balance of versatility, mainstream acceptance and security".)

Post reply on HN