Live data from Hacker News

Signal Server code on GitHub is up to date again

github.com

61–70 of 206 posts

Re: Signal Server code on GitHub is up to date again

#61
post #56

So it just took close to a year to dump thousands of private commits into the public repo! Is there an official response as to why they stopped sharing the code for so long and more importantly, why they started sharing it publicly again? Who gains what with the publication now? And seriously, why is it even relevant anymore?

The first commit that they omitted in April 2020 is related to the payment feature they just announced. So the two events coinciding (server code being published and payment feature being announced) might not have been a coincidence. They apparently didn't want to bother creating a private test server running a private fork of the server code and just pushed their experiments to production, just not releasing the sou…

This leaves a very bad taste in my mouth. Unclear how much practical damage this caused (how many security analysts are using the Signal server source to look for vulns?) but this is damaging to the project's claims of transparency and trustworthiness.

It’s quite clear that this crypto integration provides a perverse incentive for the project that points in the opposite direction of security.

Re: Signal Server code on GitHub is up to date again

#62

So it just took close to a year to dump thousands of private commits into the public repo! Is there an official response as to why they stopped sharing the code for so long and more importantly, why they started sharing it publicly again? Who gains what with the publication now? And seriously, why is it even relevant anymore?

Here's a response by MobileCoin folks:

> Signal had to verify that MobileCoin worked before exposing their users to the technology. That process took a long time because MobileCoin has lots of complicated moving parts.

> With respect to price, no one truly understands the market. It’s impossible to predict future price.

- https://twitter.com/mobilecoin/status/1379830618876338179

Reeks of utter BS. As the reply on this tweet says, features can be developed while being kept switched off with a flag.

Re: Signal Server code on GitHub is up to date again

#63
post #53

After people started to realize that WhatsApp, owned by Facebook, started changing their privacy settings from terrible to slightly differently terrible, people flocked to and were recommended Signal by so called experts. Yet no one at that time bothered to point out that signal has been opaque as fuck about just about anything they do. On the other hand a free, self-hostable, highly transparent, highly secure altern…

> the bulk of users is either too stupid or unwilling to invest even the tiniest amount of effort into their privacy.

Those of us who have worked in security have known this for years. There are countless examples of massive security gains through minor inconvenience, and users rejecting them. Two factor auth is a big one. Yeah, it's a slight hassle. It gives major security improvements. Even security people don't like to use it. Even people who have been scammed multiple times, and told if they just turned on 2FA it help, would rather deal with being scammed again than use 2FA (I saw this at eBay and PayPal a few times, where the user rejected a free security token despite having been scammed multiple times).

Users hate friction. If it's not as easy as "download app, put in contacts" they aren't interested.

Re: Signal Server code on GitHub is up to date again

#64
post #53

After people started to realize that WhatsApp, owned by Facebook, started changing their privacy settings from terrible to slightly differently terrible, people flocked to and were recommended Signal by so called experts. Yet no one at that time bothered to point out that signal has been opaque as fuck about just about anything they do. On the other hand a free, self-hostable, highly transparent, highly secure altern…

> highly secure alternative exists in the form of matrix

At least for metadata, as of now, Signal seems to provide better guarantees than Matrix.

I can imagine Matrix competing with Discord and Slack, but I don't think they'll ever be able to compete with WhatsApp and Signal. You can blame "stupid" users and the media all you want, that won't change the path of least resistance. I really like Matrix as an IRC replacement though.

Re: Signal Server code on GitHub is up to date again

#66
post #61
post #56

Earlier quoted context omitted.

The first commit that they omitted in April 2020 is related to the payment feature they just announced. So the two events coinciding (server code being published and payment feature being announced) might not have been a coincidence. They apparently didn't want to bother creating a private test server running a private fork of the server code and just pushed their experiments to production, just not releasing the sou…

This leaves a very bad taste in my mouth. Unclear how much practical damage this caused (how many security analysts are using the Signal server source to look for vulns?) but this is damaging to the project's claims of transparency and trustworthiness. It’s quite clear that this crypto integration provides a perverse incentive for the project that points in the opposite direction of security.

It was called out as recently as 4 weeks ago [0] and was voted to the front-page but then weighted-out possibly incorrectly by mods (may be because the top comment is dismissive of concerns raised [1]?) before a discussion could flourish.

cc: @dang

[0] https://news.ycombinator.com/item?id=26345937

[1] The title is the only thing worth reading in this pile of speculation and hand waving.

Re: Signal Server code on GitHub is up to date again

#67
post #53

After people started to realize that WhatsApp, owned by Facebook, started changing their privacy settings from terrible to slightly differently terrible, people flocked to and were recommended Signal by so called experts. Yet no one at that time bothered to point out that signal has been opaque as fuck about just about anything they do. On the other hand a free, self-hostable, highly transparent, highly secure altern…

> To me this drives home one key issue: the bulk of users is either too stupid or unwilling to invest even the tiniest amount of effort into their privacy.

Something tells me you've never given tech support to non-technical family members. (And that's being generous – because outright considering everyone non-technical "stupid" would be a pretty sad worldview.)

Re: Signal Server code on GitHub is up to date again

#68
post #53

After people started to realize that WhatsApp, owned by Facebook, started changing their privacy settings from terrible to slightly differently terrible, people flocked to and were recommended Signal by so called experts. Yet no one at that time bothered to point out that signal has been opaque as fuck about just about anything they do. On the other hand a free, self-hostable, highly transparent, highly secure altern…

This is an unhelpful attitude, IMHO. Your best chance, as a privacy-conscious, tech-savvy individual is to push for mass-market adoption of strong encryption and good government privacy regulations that will help everyone. Lacking those, you will stand out like a sore thumb as one of a tiny number of "weirdos" using Matrix, or Brave, or Tor or GrapheneOS or whatever other hardcore self-hosted, federated niche tools y…

But if you are promoting something that is opaque and in some situations worse than an already-existing alternative, is it really the right path to recommend the problematic tool because it is more popular?

Re: Signal Server code on GitHub is up to date again

#69

So it just took close to a year to dump thousands of private commits into the public repo! Is there an official response as to why they stopped sharing the code for so long and more importantly, why they started sharing it publicly again? Who gains what with the publication now? And seriously, why is it even relevant anymore?

Here's a response by MobileCoin folks: > Signal had to verify that MobileCoin worked before exposing their users to the technology. That process took a long time because MobileCoin has lots of complicated moving parts. > With respect to price, no one truly understands the market. It’s impossible to predict future price. - https://twitter.com/mobilecoin/status/1379830618876338179 Reeks of utter BS. As the reply on thi…

> features can be developed while being kept switched off with a flag

But maybe you don't want everyone to know about all the features / announcements months in advance?

Re: Signal Server code on GitHub is up to date again

#70
Given that you have said...

"the bulk of users is either too stupid or unwilling to invest even the tiniest amount of effort into their privacy."

I don't feel the need to pull my punches.

This is the most deluded, idiotic response I've seen on hacker news in a long time.

It seems unlikely that the average person (or even a non-techie person of above average intelligence - e.g. a doctor) will be able to set up matrix in a way that is more secure than just installing signal. Your security relies not just on you but on the weakest node in your network. Getting good security might require trade-offs. Your all or nothing mindset will not achieve it. The saying "Perfect is the enemy of done" comes to mind. Perfect security (or what you purpose) is not one of the options in a secure system that has to exist in the real world.

Please remove your head from it's dark cavernous home.

Love, Me

Post reply on HN