Live data from Hacker News

Signal Server code on GitHub is up to date again

github.com

121–130 of 206 posts

Re: Signal Server code on GitHub is up to date again

#122
post #61
post #56

Earlier quoted context omitted.

The first commit that they omitted in April 2020 is related to the payment feature they just announced. So the two events coinciding (server code being published and payment feature being announced) might not have been a coincidence. They apparently didn't want to bother creating a private test server running a private fork of the server code and just pushed their experiments to production, just not releasing the sou…

This leaves a very bad taste in my mouth. Unclear how much practical damage this caused (how many security analysts are using the Signal server source to look for vulns?) but this is damaging to the project's claims of transparency and trustworthiness. It’s quite clear that this crypto integration provides a perverse incentive for the project that points in the opposite direction of security.

The server being or not being secure is only important to the people who operate it. You can examine the client code and see that your messages are encrypted end to end. Signal's entire security model revolves around the idea that you don't need to trust the server.

Re: Signal Server code on GitHub is up to date again

#123
post #64
post #53

After people started to realize that WhatsApp, owned by Facebook, started changing their privacy settings from terrible to slightly differently terrible, people flocked to and were recommended Signal by so called experts. Yet no one at that time bothered to point out that signal has been opaque as fuck about just about anything they do. On the other hand a free, self-hostable, highly transparent, highly secure altern…

> highly secure alternative exists in the form of matrix At least for metadata, as of now, Signal seems to provide better guarantees than Matrix. I can imagine Matrix competing with Discord and Slack, but I don't think they'll ever be able to compete with WhatsApp and Signal. You can blame "stupid" users and the media all you want, that won't change the path of least resistance. I really like Matrix as an IRC replace…

> At least for metadata, as of now, Signal seems to provide better guarantees than Matrix.

Agree here. Matrix servers log everything by default. If somebody cares about protecting metadata, I don't know why they'd choose Matrix over Signal.

Re: Signal Server code on GitHub is up to date again

#124
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

Signal Foundation has legitimate self-serving strategic reasons to prefer such secrecy, sure.

But users also have legitimate reasons to want more transparency into both source-code & strategy.

Whether such secrecy best serves the users & the cause of private messaging is an open question.

Re: Signal Server code on GitHub is up to date again

#125
post #74
post #61

Earlier quoted context omitted.

This leaves a very bad taste in my mouth. Unclear how much practical damage this caused (how many security analysts are using the Signal server source to look for vulns?) but this is damaging to the project's claims of transparency and trustworthiness. It’s quite clear that this crypto integration provides a perverse incentive for the project that points in the opposite direction of security.

Forgive me if this is a stupid question, but how exactly is that the case? It's been damaging to their claims of transparency for almost a year now, if anything this should be the first step in repairing that slight. How is dumping a year's worth of private work into your public repo somehow doing damage to their trustworthiness?

For one security through obscurity is a thing. Depending on it as your primary "security measure" is stupid on all levels but being part of your security is not a bad thing. Before all someone could get would be your chat history. Other than police, jilted lovers, and state actors no one else gives a crap about that most likely unless you are targeted as an individual. Now by adding access to money that might be accessible via Signal adds more incentive for hackers to not try to hack something else and now make a beeline for Signal. Also it dilutes the efforts of the Signal developers efforts to make a better messaging app. Also crypto in and of itself is questionable, but one that is 85% by one entity waiting to liquidate has been questioned by many organizations as well. The people who own that will expect fair value for it and in essence become billionaires several times over if this really comes to fruition.

Re: Signal Server code on GitHub is up to date again

#126
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

> Whether or not Signal's server is open source has nothing to do with security

This true only when you are exclusively concerned about your messages' content but not about the metadata. As we all know, though, the metadata is the valuable stuff.

There is a second reason it is wrong, though: These days, lots of actual user data (i.e. != metadata) gets uploaded to the Signal servers[0] and encrypted with the user's Signal PIN (modulo some key derivation function). Unfortunately, many users choose an insecure PIN, not a passphrase with lots of entropy, so the derived encryption key isn't particularly strong. (IMO it doesn't help that it's called a PIN. They should rather call it "ultra-secure master passphrase".) This is where a technology called Intel SGX comes into play: It provides remote attestation that the code running on the servers is the real deal, i.e. the trusted and verified code, and not the code with the added backdoor. So yes, the server code does need to be published and verified.

Finally, let's not forget the fact that SGX doesn't seem particularly secure, either[1], so it's even more important that the Signal developers be open about the server code.

[0]: https://signal.org/blog/secure-value-recovery/

[1]: https://blog.cryptographyengineering.com/2020/07/10/a-few-th...

Re: Signal Server code on GitHub is up to date again

#127
post #31

Earlier quoted context omitted.

better question yet: Did we ever get a full post-mortem of the six day outage the service had? other than hand waving statements about user subscriptions? what fixes were made or lessons learned?

The Signal outage was SIX DAYS?

no it wasn't

Re: Signal Server code on GitHub is up to date again

#128
post #122
post #61

Earlier quoted context omitted.

This leaves a very bad taste in my mouth. Unclear how much practical damage this caused (how many security analysts are using the Signal server source to look for vulns?) but this is damaging to the project's claims of transparency and trustworthiness. It’s quite clear that this crypto integration provides a perverse incentive for the project that points in the opposite direction of security.

The server being or not being secure is only important to the people who operate it. You can examine the client code and see that your messages are encrypted end to end. Signal's entire security model revolves around the idea that you don't need to trust the server.

There's no concern about metadata leakage?

Re: Signal Server code on GitHub is up to date again

#129
post #96

A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex. Here's the deal: - Whether or not Signal's server is open source has nothing to do with security. Signal's security rests on the user's knowledge that the open source client is encrypting messages end to end. With that knowledge, the server code could be anything, and Signal inc. would still not be able to read your messages. In f…

> A lot of these comments are just manifestations of the kneejerk HN "crypto bad" reflex.

Nope. It's a reaction to "who the f* asked for this in a messaging app?!".

Re: Signal Server code on GitHub is up to date again

#130
post #114

The crapcoin thing is REDICULOUS! THIS is what we setup nonprofits to support - some private entity and their crapcoin? How is this legal? How is this not a conflict of interest? How is this not private inurment? The crapcoin is totally opaque to. With premined coins.

It probably isn't legal but people use non-profits all the time for personal gain and get away with it almost always.

Exploiting nonprofit status to generate a personal benefit is not legal in the US. So if the board members, officers or whomever have some personal benefit to this crapcoin taking off, it's not legal for them to use nonprofit resources and tax breaks to push for that.
Post reply on HN