Signal has been adding lots of silly social media like features lately, not surprising that they are messing up the core value prop. I’m shopping for a new encrypted messenger. They used to say every program expands in scope until it can read email, now every app expands until you can add Snapchat filters to your selfies.
Signal on Android: Images sent to wrong contacts
241–250 of 403 posts
Re: Signal on Android: Images sent to wrong contacts
#242And they say that I don't value privacy since I use Telegram and not Signal... in reality Telegram may not be end to end encrypted like Signal, but I never recall doing a think like that. It means poor attention to the security of the application, and poor testing.
You will never use an app that HAD 0.000000001% chance of outputting a file on your phone to wrong peer over 100% end-to-end encrypted channel...
but...
You knowingly use an app that leaks 100% of your group chats, including attachments, 100% of your 1:1 desktop messages to the service provider, who can be bought, or hacked at any time without you (or them) knowing, and that doesn't provide any kind of active protection mechanism against similar bugs than this one...
...on the grounds...
...that such bug hasn't happened, yet?
Is that what I'm reading?
Re: Signal on Android: Images sent to wrong contacts
#243I'm rooting for Delta Chat [1] which puts a nice chat UI on top of email. It is such a brilliant and simple solution. It is decentralized unlike Signal which recently had big reliability problems when new users flooded in. [1] https://delta.chat
Re: Signal on Android: Images sent to wrong contacts
#244Earlier quoted context omitted.
I think what I'm trying to get at is that incorrectly believing you have access to a secure messenger can be worse than acting as if you don't, if those are your options. The whistleblower might choose not to make contact, but if the alternative is making contact and immediately going to prison (because someone else on your contact list saw a classified screenshot from you and told the authorities), maybe that's bett…
> I think what I'm trying to get at is that incorrectly believing you have access to a secure messenger can be worse than acting as if you don't, if those are your options. For the average person, I do not believe this is true. For the non-average person, I believe you are correct but most of these people are aware and should be constantly trained. I'm not saying you're wrong, I'm saying that there are two different…
It's a little weird that Signal is both the "baseline security that everyone should have" product (a la HTTPS or WPA2) and the "you are literally hiding from the government" product. Of course, the target market for the latter, when you are not another government yourself, is by definition mostly illegal activity (whether or not the laws are justifiable), so it makes sense that there isn't a good product just for that.
In this particular case, it also complicates things that people who are literally hiding from the government also have normal ordinary conversations with lots of people, and it helps things for those ordinary conversations to happen on Signal, but this bug is particularly bad if you do that.
(I'm also not really sure where, say, people buying recreational drugs fit on the "average"/"non-average" axis. Is it a reasonable precaution to not text incriminating information to your drug dealer over Signal? It feels like it shouldn't be necessary, but I can see the argument for it.)
Re: Signal on Android: Images sent to wrong contacts
#245Earlier quoted context omitted.
Email. Why are we still trying to push these instant messaging apps that are a privacy and security nightmare? (I realise email has security issues too).
Email has weaker EtoE encryption than these IM solutions. Even with GPG. Too much metadata is leaked. However the decentralised nature of email is one crucial advantage it has over these apps.
Re: Signal on Android: Images sent to wrong contacts
#246Earlier quoted context omitted.
I disagree. If that really is the choice, they should drop the secure moniker without further debate. -- If you produce a product that claims to be secure, the onus is on you to back up those claims. Off the top my my head there are many ways to implement measures that can help to encourage security going forward. One of the benefits of coding in the open, and ascribing to opens standards and protocols is transparenc…
> One of the benefits of coding in the open, and ascribing to opens standards and protocols is transparency and the ability for all to interrogate the code. They already do all of those things. https://github.com/signalapp/Signal-Android
These actions betray trust, and trust is Signal's entire reason for being.
Re: Signal on Android: Images sent to wrong contacts
#247Earlier quoted context omitted.
I appreciate that this was a difficult and rare bug, but for an app that sells itself as 'secure', it feels like this isn't acceptable. How can users be assured that this type of issue won't occur again?
Users are not entitled to a guarantee that this will never happen again, because Signal is free and open source software provided free of charge and without warranty. The Android app is GPL licensed. The license clearly states: > For the developers' and authors' protection, the GPL clearly explains that there is no warranty for this free software. If you feel let down by open source software, you have many options av…
Re: Signal on Android: Images sent to wrong contacts
#248Earlier quoted context omitted.
Well he just wanted to make an example. One could also construct an example, where the bug only occurs for people with a rare sequence of unicode symbols (e.g. U+2600 U+2601 U+2602) in their username and have a specific date (e.g. 05.04.1920) as their birthday.
Your argument depends on Signal implementing username support, because we do not support unicode in phone numbers.
Re: Signal on Android: Images sent to wrong contacts
#249Earlier quoted context omitted.
>for the sake of argument
Yes. And for the sake of the same argument I made a counter argument, stating that some initially believed to be rare circumstances are actually not that rare.
Re: Signal on Android: Images sent to wrong contacts
#250Earlier quoted context omitted.
Users are not entitled to a guarantee that this will never happen again, because Signal is free and open source software provided free of charge and without warranty. The Android app is GPL licensed. The license clearly states: > For the developers' and authors' protection, the GPL clearly explains that there is no warranty for this free software. If you feel let down by open source software, you have many options av…
Moxie Marlinspike is famously belligerent against Signal forks, so no, the license does not really help here.
They don't like forks using their servers, but it's the users who connect to their servers, not the fork publisher. Those users are permitted to connect via the TOS, which is independent from the GPL.