Live data from Hacker News

Signal on Android: Images sent to wrong contacts

github.com

281–290 of 403 posts

Re: Signal on Android: Images sent to wrong contacts

#281

Hi there, Signal-Android developer here. I updated the issue to reflect this, but this bug has been fixed. I was tracking it on a separate issue, and had forgotten to close this one. We do, in fact, take issues like this very seriously. This bug was extraordinarily rare, and because we have no metrics/remote log collection, there was an initial period where we had to spend time adding logging and collecting user-subm…

One thing I wonder is: how could this happen at all? Considering the E2E Encryption in place, I would expect the incorrect recipient simply wouldn't be able to decode the image considering they never have exchanged keys with the sender?

"How could this happen at all"

> I remember before Jellybean Android, sending SMS would break up my message and send it to multiple people, and the Android alarm clock would drift by hours.

So how could this happen? Because software is hard.

Re: Signal on Android: Images sent to wrong contacts

#282
post #56
post #47

Earlier quoted context omitted.

Why on Earth are people downvoting you? This is an absolute dealbreaker for any messaging app, much less one whose raison d'etre is privacy and secure messaging.

Probably because the common mindset here is that anyone can make a mistake, and that the person who did it learned their lesson and will never do it again.

Let’s be honest, if Telegram or WhatsApp did that mistake, all of that mindset would beat it to death and then jump on its corpse for three days straight.

Re: Signal on Android: Images sent to wrong contacts

#283
post #251

Earlier quoted context omitted.

"Weaker E2EE" as in "PFS is not commonly used with email". As for the metadata, no metadata is leaked that signal does not also leak.

>As for the metadata, no metadata is leaked that signal does not also leak. Signal does not leak to third party servers with whom I talk to. There's encrypted comms to the server, and that's it. I try to talk to someone who has gmail account, Google now has access to 100% of my metadata with that contact. I trust Signal more than I trust Google with my metadata. Also, there's precedent from TWO court cases Signal doe…

Metadata is leaked only to your server and to the server of the person that receives the email, just like signal. The only difference is that with email you get a maximum of 2 servers while with signal you get one.

> I trust Signal more than I trust Google with my metadata.

Fair enough, I will agree with this.

Re: Signal on Android: Images sent to wrong contacts

#284
post #279
post #250

Earlier quoted context omitted.

It does. You are allowed to fork or reimplement the Signal client, and even distribute it, with the official Signal servers configured, so long as you do not infringe the Signal trademark. They don't like forks using their servers, but it's the users who connect to their servers, not the fork publisher. Those users are permitted to connect via the TOS, which is independent from the GPL.

They also refuse to open source their server software. This is the problem in my mind. Open source in words, but not spirit.

This is false https://github.com/signalapp/Signal-Server

Re: Signal on Android: Images sent to wrong contacts

#285

Earlier quoted context omitted.

You are arguing against a hypothetical situation of your opponent's creation. This is like when Ross tried to beat Chandler at Cups

I am curious how different that alternative universe needs to be for my argument to be invalid.

It's not that your argument was incorrect. It's that it is tangential to the parent comment. hnarn was not making the point of something being rare, they were demonstrating that a developer can estimate the rarity based on the conditions that trigger it. The rarity itself is no matter.

Arguing over small semantic or circumstantial differences is often considered impolite

Re: Signal on Android: Images sent to wrong contacts

#286
post #279
post #250

Earlier quoted context omitted.

It does. You are allowed to fork or reimplement the Signal client, and even distribute it, with the official Signal servers configured, so long as you do not infringe the Signal trademark. They don't like forks using their servers, but it's the users who connect to their servers, not the fork publisher. Those users are permitted to connect via the TOS, which is independent from the GPL.

They also refuse to open source their server software. This is the problem in my mind. Open source in words, but not spirit.

Not only is it false as has already been pointed out, it doesn't matter at all. There is nothing stopping them from silently running a fork.

Re: Signal on Android: Images sent to wrong contacts

#287
post #279

Earlier quoted context omitted.

They also refuse to open source their server software. This is the problem in my mind. Open source in words, but not spirit.

This is false https://github.com/signalapp/Signal-Server

So are you telling me I can run my signal server and use it to communicate with others on the signal network?

Re: Signal on Android: Images sent to wrong contacts

#288
post #286
post #279

Earlier quoted context omitted.

They also refuse to open source their server software. This is the problem in my mind. Open source in words, but not spirit.

Not only is it false as has already been pointed out, it doesn't matter at all. There is nothing stopping them from silently running a fork.

As far as I'm aware, I have to use the official server if I wish to communicate via the platform.

If this isn't true, I'd be very interested to learn more.

Re: Signal on Android: Images sent to wrong contacts

#289
post #287

Earlier quoted context omitted.

This is false https://github.com/signalapp/Signal-Server

So are you telling me I can run my signal server and use it to communicate with others on the signal network?

I am telling you that "They also refuse to open source their server software." is false.

Re: Signal on Android: Images sent to wrong contacts

#290

Several years ago, when I worked at FB, I ran into a similar bug on an early internal version of a Messenger rewrite. Sent pictures to one chat, showed up in another. My bug report on it kicked off an absolute maelstrom of dev activity and investigation. High level engineers showed up in the comments. Lots of immediate followup. The severity was clearly understood and resolving it was clearly prioritized. I exclusive…

I don't think Signal has many devs[0] and if you look at the contributors[1] you can see that Grayson is pretty much the only dev for the Android app. So seeing a second dev get involved is probably them freaking out. [0] Personally I believe this is a big bump in the road for Signal and is why a lot of people are frustrated. About promises about things like usernames (it is no longer early 2021), channels, and every…

If this is the case, then we should just say:

Signal is not secure because they have limited resource and cannot invest in an area with Security adequately.

Post reply on HN