Live data from Hacker News

Signal on Android: Images sent to wrong contacts

github.com

321–330 of 403 posts

Re: Signal on Android: Images sent to wrong contacts

#321

All facts aside about how it's now resolved and only surfaced using a certain setting, etc... This an absolutely horrific bug - worse than even an encryption snafu. Can you imagine depending on Signal's privacy features, possibly with your life, and encountering this bug? Fuck - this could ruin someone that hasn't even done anything wrong. If I knew this bug existed and I was on this team, I would have been in all ou…

One among many reasons I use different apps for different people in my life. My partner is the only person I message on one, my friends on another, my family only over text messages, and my coworkers only over email or phone calls.

Re: Signal on Android: Images sent to wrong contacts

#322

All facts aside about how it's now resolved and only surfaced using a certain setting, etc... This an absolutely horrific bug - worse than even an encryption snafu. Can you imagine depending on Signal's privacy features, possibly with your life, and encountering this bug? Fuck - this could ruin someone that hasn't even done anything wrong. If I knew this bug existed and I was on this team, I would have been in all ou…

One among many reasons I use different apps for different people in my life. My partner is the only person I message on one, my friends on another, my family only over text messages, and my coworkers only over email or phone calls.

I've never thought of doing this, but I often feel a pang of uncertainty whenever I open my phone's share sheet.

Like.. when I pick person A, is the app going to screw it up and send it to person B somehow?

I honestly have nothing life ruining going on, but huge embarrassment sometimes if a mistake were made? Definitely.

This bug is a worst fear realized.

Re: Signal on Android: Images sent to wrong contacts

#323
post #104

Earlier quoted context omitted.

> This bug was extraordinarily rare, and because we have no metrics/remote log collection, there was an initial period where we had to spend time adding logging and collecting user-submitted logs to try to track it down. Without telemetry, can you actually back up the claim that this issue was extremely rare?

Some details on how this assumption was made would be nice, but I think it's pretty obvious that any developer involved in a project can make a reasonable assumption of how rare a bug is depending on the technical details on what is required for the bug to happen. For example, if we say for the sake of argument that a hypothetical bug requires you to have more than ten contacts of the exact same name and these also n…

> it's pretty obvious that any developer involved in a project can make a reasonable assumption of how rare a bug is

... is it? The fact that a bug exists means there's a logic gap. You can try and patch it with theory, but that's just adding assumption to a scenario created from broken assumptions. Also, the job of telemetry in incident reporting isn't to be vague - its to add precision.

Re: Signal on Android: Images sent to wrong contacts

#324
post #313

Earlier quoted context omitted.

I'm not convinced. The bug is rare and requires a specific set of circumstances that not many people are going to perform. That is not an argument to collect metrics, or in other words, change the entire paradigm of Signal (no collection of Metadata). It does propose an argument for more audits, more eyes, and more care. But we do not expect Signal to be perfect, as no software is. Systematic failure, on the other ha…

> I'm not convinced. The bug is rare and requires a specific set of circumstances that not many people are going to perform. I don't think you would say the exact same thing if this happened to closed-source apps like WhatsApp or Discord and open-source apps like Telegram or Element. All of these apps have funding behind them and lots of resources to urgently address security issues when reported or discovered. The s…

> I don't think you would say the exact same thing if this happened to closed-source apps like WhatsApp or Discord

You're right. Because I judge a project backed by a company worth hundreds of billions of dollars and with hundreds of developers differently than I judge a company with a few tens of millions and only a dozen developers. I'm not sure why any sane person would judge these with the same metric. 15 devs just can't do what 1500 can. I'm not sure why you think differently.

Re: Signal on Android: Images sent to wrong contacts

#325

Earlier quoted context omitted.

One of the biggest problems with open source software is enormously entitled users; who don't pay for it, don't work on it, yet feel remarkably offended when some whim of theirs is not catered to. Just saying.

If you call it a "whim" if I point out that the latest version of the Signal server is proprietary software most of the time then so be it. Or maybe you are referring to the other commenters who were entitled to expect that the one critical task of a crypto messenger is ensuring the confidentiality of communication, which has been broken by this bug (and at least one similar bug before it, https://github.com/signalap…

> If you call it a "whim" if I point out that the latest version of the Signal server is proprietary software most of the time then so be it.

For whimsical definitions of "proprietary."

> Or maybe you are referring to the other commenters who were entitled to expect...

Anyone who feels entitled to bug free software is going to be disappointed, and rightly so.

> You can both be grateful that Signal is free and at the same time call out shenanigans of its owners. Just saying.

Remember: they're giving this stuff to you for free.

There's a wise expression that's worth remembering: "don't look a gift horse in the mouth." But if you don't want to take that advice, then you're https://www.youtube.com/watch?v=zq7Eki5EZ8o.

Re: Signal on Android: Images sent to wrong contacts

#326

Earlier quoted context omitted.

> How can users be assured that this type of issue won't occur again? By not using software. And I mean software in general, not this software in particular. You're basically asking for assurance that they won't have any more bugs, but no one can actually provide such an assurance in the real world.

Yes, they can.

> Yes, they can.

If they do, they're either incompetent, lying, or building something enormously expensive yet completely impractical for most if not all real world uses.

Re: Signal on Android: Images sent to wrong contacts

#328
post #104

Earlier quoted context omitted.

Some details on how this assumption was made would be nice, but I think it's pretty obvious that any developer involved in a project can make a reasonable assumption of how rare a bug is depending on the technical details on what is required for the bug to happen. For example, if we say for the sake of argument that a hypothetical bug requires you to have more than ten contacts of the exact same name and these also n…

> it's pretty obvious that any developer involved in a project can make a reasonable assumption of how rare a bug is ... is it? The fact that a bug exists means there's a logic gap. You can try and patch it with theory, but that's just adding assumption to a scenario created from broken assumptions. Also, the job of telemetry in incident reporting isn't to be vague - its to add precision.

There's probably a ratio of bug-report-to-occurrences that they're used to for difference kinds of bugs. Ex: If user-visible security bugs have good report rates, say 100-1000 leaks per 1 report, and 10 reports, then 1K-10K incidents. This is harder in b2b, but in b2c, PM's should have a feel for it..

Re: Signal on Android: Images sent to wrong contacts

#329

Earlier quoted context omitted.

If you call it a "whim" if I point out that the latest version of the Signal server is proprietary software most of the time then so be it. Or maybe you are referring to the other commenters who were entitled to expect that the one critical task of a crypto messenger is ensuring the confidentiality of communication, which has been broken by this bug (and at least one similar bug before it, https://github.com/signalap…

> If you call it a "whim" if I point out that the latest version of the Signal server is proprietary software most of the time then so be it. For whimsical definitions of "proprietary." > Or maybe you are referring to the other commenters who were entitled to expect... Anyone who feels entitled to bug free software is going to be disappointed, and rightly so. > You can both be grateful that Signal is free and at the…

What a buzz kill. If I understand you correctly we shouldn't have expectations or constructive criticism on stuff we don't directly pay money for. I think that's nonsense. Does this only apply to certain opinions?

You are not paying money for Signal. But by using it, and getting others to use it, you are definitely improving their position on the market by helping them become a monopoly. Money isn't everything.

Re: Signal on Android: Images sent to wrong contacts

#330

Earlier quoted context omitted.

> it's pretty obvious that any developer involved in a project can make a reasonable assumption of how rare a bug is ... is it? The fact that a bug exists means there's a logic gap. You can try and patch it with theory, but that's just adding assumption to a scenario created from broken assumptions. Also, the job of telemetry in incident reporting isn't to be vague - its to add precision.

There's probably a ratio of bug-report-to-occurrences that they're used to for difference kinds of bugs. Ex: If user-visible security bugs have good report rates, say 100-1000 leaks per 1 report, and 10 reports, then 1K-10K incidents. This is harder in b2b, but in b2c, PM's should have a feel for it..

You’d be surprised how difficult it is to estimate the frequency that someone sees a bug. The only way to have a “feel for it” is to base it on… other data.

Say there is a bug that happens in the photo taking flow – you’d need to know how often people take photos in Signal. You’d think you could spitball something for that, but it is actually really hard. But if you log how often photos are taken, then that is a great starting point.

But further, lower level logic errors like this, especially ones involving race conditions, are even harder to pin down. That is why on iOS you can log “faults” which are non-fatal but very not-expected events:

https://developer.apple.com/documentation/os/logger/3551617-...

They generate reports with stack traces that you can use to a) judge the prevalence of an issue and b) see where it originated

Post reply on HN