Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

141–150 of 336 posts

Re: Signal says it won’t compromise on encryption

#141
post #121

Earlier quoted context omitted.

It's propaganda. It's the same reason why a large portion of Indians (even with full internet access...) are fervently pro-Putin in the context of the Ukraine-Russia war.

I'm not an Indian, but I can understand why a country that was oppressed by the Great Britain for such a long time, and endured such atrocities, can opt to support the party that stands on the opposite side of Britain. That alone could explain why not only India, but big parts of the worlds, especially the ones that suffered from the British and American imperialism, would rather see an arch-enemy of their usurper wi…

India was the chief non-aligned country of the Cold War, and for decades has warmer relations with the Russian Federation (and it's predecessor the USSR) than the west.

https://en.wikipedia.org/wiki/India%E2%80%93Russia_relations

Re: Signal says it won’t compromise on encryption

#142
post #116
post #60

Earlier quoted context omitted.

I thought Matrix homeservers had access to way more metadata than Signal. Is it better than what I thought?

you can easily run your own. though you will need lotsa RAM for federation if you use synapse (mine keeps bogging down now after a year of mild use (could also be a bug idk, it allocates all the RAM and then nothing goes), now im waiting for the new server software dendrite to be able to migrate from synapse... allthough i wouldnt lose much if i just nuked the synapse instance)

> you can easily run your own.

Yes, and I have in the past. But that does not solve the issue completely. If the police asks me some information about one of my contacts, I'll have some metadata stored in my homeserver, and I'll need to hand it over. And vice versa.

It's better that the server does not have access to this information at all in the first place.

Re: Signal says it won’t compromise on encryption

#143

Here's one major problem with Signal - you cannot delete contacts. Following scenario: 1) X communicates with Y using Signal trying to hide from Iranian police 2) Y is getting arrested and who ever is found to have his phone number is getting in to trouble as well 3) X deletes Y from its contacts 4) Y stays in X's contacts on Signal no matter what now what should X do? delete Signal? theoretically the police could re…

it's either one pile of poo or another it seems... hosting your own matrix homeserver is probably not a thing you would like to do?

Re: Signal says it won’t compromise on encryption

#144
post #131

Earlier quoted context omitted.

Not at all like Signal. They only have your account creation time and your last connection time https://signal.org/blog/looking-back-as-the-world-moves-forw... (edit: answering to your initial message, that said that Signal operators also have access to the same metadata, but I guess my comment still answers your sentence "Most important is who when with who which both leak to the server operators" - Signal operators…

If you don't store that data or delete it, you can't provide it. But Signal could store that data because they have access to that dats

> If you don't store that data or delete it, you can't provide it.

Can I do this easily and still have my homeserver work correctly with Matrix?

Anyway, the law would probably require any operator to keep this data for a while since they have access to it. And I can't rely on my contact's homeservers to delete this data even if they can (technically and legally).

Re: Signal says it won’t compromise on encryption

#145
post #6
post #5

Earlier quoted context omitted.

Maybe not, imagine possession of such program is treated same way as a child pornography.

How popular would it be to treat people like pedos, just because of an app that they use?

The average person uses whatsapp, has no idea about security, has never heard of signal. The media will tell them signal is specifically setup up to prevent law enforcement. They will give an example of a drug dealer that gets caught and has the app on their phone. Even if the dealer didn't use signal for dealing the connection is presented.

The average person will connect the dots. Signal is an underground app for illegal stuff. I have nothing to hide so I don't need Signal to exist. People must use signal for the most illegal and disturbing thing I can think of. Signal users must be pedos. Signal must be banned.

This is how power uses media to control the masses. They don't need to make the claim they simply present facts in a narrative and allow the average person to connect the dots making them feel like they figured it all out themselves.

Re: Signal says it won’t compromise on encryption

#146
post #144

Earlier quoted context omitted.

If you don't store that data or delete it, you can't provide it. But Signal could store that data because they have access to that dats

> If you don't store that data or delete it, you can't provide it. Can I do this easily and still have my homeserver work correctly with Matrix? Anyway, the law would probably require any operator to keep this data for a while since they have access to it. And I can't rely on my contact's homeservers to delete this data even if they can (technically and legally).

Signal certeinly can store it, because they have access to it.

They have access to that data alone through the fact that they are in control of their servers and, thus, can see who sends and receives messages.

Re: Signal says it won’t compromise on encryption

#147
Encryption is just a tip of the iceberg here.

There are several major problems with Signal:

- it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways.

- as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t restrict your social circle to allow only chosen people or let’s say people only from your contact list to message you.

- Signal protocol is probably great from the e2ee perspective but it is not federated and unlike XMPP you cannot spin up your own server and have full control over it.

- Since the end product is not a protocol or a framework or a platform it is a product that is run by other people who you can only trust albeit you can verify and audit source code by yourself(or by hiring someone to do it on your behalf). And I am sure you cannot run an end-to-end audit of the whole Signal platform to verify that what they actually run has been built from the source code you have audited.

- Since it is centralized, Signal is prone to censorship in those countries that decide to fight it. This leads to introducing workarounds like this https://signal.org/blog/run-a-proxy/ to help people circumvent limitations in affected regions and territories.

Re: Signal says it won’t compromise on encryption

#148
post #121

Earlier quoted context omitted.

It's propaganda. It's the same reason why a large portion of Indians (even with full internet access...) are fervently pro-Putin in the context of the Ukraine-Russia war.

I'm not an Indian, but I can understand why a country that was oppressed by the Great Britain for such a long time, and endured such atrocities, can opt to support the party that stands on the opposite side of Britain. That alone could explain why not only India, but big parts of the worlds, especially the ones that suffered from the British and American imperialism, would rather see an arch-enemy of their usurper wi…

I understand this. I'm simply asserting that if one believes in this political drivel, ignoring the onslaught happening in Ukraine, then you've not progressed as a human much beyond the middle ages.

Re: Signal says it won’t compromise on encryption

#149
Neither Signal, WhatsApp, or Telegram are particularly secure. On Signal for example, your private key is protected only by a verification text message and short PIN. That's very low entropy compared to a full ED25519 keypair. It's better than SMS but don't be fooled into thinking you have Snowden-level opsec because you use one of these apps.

Use PGP and email.

Re: Signal says it won’t compromise on encryption

#150
post #144

Earlier quoted context omitted.

> If you don't store that data or delete it, you can't provide it. Can I do this easily and still have my homeserver work correctly with Matrix? Anyway, the law would probably require any operator to keep this data for a while since they have access to it. And I can't rely on my contact's homeservers to delete this data even if they can (technically and legally).

Signal certeinly can store it, because they have access to it. They have access to that data alone through the fact that they are in control of their servers and, thus, can see who sends and receives messages.

But they can't. That's the thing.

https://signal.org/blog/sealed-sender/

Post reply on HN