Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

211–220 of 336 posts

Re: Signal says it won’t compromise on encryption

#211
post #198

Earlier quoted context omitted.

> ...your account will be associated with this phone number anyways. Messages exchanged in Signal are repudiable. That said, in a recent blog post Signal indicated that arbitrary usernames is something they're working on. > ...unlike XMPP you cannot spin up your own server and have full control over it. Signal is a better alternative for the likes of PGP because it is centralized [0]. Spam notwithstanding, Matrix has…

> Signal indicated that arbitrary usernames is something they're working on. no offense but they've been saying this for years, the feature may eventually come but I'm not holding my breath

In the most recent beta they have enabled the backend infrastructure for usernames

Re: Signal says it won’t compromise on encryption

#212
post #115

Earlier quoted context omitted.

I'm trying to imagine a ban on https for better understanfing and I remember that Australia implemented anti-encryption laws some 3-4 years ago. Can someone comment on how Australian anti-encryption laws work in a case of https? Is it illegal to use encryption (like https to send data to server in a browser) without a backdoor now in Australia?

Australia law doesn't require you to do anything until explicitly asked by the intelligence agencies. The first stage is a gentle "Request for Technical Assistence" with no penalties for no saying no. But then they can then ask again and demand you provide assistance with jail time/fines for non-compliance. The orders also come secrecy notices so you can't inform anyone (except your lawyers) that you've received the…

> The chilling effect of it is. What if they demand you give them information you do not have a way of accessing. (Eg Signal). How would you comply? Do you have to pre-empt whatever requests you MIGHT get and ensure you could back-door a user if it were required.

That's what Technical Capability Notices are for. You don't have to implement a backdoor until they force you to. They have worded the legislation to make it sound as though this cannot be used to implement "systemic weaknesses" but this is bullshit (their definition of a "systemic weakness" would be something like getting a backdoor into OpenSSL, while a backdoor in Facebook Messenger is not a "systemic weakness" because it only affects one application).

Re: Signal says it won’t compromise on encryption

#213
post #190

Earlier quoted context omitted.

Also: - There is no way to back up your message history (with photos, etc). This could be done using their (annoyingly pushed to users) "PIN", but isn't. Few people realize that if your phone dies today, your history is GONE. From what I saw, once people do realize this, it's game over for Signal. WhatsApp is just easier, "everybody is there", and it does back up your history. EDIT: Yes, it's on iOS. Yes, I realize t…

I see no reason to back-up my history ever. I don't use signal for anything that needs to be archived. Nor do any of my friends. One of the selling points of signal is the feature that it doesn't automatically save photos, this is a good feature. You manually save the photos you want to save. And I thought people regularly backed up everything worth saving from phones to non phone archive anyway.

> I see no reason to back-up my history ever. I don't use signal for anything that needs to be archived.

Every single time this comes up, someone chimes in saying they don't need it.

That does not invalidate the users who do need it. If I can't keep my messages from device to device, I'm not going to use Signal.

With far more manual effort than should be required, I can move my messages from Android device to Android device, if the old device is still functional. That's still not fully sufficient; I need a reliable automatic (encrypted) backup solution.

Re: Signal says it won’t compromise on encryption

#214
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

If you care about privacy, stop using your phone and any app. There, problem solved.

Re: Signal says it won’t compromise on encryption

#215

Earlier quoted context omitted.

Thanks. This bill seems to be about telecom infrastructure. Does not talk about metadata, or encryption. As far as I can find does not seem to touch on messaging apps as well. Was anyone able to find anything related to which provision in the bill would impact Signal.

It's explicit on the interception of any kind of data. It defines message as: “message” means any sign, signal, writing, image, sound, video, data stream or intelligence or information intended for telecommunication; And then it says that said "messages" can be "intercepted or detained or disclosed", for a really wide range of reasons, apparently without the intervention of a judge. 24.4 On the occurrence of any publ…

Thanks. To me it looks like client side encryption should be fine, or real P2P for that matter. Officer: give me the messages

Service: here they are

Officer: decrypt for me

Service: Sorry, don't have the keys.

Re: Signal says it won’t compromise on encryption

#216
post #194

Earlier quoted context omitted.

It's easy to use the free server at matrix.org. For $5/month you can get a hosted server from EMS with optional bridges to Signal/Telegram/WhatsApp. Or another paid provider: https://matrix.org/hosting/

Try to convince non-technial users to pay for something they already use for free… They don’t understand the benefits.

But why would you need to convince them? There's nothing wrong with using a free matrix.org account unless and until you do understand the benefits of using something else.

The good thing about having the federated protocol is that people can use different providers and change providers without destroying the network effects.

It's perfectly fine if most people end up using one of very few big providers as long as all providers support federation.

I think we have to make a distinction between personal communication and mass communication. The former is a question of privacy. The latter is a question of political freedoms.

Re: Signal says it won’t compromise on encryption

#217
post #190

Earlier quoted context omitted.

Also: - There is no way to back up your message history (with photos, etc). This could be done using their (annoyingly pushed to users) "PIN", but isn't. Few people realize that if your phone dies today, your history is GONE. From what I saw, once people do realize this, it's game over for Signal. WhatsApp is just easier, "everybody is there", and it does back up your history. EDIT: Yes, it's on iOS. Yes, I realize t…

Signal has backup on Android, and fairly fast image management, but it's lacking on iOS. That points to a lack of developer resources. What you call WhatsApp history is other people being able to read your messages. WhatsApp is violently agressive in demanding you use your phone and give access to your contacts. You can't use it without feeling violated.

Signal is similarly coercive about contacts - only "Yes" and "Not now", and once they get them, there's no way to delete the data they've got.

Desktop Signal still keeps showing me other people who also have Signal, but whom I've never even tried to contact via Signal, only because years ago I've mistakenly let them see my contacts.

Re: Signal says it won’t compromise on encryption

#218
post #198

Earlier quoted context omitted.

> ...your account will be associated with this phone number anyways. Messages exchanged in Signal are repudiable. That said, in a recent blog post Signal indicated that arbitrary usernames is something they're working on. > ...unlike XMPP you cannot spin up your own server and have full control over it. Signal is a better alternative for the likes of PGP because it is centralized [0]. Spam notwithstanding, Matrix has…

> Signal indicated that arbitrary usernames is something they're working on. no offense but they've been saying this for years, the feature may eventually come but I'm not holding my breath

i think SMS support was part of the reason they could not do it before, since usernames would break that feature. removing SMS makes this a non-issue. the phone number is now just an arbitrary ID string which can be replaced by any other

Re: Signal says it won’t compromise on encryption

#219
post #85

Big govt vs big tech, a battle that is being played out all over the world. Any country that value sovereignty and sees itself as an independent actor rather than a vassal state, must take the position India is taking, or else be susceptible to foreign owned apps influencing its citizenry. The only alternative would be to insist Signal hire its security agents into product / moderator roles, so that oversight can be…

Two mathematicians could literraly communicate encrypted on a piece of paper, and there would be no way to stop them other than scaring them put of doing it with threats of violence, jail or similar. There is an aspect ro this we have to acknowledge: we live in a world where everybody who knows how can create encrypted communications that are impossible or at least very costly to break. You cannot stop them from doin…

>If we ban that kind of communications, the only persons making use of it will be people who really have something to hide. Criminals, drug cartels, financial fraudsters, terrorists and the likes. Which also means they are the only ones who got to get safe communication channels.

They wouldn't be safe, though. Merely using encrypted communication would be enough to warrant attention. Encryption only provides plausible deniability if everyone uses it for mundane stuff.

Re: Signal says it won’t compromise on encryption

#220
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

>> Since it is centralized, Signal is prone to censorship in those countries that decide to fight it.

Yes, this. It might be "fighting for privacy" now, but they can change their mind at any point. With new management, eventual profit seeking, government coercion, etc, this could change with a simple app update. It is more likely to me that it remains private because it isn't particularly successful. I find a lot of people have it but rarely use it.

It also isn't clear to me what is in it for donors such as EM. It is much easier to trust a system with correctly designed incentive structures.

Post reply on HN