Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

241–250 of 336 posts

Re: Signal says it won’t compromise on encryption

#241

Neither Signal, WhatsApp, or Telegram are particularly secure. On Signal for example, your private key is protected only by a verification text message and short PIN. That's very low entropy compared to a full ED25519 keypair. It's better than SMS but don't be fooled into thinking you have Snowden-level opsec because you use one of these apps. Use PGP and email.

> your private key is protected only by a verification text message and short PIN. That's very low entropy compared to a full ED25519 keypair. Can you explain what you mean by this? In practice, I can see the argument that the only verified identity (phone number) for most users is the one protected by a flimsy SMS verification message, but I don't believe that that implies your private key is terribly vulnerable to…

> True that Signal's UI makes this hard to do

Do you think so? The app provides a "Safety Number" and QR code with built-in scanner to verify that yup, your device and their device have nobody in the middle. It has a visible reminder that you checked this person's actual identity (if you did) and a message appears if the keys change. If you are "rigidly adhering" to protocol your response should be to arrange an in-person meet-up to reconfirm, not "New phone? Cool".

Re: Signal says it won’t compromise on encryption

#242
post #180

Earlier quoted context omitted.

90% world the world (i.e. nearly everybody outside the west) has a similar position on the Russia-Ukraine issue as India though. Is 90% of the world propagandized? Or can they have a legit different perspective on things?

This is inaccurate at best. Most Asian countries have shown support for Ukraine. Most African countries as well, with a few notable exceptions. There's no "different perspective" when it comes to slaughtering innocent civilians and other war crimes.

Countries can have more complex positions than the simple "Ukraine good, destroy Russia" (or its inverse, "Russia good, invade Ukraine") dichotomy that many in the west go for. Many countries don't approve of Ukraine's invasion, but also don't like NATO very much and show some understanding for Russia's position.

Most countries wish to be neutral on this matter, continuing to trade with both Russia and the west, i.e. similar to India's position. Look at how many countries chose to sanction Russia. Of those who voted against Russia, most who chose to sanction are western countries. Very few Asian and African countries imposed sanctions. 87% of countries chose not to impose sanctions.

Re Africa, see Why African Countries Had Different Views on the UNGA Ukraine Resolution, and Why This Matters — Center for Strategic and International Studies: https://www.csis.org/analysis/why-african-countries-had-diff...

Re: Signal says it won’t compromise on encryption

#243

I have nothing against Signal, Moxie, etc — but it attracts high-value targets. As such, Signal is an extremely high-value target. >> Signal knows nothing about who you are. This is based on trust, not systematic proofs, Signal knows this, yet never tells its users. For example, Signal uses Intel’s Software Guard Extensions (SGX) - which is know to have multiple attacks, any of which Signal might be forced to run usi…

> any of which Signal might be forced to run using national security letter. NSLs can demand information but cannot compel action. The govt cannot use an NSL to force you into military service, for example, or force you to hack someone else’s computer (which is essentially what you are suggesting).

This is correct but the All Writs Act can compel third parties to help in a criminal investigation, like a phone company being asked to help wiretap a phone. Signal by design at the most would have only contacts that you shared and IP address/access log. Apple was able to argue that they shouldn’t be forced to push an update to unlock the phone of that terrorist in California so there are limits to it but they are not entirely clear.

Re: Signal says it won’t compromise on encryption

#244
post #166

Earlier quoted context omitted.

The solutions for the most of the issues you are describing comes with great usability costs. It is already hard to make non-tech people to switch from WhatsApp.

How come, signal works exactly the same as whatsapp. I forced my friends and (older) relatives to change to signal and there has been no problems and everyone is happy.

> How come, signal works exactly the same as whatsapp.

I think right there is a powerful impediment. It's not compelling to switch for most, especially when people they know are still on whatsapp.

Re: Signal says it won’t compromise on encryption

#245
post #190
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

Also: - There is no way to back up your message history (with photos, etc). This could be done using their (annoyingly pushed to users) "PIN", but isn't. Few people realize that if your phone dies today, your history is GONE. From what I saw, once people do realize this, it's game over for Signal. WhatsApp is just easier, "everybody is there", and it does back up your history. EDIT: Yes, it's on iOS. Yes, I realize t…

Not having the ability to backup and archive my messages means Signal controls my data, not me. It reminds me of my past fights with closed source, proprietary software and file formats.

Re: Signal says it won’t compromise on encryption

#246
post #224

Earlier quoted context omitted.

How come, signal works exactly the same as whatsapp. I forced my friends and (older) relatives to change to signal and there has been no problems and everyone is happy.

Network effects and minor UX issues. “VERIFY PIN NOW” pop-up every week for example.

I love that feature

Re: Signal says it won’t compromise on encryption

#248

Is there anything more secure than signal that is widely used? Maybe something that doesn’t leak metadata or require a phone number?

What metadata does signal leak? They have sealed sender since 2018 which means the most interesting metadata isn’t shared. Just don’t share contacts and register with a disposable number.

Re: Signal says it won’t compromise on encryption

#249
post #178

Earlier quoted context omitted.

This talk by professor Jeffrey Sachs at the Athens Democracy Forum couldn't be more timely. https://youtu.be/Ec2E4k1K52E Different countries have long, deep-rooted political cultures that go back centuries. "Democracy vs authoritarianism" is the wrong lens: different systems are complex and cannot be ranked on an easy scale like we want them to.

It's not the wrong lens, it's a lens that authoritarian governments and their supporters ( https://en.wikipedia.org/wiki/Jeffrey_Sachs#China ) don't want people to use.

Interestingly, those push this sentiment the strongest, are also often those who deny others of having any sort of legitimate perspective, using methods that boil down to character assasination rather than argumentative refutation. It seems that such people want to monopolize on what constitutes the truth. That seems a bit... authoritarian to me?

Re: Signal says it won’t compromise on encryption

#250
post #243

Earlier quoted context omitted.

> any of which Signal might be forced to run using national security letter. NSLs can demand information but cannot compel action. The govt cannot use an NSL to force you into military service, for example, or force you to hack someone else’s computer (which is essentially what you are suggesting).

This is correct but the All Writs Act can compel third parties to help in a criminal investigation, like a phone company being asked to help wiretap a phone. Signal by design at the most would have only contacts that you shared and IP address/access log. Apple was able to argue that they shouldn’t be forced to push an update to unlock the phone of that terrorist in California so there are limits to it but they are no…

Idea that Apple would not add backdoors privately regardless of what actions they take publicly is a stretch give Apple has obviously been more than happy to tailor their systems to China’s demands. Core difference between China and US is that US is fine on government spying on it as long as it’s done in secrecy.
Post reply on HN