Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

301–310 of 336 posts

Re: Signal says it won’t compromise on encryption

#301
post #219
post #85

Earlier quoted context omitted.

Two mathematicians could literraly communicate encrypted on a piece of paper, and there would be no way to stop them other than scaring them put of doing it with threats of violence, jail or similar. There is an aspect ro this we have to acknowledge: we live in a world where everybody who knows how can create encrypted communications that are impossible or at least very costly to break. You cannot stop them from doin…

>If we ban that kind of communications, the only persons making use of it will be people who really have something to hide. Criminals, drug cartels, financial fraudsters, terrorists and the likes. Which also means they are the only ones who got to get safe communication channels. They wouldn't be safe, though. Merely using encrypted communication would be enough to warrant attention. Encryption only provides plausibl…

> They wouldn't be safe, though

Provided they are using the same channels as the rest of us. Which they will not do, unless they are stupid.

Re: Signal says it won’t compromise on encryption

#302

They might not compromise on encryption, but they have no intentions of open sourcing their censorship module either: https://github.com/signalapp/Signal-Server/blob/90490c9c8485...

Can y'all chill with calling every instance of a message being deleted censorship? I've heard everything from minecraft chat profanity filters to copyright infringement detection called "censorship", meanwhile there are systems filtering and changing SMS messages based on political sentiment and people living in fear of being arrested, tortured and executed for saying bad things about the ruling class.

Call it what it is: Signal is keeping their spam filter private. And history has shown that this is usually the right move.

Re: Signal says it won’t compromise on encryption

#304

They might not compromise on encryption, but they have no intentions of open sourcing their censorship module either: https://github.com/signalapp/Signal-Server/blob/90490c9c8485...

Can y'all chill with calling every instance of a message being deleted censorship? I've heard everything from minecraft chat profanity filters to copyright infringement detection called "censorship", meanwhile there are systems filtering and changing SMS messages based on political sentiment and people living in fear of being arrested, tortured and executed for saying bad things about the ruling class. Call it what i…

The difference between an 'abuse filter' and a censorship mechanism is semantics. By classifying political speech or image hashes you don't like as "spam", you've effectively implemented a political censorship mechanism and just gave it a different name. This is also why many privacy and security advocates are against on-device CSAM scanning. By classifying hashes of memes shared among political opposition parties as CSAM, you enable censorship, or even worse, targeted tracking of individuals over protected political speech. These systems need to be evaluated by what they can be made to do, not by what we're told they're for.

I have personally witnessed political messages being censored on Signal, server-side.

I recognize that keeping that private is what makes it effective. The argument being made isn't that the filter would be more effective if it were open source, the argument is that the filter is being abused to perform censorship, and that's the reason why it's not open source.

One of many downsides of trusting centralized platforms/services like Signal.

Re: Signal says it won’t compromise on encryption

#305
post #297

They might not compromise on encryption, but they have no intentions of open sourcing their censorship module either: https://github.com/signalapp/Signal-Server/blob/90490c9c8485...

There are legitimate reasons for not open sourcing it. It would become effortless to circumvent.

The argument isn't that it should be open sourced to improve spam detection or efficacy, the argument is that it's being misused as censorship mechanism without calling it that, and that's why it's not open source - it would become readily apparent that it's being used for political censorship if it was open source.

If it was just being used for spam filtering and not censorship, it would make much more sense to implement the blocking client-side (on the recipient's device) and provide a user-toggleable flag to disable that functionality. This would enable those who don't want spam and trust the filter to keep the exact same functionality, while allowing those who distrust it or suspect it of censorship to voluntarily opt-out for messages they receive. This would also offload processing costs from Signal's servers to user's devices, which would decrease the operational expenditure incurred by Signal.

One reason not to take advantage of that economic incentive is that you don't want your users to have the choice, and you'd not want them to have the choice if you're trying to censor them.

Re: Signal says it won’t compromise on encryption

#306
post #11

Requiring handing over encryption keys as a requirement to do business there sounds like a good way to sanction yourself from the modern world.

Especially when companies are looking to move their manufacturing from China... India just shot itself in the foot

China has been regulating encryption and requiring escrow on businesses and breaking encryption for years

Re: Signal says it won’t compromise on encryption

#307

Earlier quoted context omitted.

Signal does marketing by omission: "Intel’s SGX protects against introspection", "we depend on donations from our community", etc.

Would it be possible for you to expand on Signal not being dependent on donations?

"we depend on donations from our community" + a $105 million 0% interest loan (until 2068)¹.

¹ https://en.wikipedia.org/wiki/Brian_Acton#Signal

Re: Signal says it won’t compromise on encryption

#308

Tech companies will make all sort of noise when India, China, Turkey ask to have access and control over the data of their own people. However when NSA comes around with their secret laws and courts, they all bend the knee ...

Or go to jail.

https://en.wikipedia.org/wiki/Joseph_Nacchio

Re: Signal says it won’t compromise on encryption

#309
post #179

Earlier quoted context omitted.

It really feels like a pro-war comment. You seem to be missing a lot of context, at best.

We're going a bit off topic here but I'll expand a bit. If we both (presumably) start from the premise of "this invasion is a bad thing", then following this up with "anyone who supports it is just a moron duped my propaganda" and/or "the Russian administration are simply crazy" isn't helpful. This did not happen in isolation, it happened against a backdrop of decades of western failures in diplomacy & deterrence. Th…

I said neither of those things

Re: Signal says it won’t compromise on encryption

#310

> Signal makes its code open-source. Is anyone aware of whether they are still obscuring spam related code? For the downvoters: - https://www.reddit.com/r/privacy/comments/qlw1ag/signal_is_a... - https://signal.org/blog/keeping-spam-off-signal/

Okay, but so what? Why is this a problem? You can run a functional signal server without their spam filtering code.
Post reply on HN