Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

331–336 of 336 posts

Re: Signal says it won’t compromise on encryption

#331

Earlier quoted context omitted.

The difference between an 'abuse filter' and a censorship mechanism is semantics. By classifying political speech or image hashes you don't like as "spam", you've effectively implemented a political censorship mechanism and just gave it a different name. This is also why many privacy and security advocates are against on-device CSAM scanning. By classifying hashes of memes shared among political opposition parties as…

Evidence?

Be more specific. I already linked to the exact line number in Signal's code where they admit both that a server-side message filter exists and that the implementation is private, look at the top level comment.

Re: Signal says it won’t compromise on encryption

#332
post #276

Earlier quoted context omitted.

Those actions were not the result of a national security letter. NSLs can only require the production of existing records. They cannot require the release of the content of communications nor the collection of records which don't already exist. They must also specify the time period the records request covers which can only include up to the date the NSL was received.

As I said, they’re related. That is All Writs Act is a United States federal statute, codified at 28 U.S.C. § 1651, which authorizes the United States federal courts to issue all writs necessary or appropriate in aid of their respective jurisdictions and agreeable to the usages and principles of law. A writ is a form of written command in the name of a court or other legal authority to act, or abstain from acting, in…

NSLs don't involve data feeds. The All Writs Act involves a judicial review and issuing of a judicial subpoena. A judicial subpoena may well involve ongoing data collection. NSLs are administrative subpoenas which aren't reviewed by the judiciary before being issued and limited in scope because of that. Actions taken "via All Writs Act" are not to enable NSLs.

Re: Signal says it won’t compromise on encryption

#333

Earlier quoted context omitted.

Can y'all chill with calling every instance of a message being deleted censorship? I've heard everything from minecraft chat profanity filters to copyright infringement detection called "censorship", meanwhile there are systems filtering and changing SMS messages based on political sentiment and people living in fear of being arrested, tortured and executed for saying bad things about the ruling class. Call it what i…

The difference between an 'abuse filter' and a censorship mechanism is semantics. By classifying political speech or image hashes you don't like as "spam", you've effectively implemented a political censorship mechanism and just gave it a different name. This is also why many privacy and security advocates are against on-device CSAM scanning. By classifying hashes of memes shared among political opposition parties as…

You seem to be under the impression that this filter is based on message content. It's not. All content is e2ee, and this filter is not downloaded to the client. The filter is to stop abusive network behavior, e.g., someone enumerating every phone number to get a list of all Signal users. If you'd like, I can link you to some of the research that has been done to determine some of what they're doing (or you can search google scholar).

edit to add: I guess I should clarify, the messages in Signal are properly e2ee with ephemeral keys, and there is no content hashing or the like to leak anything to the server. It's not public yet, but if you'd like, I can share some of my research into the structure of an actual Signal message, from the TCP layer down to the encrypted payload.

Re: Signal says it won’t compromise on encryption

#334

Signal is too small a player and is therefore more likely to be bullied by governments. India is taking pot shots at it to see if it can get away with forcing them into intercepting communications. If they leave as a result, they'll simply shrug and move on. Also, I'm convinced that if Signal were to become popular they'd probably sell it to some commercial provider, since the cost of maintaining a service used by hu…

How do you know that there is not a back door in WhatsApp?

No post body was provided.

Re: Signal says it won’t compromise on encryption

#335
post #172

Earlier quoted context omitted.

The good answer: They can't verify the integrity of alternative clients and that they don't leak info The other answer: They've got somewhat of a "we know best" vibe going for them which also comes in play when you see their response to feature requests - e.g. for usernames instead of phone numbers or for "edit message" functionality like Telegram has.

>The good answer: They can't verify the integrity of alternative clients and that they don't leak info The good answer isn't even a good argument. The client is open source. People have forked it and used the Signal network. Signal asked them to stop and they did, but there is nothing stopping people from ignoring Signal's request in the future. This has nothing to do with federation. Signal could federate their netw…

What exactly is the problem anyone would be trying to solve by adding third party clients?

Re: Signal says it won’t compromise on encryption

#336
post #11

Requiring handing over encryption keys as a requirement to do business there sounds like a good way to sanction yourself from the modern world.

unfortunately, there are things they could do without "turning over encryption keys".

Scanning for keywords, doing content id on images, all kinds of other stuff that would not "turn over encryption keys".

I suspect other services do these things for advertising keywords, and to prevent objectionable images from being sent.

Post reply on HN