Live data from Hacker News

Registration without a phone number on Signal will use zero-knowledge proofs

community.signalusers.org

61–70 of 201 posts

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#61

Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.

Ugh wtf so I need a Google account on Android? That's not going to happen. For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet. Just allow monero payments or something. Alongside Google play for the sheep that want to use that.

Are you being hyperbolic, or do you really consider Google the worst with regards to privacy.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#62
post #54

Earlier quoted context omitted.

They avoid Monero because Signal and the EFF are actually the feds and this is all theater.

Claims without evidence can be dismissed without evidence. Signal is not robust for metadata protection. Neither do they advertise anonymity. They take steps to protect metadata but it's nothing compared to SimpleX. If it's "the feds", then how? There's reproducible builds on all platforms except iOS so we know the source code is what's running on our devices. Can you point to the code where the E2EE is compromised?…

[dead]

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#63
post #60

Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.

OpenAI is 501c3, should they also be required to release everything?

Yes

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#64
post #22

Earlier quoted context omitted.

Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not? I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?

> Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not? While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data. I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connect…

It's true someone snooping at either end of a conversation could over time correlate timing and sizes to show that two users are communicating, but that's the most they can do. Signal is not peer to peer so you're not connecting to your recipient, and signal itself has enough raw volume that simply correlating sizes and timing of a small number of messages wouldn't really be sufficient to know who is communicating with who.

I think they could make that significantly more difficult by adding csprng delays and padding to the messages. That way you can't really effectively correlate timing and sizes without direct access to signals inner workings. I'm not sure what signal's actual throughput is, but if think as a paid feature it could be economical.

Another crazier way would be to send every message to a large number random latched recipients. Good way to 1000x your bandwidth.

> The metadata is as valuable as the data.

This can be true if you are able to get ahold of a user's device and access their signal messages. It's not true in most other cases. I don't particularly care if you know that I am talking to someone specific as much as I care that you don't know what I'm saying.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#65
post #22

Earlier quoted context omitted.

Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not? I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?

> Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not? While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data. I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connect…

> the surveillance networks can capture metadata - who talks to who and when

If this is part of your threat model then I would suggest a different tool such as SimpleX since it uses onion routing and can be configured to always use private routing/relays.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#66

I know for a fact If you use "signal" matrix or whatever "security" app, you will get branded a terrorist in India, your life will be upended and you will face a long list of problems. https://timesofindia.indiatimes.com/india/ats-probes-use-of-... https://www.aninews.in/news/national/general-news/accused-da... https://www.deccanherald.com/india/secure-messaging-apps-lik... https://india-employmentnews.com/tech-categ…

[dead]

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#67
post #61

Earlier quoted context omitted.

Ugh wtf so I need a Google account on Android? That's not going to happen. For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet. Just allow monero payments or something. Alongside Google play for the sheep that want to use that.

Are you being hyperbolic, or do you really consider Google the worst with regards to privacy.

The most ubiquitous, absolutely. Their data collection is unparalleled. They're on almost every website, app, they have fingers into payment and browsers and mobile OSes.

In terms of what they do with big data there's more evil parties like Palantir but data abuse starts with collecting it, and I would object to it even if Google promised to only use it for good. For me my privacy is already violated when my data is collected, not just when it's abused. And I do consider Google's use of that data abusive, just not in the worst ways.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#68
post #60

Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.

OpenAI is 501c3, should they also be required to release everything?

Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#69

Earlier quoted context omitted.

I'm not about to trust a google branded device. Even if the Graphene folks are on the up and up, google sure as hell isn't.

That's not based in reality. Why would Google have a hardware backdoor when 99.9% of their users run their software giving them the data they want. Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation. It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the fi…

But GrapheneOS relies on a proprietary, black-box security chip from Google... who pinky-promised to open-source it but never did, and that just doesn't sit well with me.

I think it's entirely possible that a compromised Titan module (whether such code ships with the device or is updated at a later point) could leak keys via some covert method, and possibly transmit via the baseband or through some other application/method where the OS is not really aware of what's going on.

Post reply on HN