Live data from Hacker News

Registration without a phone number on Signal will use zero-knowledge proofs

community.signalusers.org

91–100 of 201 posts

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#91
post #15

I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".

Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there. I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.

WhatsApp is also sufficient for the average person. So is SMS. But they're not even slightly secure.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#92
post #22

Earlier quoted context omitted.

> Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not? While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data. I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connect…

> the surveillance networks can capture metadata - who talks to who and when If this is part of your threat model then I would suggest a different tool such as SimpleX since it uses onion routing and can be configured to always use private routing/relays.

Session uses onion routing. SimpleX does not.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#93

Earlier quoted context omitted.

That's not based in reality. Why would Google have a hardware backdoor when 99.9% of their users run their software giving them the data they want. Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation. It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the fi…

But GrapheneOS relies on a proprietary, black-box security chip from Google... who pinky-promised to open-source it but never did, and that just doesn't sit well with me. I think it's entirely possible that a compromised Titan module (whether such code ships with the device or is updated at a later point) could leak keys via some covert method, and possibly transmit via the baseband or through some other application/…

The government only gets to use this once, and they probably won't use it on you.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#94
post #22

Earlier quoted context omitted.

> Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not? While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data. I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connect…

It's true someone snooping at either end of a conversation could over time correlate timing and sizes to show that two users are communicating, but that's the most they can do. Signal is not peer to peer so you're not connecting to your recipient, and signal itself has enough raw volume that simply correlating sizes and timing of a small number of messages wouldn't really be sufficient to know who is communicating wi…

> Signal is not peer to peer

Isn't it? I think it has a setting, disabled by default, to proxy connections via a Signal server. If you're not doing that ... it must be P2P? Probably with the IP address of the person you're communicating with in the header of every packet?

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#95
post #88

Earlier quoted context omitted.

Maybe WhatsApp gives them a ton of metadata like all their contacts, when they chat and with who, IPs, etc. Signal only gives out either time registered or last used last time I checked.

WhatsApp uploads decrypted chats to the cloud once a week.

Source?

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#96
post #68

Earlier quoted context omitted.

Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.

Perhaps it shouldn't necessitate it, but I can't think of a good reason why not. If it were expensive to release it, that would be a reason. But it costs roughly zero dollars to create a public repo on GitHub and a cron job to push to it once a day. Making the system public potentially increases the likelihood of a hack, which would be bad for Signal users. But relying on this argument to keep the source secret is, I…

How about they: 1. Don’t want hack competitors launching products using their code 2. Don’t want the resulting fracture in the community

If I were Signal I wouldn’t want either of those.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#97

Per the commits, this will require a purchase with Google Play Billing to mitigate spam while keeping the SMS verification option.

Ugh wtf so I need a Google account on Android? That's not going to happen. For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet. Just allow monero payments or something. Alongside Google play for the sheep that want to use that.

> Just allow monero payments or something.

This is the right solution. A one-time payment in crypto, say $5, ought to be enough to prevent spam. That being said, Signal has demonstrated (when presented a warrant) that they do not store phone numbers. If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#98
post #97

Earlier quoted context omitted.

Ugh wtf so I need a Google account on Android? That's not going to happen. For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet. Just allow monero payments or something. Alongside Google play for the sheep that want to use that.

> Just allow monero payments or something. This is the right solution. A one-time payment in crypto, say $5, ought to be enough to prevent spam. That being said, Signal has demonstrated (when presented a warrant) that they do not store phone numbers. If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.

> If I remember correctly all they stored was an account ID and a UNIX timestamp such as the last login.

How do they perform address book matching without an phone number? It just being accessible by SGX does not really count as not storing it.

Problem with phone numbers is they are to short to store as a hash, since you can brute force the sha256 of an phone number in a trivial amount of time on a single consumer device

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#99

Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.

Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims about being privacy conscious.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#100
post #61

Earlier quoted context omitted.

Ugh wtf so I need a Google account on Android? That's not going to happen. For an org that pretends to care about privacy you'd imagine there'd be a way to avoid, you know, the biggest privacy invader on the planet. Just allow monero payments or something. Alongside Google play for the sheep that want to use that.

Are you being hyperbolic, or do you really consider Google the worst with regards to privacy.

Google is a bad as a phone number since it also has strong ties to your real identity
Post reply on HN