Live data from Hacker News

Registration without a phone number on Signal will use zero-knowledge proofs

community.signalusers.org

191–200 of 201 posts

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#191
post #93

Earlier quoted context omitted.

But GrapheneOS relies on a proprietary, black-box security chip from Google... who pinky-promised to open-source it but never did, and that just doesn't sit well with me. I think it's entirely possible that a compromised Titan module (whether such code ships with the device or is updated at a later point) could leak keys via some covert method, and possibly transmit via the baseband or through some other application/…

The government only gets to use this once, and they probably won't use it on you.

Why? They’ll use it as many times as they want while claiming they used something else.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#192
post #184

Earlier quoted context omitted.

Matrix is a vastly different protocol with vastly different privacy implications. Things like leaking reaction metadata outside of the encrypted envelope (though there finally is an MSC to fix that) should make that obvious. Matrix is cool tech and I use it every day, but comparing Matrix to Signal doesn't make much sense. You can't do what Signal does with Matrix or XMPP, simply because the lack of federation afford…

> As for the second point, Matrix's ever-moving target of a protocol makes selecting a client or server that covers all of your needs a massive pain. Currently, Matrix's primary server software, Synapse (which is also at the base of the matrix.org server many people default to when joining the network), is violating the Matrix protocol, making it impossible to invite users to chat if they are on compliant Matrix serv…

This will be referring to enforcing MSC4311 (https://github.com/matrix-org/matrix-spec-proposals/pull/431...) stripped state validation. Synapse announced a 1 year compatibility window to avoid ecosystem fragemtnation: https://github.com/element-hq/synapse/issues/19943. However, due to MSC4311 not better outlining how to handle compatibility, another server implementation chose to enforce the MSC more rapidly, breaking compatibility with everyone who hadn't yet implemented the MSC - including Synapse, which hadn't actually implemented it yet. Speaking as the lead of the Matrix Spec Core Team, we should have handled this better. https://github.com/element-hq/synapse/pull/19723 is the Synapse implementation which is now in the process of landing.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#193

Earlier quoted context omitted.

I'm not about to trust a google branded device. Even if the Graphene folks are on the up and up, google sure as hell isn't.

That's not based in reality. Why would Google have a hardware backdoor when 99.9% of their users run their software giving them the data they want. Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation. It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the fi…

Why would google serve malware and scams in their ad network?

Google is a dodgy company. Placing any trust in them is foolish.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#194
post #99

Earlier quoted context omitted.

Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims abou…

"Federation freezes the technology" https://signal.org/blog/the-ecosystem-is-moving/

> "Federation freezes the technology" https://signal.org/blog/the-ecosystem-is-moving/

I didn't say it needed to be federated, I said the infra automation code needs to be opened.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#195

Earlier quoted context omitted.

Forgot about that and that def was bad, though imo not really on Signal and would have just as much affected any XMPP app, no? To me this definitely didn't "[throw] it all away" as in your messages were still only on your phone and never decrypted on any server or w/e.

Well that's the thing, you just don't know what happens once you let Signal send notifications via Apple/Google - clearly they get them plaintext, and who knows if they're retained and subpoena-able directly from Apple/Google. The leak via notifications DB not being cleaned up is just the shot across the bow. You pay a price for convenience. Anyway, I'm not OP, and they have a mad setup (XMPP via Tor) which is a flak…

to be clear though notifications do the decryption on device themselves. signal uses apple/play services only to notify the device that there has been a message, none of the contents are delivered over these services. if you cant trust the device to do that then no messaging app could ever be secure enough

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#196
post #15

Earlier quoted context omitted.

Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there. I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.

>Figure out your adversaries, how much power they have and what they are willing to spend. All of it.

Unless your adversary is divine this isn't true. In general people who believe this way make really bad trade-offs and as a result probably have worse security than most people.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#197
post #91
post #15

Earlier quoted context omitted.

Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there. I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.

WhatsApp is also sufficient for the average person. So is SMS. But they're not even slightly secure.

The average person might be legit worried about dragnet (non targeted) evensdropping of non encrypted communication. This is rational given what Snowden said.

So for the average person, WhatsApp (which is E2E encrypted) is probably quite secure. SMS is not.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#198

Earlier quoted context omitted.

Well that's the thing, you just don't know what happens once you let Signal send notifications via Apple/Google - clearly they get them plaintext, and who knows if they're retained and subpoena-able directly from Apple/Google. The leak via notifications DB not being cleaned up is just the shot across the bow. You pay a price for convenience. Anyway, I'm not OP, and they have a mad setup (XMPP via Tor) which is a flak…

to be clear though notifications do the decryption on device themselves. signal uses apple/play services only to notify the device that there has been a message, none of the contents are delivered over these services. if you cant trust the device to do that then no messaging app could ever be secure enough

> if you cant trust the device to do that then no messaging app could ever be secure enough

This is the whole point. Signal actively prevents me from using it outside of the Apple-Google duopoly. Other messaging apps are not like this.

Re: Registration without a phone number on Signal will use zero-knowledge proofs

#199
post #134

Earlier quoted context omitted.

Is there a messenger that allows anonymous group chats, i.e. for union organizing in a company? As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it. Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.

Why not? Plenty people already use a dedicated '2FA' phone for Work under BYOD policies when they don't want to install any 'work' software on their 'personal' phone.

But they won‘t buy a second personal phone to protect their privacy in a chat group.
Post reply on HN