Live data from Hacker News

Signal app downloads spike as US protesters seek message encryption

qz.com

1–10 of 367 posts

Re: Signal app downloads spike as US protesters seek message encryption

#3

I hope one day apps like Signal will be the default for everyone , not just protesters in a time of crisis.

will only happen if phone manufactures ship them by default rather than the unsecure by default ones they ship atm.

Sounds crazy when I say it outloud...

Re: Signal app downloads spike as US protesters seek message encryption

#4
One has to wonder about behind the scenes heuristics as it pertains to taking a chance distributing a backdoored version sideloaded into the App Stores. One also wonders about whether the encryption or app are possibly compromised generally (even if the source is vetted and distributions are verified)

Perhaps most of interest though would be how many phones are owned otherwise, to give access to the protester Signal comms anyway

And also metadata must still fly around anyway, no?

Re: Signal app downloads spike as US protesters seek message encryption

#5

One has to wonder about behind the scenes heuristics as it pertains to taking a chance distributing a backdoored version sideloaded into the App Stores. One also wonders about whether the encryption or app are possibly compromised generally (even if the source is vetted and distributions are verified) Perhaps most of interest though would be how many phones are owned otherwise, to give access to the protester Signal…

Signal does a pretty good job at minimizing the metadata it has access to. For example, the app can tell you who of your contacts has Signal installed but the Signal service itself never gets to see your contacts (https://signal.org/blog/private-contact-discovery/).

Re: Signal app downloads spike as US protesters seek message encryption

#7
Just an anecdote, I live close to the town I grew up in, which happens to have a large high-end mall. Over the weekend there have been large peaceful protests (“protest” perhaps isn’t even the right word, more like a show of solidarity) in the town common, a 2-acre square at the center of town.

Police apparently got a tip on Monday night that a separate group was planning on looting the mall. They intercepted a convoy of cars many with out of state plates gathering in the empty parking lot and which fled when they saw the police.

I guess that’s one thing that works in favor of suburban malls being only reachable via car, versus the destruction inflicted upon urban malls in my State.

Apparently there had been public social media posts calling for the looting which got passed along to local police which deployed ahead of time to close the mall and clear out the parking lots.

Op sec is particularly difficult I guess when these groups do not have pre-formed networks and are just sending out public recruitment posts to commit crimes.

Anecdote aside, I think that Signal isn’t going to support the many-to-many broadcast messaging that large groups would need to organize effectively (whether peaceably or otherwise) and a system which allowed mass coordination is that much more likely to be infiltrated (see e.g. Project Veritas’ latest work against Antifa).

Re: Signal app downloads spike as US protesters seek message encryption

#9

Honest question for those in the know: If I wanted to run my own personal “analysis” to verify the security of Signal, where would I start? Is it even possible? Just curious if there was a way to “know” rather than “trust”.

Learn cryptography to a high level then read the source code?

Re: Signal app downloads spike as US protesters seek message encryption

#10

Honest question for those in the know: If I wanted to run my own personal “analysis” to verify the security of Signal, where would I start? Is it even possible? Just curious if there was a way to “know” rather than “trust”.

Learn cryptography to a high level then read the source code?

How do you know that the binary you run actually corresponds to the source code you read?

EDIT: and would you then also review every commit to make sure nothing bad gets introduced? No, at some point you have to place trust in the vendor, the developers, independent audits, etc.

Post reply on HN