For people curious, it looks like they are discussing it in the community but only the mod is involved and I don't think they (Herohtar) are an employee. While the block was unintentional this doesn't seem like the right way to handle the situation and Moxie should have been clearer and that would have avoided the issue. It is easy to interpret the response given as being brushed off. TLDR: DuckSoft got autobanned be…
People who run the project get to pick the bug tracker. Its really next level entitlement to not let maintainers choose the place they track bugs.
Signal's TLS Proxy Failed to Be Probing Resistant
11–20 of 46 posts
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#12How long did he wait for the signal forum to approve his account? The guy, or girl, seems rather aggressive. It's mentioned they've not slept in a while...
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#13Earlier quoted context omitted.
People who run the project get to pick the bug tracker. Its really next level entitlement to not let maintainers choose the place they track bugs.
That's fine. I'm not sure why that means they shouldn't be more clear. The GH comment was a preference. The problem here is that the message Signal sent sounds generic and can easily be interpreted as brushing the person off. They clearly interpreted it that way.
Afaict, its not like they are reporting a drop everything issue. Did anyone actually think that a determined adversary would not be able to distinguish between one of their proxies and a generic TLS server, given sufficient resources?
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#14Although i do wonder why signal didn't reuse the work tor did with obfuscated bridges.
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#15Earlier quoted context omitted.
That's fine. I'm not sure why that means they shouldn't be more clear. The GH comment was a preference. The problem here is that the message Signal sent sounds generic and can easily be interpreted as brushing the person off. They clearly interpreted it that way.
Why shouldn't people who post in the wrong place get a generic message? Afaict, its not like they are reporting a drop everything issue. Did anyone actually think that a determined adversary would not be able to distinguish between one of their proxies and a generic TLS server, given sufficient resources?
Because people aren't clairvoyant and it is reasonable to assume that people that post stuff on GitHub accept issues, just like the main Signal account does. The generic message, without original clarity in how to note an issue, is easy to interpret as being ignored. Especially as they had a false positive ban being flagged as spam. I understand Signal's pov and I understand DuckSoft's. I think Signal has the higher responsibility in clarity than some random person trying to note a flaw they found.
Look, you can like Signal and still think they made the wrong move. I've used it every day for years and converted the majority of my friends. No one expects Signal to be perfect.
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#16I get why the signal team wanted something to use HTTPS, even networks with completely insane firewalls accept it and they get to reuse existing domain fronting code, but existing tools continues to viable in Iran and would have made much more sense in the circumstances.
[1] https://blog.torproject.org/learning-more-about-gfws-active-...
[2] https://github.com/Yawning/obfs4/blob/master/doc/obfs4-spec....
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#17Earlier quoted context omitted.
Why shouldn't people who post in the wrong place get a generic message? Afaict, its not like they are reporting a drop everything issue. Did anyone actually think that a determined adversary would not be able to distinguish between one of their proxies and a generic TLS server, given sufficient resources?
> Why shouldn't people who post in the wrong place get a generic message? Because people aren't clairvoyant and it is reasonable to assume that people that post stuff on GitHub accept issues, just like the main Signal account does. The generic message, without original clarity in how to note an issue, is easy to interpret as being ignored. Especially as they had a false positive ban being flagged as spam. I understan…
Luckily they have a generic message to read. No clairvoyancey required.
I'm not defending signal here because i just like signal. Almost any other open source project would have responded the same way. Many would probably have been less polite about it. If you send a personalized note to everyone who reports a bug incorretly, you won't have any time to actually fix bugs.
Edit: i agree though that the false positive spam ban is a bit unfortunate. Shit happens sometimes. I maintain the generic message was totally reasonable and they should not do anything different in that regard if they could do it over again. The spam ban however was understandable but obviously should not have happened.
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#18Moxie deserves an ACM award for his contributions to crypto but he shouldn't be leading the project. Maybe posting on the Discourse forum was the right thing to do here. I just see a lot of hostility between Signal employees and those wishing to make the project a little bit better.
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#19Earlier quoted context omitted.
People who run the project get to pick the bug tracker. Its really next level entitlement to not let maintainers choose the place they track bugs.
That's fine. I'm not sure why that means they shouldn't be more clear. The GH comment was a preference. The problem here is that the message Signal sent sounds generic and can easily be interpreted as brushing the person off. They clearly interpreted it that way.
Re: Signal's TLS Proxy Failed to Be Probing Resistant
#20Moxie deserves an ACM award for his contributions to crypto but he shouldn't be leading the project. Maybe posting on the Discourse forum was the right thing to do here. I just see a lot of hostility between Signal employees and those wishing to make the project a little bit better.
That so-called hostility seems to be pretty one-sided IMO. The response from the Signal dev seemed pretty calm and reasonable, but OP seemed to take it as a personal insult for no reason. Some projects don't want to discuss issues on GitHub and prefer a forum they have control over; that's totally understandable.
I'm not gonna sign up to the fivetrillionth forum or bug tracker for your special snowflake software. If you don't allow bug reports via github issues, you won't get mine.