Live data from Hacker News

I don't trust Signal

drewdevault.com

101–110 of 473 posts

Re: I don't trust Signal

#101
post #27

>Google Play use yalp store > Packages on F-Droid are reviewed by a human being and are cryptographically signed >The app has to update itself, using a similarly insecure mechanism. F-Droid handles updates and actually signs their packages so are all android APKs. granted it's trust on first use: it accepts any signature for the first install, and only enforces the signature if you try to install an update. >A checks…

This doesn't even touch on the fact that Signal depends on Play Services. It has a websocket option, but the setting is actually not in the GUI

Hmm, how do you configure it? IIRC it just automatically used it because I don't have Play Services.

Re: I don't trust Signal

#102
This is a really poor post. Lots of in-the-weeds long-running-feud grudge holding snark, but no real examination of the issues at hand. And his assertions don't make sense in any case. You can't trust the Google Play store because a malicious actor might have swapped out the trusted roots on you. But then why should we trust F-Droid's signing infrastructure?

Then he gripes that the posted APK has to be manually checksummed to use it. If you are truly paranoid, trusting a checksum you get from the same page you get a binary is as secure as ignoring the checksum altogether. But why would you trust a hidden signature process you can't see any more? How do you know your F-Droid binary was secure?

But worst of all is this pointless assertion: "Truly secure systems don’t require trust."

There are no truly secure systems. Malicious actors could replace your Matrix app with a lookalike clone. Your phone could have a hidden keylogger built into the OS. Or the hardware. The person's phone on the other end of your communication could have been compromised. You could be being monitored by all sorts of undetectable means.

Perfect security is an unattainable goal, but good security requires acknowledging and enabling trust to play a role in the protocols and systems we develop.

Re: I don't trust Signal

#103
Seriously, if Signal become decentralized and doesn't require a phone number to use, I'd switch to it without hesitate. Call me lunatic or whatever, all the court related news, security analysis only makes me feel Signal is just another honey trap or will become one eventually, because none of these positive reviews solves trust issues existed long ago. There are better models out there, they just don't want apply, I can't stop asking why. You'd think they'll re-consider the options after so many users expressed their concerns, or at least provide multiple choices, but no, it's been years, nothing has changed.

I'd keep using Riot until then, even it's less secure and less user friendly, but it's good enough for me.

Re: I don't trust Signal

#104
post #94

Earlier quoted context omitted.

I am happy to see I am not the only person in the world that feels like this about Signal. The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.) I admire Wire for a n…

I was on Wire for a time and even got other people on board. Then the experience suddenly degraded out of nowhere. The desktop and web clients would never finish syncing. Some other stuff I don't remember. I really liked the app though. I mean the unfortunate reality of chat programs is that there are so many that when I'm having weird problems I'm not gonna spend time opening issues on GitHub and sending logs; I'll…

This. User experience is everything.

In my case, not Wire, but Signal. My Signal contact list is exactle two people long. Trying to get people to move from WhatsApp elsewhere is hard, especially if some of them even additionally installed Threema a few years back when Facebook bought WhatsApp.

But at least two people. With one of them I was regularly conversing on Signal, so much that she even preferred it to WhatsApp.

One day she messaged me on WhatsApp again. She said Signal had not set notifications for my messages a few times now, and she's fed up.

I never had that problem. Maybe she misunderstood or misconfigured something. But it doesn't matter. Signal is dead to her.

It's really easy to lose perspective as a developer how much this usability stuff matters. Sure, we all pay lip service to it, tell each other how bad the UI on some tool is and fake humility about our missing sense for anything design (including UI design).

But we don't really get it.

Re: I don't trust Signal

#105
What's wrong with using Google Play Services?

Correct me if I'm wrong, but I assume it has to do with message notifications. So, by using GCM, Signal would be leaking some metadata about when and who, etc. I assume. But wouldn't someone be able to get that same information from your ISP (with a little more work)?

You're losing the benefits of longer battery life for basically nothing.

Security isn't absolute. I don't know why this blogger has the attitude that there is such a thing.

Re: I don't trust Signal

#106
post #96

Earlier quoted context omitted.

Author here, this is a fair criticism. Other alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring (not an endorsement of any of these). I'm an old curmodgen who just uses IRC+OTR and GPG, though, so I have to depend on others for recommendations. Also, Matrix enables end-to-end encryption by default on clients that support it.

Why would you rely on others for recommending those, but not for Signal? Just don't recommend anything then, or don't criticise Signal. What's the point of convincing people to move to worse alternatives?

I personally reviewed Matrix before recommending it on my blog. The other alternatives I listed here are not endorsements.

Re: I don't trust Signal

#107
post #94

Earlier quoted context omitted.

I am happy to see I am not the only person in the world that feels like this about Signal. The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.) I admire Wire for a n…

I was on Wire for a time and even got other people on board. Then the experience suddenly degraded out of nowhere. The desktop and web clients would never finish syncing. Some other stuff I don't remember. I really liked the app though. I mean the unfortunate reality of chat programs is that there are so many that when I'm having weird problems I'm not gonna spend time opening issues on GitHub and sending logs; I'll…

Wire mobile apps have been reliable through several years of daily use. Does not require a phone number and Wire is working on interoperability with other E2E messaging services, via the IETF MLS protocol.

Re: I don't trust Signal

#108

Signal is not for state-proof encrypted communication. Not large states like the USA or Russia. If you think it is, you've been misinformed. For state actor proof communications you need to evaluate every action you take and think: "What are the assumptions that I'm making here?" One assumption is that you're not currently on anyone's radar. Are you willing to bet the entire enterprise on this assumption? How certain…

> Signal is not for state-proof encrypted communication. Not large states like the USA or Russia. If you think it is, you've been misinformed.

Ok, but in that case what does Signal offer that any random messenger with transport encryption doesn't? If your threat model doesn't include state actors then you can probably trust a) the HTTPS certificate infrastructure b) an international corporation like Facebook, so you can probably assume that no-one would tap your FB messenger messages in transit. "Not pushed to your iPad" sounds more like a bug than a feature - I want to be able to read my messages anywhere that I'm logged in as me (at least while I have my yubikey or what have you plugged into that device). Automatic deletion... eh, I would rather make a deliberate decision about when to delete things, personally.

Re: I don't trust Signal

#109
post #64
post #49

Earlier quoted context omitted.

Read the end of an article as well. We have solutions like Matrix, and like XMPP with OMEMO.

Signal did what those things failed to do which is to actually gain some popularity outside of HN. I hope Matrix takes off! In the meantime if people are convincing their families and friends to get on Signal then that's a net positive to me.

What's the point of gaining traction if it doesn't deliver on its fundamental promise?

Re: I don't trust Signal

#110
post #94

Earlier quoted context omitted.

I was on Wire for a time and even got other people on board. Then the experience suddenly degraded out of nowhere. The desktop and web clients would never finish syncing. Some other stuff I don't remember. I really liked the app though. I mean the unfortunate reality of chat programs is that there are so many that when I'm having weird problems I'm not gonna spend time opening issues on GitHub and sending logs; I'll…

Wire mobile apps have been reliable through several years of daily use. Does not require a phone number and Wire is working on interoperability with other E2E messaging services, via the IETF MLS protocol.

I'm happy for you. Buf that doesn't undo what happened to us.
Post reply on HN