Live data from Hacker News

I don't trust Signal

drewdevault.com

111–120 of 473 posts

Re: I don't trust Signal

#111

"If Edward Snowden and Bruce Schneier are going to spout the virtues of the app, I expect it to actually be secure when it matters - when vulnerable people using it to encrypt sensitive communications are targeted by smart and powerful adversaries." Because if the adversary is, say, an abusive ex that happens to work for the telco, for example, then it doesn't matter. Unless you're actively hunted by a G7 country you…

How do you defend abused spouses in discourse by comparing their needs to people hunted by the most powerful political forces? Surely these two cases ought not be on the same table for comparison.

The original autor outright dismissed the entire class of threats, which, while they may seem "lesser," are also far more common. And it's not just abusive exes, not even every state actor has access to an NSA. Neither Signal nor any other existing application based by the same protocol (which exist and are _more_ popular than Signal itself — What's App is one, for example) are sufficient, but on the other hand, it requires far less knowledge to operate.

Signal comes from recognition that very few people can practically operate high-effort tools, and if the effort to operate a fancy tool distracts them too much from the things they actually aim to do (it's rare that someone's goal in life is "using Matrix"), they'll fall back on something that doesn't distract them.

For example, even when facing a state actor — if training your cadres to securely operate an encryption tool takes away too much from the core activism of your organization, the tool is no longer helpful. Same applies if the actual overhead of using it ("both have to be online" requirements, for example, or for somewhat lower threat profiles, "no emoji") makes it impractical.

For most people the threat is going to be someone they know, or high-volume-low-effort attempts. Whether it's an ex or a boss or even most states, it's unlikely they're facing NSA. They often have a lot of other things to do, and neither their ability nor want to enforce technical solutions on others are high. That's the range Signal-backed apps generally target.

Re: I don't trust Signal

#112
post #67

Earlier quoted context omitted.

I’m pretty sure that isn’t true. They can be used to compel you to build interception capabilities.

source?

The big Apple vs FBI high profile lawsuit for one. Granted that was a telegraphed precedent seeking exercise by "accidentally" losing access to the work phone after the terrorists destroyed their personal phones before the attack.

Re: I don't trust Signal

#113
post #36
post #2

I trust it more than unencrypted SMS or Facebook Messenger. I trust it less than p2p chat over an encrypted network I control with layered defense in depth. Security is not a boolean.

Security is not a boolean, but when your whole selling point is security you'd better be good at it. I trust Signal the same amount as Facebook Messenger or any other centralised messaging system that uses transport encryption (e.g. Skype, IRC+SSL, WhatsApp...). But what's the USP that means I should use Signal rather than any alternative?

Their USP is "security made simple", in other words: use Signal because it's as easy as the mainstream alternatives, but far more secure (but not perfect).

Re: I don't trust Signal

#114
post #110

Earlier quoted context omitted.

Wire mobile apps have been reliable through several years of daily use. Does not require a phone number and Wire is working on interoperability with other E2E messaging services, via the IETF MLS protocol.

I'm happy for you. Buf that doesn't undo what happened to us.

Have you filed a bug report on github?

Re: I don't trust Signal

#116
post #60
post #13

TL;DR he doesn’t trust Signal because he doesn’t trust the Android operating system, and something about federation. > No doubt these are non-trivial problems to solve. But I have personally been involved in open source projects which have collectively solved similarly difficult problems a thousand times over with a combined budget on the order of tens of thousands of dollars. Shut up and code then. I’ll personally r…

The author expressly endorses Matrix.

[deleted]

Re: I don't trust Signal

#117
post #92
post #82

Earlier quoted context omitted.

Is it even possible for the Signal servers to keep track of who you talk to, when, and how often? I was under the impression that those two data points they stored were the only thing they _could_ store, because the rest is sent to the servers encrypted. Edit: Yes, apparently they have a method of doing private contact discovery and, IIUC, even a method for the client to verify that the server is running the source c…

Signal has to be able to route messages from user a to user b through their centralized server, so at a minimum they are capable of logging "This user sent a message that we relayed to this other user".

Further, they don't have to look at the message to also log the time the message was received.

That's why I've always appreciated the concept of Mixmaster's ability to delay sending messages by a fixed number of hours or a random amount in a range as an attempt to stymie traffic analysis.

Re: I don't trust Signal

#118
post #96

Earlier quoted context omitted.

Why would you rely on others for recommending those, but not for Signal? Just don't recommend anything then, or don't criticise Signal. What's the point of convincing people to move to worse alternatives?

I personally reviewed Matrix before recommending it on my blog. The other alternatives I listed here are not endorsements.

Then why would you recommend a solution that hasn't even enabled end-to-end encryption by default?

Re: I don't trust Signal

#119
post #110

Earlier quoted context omitted.

I'm happy for you. Buf that doesn't undo what happened to us.

Have you filed a bug report on github?

I already mentioned in my comment above that when a chat app misbehaves I don't spend time doing that and that my friends are even less likely to. It might seem unfair to you but that's just how it is. If it doesn't work I move on. Best of luck to Wire though.

Re: I don't trust Signal

#120
post #38

I don't know anything about Moxie derailing threads or anything like that but if we just listened to critics all the time then we just wouldn't have anything. Signal is better than a lot of what is out there and being used as scale and that counts for something. More secure is always better than not secure at all.

For most products it's better to have something than nothing, but not for cryptography. Bad encryption can be worse than no encryption, since it leads to a false sense of security. So it's really important to get it right, and worth criticizing even if you don't have anything better.
Post reply on HN