Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

111–120 of 336 posts

Re: Signal says it won’t compromise on encryption

#111
post #11

Requiring handing over encryption keys as a requirement to do business there sounds like a good way to sanction yourself from the modern world.

I remember an IETF meeting where this was discussed and turned down. This was 25+ years ago, and it seems to pop up again and again.

https://www.ietf.org/rfc/bcp/bcp200.html

Re: Signal says it won’t compromise on encryption

#112
post #99

Earlier quoted context omitted.

Presumption of innocence, or do you have seen any evidence to prove it exist, besides Durov's shit from time to time?

In the context of privacy, you can pretty much assume every black box is compromised. With Telegram this black box is the server (the client is open source); with WhatsApp, it's the client. I suppose there's threat models where WA still wins, but knowing it's owned by Meta, I have a hard time imagining what such a threat model would look like.

Is the Whatsapp client really a black box? APKs are fairly straightforward to decompile back to Smali or a reasonable approximation of Java, or people on rooted devices can hook it with Frida. Of course source code would be better, but it would be pretty brazen to stick a backdoor in an app store release. App versions for popular apps get archived by numerous third-party sites, so even a temporary backdoor in one specific version would be archived forever. That would be putting their reputation and billions of dollars on the line.

Non-E2E with black box server code like Telegram is far more concerning, in my opinion. With a system like that, it would be trivial to backdoor and leave behind no evidence after the fact.

Re: Signal says it won’t compromise on encryption

#113

Earlier quoted context omitted.

> Any country that value sovereignty and sees itself as an independent actor rather than a vassal state, must take the position India is taking, or else be susceptible to foreign owned apps influencing its citizenry. The only alternative would be to insist Signal hire its security agents into product / moderator roles, so that oversight can be conducted in more implicit ways. Horrifying take: The implications from su…

would the US accept an Indian owned app, which was not subject to US legal jurisdiction?. The issue at stake is one of national security - we have seen that this trumps individual rights whenever the two are in conflict. Look at the creation of NSA post 9/11 - the people broadly accepted this in order to avoid another terrorist attack - and have continued to accept it even as the natsec apparatus continues to expand

> Look at the creation of NSA post 9/11

https://en.wikipedia.org/wiki/NSA was created during World War II, renamed to its current name in 01952, and played a key role in weakening DES in the 01970s.

Re: Signal says it won’t compromise on encryption

#114

Earlier quoted context omitted.

Proposed law draft (I hate that news outlets do not link to the law they discuss) https://dot.gov.in/sites/default/files/Draft%20Indian%20Tele...

Thanks. This bill seems to be about telecom infrastructure. Does not talk about metadata, or encryption. As far as I can find does not seem to touch on messaging apps as well. Was anyone able to find anything related to which provision in the bill would impact Signal.

> “telecommunication services" means service of any description (including [..] electronic mail, voice mail, voice, video and data communication services, [..], internet based communication services,

Which I think Signal would fall under at least one of those services.

you can control+f your way through to see everything related to that phrase.

Re: Signal says it won’t compromise on encryption

#115

India wants to read everything? Why don't they just forbid the use of https. So that everyone can read everything on the internet

I'm trying to imagine a ban on https for better understanfing and I remember that Australia implemented anti-encryption laws some 3-4 years ago. Can someone comment on how Australian anti-encryption laws work in a case of https? Is it illegal to use encryption (like https to send data to server in a browser) without a backdoor now in Australia?

Re: Signal says it won’t compromise on encryption

#116
post #60

Earlier quoted context omitted.

matrix

I thought Matrix homeservers had access to way more metadata than Signal. Is it better than what I thought?

you can easily run your own.

though you will need lotsa RAM for federation if you use synapse (mine keeps bogging down now after a year of mild use (could also be a bug idk, it allocates all the RAM and then nothing goes), now im waiting for the new server software dendrite to be able to migrate from synapse... allthough i wouldnt lose much if i just nuked the synapse instance)

Re: Signal says it won’t compromise on encryption

#117

Earlier quoted context omitted.

Proposed law draft (I hate that news outlets do not link to the law they discuss) https://dot.gov.in/sites/default/files/Draft%20Indian%20Tele...

Thanks. This bill seems to be about telecom infrastructure. Does not talk about metadata, or encryption. As far as I can find does not seem to touch on messaging apps as well. Was anyone able to find anything related to which provision in the bill would impact Signal.

It's explicit on the interception of any kind of data.

It defines message as:

  “message” means any sign, signal, writing, image, sound, video, data stream or intelligence or information intended for telecommunication;
And then it says that said "messages" can be "intercepted or detained or disclosed", for a really wide range of reasons, apparently without the intervention of a judge.

  24.4 On the occurrence of any public emergency or in the interest of the public safety, the Central Government or a State Government or any officer specially authorized in this behalf by the Central or a State Government, may, if satisfied that it is necessary or expedient to do so, in the interest of the sovereignty, integrity or security of India, friendly relations with foreign states, public order, or preventing incitement to an offence, for reasons to be recorded in writing, by order:

  (a) direct that any message or class of messages, to or from any person or class of persons, or relating to any particular subject, brought for transmission by, or transmitted or received by any telecommunication services or telecommunication network, shall not be transmitted, or shall be intercepted or detained or disclosed to the officer mentioned in such order;

Re: Signal says it won’t compromise on encryption

#118
post #26

Earlier quoted context omitted.

Easy. Make everyone think that you have to hide something or create a fake stories that pedos use app X. > if you have nothing to hide, why don’t you show it? Is also “nice” rhetoric that laymen agree with.

I'd assume that India has its fair share of smart people who are able to spot fallacious rhetorics and want to see the bank accounts of officials in return.

India has such stuff:

https://www.thehindu.com/news/national/lok-sabha-passes-bill...

https://indianexpress.com/article/business/banking-and-finan...

Re: Signal says it won’t compromise on encryption

#119

Whenever India and its authoritarian stances are mentioned, a number of folks (I presume Indians, both on HN and elsewhere) come out of the woodwork to sing praises of "national security" while saying nothing about how such power can be abused. It is truly sad to see that an entire populace can't see the perils of a government with broad-reaching powers, when government institutions jailing the opposition, censoring…

Well that's what we call power of propaganda, I say that as an Indian(still living in India).

I honestly couldn't do anything even after writing letters, talking to friends who can talk to people who make shitty decisions, just cause there is no larger sentiment against these decisions, things just go by.

And now I have to say I am not sure when will the general public understand this issue, or will they ever. Are we just too lazy to do anything about it, or too divided to put up a fight...

Truly sad to see. Taking away rights to privacy is not the way of fighting the wrongs and problematic elements, and considering how corrupt our system can be I have no hope of it not being abused wildly. :(

Re: Signal says it won’t compromise on encryption

#120
Here's one major problem with Signal - you cannot delete contacts.

Following scenario:

1) X communicates with Y using Signal trying to hide from Iranian police

2) Y is getting arrested and who ever is found to have his phone number is getting in to trouble as well

3) X deletes Y from its contacts

4) Y stays in X's contacts on Signal no matter what

now what should X do? delete Signal? theoretically the police could reinstall it and see who you had in your contacts.

There have been several issues opened for this problem on GitHub for years. They all get closed by their bot after couple of weeks.

I have several ghost numbers and even ghost user names on my Signal clients. Super annoying and cluttering my list of contacts. For me Signal is just one option to avoid WhatsApp. But boy do I prefer Telegram ...

Post reply on HN