Live data from Hacker News

I don't trust Signal

drewdevault.com

141–150 of 473 posts

Re: I don't trust Signal

#141
post #88
post #39

Some version of this post seems to circulate every few months or so. This one is more direct in its accusations of Moxie acting in bad faith. I think this is disingenuous. Moxie has been very clear[0] about the tradeoffs that Signal has made and the reasons for them. It's fine to be dissatisfied with those choices. It's another thing entirely to accuse Moxie of dissimulating. Personally, I'd like to see Signal replac…

I would agree with you if only Signal would not ask for so many permissions on my phone.

It would be great if it asked for those permissions when it needed to do something - for example ask for mic permission at the point you want to make your first voice call. I see some apps going that direction and it's refreshing.

edit: Apparently, Signal does this for some things? See comment-replies.

Re: I don't trust Signal

#142

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

If I read that document correctly, it's more accurate to say that Signal stores at least two integers, rather than exactly. Signal did not provide information that does not fall under certain information categories, and they say that a court order would be needed to force them to disclose any of that information (if they possess any, which they deny).

Re: I don't trust Signal

#143
post #118

Earlier quoted context omitted.

Then why would you recommend a solution that hasn't even enabled end-to-end encryption by default?

When did I do this?

You recommended Matrix in your blog which, according to the first comment in this thread, is not end-to-end encrypted by default (which you acknowledged in your first response). Why would you recommend that instead of Signal?

Re: I don't trust Signal

#144
post #126
post #118

Earlier quoted context omitted.

Then why would you recommend a solution that hasn't even enabled end-to-end encryption by default?

Because for some that's not a show-stopper.

In the context of this article, framed as an alternative to Signal, I think it should be.

Re: I don't trust Signal

#145
post #53

> Truly secure systems don’t require trust. This is a chat app so, by definition, security requires trusting at least one other person. Also, I think experience shows that secrets can often be least trusted to those who have some interest in/use for them, with the secret owner often being the least trustworthy of all. So I'd say that if you trust yourself you're already probably trusting one of the weakest links in w…

> Trustless security does not exist, and attempting to achieve it by adding more technological layers and more complexity reduces rather than enhanced security.

How so? If you can minimize trust to the point where you have to trust someone to only properly design federated or peer-to-peer open protocol and trust that others will participate and oversee the process it's one thing, as there is no control or power to go around. Open and secure enough implementations from other parties can emerge with more parties verifying them and a possibility to switch in case someone does something sneaky. But if you also have to trust the same organization with implementation, infrastructure, distribution, there is not much security to talk about. There is no way to even verify claims that the thing they open sourced is the same thing they compile and distribute. And so much centralized power makes the organization a lucrative target for state actors with no realistic possibility to defend.

The more centralized trust you have the less secure system can be. It's like an upper bound on security.

Re: I don't trust Signal

#146
post #129

Google, APK ... if you're concerned about security, you would use Apple iOS only.

Apple has root access to every device just like Google has to Android phones running Google Play Services.

Security wise, Apple iOS is superior in any possible aspect to Android. Forensics people never complain how hard it is do Android, never :)

Re: I don't trust Signal

#147
most of these services aren't allowed to grow (i.e. not heavily invested in by the people with actual money) if they dont have some form of data mining or things like 'oops we facilitated key generatyion and kept all the keys' etc.

If you want to securely communicate, either be smart about it outside of the app you chose. (encrypted or encoded with your own keys / tools where an app is just a medium of transfer) or create your own secure channels (not too difficult these days with good vetted open source implementations of crypto on multiple platforms...)

I would say anyone who fully trusts any of these apps, and is worried about their privacy, is contradicting their worries with their behaviour.

just google 'signal vulnerabilities' or that for any other of these apps... even if they have some good form of archntecture it's riddled with bugs... people can access your data. live with it, avoid it, or make the actual data incomprehensible for any 'eve' yourself instead of trusting another to do it for you.

Re: I don't trust Signal

#148
post #143

Earlier quoted context omitted.

When did I do this?

You recommended Matrix in your blog which, according to the first comment in this thread, is not end-to-end encrypted by default (which you acknowledged in your first response). Why would you recommend that instead of Signal?

Oh, I should have caught that and addressed it in my earlier response. Matrix is end-to-end encrypted by default on clients that support it. The valid criticism is that some clients don't.

Re: I don't trust Signal

#149
post #40

> P.S. If you’re looking for good alternatives to Signal, I can recommend Matrix. Yes, if you're looking for alternatives to Signal, you should totally use a solution that hasn't rolled out end-to-end encryption by default[0]. /s ...and that only two clients have implemented so far, out of 50ish that they list on their website. [0] https://matrix.org/docs/guides/faq.html#what-is-the-status-o...

Fwiw, Matrix E2E actually exists in separate codebases in: Riot/Web, Riot/iOS, Riot/Android, nheko, matrix-python-sdk, libpurple (in PR), and shortly in Fractal (thanks to https://gitlab.gnome.org/jhaye/olm-rs etc). So yup, it sucks that it's not turned on by default in private rooms, but we're working away as fast as we can.

I love your project and am really looking forward to replacing a lot of stuff with Matrix-powered chat.

However, I strongly disagree with the author that Matrix should be recommended as a secure communication platform until E2E is stable (and, from what I understand about your project, you'll enable it by default as soon as you consider it stable enough).

Re: I don't trust Signal

#150
I don't prefer messaging apps that require phone numbers, they always feel less trustworthy to me because that one aspect of privacy isn't there
Post reply on HN