Redphone component. I don't know why it's closed source. It's been suggested elsewhere in this thread that it was potentially IP issues they kept it closed for. Is it possible loose US CALEA law interpretation influences the reasoning? Or a gag? I honestly don't know why they chose to do that but I wanted to comment in to see if a lawyer or someone from the project could hint at the reasoning.
Why I won't recommend Signal anymore
171–180 of 350 posts
Re: Why I won't recommend Signal anymore
#172Earlier quoted context omitted.
You are not a cryptographer and not a hipster and apparently never had your life on the line in a way that made it imperative that your communications not be associated with your phone number. Whether you are a journalist or an abused individual hiding from the ex spouse/parents/whomever that abused you, if your life and/or the lives of other people are on the line, this detail (and perhaps others, as I am not super…
I'm .. confused. Aren't you basically just confirming my position, with stronger examples? Are we on the same side or do you disagree with my comment? I mean, I think I wrote[1] that I really dislike the connection between identity and phone numbers. I happen to use Telegram at the moment (I have exactly 5 contacts, one of those is the Telegram 'we updated the software' bot, another one is a random 'Sticker' bot), bu…
To me, remarks like this one read as "Eh, if Signal is not to your tastes, no big, but no reason to trash it either." But the article and I and others here are saying, "Yeah, no. This is not the same thing as picking a phone because you like red more than blue. This is more like refusing the blue one because it explodes sometimes when you answer it."
For people for whom lives are on the line, this goes a lot deeper than personal preference.
Re: Why I won't recommend Signal anymore
#173Earlier quoted context omitted.
Hi, author here. I don't think LibreSignal or indeed Signal will ever be the dominant mobile messenger out there. There's simply a lot of inertia to fight against. It's the same reason why it's hard to convince e.g. Facebook friends to move to a different social network, why Google+ failed, etc. Whenever the social aspect gets involved, companies can very easily create lock-in by being early, and then the social aspe…
You don't understand what I'm saying. I agree that crypto alone doesn't equal privacy --- it's table stakes. Clearly: it does not follow from that observation that crypto doesn't matter. If you cannot at least be cryptographically secure , the rest of what you do doesn't matter. We now have two examples --- CryptoCat and Telegram --- of "secure messaging" systems being used by governments as a way of hunting down act…
I recall e.g. that Moxie reviewed Telegram's security, found that none of it made any sense and that its authors didn't know what they were doing. https://tobtu.com/decryptocat.php looks like the cryptocat analogue of that. Have the two projects improved somehow? Have some people joined or others left?
Could you please also provide links for the claim that CryptoCat and Telegram are being used by governments to hunt down activists?
Re: Why I won't recommend Signal anymore
#174Earlier quoted context omitted.
Hi, author here. I don't think LibreSignal or indeed Signal will ever be the dominant mobile messenger out there. There's simply a lot of inertia to fight against. It's the same reason why it's hard to convince e.g. Facebook friends to move to a different social network, why Google+ failed, etc. Whenever the social aspect gets involved, companies can very easily create lock-in by being early, and then the social aspe…
You don't understand what I'm saying. I agree that crypto alone doesn't equal privacy --- it's table stakes. Clearly: it does not follow from that observation that crypto doesn't matter. If you cannot at least be cryptographically secure , the rest of what you do doesn't matter. We now have two examples --- CryptoCat and Telegram --- of "secure messaging" systems being used by governments as a way of hunting down act…
I used cryptographic software as an end-user for many years, like GPG for instance, and agree that it's hard, and we need to train people to use correct security habits (infosec and opsec), to minimise exposure to hostile elements.
I've tought at cryptoparties and other events, I have spoken to many intelligence whistleblowers, some of which I consider to be close friends, and they've told me about some of the techniques used on the national intelligence agency level and how wrong use of crypto and general bad operational security practices can expose you. So while I'm not a trained cryptographer, and do not claim to be, I have extensive experience not only building secure software, but also, thanks to whistleblowers know about some of the ins and outs of the intelligence industry re crypto and surveillance.
Re: Why I won't recommend Signal anymore
#175Earlier quoted context omitted.
Crypto engineers tend to like the Axolotl design, which is an unusually serious cryptographic design for a messaging protocol (historically, messaging crypto has been cryptographically slapdash, with the exception of OTR). But the reason crypto people are so positive about Signal Protocol isn't just that they like the ratchet. It's also that they trust the entire design of the system, not just the ratchet but all the…
Well, I hope on Matrix we've not been blindly namedropping axolotl/double-ratchet: instead we've tried to be as transparent as possible (more-so perhaps than OWS) in terms of speccing what we've been doing ( https://matrix.org/docs/spec/olm.html , https://matrix.org/docs/spec/megolm.html , http://matrix.org/docs/olm_signing.html , https://matrix.org/speculator/spec/drafts%2Fe2e/client_serve... etc). Thanks to the Ope…
Re: Why I won't recommend Signal anymore
#176Earlier quoted context omitted.
You don't understand what I'm saying. I agree that crypto alone doesn't equal privacy --- it's table stakes. Clearly: it does not follow from that observation that crypto doesn't matter. If you cannot at least be cryptographically secure , the rest of what you do doesn't matter. We now have two examples --- CryptoCat and Telegram --- of "secure messaging" systems being used by governments as a way of hunting down act…
Regarding qualifications: I spent years building secure technology (publication platforms, websites) for whistleblowers including Ed Snowden himself (I built his official website ( https://edwardsnowden.com ) for the Courage Foundation (his official defence fund) plus the tech behind it that supports it. This allows our editors to submit anonymously to the site through the Tor network. I used cryptographic software a…
Re: Why I won't recommend Signal anymore
#177Earlier quoted context omitted.
Regarding qualifications: I spent years building secure technology (publication platforms, websites) for whistleblowers including Ed Snowden himself (I built his official website ( https://edwardsnowden.com ) for the Courage Foundation (his official defence fund) plus the tech behind it that supports it. This allows our editors to submit anonymously to the site through the Tor network. I used cryptographic software a…
One thing I wanted to add, regarding the tech: of course I do that in cooperation with other people some of who are indeed trained cryptographers.
Re: Why I won't recommend Signal anymore
#178Earlier quoted context omitted.
Hi, author here. I don't think LibreSignal or indeed Signal will ever be the dominant mobile messenger out there. There's simply a lot of inertia to fight against. It's the same reason why it's hard to convince e.g. Facebook friends to move to a different social network, why Google+ failed, etc. Whenever the social aspect gets involved, companies can very easily create lock-in by being early, and then the social aspe…
You don't understand what I'm saying. I agree that crypto alone doesn't equal privacy --- it's table stakes. Clearly: it does not follow from that observation that crypto doesn't matter. If you cannot at least be cryptographically secure , the rest of what you do doesn't matter. We now have two examples --- CryptoCat and Telegram --- of "secure messaging" systems being used by governments as a way of hunting down act…
An alternative needs to be as a bare minimum cryptographically secure. And then on top of that it would be very nice if there was federation, not tied to phone numbers and all the components being open source. Those last 3 points is where Signal fails currently. Federation is something that moxie tried, didn't work out, now he's basically not in favour of that, the phone number issue is of course well known, and the redphone server component is not open source.
Re: Why I won't recommend Signal anymore
#179Earlier quoted context omitted.
I'm .. confused. Aren't you basically just confirming my position, with stronger examples? Are we on the same side or do you disagree with my comment? I mean, I think I wrote[1] that I really dislike the connection between identity and phone numbers. I happen to use Telegram at the moment (I have exactly 5 contacts, one of those is the Telegram 'we updated the software' bot, another one is a random 'Sticker' bot), bu…
Signal is a great project and most criticism I've seen here so far is not 'Signal sucks', it is usually more a long the line of 'Signal is not for me' and I have a hard time understanding why that is debatable or why this shouldn't be a valid position. To me, remarks like this one read as "Eh, if Signal is not to your tastes, no big, but no reason to trash it either." But the article and I and others here are saying,…
Yes, you (and I, let's not forget that we kinda agree that this is bad design) might not want to share your private phone number just to contact someone via Signal. But I feel you're painting this a bit too black or white.
If lives are at stake or not, Signal might or might not be the right solution. If people feel that their life is at risk, I hope they know how to evaluate the trade-offs - or have someone around that can explain it.
We both don't like Signal. I don't agree that it should be dismissed and emotional appeals are ~questionable~, can probably be turned around (see first paragraph). Individual decisions need to be made and if Signal is a good fit or not for a specific scenario isn't an good indicator about the general fitness of Signal in general imo.
Re: Why I won't recommend Signal anymore
#180Earlier quoted context omitted.
One thing I wanted to add, regarding the tech: of course I do that in cooperation with other people some of who are indeed trained cryptographers.
Who are those people? There aren't many of them, in, like, the world.