Live data from Hacker News

I don't trust Signal

drewdevault.com

191–200 of 473 posts

Re: I don't trust Signal

#191
post #36
post #2

I trust it more than unencrypted SMS or Facebook Messenger. I trust it less than p2p chat over an encrypted network I control with layered defense in depth. Security is not a boolean.

Security is not a boolean, but when your whole selling point is security you'd better be good at it. I trust Signal the same amount as Facebook Messenger or any other centralised messaging system that uses transport encryption (e.g. Skype, IRC+SSL, WhatsApp...). But what's the USP that means I should use Signal rather than any alternative?

Not giving all your metadata to Facebook (Messenger, WhatsApp) or Microsoft (Skype) for a start. The message may be e2e encrypted, but damn sure these companies are logging as much as possible about who's chatting with whom, when, & where each of them are, how much data is sent each time, etc.

Some people trust Moxie / OWS more than the others, and with good reason.

Re: I don't trust Signal

#192

Google, APK ... if you're concerned about security, you would use Apple iOS only.

If you're concerned about security you don't use a smart phone and don't use your phone as a computing device. I know it's a lot to ask of people and so most will simply ignore the massive, unfixable (at least yet), security and privacy issues (ie, 5 years of your location 24 hours a day tracked, stored, and sold to whoever wants to pay). But really, smart phones are bad. Even dumb cell phones are bad. And if you car…

Totally agree, and will use a real computer once I find pants with wide enough pocket for it :)

Re: I don't trust Signal

#193

Earlier quoted context omitted.

But in the linked post he does not explain, why he does not maintain a F-Droid repository for people who do not trust google, nor why the original Signal Client does not connect to Signal Forks, even if they use everything the same. Security reasons? Ordinary smartphones are full of rootkits anyways, so someone using a forked Signal version probably is better of anyway, as he knows a bit more what he is doing. So the…

> Moxie forbids you from distributing branded builds of the Signal app ... Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction. > ... and if you rebrand he forbids you from using the official Open Whisper servers. This seems pretty fair to me. Not only could you abuse their resources, it would greatly hinder their ability to make changes and respon…

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play.

The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't.

This alone is enough for me to lose trust in Signal.

Re: I don't trust Signal

#194
post #140

Earlier quoted context omitted.

> In an article about "trust", can you explain how exactly you trust F-Droid packages and not Google Play ones? It's easier for Google to manipulate a package on Google Play than on F-Droid. > Signal has introduced state-of-the-art encryption to millions of people in an accessible way. WhatsApp has done that to even more people, so what's the point of Signal?

> It's easier for Google to manipulate a package on Google Play than on F-Droid. That's not how Android app signing works. It's a "trust on first use" model, so once you install an app, any update must be signed by the same key or the system will refuse to install it. That key is held by Signal, not Google, so Google cannot sign updates to apps. > WhatsApp has done that to even more people, so what's the point of Sig…

> That's not how Android app signing works. It's a "trust on first use" model, so once you install an app, any update must be signed by the same key or the system will refuse to install it. That key is held by Signal, not Google, so Google cannot sign updates to apps.

My understanding (and I'd love to be corrected if I'm wrong) is that Google Play Services run with access to root privileges, and thus can circumvent this protection without the user becoming aware.

Re: I don't trust Signal

#195
post #140

Earlier quoted context omitted.

> In an article about "trust", can you explain how exactly you trust F-Droid packages and not Google Play ones? It's easier for Google to manipulate a package on Google Play than on F-Droid. > Signal has introduced state-of-the-art encryption to millions of people in an accessible way. WhatsApp has done that to even more people, so what's the point of Signal?

> It's easier for Google to manipulate a package on Google Play than on F-Droid. That's not how Android app signing works. It's a "trust on first use" model, so once you install an app, any update must be signed by the same key or the system will refuse to install it. That key is held by Signal, not Google, so Google cannot sign updates to apps. > WhatsApp has done that to even more people, so what's the point of Sig…

> That's not how Android app signing works.

Google has root, so it can change how app signing works at any time.

> Both have their pros and cons, and both have legitimate reasons to exist.

I just looks to me like whenever someone mentions a pro point of Signal, it's something where WhatsApp shines even more (e.g. "brings end-to-end encryption to the masses", "it's available on the App stores", "better iOS support than something like Tox", ...).

Re: I don't trust Signal

#196

Earlier quoted context omitted.

If you're concerned about security you don't use a smart phone and don't use your phone as a computing device. I know it's a lot to ask of people and so most will simply ignore the massive, unfixable (at least yet), security and privacy issues (ie, 5 years of your location 24 hours a day tracked, stored, and sold to whoever wants to pay). But really, smart phones are bad. Even dumb cell phones are bad. And if you car…

Totally agree, and will use a real computer once I find pants with wide enough pocket for it :)

My everyday solution is pretty simple. I don't carry a computing device with me. If I do carry a cell phone it's turned off.

If I'm in my car I use an old thinkpad laptop and my own 900 MHz wireless network using ubiquiti transceivers and a 30ft pole on my house at home with a custom antenna sticking up out of my vehicle's sunroof. The car's kit re-serves this IP link to my home network over wifi to any devices in the vicinity of my car. ie, I park it in front of my friend's house.

Re: I don't trust Signal

#197
post #72
post #28

Earlier quoted context omitted.

Apart from not being encrypted by default, Telegram uses its own homegrown crypto instead of a tried and tested one for its secret chat feature. That itself is a red flag.

Technically, Signal also uses homegrown crypto. The difference here was it was endorsed by Moxie's acquaintances from the crypto circles, followed by a very loud and aggressive disparaging campaign against Telegram led by some of these people. I've been on metzdowd list for a very long time and while cryptographers aren't the chummiest people in the slightest, there's always an underlying mutual respect. The Telegram…

upvoting, I am having same feelings towards Telegram vs Signal. Both are man made things, maybe Telegram has not made audit on their crypto yet, but whenever I see something related to IM + crypto, people praise Signal, write hate speech towards Telegram, as if were people are waiting HN to have a mention of Telegram and writing some bad words about it.

Re: I don't trust Signal

#198
post #67

Earlier quoted context omitted.

I’m pretty sure that isn’t true. They can be used to compel you to build interception capabilities.

source?

I really can’t say. Take for what it’s worth.

Edit: I may be thinking of a FISA order as opposed to an NSL. Doesn’t matter though, obviously the concern is that they would be served with whichever does allow that.

Re: I don't trust Signal

#199
post #190
post #181

Earlier quoted context omitted.

It could do that.

Google certainly doesn‘t need the Play services to do that. If you assume Google to be malicious in that way, no app on your Android phone can be secure.

Sure, but the Play services make it A LOT easier for them.

Re: I don't trust Signal

#200

Earlier quoted context omitted.

Ya really think phone numbers are hard to get?

Since there is someone above claiming that getting a phone number in some countries "requires" biometric identification, I'd say yes.

As usual with restrictions and regulations, it's easy to obtain for bad guys and not easy for good guys.
Post reply on HN