Live data from Hacker News

I don't trust Signal

drewdevault.com

21–30 of 473 posts

Re: I don't trust Signal

#21
post #2

I trust it more than unencrypted SMS or Facebook Messenger. I trust it less than p2p chat over an encrypted network I control with layered defense in depth. Security is not a boolean.

> Security is not a boolean.

Very true.

Re: I don't trust Signal

#22
"The APK direct download doesn’t even accomplish the stated goal of “harm reduction”. The user has to manually verify the checksum, and figure out how to do it on a phone, no less. A checksum isn’t a signature, by the way - if your government- or workplace- or abusive-spouse-installed certificate authority gets in the way they can replace the APK and its checksum with whatever they want."

This is true for just about every single piece of software that one downloads. But nice job deflecting it onto Signal to solve for you. Installing an APK by hand is not difficult either, you transfer it to your phone and open it. I don't see how Signal is doing any better or worse of a job from similar apps. Also, Signal's checksum verification is SHA-256 which I'd say is "good enough." It's also being served from an HTTPS webpage. Is there something missing here?

Re: I don't trust Signal

#23
post #13

TL;DR he doesn’t trust Signal because he doesn’t trust the Android operating system, and something about federation. > No doubt these are non-trivial problems to solve. But I have personally been involved in open source projects which have collectively solved similarly difficult problems a thousand times over with a combined budget on the order of tens of thousands of dollars. Shut up and code then. I’ll personally r…

"It's easy! Just just generate a 2048 bit PGP key using this command (make sure you don't use the default insecure options) and then mail it through the post to anyone you need to communicate with."

Re: I don't trust Signal

#26

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

If Open Whisper Systems had received a national security letter requiring them to collect more information and keep it secret that they were doing so, how would you expect them to have responded to that subpoena?

Re: I don't trust Signal

#27
>Google Play

use yalp store

> Packages on F-Droid are reviewed by a human being and are cryptographically signed

>The app has to update itself, using a similarly insecure mechanism. F-Droid handles updates and actually signs their packages

so are all android APKs. granted it's trust on first use: it accepts any signature for the first install, and only enforces the signature if you try to install an update.

>A checksum isn’t a signature, by the way - if your government- or workplace- or abusive-spouse-installed certificate authority gets in the way they can replace the APK and its checksum with whatever they want

this is probably the only legitimate concern, to use f-droid so you have a permanent anchor of trust (f-droid, rather than whatever CAs you have installed) for the first install. this isn't even that big of an issue when you can install using yalp store. google might be a rootkit or whatever, but at least you can be reasonably sure that the apks are the originals.

Re: I don't trust Signal

#29
post #26

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

If Open Whisper Systems had received a national security letter requiring them to collect more information and keep it secret that they were doing so, how would you expect them to have responded to that subpoena?

NSLs don’t allow that.
Post reply on HN