Live data from Hacker News

Signal to leave Sweden if backdoor law passes

swedenherald.com

211–220 of 283 posts

Re: Signal to leave Sweden if backdoor law passes

#211
post #91

Earlier quoted context omitted.

Is Signal hosted in just 1 country?

Good question! I assumed it was US only but things have changed a while back after it becoming popular it seems. Going by https://signal.org/blog/signal-is-expensive/ >Because everything in Signal is end-to-end encrypted, we can rent server infrastructure from a variety of providers like Amazon AWS, Google Compute Engine, Microsoft Azure, and others while ensuring that your messages and calls remain private and secur…

Your source doesn't support your claim. The exact snippet you quoted, interpreted strictly, only means they have the option to host it across providers, not that they actually do so. It also doesn't say anything about where it's hosted. It can be hosted in AWS, GCP, and azure, but all in the US, for instance.

Re: Signal to leave Sweden if backdoor law passes

#212
post #85

Earlier quoted context omitted.

Not familiar with Swedish law, but in most of the world the courts have a concept of jurisdiction. Otherwise a small country could just fine Apple $1T and solve its budget woes, and probably build a giant waterslide. I would be surprised if Swedish law allowed for prosecuting a foreign company with not one bit of operations in the country.

> a foreign company with not one bit of operations in the country. Borrowing from how tax & law is usually applied for companies trading outside of their incorporated country, at least in many places including the EU: If you have users/customers in a certain country, even if your product is purely software, you can be considered to have operations in that country.

> even if your product is purely software, you can be considered to have operations in that country

Couldn't users in pretty much every internet-connected country use VPNs and other methods of cross-borders indirection to access even those US services which explicitly block non-US IP ranges?

If this is the case, then is it not the case under the quoted reasoning above that any internet company should be expected to have operations in every other internet-connected country?

Re: Signal to leave Sweden if backdoor law passes

#213
post #185

Earlier quoted context omitted.

Whether it's useful to the current "grand majority" or not / holds the value it does today is orthogonal to whether the technology can be stopped and whether it still provides value to those who continue to use it. I did worry this example would be too political, hence including the BitTorrent example as well.

Much like how PGP was disseminated by Phil Zimmermann, and then the government decided to come down on him like the plague in the early 90s. What the US government didn't know was that it was too late and such technology was out in the zeitgeist. Bitcoin is in a similar situation. The actual software and code? Good luck getting that genie back in the bottle now. But, you can certainly hamstring it in other ways, and…

I think we're in agreement.

> The actual software and code? Good luck getting that genie back in the bottle now. But, you can certainly hamstring it in other ways, and frankly, that should be good enough.

This is my point - the technology is out of the bottle. You can't stop it. You can disincentivize its use in all sorts of social and legal manners, but to go all the way back to my original comment: you can stop Apple (Coinbase) from operating, you can penalize individuals for using encryption (or cryptocurrency in this case), but encryption (and blockchain) still exists and can be self-hosted, and individuals can continue to utilize those tools.

Again, look at torrents. Its primary use case is illegal. What.CD, Oink, even TPB (at various points) have all been taken down. Yet torrenting still enjoys widespread use across the globe.

I'm not a fan of cryptocurrency either, but I do want to note that "hamstringing" it at this point will likely have many negative downstream effects on the overall economy.

Re: Signal to leave Sweden if backdoor law passes

#214

Signal is headquartered in the US and presumably has no employees in Sweden (and perhaps the entire European Union). There is utterly nothing the Swedish government can do to stop Signal except for pressuring app stores and/or ISP-level censorship. Preemptive surrender is extremely disappointing, especially for a non-profit - there isn’t even any revenue that can be ‘fined’ by the EU!

Sweden is part of the expanded 5 eyes (now 14 eyes). As a workaround for restrictions on domestic spying, they subcontract their dirty work to each other. Hence, you can expect the US to assist in pressuring them (ostensibly on behalf of Sweden)

Re: Signal to leave Sweden if backdoor law passes

#215

Earlier quoted context omitted.

It may be wrong, but it proves that technology can't beat politics and policy. The issue with Apple caving to UK demands regarding encryption, and now Signal being in a similar situation, shows that you can't just focus on technology and ignore policy and politics. And you'll find out that a ton of people here on HN will care, but most of the public won't. People should take XKCD 538 really to heart (The 5$ wrench on…

>The issue with Apple caving to UK demands regarding encryption Apple "caving" would've looked different; in fact, we probably never would have known, given the insidious nature of the underlying statute in the UK. Apple is making noise about the fact that they pulled the product, and the tech press is making it clear WHY even though Apple itself is legally prohibited from giving any additional context. I feel like t…

Removing the advanced encryption option for new accounts is really 'caving' to the demands of the government in my view.

And in time, they will also remove the e2e encryption on existing accounts using the e2e feature to comply with UK demands.

They may have sounded the alarm, which I appreciate, but they still have to 'cave' and do as the UK government tells them or they have to cease operations in the UK.

Re: Signal to leave Sweden if backdoor law passes

#216

Earlier quoted context omitted.

The problem is that some forks are malware [1], so switching to a fork by developers you don't know is risky. How do non-technical users learn which software developers to trust? [1] https://www.securityweek.com/malware-delivered-via-malicious...

Worst-case, they could hire someone they trust to review the source code. More realistically, you generally don't have to switch to a fork in the first place because the mere threat of a fork is enough to prevent the deployment of user-hostile features. And when a project does get forked it's often a highly publicized affair with a lot of community drama which produces no shortage of information about who's trustwort…

This is only somewhat true for the software most popular with technical users - the sort of thing the average Hacker News reader might be familiar with.

There is a long tail of malware in app stores, despite the efforts of app vendors to police such things. Nobody would be bothering to fork them because most technical users don't care about them, but they still attract lots of victims.

Example: malicious Chrome extensions. Authors of Chrome extensions receive enticing offers to sell and sometimes they do.

Re: Signal to leave Sweden if backdoor law passes

#218
post #105

Earlier quoted context omitted.

> technology can't beat politics and policy. It often only can't in a world of mandatory centralized app stores. That's not the only possible world.

We technologists will probably be able to circumvent any Signal-ban. But we don't exist in a vacuum, we are a small part of a larger society. Who's at the other end of your conversation? Most 'regular/normal' people won't and most importantly - don't want to - jump through the technical hoops to keep using Signal. Although the downside of the official app stores is clear, the alternative might result in a swift retur…

I think malware and viruses are less common for many reasons, but I suspect increased awareness and security posture (including the architecture of modern OS) has more to do with this than "walled gardens." Malware does make it onto closed app stores, and many users (e.g. on Windows) still don't use app stores.

The answer you're looking for is probably to build more decentralized, FOSS software with better UX. Much easier said than done of course.

Re: Signal to leave Sweden if backdoor law passes

#220
post #43
post #3

> The Armed Forces, on the other hand, are negative and write in a letter to the government that the proposal cannot be realized "without introducing vulnerabilities and backdoors that can be exploited by third parties First time I am seeing an organization against this. Kudos to them for standing up.

I question the use of an instant messaging service hosted in another country for your armed forces, is that a good idea, especially now? As good as Signal is I mean, you will want something under your control.

Any decent military will be using multiple forms of communication systems.

I was a communications specialist for the Swedish Armed forces 10+ years ago, including a tour in Afghanistan and a tour in Kosovo.

We used radio links for internet that I can tell you, were more adversarial than friendly.

The Swedish military is highly capable when it comes to network communications. A small nation will have to think differently.

You could potentially use an instant messaging system in control by someone else, if you are willing and capable of sharing encryption keys with whomever you are going to communicate with beforehand.

Post reply on HN