Live data from Hacker News

I don't trust Signal

drewdevault.com

221–230 of 473 posts

Re: I don't trust Signal

#221
post #39

Some version of this post seems to circulate every few months or so. This one is more direct in its accusations of Moxie acting in bad faith. I think this is disingenuous. Moxie has been very clear[0] about the tradeoffs that Signal has made and the reasons for them. It's fine to be dissatisfied with those choices. It's another thing entirely to accuse Moxie of dissimulating. Personally, I'd like to see Signal replac…

But in the linked post he does not explain, why he does not maintain a F-Droid repository for people who do not trust google, nor why the original Signal Client does not connect to Signal Forks, even if they use everything the same. Security reasons? Ordinary smartphones are full of rootkits anyways, so someone using a forked Signal version probably is better of anyway, as he knows a bit more what he is doing. So the…

"why he does not maintain a F-Droid repository for people who do not trust google"

Are you paying him to do that? No? Well, there you go. It's more work, for what appears to be very little benefit.

Re: I don't trust Signal

#222
post #72
post #28

Earlier quoted context omitted.

Apart from not being encrypted by default, Telegram uses its own homegrown crypto instead of a tried and tested one for its secret chat feature. That itself is a red flag.

Technically, Signal also uses homegrown crypto. The difference here was it was endorsed by Moxie's acquaintances from the crypto circles, followed by a very loud and aggressive disparaging campaign against Telegram led by some of these people. I've been on metzdowd list for a very long time and while cryptographers aren't the chummiest people in the slightest, there's always an underlying mutual respect. The Telegram…

You conveniently left out the fact that Telegram has a history of actual backdoors http://habrahabr.ru/post/206900/

Re: I don't trust Signal

#223
AFAIK, Signal has an open source client, and an open source server. If you want federation, you can go ahead and build it, and find users, and you can start from a reasonably well working base. Moxie isn't going to build it, because he doesn't think federation works; to convince him, you'll need to show him it works, not just tell him. Is there an example of a federated chat service which has end to end encryption that just works?

Peer to peer chat is interesting, but it means that IPs of communicating users are more widely exposed -- now anybody in the network path between two users can see they're communicating with each other, not just that they're both communicating with Signal. I may not want to share my IP with some (or most) people I communicate with. Additionally, there's a lot of hard work around actually getting a peer to peer connection on today's internet, for a large fraction of connections, you're going to have to proxy packets for them anyway.

Re: I don't trust Signal

#224
post #193

Earlier quoted context omitted.

> Moxie forbids you from distributing branded builds of the Signal app ... Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction. > ... and if you rebrand he forbids you from using the official Open Whisper servers. This seems pretty fair to me. Not only could you abuse their resources, it would greatly hinder their ability to make changes and respon…

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play. The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't. This alone is enough for me to lose trust in Signal.

Are you going to pay for him to do that?

Re: I don't trust Signal

#225

"The APK direct download doesn’t even accomplish the stated goal of “harm reduction”. The user has to manually verify the checksum, and figure out how to do it on a phone, no less. A checksum isn’t a signature, by the way - if your government- or workplace- or abusive-spouse-installed certificate authority gets in the way they can replace the APK and its checksum with whatever they want." This is true for just about…

Additionally with Android APKs, the APK has to be signed and additional updates will be verified to match the same vendor.

Which as far as I can tell is what Marlinspike meant by harm reduction.

It's not preventing anyone from hijacking your encrypted session and serving you a bad app, I'm not sure how it could. ("How do you secure your connection given that your security has already been silently compromised?" isn't a question I really understand.) But it helps ensure that people are at least requesting the genuine app, and if they get it then they'll get signature verification for future versions.

Re: I don't trust Signal

#226
post #155

Earlier quoted context omitted.

> Security wise, Apple iOS is superior in any possible aspect to Android. One aspect where Android is superior is that more of it is open-source.

"Google Play Services is a proprietary background service and API package for Android devices from Google" [0] - I don't know a phone running pure AOSP without any proprietary code. [0] en.wikipedia.org/wiki/Google_Play_Services

> more of it

not all of it

Re: I don't trust Signal

#227

Earlier quoted context omitted.

> Moxie forbids you from distributing branded builds of the Signal app ... Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction. > ... and if you rebrand he forbids you from using the official Open Whisper servers. This seems pretty fair to me. Not only could you abuse their resources, it would greatly hinder their ability to make changes and respon…

"Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction" In this particular case, not likely. People who are into more secure communication do not randomly click on anything. They know what they are doing, or get it installed from people they trust. And if they don't - their fault. Not Signals. And Signal can continue to work and introduce breaking ch…

" People who are into more secure communication do not randomly click on anything."

That's not the sole market of people who would try Signal, though.

Re: I don't trust Signal

#228

Earlier quoted context omitted.

It would be great if it asked for those permissions when it needed to do something - for example ask for mic permission at the point you want to make your first voice call. I see some apps going that direction and it's refreshing. edit: Apparently, Signal does this for some things? See comment-replies.

On Android that's version dependant. Older Android versions only had the idea of the app declaring "I need to be able to use your Camera, read your Contacts, and make $$$ phone calls" and then you pick "No" and don't get the app or you pick "OK". This more or less railroads users into pressing "OK", except for the most security conscious, who go without the app. A few releases back Google had an unofficial feature th…

The permissions system that android apps use is entirely dependent on which API version you target. Last I understood, if you made a new app today and purposely chose to target an old API version, you could force it to use the "all or nothing", user hostile permissions query you described

Re: I don't trust Signal

#229
post #137

Earlier quoted context omitted.

The big Apple vs FBI high profile lawsuit for one. Granted that was a telegraphed precedent seeking exercise by "accidentally" losing access to the work phone after the terrorists destroyed their personal phones before the attack.

That was not an NSL.

True - they are less publicly tested but it is suggestive in its own way. If they could just NSL their way to access why bother with precedents? It is wild speculation but that is what lack of transparency has wrought.

Re: I don't trust Signal

#230

Earlier quoted context omitted.

"Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction" In this particular case, not likely. People who are into more secure communication do not randomly click on anything. They know what they are doing, or get it installed from people they trust. And if they don't - their fault. Not Signals. And Signal can continue to work and introduce breaking ch…

> People who are into more secure communication do not randomly click on anything I think you overestimate people. I told my wife to install Signal because she needed a password for something and it was way to complicated for her to remember. I know what the signal app is and could likely avoid fakes - she would not. I think it is often the case that only one party of the conversation is security minded, while the ot…

People who do click on the wrong "Signal" probably clicked on many other wrong things, too. Their Security is not existent anyway, even if they accidently use the official Signal build.
Post reply on HN