> The Armed Forces, on the other hand, are negative and write in a letter to the government that the proposal cannot be realized "without introducing vulnerabilities and backdoors that can be exploited by third parties First time I am seeing an organization against this. Kudos to them for standing up.
TOR was sort of famously contributed to by a dude in US Naval research early on, right? They are militaries, not police or intelligence forces. The job is to be ready to do war, not nanny and snoop on civilians (Some of that might be a necessary side effect but it isn’t their reason for being).
Signal to leave Sweden if backdoor law passes
221–230 of 283 posts
Re: Signal to leave Sweden if backdoor law passes
#222> The Armed Forces, on the other hand, are negative and write in a letter to the government that the proposal cannot be realized "without introducing vulnerabilities and backdoors that can be exploited by third parties First time I am seeing an organization against this. Kudos to them for standing up.
TOR was sort of famously contributed to by a dude in US Naval research early on, right? They are militaries, not police or intelligence forces. The job is to be ready to do war, not nanny and snoop on civilians (Some of that might be a necessary side effect but it isn’t their reason for being).
Re: Signal to leave Sweden if backdoor law passes
#223Earlier quoted context omitted.
You don't need to get Signal from an app store (unless you're on iOS I guess)
Even then the webapp should work
Re: Signal to leave Sweden if backdoor law passes
#224Earlier quoted context omitted.
Not familiar with Swedish law, but in most of the world the courts have a concept of jurisdiction. Otherwise a small country could just fine Apple $1T and solve its budget woes, and probably build a giant waterslide. I would be surprised if Swedish law allowed for prosecuting a foreign company with not one bit of operations in the country.
> a foreign company with not one bit of operations in the country. Borrowing from how tax & law is usually applied for companies trading outside of their incorporated country, at least in many places including the EU: If you have users/customers in a certain country, even if your product is purely software, you can be considered to have operations in that country.
If no money is changing hands, good luck with that. (Or, rather, bad luck with that.)
(If money is changing hands, you might find your payments blocked by local payment providers, though even then that would take a while and might or might not happen.)
Re: Signal to leave Sweden if backdoor law passes
#225Re: Signal to leave Sweden if backdoor law passes
#226Earlier quoted context omitted.
Much like how PGP was disseminated by Phil Zimmermann, and then the government decided to come down on him like the plague in the early 90s. What the US government didn't know was that it was too late and such technology was out in the zeitgeist. Bitcoin is in a similar situation. The actual software and code? Good luck getting that genie back in the bottle now. But, you can certainly hamstring it in other ways, and…
I think we're in agreement. > The actual software and code? Good luck getting that genie back in the bottle now. But, you can certainly hamstring it in other ways, and frankly, that should be good enough. This is my point - the technology is out of the bottle. You can't stop it. You can disincentivize its use in all sorts of social and legal manners, but to go all the way back to my original comment: you can stop App…
This part does terrify me. Too many hedge funds and more common investment vehicles have gotten exposure to this. If there ever is a huge rugpull, regular folks will get nailed. Sad times.
Re: Signal to leave Sweden if backdoor law passes
#227Earlier quoted context omitted.
Worst-case, they could hire someone they trust to review the source code. More realistically, you generally don't have to switch to a fork in the first place because the mere threat of a fork is enough to prevent the deployment of user-hostile features. And when a project does get forked it's often a highly publicized affair with a lot of community drama which produces no shortage of information about who's trustwort…
This is only somewhat true for the software most popular with technical users - the sort of thing the average Hacker News reader might be familiar with. There is a long tail of malware in app stores, despite the efforts of app vendors to police such things. Nobody would be bothering to fork them because most technical users don't care about them, but they still attract lots of victims. Example: malicious Chrome exten…
When I say user-hostile features I'm not talking about malware. Yes, I suppose theoretically you could fork a Free Software malware app and make it not-malware, but that's not what I'm talking about here. I'm talking about things like Samsung putting ads on your TV home screen[1], or BMW charging a monthly subscription to access your car's seat heaters[2], or Sweden trying to install a backdoor in Signal. With Free Software, users get the final say on whether those features are installed on their devices or not.
[1]: https://www.reddit.com/r/samsung/comments/184a1j6/why_do_i_h...
Re: Signal to leave Sweden if backdoor law passes
#228This is no pie-in-the-sky statement, I've been running such a server for years and have installed several for others. System requirements and maintenance are minimal - you can run Prosody on a Raspberry Pi 1B if needed. Availability and reliability are high, it basically works as long as network connectivity and storage are available. The user experience largely depends on the client applications where Conversations on Android is probably the gold standard and in many ways comparable to Whatsapp.
When using OMEMO the server admin does not have access to cleartext communications so assuming clients are configured correctly there is not much to be gained from raiding the server. If some government entity wants to snoop on communications they'd have to gain access to at least one of the client devices since encryption is handled locally. Instead of backdooring centralised services run by Whatsapp or Signal or Telegram they'd have to get to a multitude of servers-under-stairs and client devices which makes it infeasible to use the 'dragnet approach' which is most likely the intended outcome of these backdoor laws.
Some decades ago at I heard Jello Biafra repeat his statement not to criticise the media but to become the media. This has happened, the (current incarnation of) legacy media is running on its last legs and has been overtaken by 'new' media. Here's a corollary to this statement:
Don't criticise the service providers, become the service provider
Use the internet as it was meant to be, a network of networks. Lots of networks, each running their own services with 'secure' communications between those services. I put secure in quotes because there might be a chance for some TLA or other organisation to break the encryption on one of those communication links. Even if they managed to do so they'd gain access to only a small fraction of the communications going on around the 'net.
But advocating for distributed communications only aids and abets criminals, won't you think of the children?
When guns are outlawed, only outlaws have guns. Criminals already use these services (and some of them have been broken/backdoored) so this is nothing new to them.
But you can't expect grandma to run her own server
No, I don't expect her to do so, she can use yours instead.
But but but but
You're starting to sound like a chicken.
Running this stuff is not hard. If you know how to do it, do so and help others to get started. While you're at it you can help them to secure their networks against intrusion by their service providers as well by making sure the ISP connection terminates at a router managed by the device owner, not the ISP. There is no reason to give the ISP access to your LAN since that only creates an incentive for those government entities to force the ISP to give them access to customer networks. The ISP should be used as IAP - internet access provider - and only be allowed to see whatever traffic you allow out of your network, not what goes on inside of it. That, though, is something for another post, another time.
I've been running services like this for decades, this works, it is not difficult and does not take that much time. It has only gotten easier over time, hardware has gotten cheaper and smaller, power use has gone down, performance has radically improved. This is not a pipe dream, it has been first my, then our reality for more than 30 years.
Don't criticise the service providers, become the service provider
Re: Signal to leave Sweden if backdoor law passes
#229Earlier quoted context omitted.
Yes, this is part of the problem. Application developers and the packagers should be distinct unrelated entities to reduce the chance of a malicious update being pushed to users if the developer sells out. F-Droid and Debian/etc show how this is done.
Without reproducible builds, this just means you have to trust the packager instead of the developer. Sometimes that's a good trade-off, but you still haven't really solved the problem, just moved it. With reproducible builds, you don't have to trust the packager or the developer as long as you trust at least one person who reviewed the source code.
Re: Signal to leave Sweden if backdoor law passes
#230Earlier quoted context omitted.
Also only possible because we use Signal as compiled by themselves and not by trusted third parties from a source kept clean of any future client-side backdoors. The client is open source, right? https://github.com/signalapp (Reproducible builds is a cool technique.)
Yes, this is part of the problem. Application developers and the packagers should be distinct unrelated entities to reduce the chance of a malicious update being pushed to users if the developer sells out. F-Droid and Debian/etc show how this is done.
It's all based in trust in the packager and only the packager—there are no checks and balances. The only reason why splitting up the responsibilities might help is if you find the F-Droid maintainers to be inherently more trustworthy than the Signal developers, not due to simply separating the concerns.