Earlier quoted context omitted.
And Google became a PRISM partner in 2009, as the slides here from the Snowden collection prove Read those slides more carefully: they say that collection from Google began on 1/14/09, not that Google became a willful partner of the PRISM program.
As the previous links from STRATFOR etc. prove, Google is deeply embedded in the security/intelligence apparatus. That part is definitely willing and beneficial to both parties. Of course, they're going to make changes and issue statements to the contrary regarding PRISM, because that would lose them customers. This is also an interesting read, albeit a bit long: https://wikileaks.org/google-is-not-what-it-seems/ Goo…
Why I won't recommend Signal anymore
231–240 of 350 posts
Re: Why I won't recommend Signal anymore
#232Earlier quoted context omitted.
I doubt you'd want to use it if it didn't use your contacts, though. Not many people are prepared to deal with a whole separate set of contact ids for the sake of a small amount of arguable extra privacy.
There could be two separate versions, one for paranoid users, one for those who don't care. The number of permissions Signal app requires is scary. It gets almost full control over your phone including reading SMS messages.
This is exactly why I'm shying back from recommending Signal to my family. I taught them that the equation "permissions = bad" generally holds, so Signal would look like spyware to them, even if every single permission turns out to be justified for some reason.
Re: Why I won't recommend Signal anymore
#233"Also, there’s the issue of integrity. Google is still cooperating with the NSA and other intelligence agencies. PRISM is also still a thing. I’m pretty sure that Google could serve a specially modified update or version of Signal to specific targets for surveillance, and they would be none the wiser that they installed malware on their phones." Isn't part of the reason that Moxie went with the Google Store is that h…
Google has root on your phone. That is enough for them to replace any signatures, steal keys, replace apps without you knowing etc.
Re: Why I won't recommend Signal anymore
#234Earlier quoted context omitted.
I'm not a cryptographer. I .. am reasonably sure that no one would take me for a hipster. But two issues - or call it 'differences in opinion' - in that article are relevant for me: The inability to use the service without a mobile number and federation. I understand the rationale behind the former ("It's easier"), but I don't understand why it is mandatory. I could've been 1283783127356128531312 on Signal and option…
Signal and Telegram are not the same thing. Telegram has, according to Reuters, been actively compromised by people working for oppressive regimes (Iran, in particular). If you're just using a secure messenger on general principles, it doesn't matter much which one you use. Probably WhatsApp is your best choice. But if you actually need secure messaging, you should be using the safest secure messenger. Since we don't…
As long as Telegram isn't compromised by USA-allied countries (Iran is somewhat allied with Russia), it might be a safer choice than Signal for US journalists. The reason is that USA can easily send a letter to Google that would reveal a lot about that person + they have root on the device.
Just like the safest place for Snowden right now is in Russia.
Re: Why I won't recommend Signal anymore
#235Like a lot of crypto-puritanism it is rather mixed up. He says he recommended Signal because it was easy to use (more consumer friendly I guess) and secure, then says he wouldn't have gone in the direction of making it easier to use and criticises the things that make it user friendly, like using phone numbers instead of usernames. He says he thinks the protocol is secure, then says he doesn't want it to use GCM beca…
People need to get the fact that all traffic across the Internet traverses lots of people's systems. There is no difference between it relaying off Google vs Verizon, AT&T, Amazon, OVH, or dozens of other carriers and cloud providers. Like you say that is the point of end to end crypto.
Re: Why I won't recommend Signal anymore
#236Earlier quoted context omitted.
You don't understand what I'm saying. I agree that crypto alone doesn't equal privacy --- it's table stakes. Clearly: it does not follow from that observation that crypto doesn't matter. If you cannot at least be cryptographically secure , the rest of what you do doesn't matter. We now have two examples --- CryptoCat and Telegram --- of "secure messaging" systems being used by governments as a way of hunting down act…
I see I haven't replied yet to your first point: here goes. Of course clearly an alternative has to be at least cryptographically secure . I fully agree with you on that. I'm not recommending something that isn't, and certainly am not recommending Telegram or Cryptocat. An alternative needs to be as a bare minimum cryptographically secure. And then on top of that it would be very nice if there was federation, not tie…
Hits all your technical requirements. Setting up your own homeserver is cake. Federation is a key part of the core design. End to end encryption is just about to be finalized. History syncing between multiple clients. Bridges for pulling in other chat systems like slack and IRC. Completely open source. To me, this is the perfect messaging platform. Just needs some UI polish and I could see it really taking off. Had you seen this yet?
Re: Why I won't recommend Signal anymore
#237Earlier quoted context omitted.
Signal and Telegram are not the same thing. Telegram has, according to Reuters, been actively compromised by people working for oppressive regimes (Iran, in particular). If you're just using a secure messenger on general principles, it doesn't matter much which one you use. Probably WhatsApp is your best choice. But if you actually need secure messaging, you should be using the safest secure messenger. Since we don't…
I am not using Telegram and wouldn't have used it if I was a US journalist working on something potentially dangerous, but I don't think this is a good argument. As long as Telegram isn't compromised by USA-allied countries (Iran is somewhat allied with Russia), it might be a safer choice than Signal for US journalists. The reason is that USA can easily send a letter to Google that would reveal a lot about that perso…
Re: Why I won't recommend Signal anymore
#238>I’m pretty sure that Google could serve a specially modified update or version of Signal to specific targets for surveillance, and they would be none the wiser that they installed malware on their phones. I'm not sure he understands how app signing works and why it would be impossible for Google to forge a developer's signature. He also seems to have a problem with GCM and Google in general. Perhaps he should look i…
Then later replace it with a signed version once they have the data they wanted. You would never know what happened.
Re: Why I won't recommend Signal anymore
#239For me I won't recommend it because of the horrible lack of options when you replace your phone (let alone lose it). No encrypted migrate. No backup options. Unencrypted loses content (images). Plus there's no way to search old messages.
Signal aims to be the most usable secure messenger, not the most usable messenger that also happens to be secure.
Re: Why I won't recommend Signal anymore
#240How does Signal compare to Telegram? Would you recommend Telegram as better or worse then Signal.
On Signal, every message uses end-to-end encryption. Signal's servers can't see the messages you are sending, only you and the recipient can read them. Signal's encryption protocol is carefully scrutinized and follows best-practices. Telegram sends messages in plain-text by default. Telegram servers have access to all plain-text messages that you send. Telegram's private chats use end-to-end encryption. But they use…