Live data from Hacker News

Signal says it won’t compromise on encryption

theverge.com

231–240 of 336 posts

Re: Signal says it won’t compromise on encryption

#231
post #198

Earlier quoted context omitted.

> Signal indicated that arbitrary usernames is something they're working on. no offense but they've been saying this for years, the feature may eventually come but I'm not holding my breath

I hate having to come up with a username. A better (IMHO) solution would be GUIDs or similar, generated on-device.

Bitwarden will now generate usernames for you, like it can generate passwords.

Re: Signal says it won’t compromise on encryption

#232
post #7
post #4

Reminder that Apple did this domestically for the FBI/iMessage. They intentionally maintain a backdoor in the end to end crypto of iMessage: https://www.reuters.com/article/us-apple-fbi-icloud-exclusiv...

This is incorrect. iMessage is encrypted, the encryption is end-to-end, there are no backdoors. The unencrypted backup is a clear and annoying hole in the apple privacy story, but the non-e2ee iCloud backup does not include any messages (SMS, MMS, or iMessage), Contacts, Calendars, Notes, iCloud Photos, or health data. A local backup is local, and is protected by filesystem encryption on your local storage. So no, iM…

> iMessage is encrypted, the encryption is end-to-end, there are no backdoors.

In Germany, we have a saying: "Wer glaubt wird selig." which could be translated as something like: "Blessed are they who believe."

Re: Signal says it won’t compromise on encryption

#233

I have nothing against Signal, Moxie, etc — but it attracts high-value targets. As such, Signal is an extremely high-value target. >> Signal knows nothing about who you are. This is based on trust, not systematic proofs, Signal knows this, yet never tells its users. For example, Signal uses Intel’s Software Guard Extensions (SGX) - which is know to have multiple attacks, any of which Signal might be forced to run usi…

> any of which Signal might be forced to run using national security letter. NSLs can demand information but cannot compel action. The govt cannot use an NSL to force you into military service, for example, or force you to hack someone else’s computer (which is essentially what you are suggesting).

Regardless if they were “compeled” - nation security letter related activities have included actions.

For example, this included a room and split:

- https://wikipedia.org/wiki/33_Thomas_Street

My understanding is that vendors that execute national security letters offer system integration technology to be locally installed to ingest the related data.

Signal has the data, it just requires them collecting it — hence my statement that Signal’s security is based on trust, not physics, math, etc.

Re: Signal says it won’t compromise on encryption

#234
post #147

Encryption is just a tip of the iceberg here. There are several major problems with Signal: - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways. - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers. You can’t…

Your "major problems" are fair, but nothing's perfect, so unless you have a better solution with the same design constraints (e.g. https://github.com/signalapp/Signal-Android/blob/main/CONTRI...), they are rather moot, because they're not actionable. That being said:

> - it is not that private after all since it requires a phone number. Yes, you can override this by using some virtual throwaway number if you are geeky enough but your account will be associated with this phone number anyways.

You still leak very little because of their sealed sender feature. If you allow arbitrary usernames, you need to bootstrap your trusted channel from no assumption instead of a weak one (if I receive a message from @barack_obama for the first time, I have no clue if it's actually someone I know, while a message from @+1235312 indicates that the sender at least had access to this number at some point to register). All solutions have tradeoffs.

> - as a consequence you _will_ receive spam from bots fanning out messages to phone numbers.

There's very little spam now on Signal (I think I've had 2 spam messages in about 4 years). At one point there was a bit, but server-side measures are now preventing that.

You can't really have no spam at all as long as you have a common id that's shared among your contacts, which is the case most of the time for usability, as any of these contacts can leak this id somehow.

> - Signal protocol is probably great from the e2ee perspective but it is not federated and unlike XMPP you cannot spin up your own server and have full control over it.

Signal's approach is that you shouldn't care about the server. Why do you?

> And I am sure you cannot run an end-to-end audit of the whole Signal platform to verify that what they actually run has been built from the source code you have audited.

You can do that on the client code, which is reproducible, and again mostly what you should care about.

> - Since it is centralized, Signal is prone to censorship in those countries that decide to fight it.

I'd say that their reliance on phone numbers is the main issue with censorship: if new users can't receive their registration text message, they cannot register.

AFAICT people in censored countries still rely on WhatsApp, Signal and similar messengers instead of more niche but more decentralized alternatives like Tox. Again, however bad their current approach might be, it's a moot point until there's something that works better in practice.

Re: Signal says it won’t compromise on encryption

#235

Earlier quoted context omitted.

Non profit but still against federation or anyone running an alternative client. Why?

It's a non profit so it can receive donations, but the developer is a LLC that's run for profit. It's a similar story in almost all software companies that market themselves as non-profit foundations (Mozilla too btw) https://en.m.wikipedia.org/wiki/Signal_Foundation#Signal_Mes...

There are some things non-profits are not allowed to do. But, owning a for-profit isn't one of them, and the for-profit is allowed to do those things. So hence this is a common strategy.

Example: Suppose I bulk buy T-shirts printed with my cool logo for $15 each and I sell them to consumers for $50 each. That's a for-profit activity, if Walmart was allowed to have a "non-profit" arm which did this I'm sure they would, the tax saving would be considerable.

Re: Signal says it won’t compromise on encryption

#236
post #37
post #31

Earlier quoted context omitted.

> iMessage is encrypted, the encryption is end-to-end, there are no backdoors. How would/could we know? If the NSA doesn't have a backdoor (whether that's in the non-public iMessage code, the hardware RNG on iPhones, or somewhere else), what are they even doing all day?

We know authoritatively. Buy a new iPhone and create a new Apple ID. Install an app (which automatically logs you in to iCloud and automatically enables iCloud backup). Wait 24 hours plugged in to AC power. Remove the SIM card and throw the iPhone into the sea. Forget the password for the Apple ID. Buy a new iPhone, and get Apple to reset the Apple ID password using PII/SMS/whatever. Log in and restore your iCloud ba…

Yes, this is the back door, if you want to call it that. iCloud backups are not encrypted and contain key material.

Re: Signal says it won’t compromise on encryption

#237

Earlier quoted context omitted.

Kazakstan mandated government issue man-in-the-middle TLS certificates: https://www.zdnet.com/article/kazakhstan-government-is-inter... The EU is following this govennment friendly move: https://www.bleepingcomputer.com/news/security/experts-urge-... It would not be difficult for India as well. I see itlikely Modi and BJP will make this move as part of some anti-terrorist legislation.

Personally I find it unbelievable that major governments are not already in possession of the private key for at least one of the 150+ root certificates pre-installed on my device.

This would be a lot of effort for very little reward.

The problem is that those keys can't be used passively. Just knowing these keys achieves nothing (lay people often assume you could snoop TLS, but, that's not how it works with a CA root even in archaic SSL versions) The only useful thing you can do with those keys is make certificates (the thing the CA gets to do legitimately) but presumably you'd make bogus ones.

But in most of the world's web browsers those certificates don't work unless they come with SCTs, receipts from two or more public certificate transparency logs promising they logged these certificates.

So now as well as obtaining private keys to a trusted root CA, you need to break at least two of the CT logs.

This deliberately and unavoidably creates a paper trail showing what happened. All three entities (the root CA and two logs) have their reputations destroyed and if they're for-profits presumably go bankrupt (or the business unit fails).

And what did you get for this? A forged certificate? Maybe a few dozen if you targeted carefully. Maybe you were able to pull this off for a whole week before alarm bells got too loud to ignore ?

Re: Signal says it won’t compromise on encryption

#240
Signal is already compromised. I don't understand why people still keep fooling themselves it's private and secure.

It requires a mobile number, and thus your identity is known and your device is uniquely identifiable anyway, and it's also developed in the US where three-letter agencies have infinite reach and control.

Post reply on HN