Live data from Hacker News

I don't trust Signal

drewdevault.com

251–260 of 473 posts

Re: I don't trust Signal

#251
post #108

Signal is not for state-proof encrypted communication. Not large states like the USA or Russia. If you think it is, you've been misinformed. For state actor proof communications you need to evaluate every action you take and think: "What are the assumptions that I'm making here?" One assumption is that you're not currently on anyone's radar. Are you willing to bet the entire enterprise on this assumption? How certain…

> Signal is not for state-proof encrypted communication. Not large states like the USA or Russia. If you think it is, you've been misinformed. Ok, but in that case what does Signal offer that any random messenger with transport encryption doesn't? If your threat model doesn't include state actors then you can probably trust a) the HTTPS certificate infrastructure b) an international corporation like Facebook, so you…

[deleted]

Re: I don't trust Signal

#252
post #48

Seriously, why do they use the smartphone in the first place? The smartphone ecosystem, be it Android or iPhone, is not secure. It can not be trusted. Even if we avoid Apple and Google's software distribution platform, Your smartphone still has binary blob kernel module, baseband processor and the OS runs on top of that. People who claims secure and trust on top of smartphone are all liar, idiot or both. Don't use th…

If your goal is to make secure communication possible for as many people as possible, you need to create an Android and iPhone app.

Re: I don't trust Signal

#253
If the consequences of sending messages are torture and death, I wouldn't trust any form of electronic communication. That's what face to face meetings are for and have always been for. I did not think signal is insecure, but either party could be compromised in other ways like a key logger or other local software that intercepts messages on the device they are composed on. I certainly wouldn't trust any mobile os based app although desktop ones might not necessarily be better even if they both run on a Linux os that's fully open source. Most people are not up against such threats, so in most cases it doesn't matter. For the people that are, they are brave in using such software. I would never place my life in the hands of such software. I simply wouldn't trust any such software with my life. By comparison, the software in my car or on a plane is a different matter but it's also engineered to different standards and has proven itself in a verifiable manner--I haven't died after much driving and many flights.

Re: I don't trust Signal

#255
post #193

Earlier quoted context omitted.

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play. The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't. This alone is enough for me to lose trust in Signal.

Are you going to pay for him to do that?

The Signal Foundation has 50 million dollars.

Re: I don't trust Signal

#256
post #237

Earlier quoted context omitted.

Yes, it can - for instance the Matrix servers that the French government runs do this by default already. We haven't exposed this as a config option and pushed it into mainstream Synapse yet because of https://github.com/vector-im/riot-web/issues/6779 , but the tweak for doing it is: https://github.com/matrix-org/synapse/pull/3426/files

Is this true? As far as I know, even in rooms with m.room.encryption, you can still send normal m.room.messages. Or does the config option you're describing automatically setup room PLs such that m.room.message can't be sent?

technically you can still send normal m.room.messages (or anything else), but any spec-compliant client will refuse to do so in a room where m.room.encryption has been enabled.

Re: I don't trust Signal

#257
post #193

Earlier quoted context omitted.

> Moxie forbids you from distributing branded builds of the Signal app ... Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction. > ... and if you rebrand he forbids you from using the official Open Whisper servers. This seems pretty fair to me. Not only could you abuse their resources, it would greatly hinder their ability to make changes and respon…

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play. The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't. This alone is enough for me to lose trust in Signal.

They've already made the APK available directly on their website for over a year now.[0][1] It works just fine (albeit a little heavy on battery usage) without the Google Play Store or Google Play Services. What more do you really want?

[0]https://signal.org/android/apk/ [1]https://whispersystems.discoursehosting.net/t/how-to-get-sig...

Re: I don't trust Signal

#258
post #193

Earlier quoted context omitted.

> Moxie forbids you from distributing branded builds of the Signal app ... Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction. > ... and if you rebrand he forbids you from using the official Open Whisper servers. This seems pretty fair to me. Not only could you abuse their resources, it would greatly hinder their ability to make changes and respon…

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play. The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't. This alone is enough for me to lose trust in Signal.

What I don't understand is why he's not doing that in spite of the fact that he could still keep control over Signal easily. One minor modification of the app and a forced upgrade would do the trick and render the F-Droid copies useless. The competition has been forcing users to upgrade in this way for a couple of years now. So I don't understand what he's afraid of.

Re: I don't trust Signal

#259
post #193

Earlier quoted context omitted.

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play. The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't. This alone is enough for me to lose trust in Signal.

They've already made the APK available directly on their website for over a year now.[0][1] It works just fine (albeit a little heavy on battery usage) without the Google Play Store or Google Play Services. What more do you really want? [0] https://signal.org/android/apk/ [1] https://whispersystems.discoursehosting.net/t/how-to-get-sig...

The article is clear: download from the Signal site is not secure.

Re: I don't trust Signal

#260
post #223

AFAIK, Signal has an open source client, and an open source server. If you want federation, you can go ahead and build it, and find users, and you can start from a reasonably well working base. Moxie isn't going to build it, because he doesn't think federation works; to convince him, you'll need to show him it works, not just tell him. Is there an example of a federated chat service which has end to end encryption th…

> Is there an example of a federated chat service which has end to end encryption that just works?

Yes. SilenceIM is a fork of Signal that maintains only the SMS implementation of the Axolotl ratchet. It works perfectly.

For that matter, every other chat network does too, if you use Pidgin and the pidgin-otr plugin.

End to end encryption is a property of the clients, not the network, practically by definition.

Post reply on HN