Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

251–260 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#251
post #238
post #109

Earlier quoted context omitted.

That was only added 19 days ago - after months of people (politely) asking for it to be acknowledged as a serious concern. https://github.com/signalapp/Signal-Android/commit/0a29ffcf4...

What would you consider to be an acceptable length of time for a feedback cycle for an understaffed organization who gives away their services for free? I think "months" can be entirely reasonable. At this point you're not complaining about the end result -- they did actually implement something as a result of the feedback -- you're just complaining about the time it took them to do so. Which is IMO pretty silly, as…

I think a swift acknowledgement is useful.

Moxie could have said "gosh, that sounds like a serious issue. Let us investigate it." Instead, he ignored the women reporting it, sent snarky DMs about the people involved, and stonewalled any attempt to discuss it.

The fix was made - as far as I can tell - without any engagement with the community affected by the problem.

Signal received $50m in funding a few years ago. If they're understaffed, something is awry.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#252
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

" You were blocked because you know that we don't use GH for discussion, but came here anyway and started opening fake PRs so that you could post and harass other people on GH. " That is a very odd statement.

Reading through the PR in the link, I can see where Moxie is coming from. There's very little actual discussion happening, mostly just flamewar-lite. Maybe the other PR's/issues/forum posts are better.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#253
post #73

The answer from Moxie to these people: https://github.com/signalapp/Signal-TLS-Proxy/pull/15#issuec... I think that says it all. I'm also a bit concerned that "security researchers" don't seem to understand the threat model. Signal has never claimed to be able to hide that it was being used. The TLS proxy is only meant to help circumvent censorship, not obfuscate its protocol. And indeed, as a temporary solution, it'…

" You were blocked because you know that we don't use GH for discussion, but came here anyway and started opening fake PRs so that you could post and harass other people on GH. " That is a very odd statement.

What’s odd about it?

I do wonder how Moxie knew this guy knew that GH is not used for discussion. Maybe the only way to tell is to see that there are no other active discussions?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#254
post #21
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…

> The tone is not more important than the facts. It never is.

We don’t live in the same world. Without proper tone, my message is never received. And yours is?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#255

Earlier quoted context omitted.

> Signal has never claimed to be able to hide that it was being used. From their blog post some days ago, I thought it did just that: > Unlike a standard HTTP proxy, connections to the Signal TLS Proxy look just like regular encrypted web traffic. There’s no CONNECT method in a plaintext request to reveal to censors that a proxy is being used. Valid TLS certificates are provisioned for every proxy server, making it m…

My read on that statement was "the censors can't just /dev/null anything with a plaintext CONNECT". Given its broad user base, it wouldn't hurt for Signal to clearly state "we can't keep the fact of the communication private, only the contents". That would short-circuit attempts to gain notoriety by pointing out obvious facts and calling them vulnerabilities. It's also common sense for anyone who knows their way arou…

I currently live in a country without such strong protections for individuals, and discussing this with a friend, I feel this is a disconnect between many of the HN posters who don't live in countries where such concerns are very common. This is not a judgement of "who has it worse", but more that from my observation, there are many important elements missing from the discussion that those who haven't had to consider that their posts/comments might land them or their family (or both and more) in jail.

Everyone in my country of residence uses Telegram; not because it's secure, but because for non-serious chats, it's convenient.

This is a statement/truth that I think a LOT of people don't quite get; Pavel Durov and his team might push that Telegram is secure, but no one uses Telgram for security because nothing about its security ensures a circle of trust.

This is true for any messaging app. The general consensus I've encountered is that any application you can readily pull from the AppStore/GooglePlay, so can adversarial persons. If they really want to target you for some reason, it's as simple as getting your friend and unlocking their phone, knowing the the same protections that people in the United States have don't apply world wide.

Signal et.al., can have the world's most amazing crypto, but it means nothing if the person behind the unlocked phone is an adversary, and I think a threat-vector that is missed in the 200+ post discussion here is that in many parts of the world, __this is a real threat vector__. A password/second screen/whatever is not a guarantee of protection! It's a speed bump, and how resilient you are to the person driving over the speed bump is how effective that bump is.

So, for the article when I read persons concerned about the statements made by Signal and not outlining the threat factor for countries where the Circle of Trust might literally be a matter of life or death, yeah, I side with the concerned persons. Signal has impressive tech, but again, that tech means __nothing__ if the person behind the unlocked device is adversarial.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#256
post #224

Earlier quoted context omitted.

There's no reason to post in the fashion of a glib marketing department person if you're not. And I don't think ANYBODY finds requiring a phone number "because it's discoverable, familiar, usable" is convincing especially when considering that dissidents are apparently one of the major groups this is marketed to. The whole thing smells funny, there's no reason to require a phone number other than Rosendfeld WANTS it.

What is stopping someone from running signal on a dedicated burner if they're worried about it? Different people have different threat models and I think asking for a phone number for the reasons posted above is acceptable for most people.

There really is no such thing as a dedicated burner. you don't even need NSA level threat vectors for most phone sim purchases in western countries to exfiltrate tons of user data.

Wifi is even worse, not better..

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#257
post #241
post #207

Earlier quoted context omitted.

Why is Signal positioning itself as a solution when Rosenfeld admits it’s not ready?

They're not. They released something as a stopgap measure that will help some , but not all, people in Iran get back on the app, because their better, longer-term solution is not ready, and they believed that people there needed at least something in the short term.

That something could easily get them killed.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#258
post #156
post #122

Earlier quoted context omitted.

he was banned on the forums too

He wasn't. Why lie about this? https://community.signalusers.org/u/DuckSoft/summary

im just quoting the parent article. can yall read it before commenting and making accusations?

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#260

Earlier quoted context omitted.

" You were blocked because you know that we don't use GH for discussion, but came here anyway and started opening fake PRs so that you could post and harass other people on GH. " That is a very odd statement.

What’s odd about it? I do wonder how Moxie knew this guy knew that GH is not used for discussion. Maybe the only way to tell is to see that there are no other active discussions?

How do they harass people if they don't use GitHub for discussion? What is a "fake pull request"? Why is the project on GitHub if they don't use it?
Post reply on HN