Live data from Hacker News

I don't trust Signal

drewdevault.com

261–270 of 473 posts

Re: I don't trust Signal

#261
post #239
post #236

Earlier quoted context omitted.

This seems like smoke and mirrors to me: Traditionally, in Signal that process has looked like: The client calculates the truncated SHA256 hash of each phone number in the device’s address book. The client transmits those truncated hashes to the service. The service does a lookup from a set of hashed registered users. The service returns the intersection of registered users. The phone number space is really not this…

They acknowledge that in literally the next paragraph, and the entire post is about how they improved on that old state of things. How is that "smoke and mirrors"?

Right, my bad. This does look like a sensible solution

Re: I don't trust Signal

#262
post #135
post #64

Earlier quoted context omitted.

Signal did what those things failed to do which is to actually gain some popularity outside of HN. I hope Matrix takes off! In the meantime if people are convincing their families and friends to get on Signal then that's a net positive to me.

@ynniv - because if you can coax a friend who isn't on anything but Facebook to use Signal over, say, Messenger, then it is a net win. Is it perfect? No. Is it a better situation than the current? Yes.

Exactly. Signal's most important feature is that it isn't Facebook.

Re: I don't trust Signal

#263
post #109
post #64

Earlier quoted context omitted.

Signal did what those things failed to do which is to actually gain some popularity outside of HN. I hope Matrix takes off! In the meantime if people are convincing their families and friends to get on Signal then that's a net positive to me.

What's the point of gaining traction if it doesn't deliver on its fundamental promise?

Because the theoretical possibility of being monitored on Signal is preferable to the near-certainty of being monitored on Facebook Messenger.

Re: I don't trust Signal

#264
I agree that Tox is better but at the same time I know people who truly need to stay hidden and they use Signal on a burner phone with a cash sim-card. That way it doesn't matter which medium the messages are transmitted over because it still can't be traced back to them.

And as far as I know the encryption is solid.

Unlike some other alternatives like Wickr Signal actually open sources their app and their communication protocol.

Re: I don't trust Signal

#265

Earlier quoted context omitted.

If you're concerned about security you don't use a smart phone and don't use your phone as a computing device. I know it's a lot to ask of people and so most will simply ignore the massive, unfixable (at least yet), security and privacy issues (ie, 5 years of your location 24 hours a day tracked, stored, and sold to whoever wants to pay). But really, smart phones are bad. Even dumb cell phones are bad. And if you car…

Totally agree, and will use a real computer once I find pants with wide enough pocket for it :)

Here you go: https://pyra-handheld.com/boards/pages/pyra/

Real computer with 4G voice and data, open source, isolated baseband, runs Debian, qwerty keyboard, size of an original Gameboy.

Only catch is some drivers require blobs. And it's not out yet. Any month now...

Re: I don't trust Signal

#266

Earlier quoted context omitted.

> An open-source server is certainly a step up from Signal https://github.com/signalapp/Signal-Server . You are spreading a lot of incorrect or misleading information about Signal in this thread. That makes it difficult to assume that you're arguing in good faith here.

The server might as well be closed source. We have no guarantees that Moxie is actually running this in production and he refuses to federate with third-party servers.

This is addressed in https://signal.org/blog/private-contact-discovery/ – using Intel SGX, it's possible for the clients to verify that the server is running the code it should be running. I'm not sure whether this is already deployed, but it refutes any claim that Signal isn't serious about your concern.

I don't see how federation is related to this at all. We know you're bummed about it, you don't need to inject it into every subthread.

Re: I don't trust Signal

#267
This article is entirely about the Play store and F-droid.

As a user, when an app claims to be 'secure', I expect the app itself to have made reasonable security tradeoffs. I don't however expect them to change my OS, my package manager, or anything else. The security of those other components isn't their concern.

Re: I don't trust Signal

#268

Earlier quoted context omitted.

On Android that's version dependant. Older Android versions only had the idea of the app declaring "I need to be able to use your Camera, read your Contacts, and make $$$ phone calls" and then you pick "No" and don't get the app or you pick "OK". This more or less railroads users into pressing "OK", except for the most security conscious, who go without the app. A few releases back Google had an unofficial feature th…

The permissions system that android apps use is entirely dependent on which API version you target. Last I understood, if you made a new app today and purposely chose to target an old API version, you could force it to use the "all or nothing", user hostile permissions query you described

I believe Google is asking developers to support a recent API version to push updates to the Play Store.

Re: I don't trust Signal

#269
post #39

Some version of this post seems to circulate every few months or so. This one is more direct in its accusations of Moxie acting in bad faith. I think this is disingenuous. Moxie has been very clear[0] about the tradeoffs that Signal has made and the reasons for them. It's fine to be dissatisfied with those choices. It's another thing entirely to accuse Moxie of dissimulating. Personally, I'd like to see Signal replac…

But in the linked post he does not explain, why he does not maintain a F-Droid repository for people who do not trust google, nor why the original Signal Client does not connect to Signal Forks, even if they use everything the same. Security reasons? Ordinary smartphones are full of rootkits anyways, so someone using a forked Signal version probably is better of anyway, as he knows a bit more what he is doing. So the…

He has previously explained his reasoning: https://github.com/signalapp/Signal-Android/issues/127#issue...

Re: I don't trust Signal

#270
post #193

Earlier quoted context omitted.

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play. The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't. This alone is enough for me to lose trust in Signal.

They've already made the APK available directly on their website for over a year now.[0][1] It works just fine (albeit a little heavy on battery usage) without the Google Play Store or Google Play Services. What more do you really want? [0] https://signal.org/android/apk/ [1] https://whispersystems.discoursehosting.net/t/how-to-get-sig...

>What more do you really want?

For it to be on F-Droid. I think that much was clear.

Post reply on HN