Live data from Hacker News

Looking back at how Signal works

signal.org

271–280 of 301 posts

Re: Looking back at how Signal works

#271
post #196

Earlier quoted context omitted.

It seems to be about the clients rather than the server. A level deeper than "how signal works" and more "how signal is made" For example, I'd expect a "how signal works" article to explain why they even need when an account was registered and when it was last used. "this phone number is using signal" is still a pretty large metadata leak. Especially when state actors and probably a fair few non state actors can remo…

>"this phone number is using signal" is still a pretty large metadata leak. >Especially when state actors and probably a fair few non state actors can remotely compromise devices via the stuff in the baseband processor. A more accurate phrasing would be "this phone number was used to activate signal". If you only care about messaging other Signal users, you only need to have a baseband connection exactly once, when y…

wifi is still in the baseband processor.

There have been mutiple baseband RCE exploits published in the literature and demonstrated at blackhat - and they dont include any that were put there intentionally.

If you are not using a sim smartphones are pretty useless.

Im a long way from convinced that centralised servers have any role to play in reasonably secure e2ee, they certainly are not a requirement for other services such as firechat used to use before they got shutdown and bridgefy is making use of.

Re: Looking back at how Signal works

#272

Earlier quoted context omitted.

I'm a massive Matrix fan and have high hopes for it but in experiments we've done with activist and journalist partners we've found the Riot.im client often gets a bit complicated for people to use. I think the main issue people have is related to keys. As I techie I love the options but I find many don't like having all the options. Signal of course is a lot easier as it hides many of those issues in the UI/UX.

The root problem is the requirement to verify that you are talking to who you think you are talking to. If you skip the identity verification stuff then you are inherently trusting a 3rd party. So if you are not exchanging your key fingerprints (safety numbers in Signal terms) then you are kidding yourself.

Even without verifying safety numbers, you’re still better off on Signal then you would be on another platform that doesn’t even offer the option of verification. If you’re looking to MITM a conversation on Signal you can only guess whether or not the recipients have verified each other, whereas on a platform like iMessage you know they haven’t because it’s not an available option.

Re: Looking back at how Signal works

#273
post #240
post #146

Earlier quoted context omitted.

It really depends on your threat model: do you trust the people you are talking to but not Signal (though in practice this doesn't even work as they are way too centralized, but whatever), or do you not trust the people you are talking to but are willing to trust Telegram? Clearly we should be able to have something where we don't trust either, as there is nothing about these phone numbers that is critical to Signal'…

Moxie addressed the phone number issue[0]. To save time he mentions that owning a SIM card or a smartphone with a Contacts application that holds phone numbers is a portable social network by design. Pushing his idea further it's much easier for anyone to learn the penetration of Signal by checking against existing phone numbers. I can't imagine someone with a 200+ phone numbers querying service to validate a phone n…

You are defending why phone numbers are useful, but are completely choosing to ignore the point I am making about the tradeoff of who you trust.

To be even more explicit about it, in the hope you understand: the vast majority of people trust large companies (which is bad but frankly not insane) but absolutely do not trust random assholes/creeps on the Internet. The security model of Signal is saying you don't have to trust Signal, but you weirdly do have to trust all of the random people you interact with with your phone number.

And so, in the context of this thread, that explains why someone would claim Telegram is actually better than Signal, because what people do with Telegram is join massive group chats that are either 1) public, 2) have so many people in them that if you think what you say isn't going to be logged you are fooling yourself. So the value of end-to-end encryption in this context is essentially zero; but, being able to join some large group chat with a ton of strangers to talk about some open source project or whatever you are doing without any of those people now knowing your phone number--an identifier which is tied to a large number of "real world" concerns and is ridiculously difficult to change--is actually extremely valuable.

Honestly, even if you aren't quite in those sets, the tradeoff still isn't an obvious win for Signal. As an example, let's say you are in a group of people talking about a protest. Are you more concerned that the company relaying your messages will be served a warrant to monitor your chat activity (which generally has some requirement of probable cause for a specific action, and likely requires knowing about the existence of a chat in the first place) or that one of the people in your group chat is actually a traitor or even an undercover cop (which can get in a number of groups and pretend to be an ally while passively monitoring for things they want to shut down)? The latter is actually a much more realistic attacker model, and with Signal now that person has your phone number, which means you are screwed. Using Signal correctly here requires getting a burner phone, which is way more effort than is reasonable.

The use cases for the privacy and security model of Signal are thereby inherently limited to people you trust with your phone number. Like, it is sometimes difficult enough to get people to want to use text messages sometimes as they don't want to give out their phone number: Signal doesn't solve that, and so is confined to the subset of communication that people currently do over SMS(/iMessage) and can't really ever begin to carve into the market share of Telegram, or even Facebook.

And so, realistically, Signal does not, can not, and should not manage to displace Telegram, which I say with sadness as I am someone who has not and likely never will forgive Telegram for claiming security properties their system didn't have (like, I am not Telegram fan, and while I have the app I only use it a few times a year; that said, this is more than I am willing to tolerate Signal, due to a number of reasons that are mostly unrelated to anything in this comment).

(And FWIW, I personally would not recommend usernames, and in fact would personally be much more angry about that than phone numbers for various reasons; if Signal decides to roll out unique choosable usernames I am honestly probably going to hate on it even stronger because of it: you are arguing a strawman here :/. But to claim that phone numbers are fundamentally better is awkward regardless, given how phone numbers aren't even a good security layer due to the prevalence of number porting. This is just one of the many devastating things that Moxie is wrong about.)

Re: Looking back at how Signal works

#274
post #196

Earlier quoted context omitted.

>"this phone number is using signal" is still a pretty large metadata leak. >Especially when state actors and probably a fair few non state actors can remotely compromise devices via the stuff in the baseband processor. A more accurate phrasing would be "this phone number was used to activate signal". If you only care about messaging other Signal users, you only need to have a baseband connection exactly once, when y…

wifi is still in the baseband processor. There have been mutiple baseband RCE exploits published in the literature and demonstrated at blackhat - and they dont include any that were put there intentionally. If you are not using a sim smartphones are pretty useless. Im a long way from convinced that centralised servers have any role to play in reasonably secure e2ee, they certainly are not a requirement for other serv…

> wifi is still in the baseband processor.

> There have been mutiple baseband RCE exploits published in the literature and demonstrated at blackhat - and they dont include any that were put there intentionally.

You can't target a WiFi exploit against a phone number though, so that's irrelevant to the Signal situation.

>If you are not using a sim smartphones are pretty useless.

Maybe I spend too much time hanging around places with WiFi, but I almost never need to have a sim card. I don't even have data on my current plan.

Re: Looking back at how Signal works

#275
post #164

Earlier quoted context omitted.

Signal is still open source and is not a commercial entity.

> Signal Messenger, LLC, is a software organization that was founded by Moxie Marlinspike and Brian Acton in 2018 Did you google it? You're simply wrong. It is open-source as it was, I didn't dispute that, but they are liable for their users if this bill passes, and they will easily go bankrupt. If there's no commercial entity, then liability falls to the developers most likely--whose identity can be obscured since t…

No; I didn't have to Google it because I've been paying attention to Signal for the better part of the last decade. I'm afraid it is you who are mistaken.

If you've googled it, surely you're aware of the Signal Foundation[1], the 501(c)(3) parent organization of the LLC.

And while OWS/Signal Messenger did not have formal non-profit status prior to the Signal Foundation, it was never acting as a for-profit entity[2]:

> in general, Open Whisper Systems is a project rather than a company, and the project's objective is not financial profit.

[1]: https://projects.propublica.org/nonprofits/organizations/824...

[2]: https://news.ycombinator.com/item?id=7701666 (2014)

Re: Looking back at how Signal works

#276

Earlier quoted context omitted.

anecdote time: My 6 year old son just discovered the augmented-reality tricks in the LINE app (adding a mustache, hair, glasses, sound effects etc). He got my mother (68) to install it and now they use it pretty much for all their video conversations. This replaced FaceTime, despite FaceTime having better sound and picture quality (edit: and even some effects). He's in the age (and COVID-19 environment) where he star…

Favoring mustaches over security is always the choice you can make. I don't care about adoption unless it falls below levels to make signal worth developing.

That's a false dichotomy because LINE does end-to-end encryption.

Re: Looking back at how Signal works

#277

Earlier quoted context omitted.

I would understand the urgency if this issue would occur in the app when you open it normally but the lock screen? Really? At this point I'd say you desperately look for something to complain about. Why don't you just not use it and check your PC? There is obviously something wrong with it.

I'm not talking about the lock screen, I'm talking about screen lock, and I'm talking about the mobile, not the desktop. How would you even take a photo in landscape using the desktop?

I wasn't talking about desktop with your photo issue.

And I don't know what you mean by screen lock if it's not the lock screen. However, as I said: the photos are properly oriented within the app so whatever your issue is, it can't be that urgent...

Re: Looking back at how Signal works

#278
post #273
post #240

Earlier quoted context omitted.

Moxie addressed the phone number issue[0]. To save time he mentions that owning a SIM card or a smartphone with a Contacts application that holds phone numbers is a portable social network by design. Pushing his idea further it's much easier for anyone to learn the penetration of Signal by checking against existing phone numbers. I can't imagine someone with a 200+ phone numbers querying service to validate a phone n…

You are defending why phone numbers are useful, but are completely choosing to ignore the point I am making about the tradeoff of who you trust. To be even more explicit about it, in the hope you understand: the vast majority of people trust large companies (which is bad but frankly not insane) but absolutely do not trust random assholes/creeps on the Internet. The security model of Signal is saying you don't have to…

>>You are defending why phone numbers are useful, but are completely choosing to ignore the point I am making about the tradeoff of who you trust.

You're swiftly jumping to conclusions on a comment that only describes a point of view. Not my own perception of how the trust model should be established and the capabilities current messaging services provide.

>>... but, being able to join some large group chat with a ton of strangers to talk about some open source project or whatever you are doing without any of those people now knowing your phone number--an identifier which is tied to a large number of "real world" concerns and is ridiculously difficult to change--is actually extremely valuable.

As someone who suffered harassment by getting the p/n exposed at Whatsapp and being followed by the same person almost everywhere where's it serves as an id (Signal, Telegram) i wholly share your concerns. But it's a privacy matter that almost none of the current messaging platforms really offers bundled with solid UX and data transparency.

What am i trying to convey by how i comprehend Moxie's rhetoric is that Signal tries to be a Whatsapp alternative (given the latter really can access messages in a group conversation when a participant reports contact) by not harvesting the user data (cheers Telegram) and providing little bit more control over the conversation on both ends (self destructing messages). Signal has bigger focus on security right now however the use case is to be accessible to a wider audience. From that point of view Signal really stands out. And it helps me personally to, sort of, separate communication spaces.

>>Honestly, even if you aren't quite in those sets, the trade off still isn't an obvious win for Signal. As an example, let's say you are in a group of people talking about a protest.

Look, if you propose Signal needs to accommodate guerillas, rioters and protesters organize and act with impunity it's a privacy issue and Signal isn't serving this purpose.

Re: Looking back at how Signal works

#279

Earlier quoted context omitted.

Some googling leads to this [1]. From what I read it seems to be an opt-in program (for now). Was initially very concerned when I read your post, especially because Google recently broke Magisk (likely forever). [1]: https://www.xda-developers.com/google-advanced-protection-pl...

> Google recently broke Magisk (likely forever) Can you give more details on this? I wasn't able to find anything with google-fu except this post, which is surprising.

Basically Google has actually implemented remote attestation properly (using hardware) so Magisk can't hide unlocked bootloaders anymore unless someone finds a crypto flaw. It's slowly being rolled out to Play Services but I believe cts still passes for now.

https://www.xda-developers.com/magisk-no-longer-hide-bootloa...

Re: Looking back at how Signal works

#280

Earlier quoted context omitted.

The root problem is the requirement to verify that you are talking to who you think you are talking to. If you skip the identity verification stuff then you are inherently trusting a 3rd party. So if you are not exchanging your key fingerprints (safety numbers in Signal terms) then you are kidding yourself.

Even without verifying safety numbers, you’re still better off on Signal then you would be on another platform that doesn’t even offer the option of verification. If you’re looking to MITM a conversation on Signal you can only guess whether or not the recipients have verified each other, whereas on a platform like iMessage you know they haven’t because it’s not an available option.

SS7 spoofing is not a hard thing to do. Who knows if you really are initiating to +14055551212 who you think they are. I guess using multiple techs in serial could obfuscate the initiation correctly (voice, IM, Social Media, etc)
Post reply on HN