Live data from Hacker News

I don't trust Signal

drewdevault.com

281–290 of 473 posts

Re: I don't trust Signal

#281
post #58

Federation is not some sort of magic dust that would fix signal, you'd be just exchanging one problem (centralization) with another (spam). Plus in all likelihood even if they did federate, it would just be like email with gmail that the Open Whisper Systems is the dominant player so most conversations have at least one party running on Moxie's hardware.

> one problem (centralization) with another (spam)

I'd take the risk of possibly receiving more spam over the risk of depending on yet another walled garden.

Re: I don't trust Signal

#282
post #235

Earlier quoted context omitted.

And who is paying for Signal to be on Google Play?

google, facebook, whats app, microsoft. Basically the companies that pay for signal end to end encryption in their chat apps. There are, I'm sure, apps that are better, and that's never been moxie's goal. He's said it over and over that he'd rather have encryption for the masses than the perfect messaging app. It seems disingenuous to assume that he's acting in bad faith when he's clearly doing exactly what he said h…

Pushing an app out to F-Droid is trivial. There is literally no defense for only using Google Play and unsigned binaries on his own website.

Re: I don't trust Signal

#283
post #265

Earlier quoted context omitted.

Totally agree, and will use a real computer once I find pants with wide enough pocket for it :)

Here you go: https://pyra-handheld.com/boards/pages/pyra/ Real computer with 4G voice and data, open source, isolated baseband, runs Debian, qwerty keyboard, size of an original Gameboy. Only catch is some drivers require blobs. And it's not out yet. Any month now...

[deleted]

Re: I don't trust Signal

#284

Earlier quoted context omitted.

But in the linked post he does not explain, why he does not maintain a F-Droid repository for people who do not trust google, nor why the original Signal Client does not connect to Signal Forks, even if they use everything the same. Security reasons? Ordinary smartphones are full of rootkits anyways, so someone using a forked Signal version probably is better of anyway, as he knows a bit more what he is doing. So the…

"why he does not maintain a F-Droid repository for people who do not trust google" Are you paying him to do that? No? Well, there you go. It's more work, for what appears to be very little benefit.

As another person said:

> The Signal Foundation has 50 million dollars.

Re: I don't trust Signal

#286

Earlier quoted context omitted.

"why he does not maintain a F-Droid repository for people who do not trust google" Are you paying him to do that? No? Well, there you go. It's more work, for what appears to be very little benefit.

As another person said: > The Signal Foundation has 50 million dollars.

Doesn't matter. F-Droid is more work to support.

Re: I don't trust Signal

#287
post #276
post #181

Earlier quoted context omitted.

It could do that.

How? (I work for Google, I don't work on Android)

The Play services run as root IIRC and listen to commands from Google's servers (e.g. to push updates to the devices). Even if they don't have enough priveleges to intercept the keyboard, Google has all the signing keys to replace system apps that do.

Re: I don't trust Signal

#288
post #259

Earlier quoted context omitted.

They've already made the APK available directly on their website for over a year now.[0][1] It works just fine (albeit a little heavy on battery usage) without the Google Play Store or Google Play Services. What more do you really want? [0] https://signal.org/android/apk/ [1] https://whispersystems.discoursehosting.net/t/how-to-get-sig...

The article is clear: download from the Signal site is not secure.

Based upon what? The download is served via HTTPS, and offers a checksum also secured via HTTPS. Are we entertaining security models in which PKC is considered "not secure"?

Or are we just going by the author's ignorant or disingenuous (depending on how you interpret his words) statements?

Re: I don't trust Signal

#290
I personally don't distrust Signal.

I just refuse to use it. This comes up on HN a lot and everytime I have to admit that I am kinda unfair here: Signal is heralded as the nice and secure solution - but seems incomplete to me. I don't doubt all the more clever persons that tell me that Signal is the best choice for encryption right now. But as long as it doesn't support federation (I miss XMPP) and as long as it does require a phone number (None of anyone's business, not required for my contacts, a baaaad way to handle identification) it is utterly broken for me.

I'll continue to use Telegram for family, friends and casual business stuff. The applications are awesome across platforms, I can initiate conversations with people without using a phone number. Worse encryption? Probably. Likely. Just as centralized? Yes - hate it there as well.

But I hoped that Signal would be the solution. I'm unfair. Signal gets judged for NOT being open (federation, phone number). Telegram is just a random service that I use instead then - works better anyway.

Post reply on HN