Hi, from Iran with love! First of all, thank you moxie and signal team for this proxy. Until 2018, many Iranians used telegram but Iran's regime after Russia blocked this messenger. telegram released mtproxy and this proxy was helpful. Russia lifted the ban on telegram but this app is still blocked on my country. but with VPNs, many iranians still use this app. after 2018, second most popular messaging app in iran wa…
Thx Sherwin! Just out of curiosity: is iMessage working ok in Iran?
Help users in Iran reconnect to Signal
281–290 of 417 posts
Re: Help users in Iran reconnect to Signal
#282Ironic how people want to help de-censor what's considered to be an enemy nation (by the media), but are ok with censoring half their next-door neighbors based on politics.
> One employee pointed out that fascists are often quite public about their activities, as the recent insurrection in broad daylight at the Capitol showed
https://www.theverge.com/22249391/signal-app-abuse-messaging...
Re: Help users in Iran reconnect to Signal
#283Earlier quoted context omitted.
Gross! I wonder what motivated these decisions inside Amazon & Google. This likely affects the Tor project domain fronting as well. We really should not have let the majority of internet traffic be served by a small handful of giant companies without some legal protections as to what they're allowed to do.
Probably malware using domain fronting techniques for C2 traffic played a role in that decision. E.g. https://threatpost.com/apt29-used-domain-fronting-tor-to-exe...
I'm really bothered by blanket policies that prevent beneficial uses of a tool because it can also be used to cause harm. Google and Amazon need to figure out how to disambiguate the two.
Re: Help users in Iran reconnect to Signal
#284Earlier quoted context omitted.
They could literally have a hidden function in WhatsApp that scoops up all your chat history and sends it to Facebook if the government ask them to. It’s closed source. No one has a clue what it’s doing. To be clear I’m not suggesting this is absolutely happening. I’m merely pointing out it’s entirely possible from a technological perspective given it’s closed source software owned by Facebook. That’s not a recipe fo…
Reverse engeneering is a thing, though. I would think, there is fame to be gained to show such a behavior from whatsapp, so some hackers could feel motivated to do this from time to time.
But reverse engineering is a skill in itself and modern day smartphone OS's use a lot of code obfuscation when apps are compiled. This effectively means even those talented hackers are going through the reverse engineering process pulling at threads until they get lucky.
Reverse engineering (in this context, at least) doesn't just show you the code as the developer wrote it. And FB hires a lot of very clever people including cybersecurity experts who could sneak these things in using innocent looking code scrambled around the app. Even open source projects are at risk of having backdoors put in that pass review and simply look like innocent bugs if they get discovered, let alone closed source apps that have to be reverse engineered.
Again not going conspiracy nut and saying that's what FB is doing. Just saying it'd be very easy for FB to hide it if they were doing it.
To me the biggest confirmed weakness of WhatsApp is the cloud backups. E2EE is pointless when the message database is synced up to iCloud or Google Drive. WhatsApp even tells you this itself. When you enable cloud backups (and they keep bugging you until you do it) it literally tells you the backups aren't secured by E2EE. [1] Because, well, of course they aren't.
[1] https://faq.whatsapp.com/iphone/chats/how-to-back-up-to-iclo...
"Media and messages you back up aren't protected by WhatsApp end-to-end encryption while in iCloud."
Re: Help users in Iran reconnect to Signal
#285Re: Help users in Iran reconnect to Signal
#286Earlier quoted context omitted.
What about Cloudflare?
Answer from Cloudflare team seems to be "No" - https://community.cloudflare.com/t/could-cloudflare-support-...
Re: Help users in Iran reconnect to Signal
#287Earlier quoted context omitted.
I think you mean the phone vendors, as they are the ones holding the unencrypted chat history in the users cloud storage. Facebook themselves do not have access to the chat logs (unless they are compelled to inject keys).
They could literally have a hidden function in WhatsApp that scoops up all your chat history and sends it to Facebook if the government ask them to. It’s closed source. No one has a clue what it’s doing. To be clear I’m not suggesting this is absolutely happening. I’m merely pointing out it’s entirely possible from a technological perspective given it’s closed source software owned by Facebook. That’s not a recipe fo…
This is just bullshit. If you have access to the binaries you can find out what the software does.
Re: Help users in Iran reconnect to Signal
#288Earlier quoted context omitted.
Correct, both Google and Amazon told Signal not to use them for domain fronting: https://signal.org/blog/looking-back-on-the-front/
Gross! I wonder what motivated these decisions inside Amazon & Google. This likely affects the Tor project domain fronting as well. We really should not have let the majority of internet traffic be served by a small handful of giant companies without some legal protections as to what they're allowed to do.
In the grand scheme of things, I don't like how much infrastructure technology giants control.
In this specific case, however, domain fronting is basically saying "if you want to ban me, you have to ban all of us", without asking if the rest of "us" consent to be put on the same boat.
It would be cool if they are, but it's perfectly understandable for them to disagree.
Re: Help users in Iran reconnect to Signal
#289Earlier quoted context omitted.
To be clear about the threat vector, there's also nothing stopping signal from doing the same if they wanted to. Its impossible to tell if the version of signal you download from the app store is unmodified from the code you can find on github. I trust signal more than I trust facebook, but if you use signal, even though its opensource you still have to trust them not to put anything funky in the binary they upload t…
This is very true. Reproducible builds for mobile apps would be far superior. You can build Signal from source for Android if you wish, although obviously this is a massive pain to do for each update, there’s absolutely nothing stopping you from doing it. On iOS it's a lot more difficult to get the required certificates from Apple but you can run your own build in Xcode and deploy it to your personal device if you ar…
Re: Help users in Iran reconnect to Signal
#290Earlier quoted context omitted.
That article notes that Signal has been domain fronting since 2016. I think google has cracked down on it more recently though, and hence Signal has had to circumvent censors in a new way
Correct, both Google and Amazon told Signal not to use them for domain fronting: https://signal.org/blog/looking-back-on-the-front/