Live data from Hacker News

Why I won't recommend Signal anymore

sandervenema.ch

291–300 of 350 posts

Re: Why I won't recommend Signal anymore

#291
post #286
post #282

Earlier quoted context omitted.

You are assuming that Android reports on every step you take. Do you have sources backing this claim?

It's nearly impossible to find out. But if I trust corporations like Google not to exploit the possibilities, I wouldn't be looking for an open-source alternative to WhatsApp in the first place.

Signal is not positioned as a tool for possible TAO targets. Never was, and never will be. Don't use it and please stop spreading the FUD.

Re: Why I won't recommend Signal anymore

#292

Earlier quoted context omitted.

On Signal, every message uses end-to-end encryption. Signal's servers can't see the messages you are sending, only you and the recipient can read them. Signal's encryption protocol is carefully scrutinized and follows best-practices. Telegram sends messages in plain-text by default. Telegram servers have access to all plain-text messages that you send. Telegram's private chats use end-to-end encryption. But they use…

Actually, always use Signal unless you have contacts on Telegram that refuse to migrate. Consider all communication via Telegram to be on public record.

> Consider all communication via Telegram to be on public record.

Just because the protocol has flaws, doesn't mean everyone can exploit them.

On the other hand it's possible for Google to read every communication because they have root on your phone. So using Telegram [1] with a custom ROM without Google services (e. g. [2]) will make it harder for Google at least. Not easily possible with Signal.

[1] https://f-droid.org/repository/browse/?fdfilter=telegram&fdi... [2] https://copperhead.co/android/

Re: Why I won't recommend Signal anymore

#293
post #277
post #166

Earlier quoted context omitted.

Nobody is saying Signal has less secure cryptography than others. But being able to run it in CopperheadOS without loading microg would make the whole setup much more secure. And one cannot dissociate both things.

What confuses me about the post is that the author does not make it clear if he recommends that journalists run CopperheadOS. It sounds like he does not recommend this, but rather opposes Signal's dependency on Play on general principals. But if his journalists are using Android or iOS anyway, there's no practical advantage in Signal not depending on GCM or the Play Store, and some real disadvantages (like less secur…

The point of CopperheadOS is not that it lacks Play Services... and Play does not provide more secure updates than an app store like F-Droid. In fact, Play abuses system privileges to bypass the signature system used by Android. It will happily clobber an app with another with a different signature. It moves all the security checks for that into the cloud... completely bypassing the standard trust-on-first-use signature system. Official builds of Signal could be hosted via an F-Droid repository, although there's no point when it depends on Play.

Re: Why I won't recommend Signal anymore

#294
post #291
post #286

Earlier quoted context omitted.

It's nearly impossible to find out. But if I trust corporations like Google not to exploit the possibilities, I wouldn't be looking for an open-source alternative to WhatsApp in the first place.

Signal is not positioned as a tool for possible TAO targets. Never was, and never will be. Don't use it and please stop spreading the FUD.

What exactly is a TAO target?

Re: Why I won't recommend Signal anymore

#295

Earlier quoted context omitted.

My main concern with GCM is that it's unavailable on fully open OS builds, so requiring it compromises the security of the device as a whole, rather than Signal in particular.

That's one of several things that are reasonable not to love about Signal. Criticism intended to urge Open Whisper Systems into changing their Signal policies are reasonable. A statement that someone would recommend less secure messaging solutions to investigative journalists is another --- something I find much harder to be supportive of.

There are alternatives with comparable or better security, but they tend to have other flaws. Most of the alternatives including Wire and Riot ALSO depend on GCM, otherwise they either lack push or force ridiculously bad battery life. They also have bad UX since they don't ask the user for a battery optimization exception permission, so the user would have to somehow know it's required or they'll break after a while in the background.

Conversations / OMEMO is a great Android messaging client, but it's ONLY available for Android and a desktop client (Gajim OMEMO plugin). It can use OTR (which it marks as less secure) but there isn't even a decent iOS OTR client anyway. ChatSecure iOS will probably get OMEMO and push support along with becoming a more decent client but it's going slowly. Until that happens, Conversations is problematic because there isn't a decent way to talk to iOS users.

Re: Why I won't recommend Signal anymore

#296
post #251
post #50

Earlier quoted context omitted.

I agree overwhelmingly with what you wrote, except that I want to point out that this isn't "crypto-puritanism". It's just hipsterism. The author isn't a cryptographer, and if you asked a panel of 10 cryptographic engineers what messaging system they'd recommend, 9 of them would say "Signal". The 10th wants you to use something else because they're working on an attack for that "something else", and want their paper…

I think these types of posts are also the inevitable result of people overestimating our organizational capacity based on whatever limited success Signal and Signal Protocol have had. It could be that the author imagines me sitting in a glass skyscraper all day, drinking out of champagne flutes, watching over an enormous engineering team as they add support for animated GIF search as an explicit fuck you to people wi…

> I invite those who have opinions about Signal to start by getting involved in the project.

Yeah we've been there. Do you remember someone on Github complaining about the Google dependency? You closed that issue as a wontfix. Or LibreSignal? I read the post where you basically told them to go away on Github too.

That's why I haven't recommended Signal ever since trying it myself a year or two ago.

Re: Why I won't recommend Signal anymore

#297
post #70

Nothing is stopping anyone from running their own servers, changing the username scheme, and implementing the voice signaling. Moxie doesn't complain about such usage. But that's more work than simply complaining and telling OWS what they should do. As far as usernames go, that would require the signaling key to be remembered by the user. That doesn't work well in practice. As far as contact sync goes, has anyone sub…

> Regarding federation, let's see some code. It's ridiculous to demand the small team that is OWS solve every single problem. Moxie has explicitly rejected federation. Anyone writing such code is wasting their time it won't get accepted.

The code is already written and both the signal server and clients support federation. It's not enabled in O

Re: Why I won't recommend Signal anymore

#298

Earlier quoted context omitted.

You don't understand what I'm saying. I agree that crypto alone doesn't equal privacy --- it's table stakes. Clearly: it does not follow from that observation that crypto doesn't matter. If you cannot at least be cryptographically secure , the rest of what you do doesn't matter. We now have two examples --- CryptoCat and Telegram --- of "secure messaging" systems being used by governments as a way of hunting down act…

Regarding qualifications: I spent years building secure technology (publication platforms, websites) for whistleblowers including Ed Snowden himself (I built his official website ( https://edwardsnowden.com ) for the Courage Foundation (his official defence fund) plus the tech behind it that supports it. This allows our editors to submit anonymously to the site through the Tor network. I used cryptographic software a…

You really shouldn't have to show credentials. If tpateck had cared, he could easily have looked them up. And besides, arguments should stand on their own without credentials. Our hacker space recently defined a hacker ethos: one of the first things was that credentials or certificates or something don't matter.

Re: Why I won't recommend Signal anymore

#299

Essentially this guy is saying, Signal is secure, it's mostly easy to use (with the exception of multiple phone numbers), and the only alternative he mentioned is a half broken clone. Is he seriously going to stop recommending it to people whose lives depend on secure communications because of some abstruse ideological point? In any case, Moxie's position is a reasonable one even though there are some arguments for f…

> and the only alternative he mentioned is a half broken clone.

Sorry but you've got that backwards. He doesn't propose using that, he mentions OpenWhisperSystems banned them from using the service. It's criticism towards Signal, not a product recommendation.

> my current phone doesn't support Signal

I think it's Signal not supporting your phone, not the other way around. The manufacturer probably didn't make a conscious choice to not support Signal, but depending on what the issue is exactly, Signal probably did.

Re: Why I won't recommend Signal anymore

#300
post #291
post #286

Earlier quoted context omitted.

It's nearly impossible to find out. But if I trust corporations like Google not to exploit the possibilities, I wouldn't be looking for an open-source alternative to WhatsApp in the first place.

Signal is not positioned as a tool for possible TAO targets. Never was, and never will be. Don't use it and please stop spreading the FUD.

> Signal is not positioned as a tool for possible TAO targets. Never was, and never will be.

Eh, that’s exactly what it is currently advertised as.

A tool, supported by Snowden, to be used by journalists who are at risk of being under active surveillance by state actors.

That is the very definition of a TAO target.

Post reply on HN