Live data from Hacker News

License update

whispersystems.org

31–40 of 71 posts

Re: License update

#31
Tangentially related, but since we're talking about Signal and have Moxie's attention ...

Does anybody know how the "privacy preserving contact discovery" works?

One of my unpleasant experiences with Signal was receiving a greeting from an unknown number when I installed it. Fortunately, it was a friend with a new number I hadn't known ... but the potential privacy leak - without any apparent warning, consent or opportunity to opt-out - bothered me.

Best info I could find is a blog basically saying "privacy preserving contact discovery is an unsolved problem" ... which is hardly reassuring:

https://whispersystems.org/blog/contact-discovery/

What's the story?

Re: License update

#32
post #28

Earlier quoted context omitted.

Yep, the rest of the world has moved on. Olm already provides what Signal protocol did and the app itself is now useless to many. Signal app itself still can't run on Android Open Source, because it forces centralised metadata collection on the user via Google Play Store and GCM. Installing Google privacy-invading bloatware, is a prerequisite, which also further requires you to destroy your phone's security model bec…

> Yep, the rest of the world has moved on. Olm already provides what Signal protocol did and the app itself is now useless to many. Olm/Megolm is not Signal Protocol. It is an entirely different protocol that has made different choices, and those choices have received less study and scrutiny. It hasn't been deployed anywhere that I know of. It's fine if you want to explore those choices, but I would caution against c…

Come on @moxie, you didn't just say you'd prefer them not to, you expressly forbid it:

"I'm not OK with LibreSignal using our servers, and I'm not OK with LibreSignal using the name \"Signal.\" You're free to use our source code for whatever you would like under the terms of the license, but you're not entitled to use our name or the service that we run." (https://github.com/LibreSignal/LibreSignal/issues/37#issueco...).

You know full well that it's illegal to use systems without authorisation. In the US, it's called the Computer Fraud and Abuse Act and they'd be committing a criminal offense, with severe penalties, if they did (and government could prosecute with or without OWS consent, as AaronSw experienced). There's also an open ended civil claim you'd now have against them. So whether express or implied, the project from then on, was under a direct cloud of legal threat.

'LibreSignal' never wanted their own "product" as you choose to call it. No one in that community was trying to compete with you. They just had legitimate security needs, or wanted to use Signal as it was, but without being tied to an advertising company. The App Store risks aren't even theoretical or tin-foil-hat material: https://twitter.com/SwiftOnSecurity/status/72356243560126464...

Having option to run on a reasonably secure endpoint (e.g. the Copperhead's of this world), that users have some hope of securing, seems a pretty reasonable desire. Since increased security is really the only point of using Signal, and a secure channel is useless if the endpoint is not.

The name "LibreSignal" was also not the same as "Signal". If they HAD just redistributed as "Signal" (especially if trademarked), or otherwise didn't make clear it was an independent/unofficial build, then sure that's an issue. However the developers agreed immediately to changing the name further when requested.

In terms of the voice server, I'm just going on what other developers have stated. I'm not personally aware whether the TURN server is the only missing component or not.

The fact is though, if a user wants to run Signal on a straight-forward Android Open Source device, without adding a large attack surface of Google Apps, then Signal app is not an option. Regardless whether open source clones are possible, you know communications utility comes down to the network itself too (Metcalfe's Law) and holding one tin can, with a dangling piece of string and no one on the other end is rather useless. Now Signal has captured the whole user base, there's large costs in changing.

Anyway, your code, your call. I think the key thing, is that people were surprised. Closed distribution models and controlled ecosystems, coming from a company purporting itself as being Open (and not meaning to be personal, but by a guy calling himself an anarchist), was not what people thought they'd been promoting.

We don't think you're everything bad in the world. We just wish that using Signal was an option.

Re: License update

#33
post #28

Earlier quoted context omitted.

> Yep, the rest of the world has moved on. Olm already provides what Signal protocol did and the app itself is now useless to many. Olm/Megolm is not Signal Protocol. It is an entirely different protocol that has made different choices, and those choices have received less study and scrutiny. It hasn't been deployed anywhere that I know of. It's fine if you want to explore those choices, but I would caution against c…

Come on @moxie, you didn't just say you'd prefer them not to, you expressly forbid it: "I'm not OK with LibreSignal using our servers, and I'm not OK with LibreSignal using the name \"Signal.\" You're free to use our source code for whatever you would like under the terms of the license, but you're not entitled to use our name or the service that we run." ( https://github.com/LibreSignal/LibreSignal/issues/37#issueco…

Regarding entitlement, it's not just an advertising company the 'product' is tied to. Google is of course one of the most aggressive global profit-shifters for tax 'minimisation'. I would prefer to call it avoidance, as I can't see any other reason for it, but I don't have pockets deep enough for the legal defense to use a word like that (or evasion).

Re: License update

#34
post #8
post #4

The license change is from GPLv3 to, uh, dual GPLv3/MPL-on-the-App-Store-or-something? > Additional Permissions For Submission to Apple App Store: Provided that you are otherwise in compliance with the GPLv3 for each covered work you convey (including without limitation making the Corresponding Source available in compliance with Section 6 of the GPLv3), Open Whisper Systems also grants you the additional permission…

Tough crowd! That's what we used to do, but some extremely vocal people weren't satisfied, so we've done this to integrate our intentions into the license itself.

Was this lawyered? Because the clause reads to me like Programmer Law.

> Provided that you are otherwise in compliance with the GPLv3... [we] also grants you the additional permission to convey through the Apple App Store non-source executable versions of the Program as incorporated into each applicable covered work as Executable Versions only under the Mozilla Public License version 2.0

1. The phrase "only under the [MPL]" definitely means my app store binary isn't distributed under the GPL

2. The phrase "Provided that you are otherwise in compliance with the GPLv3" does not seem to have any effect for distributing "only under the MPL". By distributing software "only under the MPL", I do not "otherwise" have GPLv3 obligations for me to not be "in compliance with".

3. Unless you intend to say that I have both GPLv3 and MPL obligations, in which case the same GPL obligations which [allegedly] prevented me from using this in the app store are still in effect. Also, this would contradict 1.

Please have a lawyer look at this. I guarantee my clients' legal counsel would not allow use of a library under these terms.

Re: License update

#35

This is probably partially in response to some of the issues that were discussed here: https://github.com/LibreSignal/LibreSignal/issues/37

Moxie has always been a huge dick in this regard. I have no respect for Signal because of his mistreatment of the open source community.

This kind of comment is not allowed on Hacker News. If you can't express yourself without a personal attack, please don't express yourself.

Re: License update

#37

Earlier quoted context omitted.

Yep, the rest of the world has moved on. Olm already provides what Signal protocol did and the app itself is now useless to many. Signal app itself still can't run on Android Open Source, because it forces centralised metadata collection on the user via Google Play Store and GCM. Installing Google privacy-invading bloatware, is a prerequisite, which also further requires you to destroy your phone's security model bec…

Just a few clarifications: * Olm isn't a replacement for 'Signal protocol' - it's just an independent (Apache license) implementation of the same 'double ratchet' cryptographic ratchet that Signal protocol uses under the hood for generating message keys. * Megolm provides the higher layer semantics for using Olm for group conversations in Matrix, and diverges significantly from Signal Protocol as far as I know. * The…

Thanks @Arathorn. That's great to hear an FDroid candidate's available. Great turn around! The only device I'd have to test it on right at the moment, unfortunately doesn't take 3rd party APKs (FDroid's been signed, but I'm reluctant to otherwise open that particular device). Will see what else I can pull together. I could sign the APK with my own OS build, but then I'd miss OTA updates (so a different security risk). MicroG sounds a good option. As for Copperhead specifically, I don't think MicroG will be on the table for a while though. Another push would be ideal I suppose (but I know you need to balance priorities).

Re: License update

#38
post #28

Earlier quoted context omitted.

> Yep, the rest of the world has moved on. Olm already provides what Signal protocol did and the app itself is now useless to many. Olm/Megolm is not Signal Protocol. It is an entirely different protocol that has made different choices, and those choices have received less study and scrutiny. It hasn't been deployed anywhere that I know of. It's fine if you want to explore those choices, but I would caution against c…

Come on @moxie, you didn't just say you'd prefer them not to, you expressly forbid it: "I'm not OK with LibreSignal using our servers, and I'm not OK with LibreSignal using the name \"Signal.\" You're free to use our source code for whatever you would like under the terms of the license, but you're not entitled to use our name or the service that we run." ( https://github.com/LibreSignal/LibreSignal/issues/37#issueco…

It's ironic that WhatsApp runs fine on open source Android, but Signal won't.

Are you _sure_ that wasn't part of the deal @moxie? ;)

Re: License update

#39

Thank you Moxie! Although we personally trusted and would've moved forward with Moxie's informal permission to distribute SignalProtocol within ChatSecure on the App Store, our funder required us to get the legal details squared away or we'd lose our funding. This announcement is an amazing gift for us, and for other GPL compatible Mac/iOS apps. This announcement also more broadly benefits the copyleft community. The…

Apple could always do what Google does, to state that in the case of copyleft licenses their term take precedence over the ToS (neutralizing restrictive terms like the redistribution ban on everything you download from the store).

Where does Google state that?

This meme keeps going around that the Android store is GPL compatible. But where is the actual license text that allows this, or at least how does the situation differ from that with iOS? I checked the current Google Play Terms of Service and the iTunes Terms and Conditions. The two were alike in several respects:

- They had no blanket exception or deference I could find to third party agreements, nor any relevant mention of the terms "open source" or "copyleft".

There is something in the Google ToS that could be interpreted as such an exception, but the wording gives it dubious applicability to third party apps, and in any case, the Google Play ToS says that "if there is any conflict between the Google Play Terms of Service and the Google ToS, the Google Play Terms of Service shall prevail".

- They dictated various random usage rules, again without any explicit exception clause.

- One of those rules was a requirement not to circumvent DRM. AFAIK, both app stores do in fact store apps obfuscated/encrypted on disk, so it wouldn't be possible to usefully redistribute the apps without engaging in such circumvention. (The requirement was in each case worded broadly enough to potentially apply to any DRM included with the app itself, though this is just another example of a random potentially-conflicting usage rule.)

- However, they both state that apps are licensed directly from the developer to the user, with the store distributing them on the developer's behalf, rather than licensed to the store and sublicensed from there to the user. (If that even means anything.) Therefore, it could be argued - I don't know how much validity this would have, but it could be argued - that the GPL's "you may not impose any further restrictions" clause is not in fact violated, because you (i.e. the app developer) are not imposing any further restrictions - the restrictions come from a separate contract you're not a party to - and Google/Apple is not bound by the terms because it's just distributing stuff on your behalf rather than on its own authority.

Therefore, on both stores GPL compatibility is possible but dubious. Where is the difference?

(By the way, I've been lazy and haven't checked the respective developer agreements. It's possible that one or both agreements have clauses that impede legally submitting GPL apps to the store, but they can't generally authorize behavior that the ToS forbids - since users are not party to them - so any such difference wouldn't affect my main point about the Play Store having similar restrictions to what people have complained about wrt the iOS App Store.)

Source:

== The Google ToS clause ==

Open source software is important to us. Some software used in our Services may be offered under an open source license that we will make available to you. There may be provisions in the open source license that expressly override some of these terms.

http://www.google.com/intl/en/policies/terms/

== Random usage rules ==

Google:

Capturing of Streams. You may not use Google Play or any Content in conjunction with any stream-ripping, stream capture or similar software to record or create a copy of any Content that is presented to you in streaming format.

Use of Android Apps. You must use apps from Google Play in accordance with the Google Play Business and Program Policies which are in place from time to time, the current version of which can be found at http://play.google.com/about/android-developer-policies.html

Apple:

(ii) If you are a commercial enterprise or educational institution, you may download and sync an App Store Product for use by either (a) a single individual on one or more iOS or tvOS Devices used by that individual that you own or control or (b) multiple individuals, on a single shared iOS or tvOS Device you own or control. [..] For the sake of clarity, each iOS or tvOS Device used serially or collectively by multiple users requires a separate license.

== No DRM circumvention ==

Google:

Security Features. You may not attempt to, nor assist, authorise or encourage others to circumvent, disable or defeat any of the security features or components, such as digital rights management software or encryption, that protect, obfuscate or otherwise restrict access to any Content or Google Play. If you violate any security feature, you may incur civil or criminal liability.

Apple:

You agree that the App and Book Services and certain App and Book Products include security technology that limits your use of App and Book Products and that, whether or not App and Book Products are limited by security technology, you shall use App and Book Products in compliance with the applicable usage rules established by Apple and its principals (“Usage Rules”), and that any other use of the App and Book Products may constitute a copyright infringement. Any security technology is an inseparable part of the App and Book Products. Apple reserves the right to modify the Usage Rules at any time. You agree not to violate, circumvent, reverse-engineer, decompile, disassemble, or otherwise tamper with any of the security technology related to such Usage Rules for any reason—or to attempt or assist another person to do so.

== On who is licensing apps to whom ==

Google:

When you buy “Content” (defined as data files, applications, written text, mobile device software, music, audio files or other sounds, photographs, videos or other images) on Google Play you will buy it either:

[..]

(c) in the case of Android apps, from the Provider of the app (an “App Sale”).

Each time that you purchase Content, you enter into a separate sale contract:

[..]

(f) with the Provider of the Content you have purchased (in the case of App Sales).

The separate sale contract in (e) or (f) above (as applicable) is in addition to your contract with Google Inc. for the use of the Service (i.e. these Google Play Terms of Service).

Apple:

You acknowledge that: you are acquiring the license to each Third-Party Product from the Application Provider; Apple is acting as agent for the Application Provider in providing each such Third-Party Product to you; and Apple is not a party to the license between you and the Application Provider with respect to that Third-Party Product.

Source:

Google: https://play.google.com/about/play-terms.html

Apple: http://www.apple.com/legal/internet-services/itunes/us/terms...

(warning: the Apple ToS has separate sections with similar terms for media and apps, and there is also a "Licensed Application End User License Agreement" that specifies it's merely a default for apps without their own terms, so make sure you look in the right sections.)

Re: License update

#40
post #20
post #17

Earlier quoted context omitted.

That's too bad, while I'm happy with Signal, I understand where people using LibreSignal are coming from and it'd be a shame to be unable to talk to them (or install yet another freaking app for it). It's hard to imagine there are enough LibreSignal users to make a notable impact on the OWS infrastructure in terms of expenses. Though over time, that could change, especially if other forks joined the party, and of cou…

> Given OWS's worries about federation and shared standards standing in the way of progress, they might want to avoid third party access simply because it might stop them from changing the server interface. Totally. Client interoperability as well. For us, the problem is that when a 3rd party client breaks compatibility, that doesn't just affect the users of those 3rd party clients, but the normal Signal users who co…

If the code is GPL then shouldn't WhatsApp need to be open source? Or did they get a different license?

The only thing listed at https://www.whatsapp.com/android/ are some changes to qcom as per the LGPL.

Post reply on HN