Live data from Hacker News

Why I won't recommend Signal anymore

sandervenema.ch

301–310 of 350 posts

Re: Why I won't recommend Signal anymore

#301
post #271

Earlier quoted context omitted.

In practice you always get TLS. That's really all you need if you trust the server. Something fairly significant has happened in the world of XMPP recently. You can get real certificates for XMPP servers under your control from letsencrypt. That means that things now work transparently between clients and servers and between servers. As a result, organizations that do things that some governments might not approve of…

TLS on the s2s side is unauthenticated. Therefore TLS only protects you in a situation where both users are on the same server and trust it. Getting a real cert for s2s doesn't really help as long as you have no agreed upon mechanism how they can enforce validation of those certs.

You need to trust both servers when doing s2s anyway. So you can just turn on certificate validation when depending on just TLS for your security. For Prosody that would be "s2s_secure_auth = true".

Of course an organization using TLS as their only security for XMPP would almost for sure just use one secure server, so I might be being a bit fanciful here. My ultimate point is that because of the way XMPP works, it is possible to make the normal default clients work securely in practice by doing the correct things at the server level.

Re: Why I won't recommend Signal anymore

#302
post #203

Earlier quoted context omitted.

I think Conversations is probably getting a lot right, but you also mention its biggest flaw: > do multiple types of encryption including OTR and OMEMO Oh and it can also do something else: no encryption at all. That's the problem with XMPP: The user is faced with three different encryption modes, none of them is the default. There shouldn't be multiple types of optional encryption. There should be one that works and…

The practical problem is that a lot of power-users have strong opinions about which e2e scheme to use in which case. That may include "none". [1] If you enforce a single e2e scheme (no matter which), you will lose a lot of potential power-users, who would double as multipliers to spread your app. I don't say that Conversations (and the XMPP community at large) couldn't do better, though. For example, there could be a…

> you will lose a lot of potential power-users, who would double as multipliers to spread your app.

Not really. I consider myself poweruser in many areas, but I would never recommend most of my tools to "ordinary" friends. The tools for them should be easy to use and difficult to misuse.

Re: Why I won't recommend Signal anymore

#303
post #293
post #277

Earlier quoted context omitted.

What confuses me about the post is that the author does not make it clear if he recommends that journalists run CopperheadOS. It sounds like he does not recommend this, but rather opposes Signal's dependency on Play on general principals. But if his journalists are using Android or iOS anyway, there's no practical advantage in Signal not depending on GCM or the Play Store, and some real disadvantages (like less secur…

The point of CopperheadOS is not that it lacks Play Services... and Play does not provide more secure updates than an app store like F-Droid. In fact, Play abuses system privileges to bypass the signature system used by Android. It will happily clobber an app with another with a different signature. It moves all the security checks for that into the cloud... completely bypassing the standard trust-on-first-use signat…

My point was that there's no real merit to the complaint that Signal requires Play Services if you're going to use an OS with Play Services installed anyway. One can reasonably argue that Signal should work on non-Play Androids, but since his target audience is non-technical users, it seems likely that they are all using (and are more secure using!) off-the-shelf iOS or Android phones, which implies a significant reliance on your vendor anyway.

Do you have any pointers on how Play bypasses local signature verification? I'm surprised about that.

Re: Why I won't recommend Signal anymore

#304
post #296
post #251

Earlier quoted context omitted.

I think these types of posts are also the inevitable result of people overestimating our organizational capacity based on whatever limited success Signal and Signal Protocol have had. It could be that the author imagines me sitting in a glass skyscraper all day, drinking out of champagne flutes, watching over an enormous engineering team as they add support for animated GIF search as an explicit fuck you to people wi…

> I invite those who have opinions about Signal to start by getting involved in the project. Yeah we've been there. Do you remember someone on Github complaining about the Google dependency? You closed that issue as a wontfix. Or LibreSignal? I read the post where you basically told them to go away on Github too. That's why I haven't recommended Signal ever since trying it myself a year or two ago.

Downvotes but no comments. What is wrong with what I said?

Re: Why I won't recommend Signal anymore

#306
post #282
post #278

Earlier quoted context omitted.

Does Google know you are using Signal? Does it know whom of your contacts use Signal? Does Google know you've sent a message? Does Google know that you are receiving a message? Does Google knows who from your contact list send this message? Can Google infer from pings who is communicating with whom? Yes to all of those, because they have root on your phone.

You are assuming that Android reports on every step you take. Do you have sources backing this claim?

Google has root on your phone. Even if they aren't "for now", good security sense says that we should assume that are.

Re: Why I won't recommend Signal anymore

#307
post #294
post #291

Earlier quoted context omitted.

Signal is not positioned as a tool for possible TAO targets. Never was, and never will be. Don't use it and please stop spreading the FUD.

What exactly is a TAO target?

Tailored Access Operations from the NSA

Re: Why I won't recommend Signal anymore

#308

Like a lot of crypto-puritanism it is rather mixed up. He says he recommended Signal because it was easy to use (more consumer friendly I guess) and secure, then says he wouldn't have gone in the direction of making it easier to use and criticises the things that make it user friendly, like using phone numbers instead of usernames. He says he thinks the protocol is secure, then says he doesn't want it to use GCM beca…

> Signal is unusual because it combines cutting edge cryptography with consumer friendliness and is actually successful.

You do realize that since last year WhatsApp actually uses the Signal protocol?

Re: Why I won't recommend Signal anymore

#309

Signal may not transmit any payload via Google Cloud Messaging, but Signal's requirement to run Google Play Services compromises the user's privacy in ways that have nothing to do with Signal. If you run Play Services then you have a device which provides your communications metadata, whereabouts, and device usage habits to Google. I don't trust Google with this information and don't want to carry such a device, but…

> 3. Showing hostility to those trying to introduce such an alternative to the project

Quite the contrary, they're actively asking people to contribute code for an alternative push mechanism [1][2]:

"I would consider a clean, well written, and well tested PR for websocket-only support in Signal. I expect it to have high battery consumption and an unreliable user experience, but would be fine with it if it comes with a warning and only runs in the absence of play services."

[1] https://github.com/LibreSignal/LibreSignal/issues/37#issueco... [2] https://news.ycombinator.com/item?id=12883410

Re: Why I won't recommend Signal anymore

#310
post #299

Essentially this guy is saying, Signal is secure, it's mostly easy to use (with the exception of multiple phone numbers), and the only alternative he mentioned is a half broken clone. Is he seriously going to stop recommending it to people whose lives depend on secure communications because of some abstruse ideological point? In any case, Moxie's position is a reasonable one even though there are some arguments for f…

> and the only alternative he mentioned is a half broken clone. Sorry but you've got that backwards. He doesn't propose using that, he mentions OpenWhisperSystems banned them from using the service. It's criticism towards Signal, not a product recommendation. > my current phone doesn't support Signal I think it's Signal not supporting your phone, not the other way around. The manufacturer probably didn't make a consc…

> OpenWhisperSystems banned them from using the service

Nobody has been banned from anything. People have been politely asked not to distribute 3rd-party builds of Signal using their name and their servers, and that's it.

Post reply on HN