Live data from Hacker News

I don't trust Signal

drewdevault.com

301–310 of 473 posts

Re: I don't trust Signal

#301
post #176
post #53

> Truly secure systems don’t require trust. This is a chat app so, by definition, security requires trusting at least one other person. Also, I think experience shows that secrets can often be least trusted to those who have some interest in/use for them, with the secret owner often being the least trustworthy of all. So I'd say that if you trust yourself you're already probably trusting one of the weakest links in w…

I like Linus' argument, if you don't work with a web of trust then you're doing it wrong. In the context of mobile secure messaging the web of trust includes: I'm trusting every hardware component on my phone, I'm trusting Apple, I'm trusting the iOS code, I'm trusting the TLS protocol, etc.

> I like Linus' argument, if you don't work with a web of trust then you're doing it wrong

I can't find the source for this, could you tell where did you take this from? (not saying it's not true, just curious to read the full text)

Re: I don't trust Signal

#302
post #41

Earlier quoted context omitted.

NSL can't require to collect new business records. They can only compel you to disclose business records that you already have. This is beyond the legal authority of an NSL.

The Core Secrets leak said the FBI "compels" U.S. companies to "SIGINT-enable" their products if they don't take money. SIGINT-enable means installing backdoors. So, yeah they can. They also do this with classification order mandating secrecy from organizations and people that are immune to prosecution. In the Lavabit case, they wanted a device attached to the network to do whatever they wanted with the company order…

That is a major accusation, can you provide source(s) to read more about this claim?

It is at odds with known cases, such as the fight with Apple over iPhone encryption.

Re: I don't trust Signal

#303
post #41

Earlier quoted context omitted.

NSL can't require to collect new business records. They can only compel you to disclose business records that you already have. This is beyond the legal authority of an NSL.

The Core Secrets leak said the FBI "compels" U.S. companies to "SIGINT-enable" their products if they don't take money. SIGINT-enable means installing backdoors. So, yeah they can. They also do this with classification order mandating secrecy from organizations and people that are immune to prosecution. In the Lavabit case, they wanted a device attached to the network to do whatever they wanted with the company order…

If for some reason those methods fail, they can use BULLRUN, which has a much larger budget[1] and specifically tasked with "defeat[ing] the encryption used in specific network communication technologies"[2].

[1] "The funding allocated for Bullrun in top-secret budgets dwarfs the money set aside for programs like PRISM and XKeyscore. PRISM operates on about $20 million a year, according to Snowden, while Bullrun cost $254.9 million in 2013 alone. Since 2011, Bullrun has cost more than $800 million." ( https://www.ibtimes.com/edward-snowden-reveals-secret-decryp... )

[2] https://en.wikipedia.org/wiki/File:Classification_guide_for_...

Re: I don't trust Signal

#304
post #39

Some version of this post seems to circulate every few months or so. This one is more direct in its accusations of Moxie acting in bad faith. I think this is disingenuous. Moxie has been very clear[0] about the tradeoffs that Signal has made and the reasons for them. It's fine to be dissatisfied with those choices. It's another thing entirely to accuse Moxie of dissimulating. Personally, I'd like to see Signal replac…

It’s not surprising. The people most interested in encryption want to trust nobody. That’s the goal of strong encryption, but as Ken Thompson says it’s not possible. Between the US Government and Moxie I’d trust Moxie but I’d rather trust neither.

Re: I don't trust Signal

#305
Drew DeVault doesn't trust Signal because its Android incarnation uses the Google Play Store --- the app market virtually all of its real users use --- and not F-Droid. DeVault would also like it if Signal would interoperate with other chat programs.

Instead, DeVault would prefer that you use Matrix, a system for which end-to-end encryption is (according to its own website) "in late beta", offered on a select subset of clients, and "not enabled by default"†.

This argument is clownish and we should be embarrassed it's on the front page.

There are people in the world that want to sysadmin their phones. It's a life choice they are free to make and I don't hold it against them. But the vast, overwhelming majority of users do not want to make the app market on their phone work more like Debian and less like the Play Store. Signal, to put it bluntly, does not care about the desires of the phone sysadmins. Even if they caved to the sysadmins, the application would, for virtually all its users, be no more secure. This bothers DeVault a lot, enough that he's constructed an entire psychoanalysis of Moxie Marlinspike to explain to himself how it could possibly happen that someone else on the Internet doesn't agree with him.

Also, just as a note to DeVault: the point of end-to-end encryption is that you don't have to trust Signal's server. All it does is arrange for the delivery of messages, which are secured client-to-client. Compare Signal's server to Wire's, which --- last I checked --- retains a record of every pair of users who have communicated in the past.

When this was pointed out downthread, DeVault responded: "[o]ther alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring". Telegram is a particularly funny reference to make, because not only is E2E not the default there, but --- last I checked --- it can't even do E2E group chat. Telegram's owners are adamant that TLS is adequate for group secure chat.

Re: I don't trust Signal

#306

Earlier quoted context omitted.

> An open-source server is certainly a step up from Signal https://github.com/signalapp/Signal-Server . You are spreading a lot of incorrect or misleading information about Signal in this thread. That makes it difficult to assume that you're arguing in good faith here.

The server might as well be closed source. We have no guarantees that Moxie is actually running this in production and he refuses to federate with third-party servers.

It's funny you put it that way. You're right: the server might as well be closed source. That is the point of end-to-end encryption.

Re: I don't trust Signal

#307
post #193

Earlier quoted context omitted.

> Moxie forbids you from distributing branded builds of the Signal app ... Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction. > ... and if you rebrand he forbids you from using the official Open Whisper servers. This seems pretty fair to me. Not only could you abuse their resources, it would greatly hinder their ability to make changes and respon…

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play. The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't. This alone is enough for me to lose trust in Signal.

This seems more like "I disagree with Moxie," not "I don't trust Moxie," unless there's some allegation that Moxie is in cahoots with Google.

I can trust people that I think made incorrect technical decisions, because I can see that they made a decision for technical reasons and have different priorities and reasoned soundly.

Re: I don't trust Signal

#308

Earlier quoted context omitted.

I am happy to see I am not the only person in the world that feels like this about Signal. The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.) I admire Wire for a n…

There is a german guide to privacy I read that has some real issues with Wire, most that I agree with [0]. I will Google translate it for you (ironic): > "10/06/2017: Wire.com operational Security > Wire.com is referred to as a new star among crypto messengers. I briefly looked at the (experimental) Linux version of Wire.com and found some significant security flaws: > Mannings Bug: Wire.com has good end-to-end encry…

To be fair,they started pinni their certificates about 3 years after claiming their VoIP stuff was encrypted. So there was only A FRIGGING THREE YEAR WINDOW when someone in your root cert db could mitm your VoIP connection. So not really friendly neighbour Hacker Joe could do, but definitely a nation state or malicious employer.

Re: I don't trust Signal

#309
post #97

Earlier quoted context omitted.

An open-source server is certainly a step up from Signal, but since Wire doesn't support federation (either in their ToS or in practice) I'd favour Matrix.

> An open-source server is certainly a step up from Signal https://github.com/signalapp/Signal-Server . You are spreading a lot of incorrect or misleading information about Signal in this thread. That makes it difficult to assume that you're arguing in good faith here.

I stand corrected - though, as another reply said, it makes little difference if you can't actually use a forked server in practice.

I don't know what I could say to convince you I'm just an ordinary person concerned about my privacy, but ultimately it doesn't matter: you should definitely consider the possibility that I'm a bad actor and take nothing on faith. Equally, you shouldn't trust that Marlinspike hasn't been compromised either.

A little thought experiment: Put yourself in the NSA's position in 2013. GPG has been out there for years and, despite your best efforts, you can't break it directly when users follow proper security practices. (You have to compromise those users' computers instead, and that's vastly more expensive; every time you use one of your rootkits or exploits you run the risk of burning it, so they're reserved for high-value targets). The world is suddenly a lot more interested in privacy, and while popular culture doesn't grasp the intricacies of key exchange or forward secrecy, there are enough cryptography experts around that any obvious downgrade from GPG will be noticed and picked up on (this is just after the conclusive failure of your Dual_EC_DRBG efforts). What do you do? How do you get the public to accept something easier to compromise?

My answer is: you find a different front to attack GPG from. You talk up different kinds of attackers. You dangle a new, desirable security property that GPG doesn't have, and a theoretically clean construction - and then you compromise the metadata subtly, down in the weeds of usability features, letting you identify the higher-value targets. You get people used to using a closed-source build that auto-updates, and have a canned exploit ready (a compromised PRNG or similar) to use on those targets. And you get people to enter their phone numbers so that you can always track their location and what hardware they're running if you do have to attack their device more directly.

Maybe I'm being paranoid, but it seems distinctly odd that we see such a push behind an app that compromises so many features that were previously thought essential to security, just as the move for encryption is finally gaining momentum.

Re: I don't trust Signal

#310
post #26

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

If Open Whisper Systems had received a national security letter requiring them to collect more information and keep it secret that they were doing so, how would you expect them to have responded to that subpoena?

This is a good question, because it illuminates design decisions that Signal has made that confuse nerds. For instance: Signal only recently got user profiles --- user profiles! --- because they took their time figuring out how to deliver them without sacrificing privacy. Take some time to look at how they implemented Giphy sharing to get an idea of what I'm talking about.

Any information the Signal client reveals to the server is, indeed, something the USG could make a legal claim on. Probably even if Signal's server code doesn't now even collect it. The Signal team has been sounding that alarm for years: when you look at a chat program with fancy whiz-bang features, consider what those features expose (traffic-analytically, even). "Maybe have fewer features until we figure this out", Signal says.

The market does not agree, and that has been rough for Signal, and they deserve credit for the stand they are taking on it.

Post reply on HN