Live data from Hacker News

I don't trust Signal

drewdevault.com

341–350 of 473 posts

Re: I don't trust Signal

#341
post #309

Earlier quoted context omitted.

> An open-source server is certainly a step up from Signal https://github.com/signalapp/Signal-Server . You are spreading a lot of incorrect or misleading information about Signal in this thread. That makes it difficult to assume that you're arguing in good faith here.

I stand corrected - though, as another reply said, it makes little difference if you can't actually use a forked server in practice. I don't know what I could say to convince you I'm just an ordinary person concerned about my privacy, but ultimately it doesn't matter: you should definitely consider the possibility that I'm a bad actor and take nothing on faith. Equally, you shouldn't trust that Marlinspike hasn't bee…

GPG has an infinitesimally small user base. Many tech savvy users still struggle to use it correctly. Moxie has explicitly stated that his aim is not to build the perfect secure messenger app, but a messenger app that provides the greatest amount of security to the greatest number of users. He has explicitly stated that he has made some design decisions that slightly compromise the ultimate security of Signal, but are necessary to establish a wide user base and avoid traps that could drastically compromise the security model because of user error.

Signal is not designed for you. Highly sophisticated, highly paranoid users already have a variety of options for securing their communications. Signal is designed to provide the greatest possible amount of security to the greatest possible number of users, which necessarily requires that some tradeoffs are made in the interests of ease-of-use.

Re: I don't trust Signal

#342

Earlier quoted context omitted.

That's not the interesting question. How easy is it to verify that the APKs are built from the published source code, without any added funny business? The F-Droid devs put a lot of work on reproducible builds. Not all software complies, but with an interest in information security there's no exucse not to. That's the use case of F-Droid, and comparing it to self publishing APKs without even as much as a GPG signatur…

There is nothing wrong with F-Droid. The problem isn’t that F-Droid is toxic. People can disagree without either side being at fault... is a point I am at pains to make in this thread.

Tell that to the VLC developers.

Re: I don't trust Signal

#343
post #4

Is there a preference of Telegram over Signal or vice versa?

Telegram doesn't use end-to-end encryption by default and likely never will. Paul Durov has been quite hostile against that feature in the past. So yes, choose Signal over Telegram. I find that instead of trying to convince friends/family to use Signal I just tell them "use Signal as your default SMS app" or install it myself for them. This tactic worked well in the Internet Explorer/Firefox and then Chrome transitio…

The problem with that is assuming they will have internet connectivity always on when you want to contact them. Which I never found true even for the few people I regularly communicate over Signal. Most people turn off data and only turn it on somewhat regularly over the day to check stuff. Older people (like family) have no idea or barely know what internet is or even the button for that does and just expect communication to work like always: sms and phoning. But if people cam do the above approach good for them. I can barely convince anyone, even tech people from work or friends to install even more chat clients/services. Most are just fed up and feel tired of the whole thing.

Re: I don't trust Signal

#344
post #241

Earlier quoted context omitted.

Evidently Facebook themselves don't agree with you, since their "Secret Conversations" feature uses Signal's protocol (many other systems also have equivalent features built out of Signal Protocol, Skype, Google Chat, XMPP ... it's a sort of trend) In terms of how Signal compares to something like Facebook Messenger using HTTPS that's an actual technical question that's worth talking about (whereas "Oh no, Moxie Marl…

> although TLS _can_ authenticate both parties, on the Web today we rarely do that. Instead the web server is authenticated using TLS but the client (a Facebook user) has some crummy HTTP layer authentication, maybe a password like "1LvUrDog" filled into an HTML form field. I would love to see more use of client certificates, but assuming good password practice is there a real security difference? Either way both par…

Edited: Hmm. I wrote a long claim here and now I'm not sure depending on exactly what you steal, from whom, and when. I will re-think and re-post this.

Re: I don't trust Signal

#345

Drew DeVault doesn't trust Signal because its Android incarnation uses the Google Play Store --- the app market virtually all of its real users use --- and not F-Droid. DeVault would also like it if Signal would interoperate with other chat programs. Instead, DeVault would prefer that you use Matrix, a system for which end-to-end encryption is (according to its own website) "in late beta", offered on a select subset…

I feel like you didn't actually read the article or my comments in this thread. >Drew DeVault doesn't trust Signal because its Android incarnation uses the Google Play Store --- the app market virtually all of its real users use --- and not F-Droid It should use both. >the point of end-to-end encryption is that you don't have to trust Signal's server. All it does is arrange for the delivery of messages, which are sec…

I read your article, carefully, twice, once this morning (I briefly tweeted about it but didn't feel like I could do it justice and deleted the tweet) and again before writing this.

I've read all of your comments in this thread to date and, as you can see, replied to some of them.

I feel like I have fairly summarized your arguments.

"It should use both", you say. Signal disagrees. That makes Signal evil, according to your argument. "That's not how the world works" is my rebuttal.

Signal could easily keep a record of every pair of users. So can every other mainstream chat application --- and several of them do. Signal doesn't. My reply on the subthread about this issue explains what Signal does differently here, and it's not "publish the source code of the server".

People can simply read your comment on the thread --- I made clear where the quote came from --- to see exactly what you said about Wire and Telegram and Tox and Ring. I'm satisfied that I've represented your argument well.

Re: I don't trust Signal

#346

Earlier quoted context omitted.

There is nothing wrong with F-Droid. The problem isn’t that F-Droid is toxic. People can disagree without either side being at fault... is a point I am at pains to make in this thread.

Tell that to the VLC developers.

Not interested. I'm not litigating F-Droid and don't need to. F-Droid advocates, and some F-Droid critics, disagree: if F-Droid is implicated in an argument, we must fully adjudicate all its pro's and con's. No, that's not how the world works. I'm sufficiently well informed about F-Droid to know --- and I mean this in a benign sense, the same way I feel about OCaml or slab allocator design --- that I don't care.

Re: I don't trust Signal

#347

Earlier quoted context omitted.

SGX is not a magic bullet, it's only part of a secure system. It's also come under some fire, check out this paper: https://www.blackhat.com/docs/us-17/thursday/us-17-Swami-SGX... SGX alone cannot solve this problem. Even in the idealized case, you can sniff traffic on the router to find out which user IPs are talking to each other and when.

Did you read that work? I did: I was on the review board that made the decision to accept it for Black Hat. Could you map Yogesh's research to something Signal is actually proposing to do and explain in any detail what the actual threat you're talking about is? Thanks.

I could, but I'm probably ill informed. I want to hear your specific rebuttal to this:

>Even in the idealized case, you can sniff traffic on the router to find out which user IPs are talking to each other and when.

Re: I don't trust Signal

#348
post #335
post #220

Earlier quoted context omitted.

> Isn't the whole point of Signal that it's e2e encrypted and therefore can't really read and share your messages? Maybe. They have an awkward, compromised design, because fundamentally you can only the key exchange stuff that's necessary for forward secrecy if you're both online at the same time, but of course they want to support offline messaging, so they have a protocol that's mostly-e2e but the server also parti…

> They have an awkward, compromised design, because fundamentally you can only the key exchange stuff that's necessary for forward secrecy if you're both online at the same time. The initial key exchange is done through the server using "pre-keys" (which, unless verified, is trust on first use). Any new key data is sent with the messages (and as such, there is not much extra done by the server) I don't see how signal…

> The initial key exchange is done through the server using "pre-keys" (which, unless verified, is trust on first use). Any new key data is sent with the messages.

How confident are you that the server can't trick the client into downgrading to a new trust-on-first-use exchange? I'd also ask what happens when one party sends multiple messages while the other is offline - eventually you must exhaust your preshared keys, at which point you have no good options - presharing more keys compromises forward secrecy, encrypting without more exchanges compromises forward secrecy, and it's very difficult to make it clear to the user what the tradeoffs are. And again, whatever approach you choose opens the door to downgrade attacks (particularly if we're assuming that the OWS servers are hostile - Signal fans always claim that you don't have to trust the server at all but then don't really commit to that when talking about these edge cases. If we really aren't trusting the server then we should assume the servers are under attacker control when analysing these edge cases)

> I would say that the goal of signal was more about making an encrypted secure messenger for my mom than making crypto nerds safe from targeted attacks by nation states.

Slurs against those who disagree with you do not improve your case.

Are there any messengers that don't use TLS left? (Even IRC servers tend to use it these days). Your mom is adequately served by transport encryption. The Venn diagram of people who need more security than transport encryption and people who can safely use phone numbers as identifiers looks like: OO

Re: I don't trust Signal

#349

Earlier quoted context omitted.

I feel like you didn't actually read the article or my comments in this thread. >Drew DeVault doesn't trust Signal because its Android incarnation uses the Google Play Store --- the app market virtually all of its real users use --- and not F-Droid It should use both. >the point of end-to-end encryption is that you don't have to trust Signal's server. All it does is arrange for the delivery of messages, which are sec…

I read your article, carefully, twice, once this morning (I briefly tweeted about it but didn't feel like I could do it justice and deleted the tweet) and again before writing this. I've read all of your comments in this thread to date and, as you can see, replied to some of them. I feel like I have fairly summarized your arguments. "It should use both", you say. Signal disagrees. That makes Signal evil, according to…

>"It should use both", you say. Signal disagrees. That makes Signal evil, according to your argument.

You're oversimplifying this. For the full rebuttal, refer to the article.

>Signal doesn't.

You cannot know this. We don't need to have this conversation in two places, I'll just link it for others who want to follow along:

https://news.ycombinator.com/item?id=17726574

>I'm satisfied that I've represented your argument well.

I don't think so.

>People can simply read your comment on the thread

Fair enough: https://news.ycombinator.com/item?id=17724300

Full disclosure: I added the text in the parenthesis and the second paragraph of this comment about an hour after it was initially posted.

Re: I don't trust Signal

#350
post #193

Earlier quoted context omitted.

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play. The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't. This alone is enough for me to lose trust in Signal.

Maybe Moxie doesnt see it as his problem to address concerns of non-contributing critics. Are there any identified, non-state-level actor threats here, or is this just an ideological rant against proprietary software? If state-level actors are your concern, using android means you have already lost.

Moxie doesn't address the concerns of conctributors, either. Here's one from this very comment thread:

https://news.ycombinator.com/item?id=17724893

Others have emailed me as well, thanking me for putting to words what they felt afraid to for fear of retribution from "Moxie and his religious following" (direct quote).

Post reply on HN