Live data from Hacker News

I don't trust Signal

drewdevault.com

391–400 of 473 posts

Re: I don't trust Signal

#391
post #48

Seriously, why do they use the smartphone in the first place? The smartphone ecosystem, be it Android or iPhone, is not secure. It can not be trusted. Even if we avoid Apple and Google's software distribution platform, Your smartphone still has binary blob kernel module, baseband processor and the OS runs on top of that. People who claims secure and trust on top of smartphone are all liar, idiot or both. Don't use th…

"Don't use smartphones" is not an effective method of getting people to communicate securely. We've had GPG forever. How many people used it?

Also, for the large majority of people their smartphone is going to be more secure than their laptop.

Re: I don't trust Signal

#392
post #129

Earlier quoted context omitted.

Apple has root access to every device just like Google has to Android phones running Google Play Services.

Security wise, Apple iOS is superior in any possible aspect to Android. Forensics people never complain how hard it is do Android, never :)

Great. Nobody cares.

There are way more android users than iphone users. If your goal is to improve the security for the most people possible, you make an android app.

Re: I don't trust Signal

#393
post #299

Earlier quoted context omitted.

It seems pretty odd to me to distrust someone because they aren't using the platform that you'd like them to use. Aren't there other issues with f-droid? You have to root your device to run it, allow third party code. Those are all security concerns too. It was posted elsewhere but here's Moxie's take: https://github.com/signalapp/Signal-Android/issues/127#issue...

> You have to root your device to run it wtf. I have been using F-Droid for many years, and this has not been the case. as far as I know, this has never been the case, as Android has always had functions for third party app stores. in fact, even today, F-Droid recommends not using root for installs, since then you don't get the screen showing permissions. > allow third party code that's called running apps. tl;dr nic…

'allow third party code' means code which is not signed. Once you tick that any unsigned code can run, not only the app you downloaded. Makes exploitation significantly easier. It would be better if Android forced you to explicitly select which code could run, but too hard for most users.

Re: I don't trust Signal

#394
post #348
post #335

Earlier quoted context omitted.

> They have an awkward, compromised design, because fundamentally you can only the key exchange stuff that's necessary for forward secrecy if you're both online at the same time. The initial key exchange is done through the server using "pre-keys" (which, unless verified, is trust on first use). Any new key data is sent with the messages (and as such, there is not much extra done by the server) I don't see how signal…

> The initial key exchange is done through the server using "pre-keys" (which, unless verified, is trust on first use). Any new key data is sent with the messages. How confident are you that the server can't trick the client into downgrading to a new trust-on-first-use exchange? I'd also ask what happens when one party sends multiple messages while the other is offline - eventually you must exhaust your preshared key…

Prekeys are to start a session with someone, it's basically a public key. You generate a new public private keypair, do a DHE to establish the session secrets, send your new public key along with the encrypted message. If you send more messages to the same person, they use the same session.

TLS is fine enough for messages in flight, but a lot of messengers store message archives on their servers, and there may be tens of thousands of employees who have potential access to that; not sure if that's really what anybody's mom needs.

Re: I don't trust Signal

#396

Earlier quoted context omitted.

I am happy to see I am not the only person in the world that feels like this about Signal. The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.) I admire Wire for a n…

Signal, in an indirect way, requires 1/6th of the world's population to part with their biometrics. It requires phone number, and in India, getting a phone # requires Aadhaar, which is a centralized, biometrics-based ID (photo, fingerprints AND iris at the moment).

Are you seriously telling me that everyone in India is using the phone number which matches their biometrics? Lol.

Besides which, there are well established ways to get a Signal number online, like Google Voice or VoIP telephony companies.

Re: I don't trust Signal

#397

Earlier quoted context omitted.

I am happy to see I am not the only person in the world that feels like this about Signal. The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.) I admire Wire for a n…

I love wire. Never have any issues with the desktop client nor mobile app. Even though it's Electron, it seems to be extremely focused on security. Unfortunately, it suffers from the same metadata issues as Signal. If you really need higher security messaging, p2p is your best bet, but then you may face correlation attacks by ISPs and whatnot... Maybe we all just need to get our HAM radio licenses :)

Well, Electron is a security trash fire. I wouldn't use it for anything if need to be remotely secure. Hopefully will be replaced by webasm in the near future, though that will likely have problems too.

Re: I don't trust Signal

#398
post #93
post #67

Earlier quoted context omitted.

source?

It's complicated, but that's kinda what happened to the Lavabit "secure" webmail service. When the owner wouldn't install a backdoor, the FBI sought the private encryption keys so they could MITM the whole site. https://www.newyorker.com/tech/elements/how-lavabit-melted-d...

That isn't building an interception mechanism, it's revealing some private information Lavabit held.

Re: I don't trust Signal

#399
post #40

> P.S. If you’re looking for good alternatives to Signal, I can recommend Matrix. Yes, if you're looking for alternatives to Signal, you should totally use a solution that hasn't rolled out end-to-end encryption by default[0]. /s ...and that only two clients have implemented so far, out of 50ish that they list on their website. [0] https://matrix.org/docs/guides/faq.html#what-is-the-status-o...

Author here, this is a fair criticism. Other alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring (not an endorsement of any of these). I'm an old curmodgen who just uses IRC+OTR and GPG, though, so I have to depend on others for recommendations. Also, Matrix enables end-to-end encryption by default on clients that support it.

I really like Wire, for a large number of reasons - privacy and user experience among them. I've talked about it in the past[1].

If you get the time, please give it a proper whirl. With the recent open-sourcing of their server and proper E2EE by default[2] (but abstracted away from the "regular user"), it's shaping up to be a really solid application. As far as I'm aware they use the same double-ratchet protocol as Signal, but you don't need your cellphone number to register (a big thing for some people - myself included).

1. https://news.ycombinator.com/item?id=16655743

2. https://wire-docs.wire.com/download/Wire+Security+Whitepaper...

Re: I don't trust Signal

#400
post #343
post #4

Earlier quoted context omitted.

Telegram doesn't use end-to-end encryption by default and likely never will. Paul Durov has been quite hostile against that feature in the past. So yes, choose Signal over Telegram. I find that instead of trying to convince friends/family to use Signal I just tell them "use Signal as your default SMS app" or install it myself for them. This tactic worked well in the Internet Explorer/Firefox and then Chrome transitio…

The problem with that is assuming they will have internet connectivity always on when you want to contact them. Which I never found true even for the few people I regularly communicate over Signal. Most people turn off data and only turn it on somewhat regularly over the day to check stuff. Older people (like family) have no idea or barely know what internet is or even the button for that does and just expect communi…

Which country are you speaking of where people turn off data (to save money presumably)?

Signal used to be TextSecure, and there is a fork which still supports encrypted SMS.

Post reply on HN