Live data from Hacker News

Snap Store administrators removed signal-desktop from Ubuntu Snap

forum.snapcraft.io

391–400 of 443 posts

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#391

Earlier quoted context omitted.

So you're saying signal requested their own program be removed from the snap store? Sorry, I'm a little confused on terms. When you say snap maintainer, are you saying you are the maintainer of the signal snap package, or that you're a maintainer of snap itself?

Wasn’t their own program. They have a binary they distribute, this was some other binary calling itself Signal without their approval.

This is simply incorrect, we were distributing the exact binaries signal produces.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#392
post #350

Earlier quoted context omitted.

Why is Signal, a company that prides itself in being tech-centric, allowing lawyers to send DMCA requests without consulting anybody?

I don't get why Signal being tech-centric (whatever that means) should disallow their lawyers from sending DMCA takedown requests.

Because it means their lawyers are firing off in random, uninformed directions. There's no copyright issue, as the maintainers of the Snap have a copyright license (the AGPLv3) to do what they are doing.

You could argue that it's a trademark issue, except that if it was, this makes a DMCA request illegal as it's not a tool to enforce trademark issues. And in addition, while the AGPLv3 has allowances for trademark carve-outs, Signal makes none.

It's not a good look for the lawyers to be completely in the dark on an issue so core to their company's business.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#393

Earlier quoted context omitted.

Presumably for the same reason they don't want someone else packaging snap for them its another party to attack in order to attack their users in a way that would destroy trust in their product given its sensitive nature.

I'm already trusting debian to provide the rest of the system without backdoors. Why would getting signal from somewhere else help in any way?

It's presumably signal not trusting 97 different stores not Debian's in particular not to get compromised.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#394
post #364

Earlier quoted context omitted.

> If Ubuntu had spent resources to develop a convenient way for developers to directly provide binaries to the users of their OS No way. I will never trust your binary.

Lol, like you audit the thousands of lines of code when you compile from source.

What made you think they'd be willing to compile from untrusted sources?

There are a lot of users that prefer the established trust model of a Linux distribution. They're willing to trust the mostly unpaid debian maintainers for example... but not John Doe, the temporarily set back billionaire who's just about to make it big

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#395
post #380
post #374

Earlier quoted context omitted.

Is it meaningfully sketchier than downloading a .deb and calling dpkg -i on it? Or cloning a git repo and building it?

Yeah, it's possible for a web server to detect and change the returned data maliciously. Even with user agent and all other factors changed to match, it's possible to detect even the difference between being piped into another command vs being redirected to a file.

It's also possible for a web server to selectively serve you a backdoored .deb or git repo

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#396
post #379

Earlier quoted context omitted.

You didn't realize what you were doing was against the license?

It wasn't against the license. It's AGPL v3, about as open as it gets.

You don't get the license without respecting the trademark.

e) Declining to grant rights under trademark law for use of some trade names, trademarks, or service marks; or

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#397
post #395
post #380

Earlier quoted context omitted.

Yeah, it's possible for a web server to detect and change the returned data maliciously. Even with user agent and all other factors changed to match, it's possible to detect even the difference between being piped into another command vs being redirected to a file.

It's also possible for a web server to selectively serve you a backdoored .deb or git repo

So what? I can inspect downloaded code and find the backdoor, or a trojan, or an error. I did it few times already in last 30 years. If you cannot do that doesn't mean that nobody can. But I cannot do that with `curl | bash`.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#398
post #383

Earlier quoted context omitted.

So, do you think the adoption of systemd was motivated to a great extent by the influence of commercial companies' interest? Would you say that's true for distributions like Debian, which you gave as an example? I'm not being facetious, it's just that this aspect has not been described to me so far, IIRC.

Systemd was a child of Redhat. Debian had to support it, mostly because at the time Gnome, another Redhat controlled project, decided to depend upon systemd.

1. Supporting it is not the same as mandating it (which it effectively has)

2. You're saying that Debian made this choice because of a choice by GNOME. But - was GNOME strong-armed by commercial interests?

3. AFAIK, The dependence of GNOME on systemd was broken quite easily (IIANM mostly by using a forked elogind).

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#399
post #252
post #210

Earlier quoted context omitted.

Except it's owned by Meta, who I really wouldn't trust even if they say it's E2EE.

To be honest I don’t see a strong reason to trust signal either except better marketing. There are so many scandals that come to mind, like not updating the FOSS code for years. I’m no fan of Meta, and they have incentive to hoover up data. But I don’t have a good reason to trust signal other than that everyone on hackernews seems to love them.

You mix up concepts. The client app is responsible for e2ee, you don't have to care about the server.

So you can actually audit the client code and make sure it is e2ee, which you cannot do with WhatsApp. In other words, for e2ee you must trust WhatsApp, not Signal.

I presume that for the outdated code, you think about the server code. That's different and would imply metadata, not message content.

Signal is e2ee, and you don't have to trust them for that.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#400

Earlier quoted context omitted.

Moxies always been fairly dictatorial about Signal. no third party clients, no decentralization. im not surprised to see a DMCA at all. So far Signal is a centralized encrypted messaging app that includes its own cryptocurrency and wallet no one asked for, shills me for donations every other release, and begs me to invite new users despite deprecating regular SMS message support. if youre a threat-actor the most male…

Wait? Really? I've been out of the loop regarding Signal. But "crypto punk/anarchist" Moxie Marlinspike is using DMCA takedowns and doesn't like decentralization and 3rd party clients? I'm flabbergasted.

Moxie is not at Signal anymore.
Post reply on HN