Live data from Hacker News

I don't trust Signal

drewdevault.com

41–50 of 473 posts

Re: I don't trust Signal

#41
post #26

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

If Open Whisper Systems had received a national security letter requiring them to collect more information and keep it secret that they were doing so, how would you expect them to have responded to that subpoena?

NSL can't require to collect new business records. They can only compel you to disclose business records that you already have.

This is beyond the legal authority of an NSL.

Re: I don't trust Signal

#42
The article actually proposes an alternative: Matrix, and Matrix is, in fact, a good piece of software, with federation options.

I tend to agree with most parts of the article, especially the lack of federation options.

My real pain point with Signal is that there is no real desktop application for it - no, a connected web interface is not a desktop application. For example, XMPP with OMEMO can be used simultaneously from Android Conversations AND Pidgin - same account, same messages (yes, it needs XMPP Carbons on the server), e2e.

Re: I don't trust Signal

#43

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

> We have at least one data point that says that Signal stores exactly two integers about you

For people wondering what they are:

> "The only information responsive to the subpoena held by OWS is the time of account creation and the date of the last connection to Signal servers for account [redacted]. Consistent with the Electronic Conununications Privacy Act ("ECPA"), 18 U.S.C. § 2703(c)(2), OWS is providing this information in response to the subpoena."

Their response to the subpoena then goes on to object to its overly broad scope, which asked for things that require a court order or a search warrant. They also object to the scope of the nondisclosure order included in the subpoena.

Re: I don't trust Signal

#44

"If Edward Snowden and Bruce Schneier are going to spout the virtues of the app, I expect it to actually be secure when it matters - when vulnerable people using it to encrypt sensitive communications are targeted by smart and powerful adversaries." Because if the adversary is, say, an abusive ex that happens to work for the telco, for example, then it doesn't matter. Unless you're actively hunted by a G7 country you…

How do you defend abused spouses in discourse by comparing their needs to people hunted by the most powerful political forces? Surely these two cases ought not be on the same table for comparison.

Re: I don't trust Signal

#46

The line about F-Droid doing no automated scanning is particularly troubling. Since he can't possibly imply that a Signal compromise would be detected this way, Moxie is making a political argument against the way people are using F-Droid to install other applications . He refuses - on principle, no less - the right for users to control their hardware and have full control over the software they install, and thinks t…

Does F-Droid support reproducible builds now? Or does it offer any other kind of assurance that the software downloaded actually comes from the purported origin?

Re: I don't trust Signal

#47
post #40

> P.S. If you’re looking for good alternatives to Signal, I can recommend Matrix. Yes, if you're looking for alternatives to Signal, you should totally use a solution that hasn't rolled out end-to-end encryption by default[0]. /s ...and that only two clients have implemented so far, out of 50ish that they list on their website. [0] https://matrix.org/docs/guides/faq.html#what-is-the-status-o...

Nonsense. You can run your own Matrix server and set whatever defaults you want.

Re: I don't trust Signal

#48
Seriously, why do they use the smartphone in the first place? The smartphone ecosystem, be it Android or iPhone, is not secure. It can not be trusted.

Even if we avoid Apple and Google's software distribution platform, Your smartphone still has binary blob kernel module, baseband processor and the OS runs on top of that.

People who claims secure and trust on top of smartphone are all liar, idiot or both.

Don't use the smartphone.

Re: I don't trust Signal

#49
post #38

I don't know anything about Moxie derailing threads or anything like that but if we just listened to critics all the time then we just wouldn't have anything. Signal is better than a lot of what is out there and being used as scale and that counts for something. More secure is always better than not secure at all.

Read the end of an article as well. We have solutions like Matrix, and like XMPP with OMEMO.

Re: I don't trust Signal

#50

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

Uhm... this is what would happen if it was a govt job
Post reply on HN