Live data from Hacker News

Snap Store administrators removed signal-desktop from Ubuntu Snap

forum.snapcraft.io

401–410 of 443 posts

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#401
post #364

Earlier quoted context omitted.

> If Ubuntu had spent resources to develop a convenient way for developers to directly provide binaries to the users of their OS No way. I will never trust your binary.

Lol, like you audit the thousands of lines of code when you compile from source.

Yes, I look at code. I'm professional developer. I will spend 1-2 minutes at scanning per thousand of lines.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#402
post #255

Earlier quoted context omitted.

Moxie is no longer involved in Signal. Blaming him for things Signal does now is pretty free of fact

Other than that he set things up to be that way. He’s not blameless for the fact it’s not federated, for example. Even if he’s not involved anymore.

Federating is hard, and Signal is trying hard to solve the metadata problem in a fundamentally different way (which I happen to believe is better).

I see you want federation, that's fine. I want private metadata. Don't use Signal if it doesn't do what you want, but maybe try to accept that not every project should do what you want. They have their preferences too.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#403

Earlier quoted context omitted.

It's 5 lines. Took me 30 seconds. Well worth it for the performance gains. wget -O- https://updates.signal.org/desktop/apt/keys.asc | gpg --dearmor > signal-desktop-keyring.gpg && cat signal-desktop-keyring.gpg | sudo tee -a /usr/share/keyrings/signal-desktop-keyring.gpg > /dev/null && echo 'deb [arch=amd64 signed-by=/usr/share/keyrings/signal-desktop-keyring.gpg] https://updates.signal.org/desktop/apt xenial main' |…

This is not secure at all because you just gave Signal root access to your system. By adding their keys you also have granted a permission for Signal to replace any packages on your system. I would instead manually download and unpack the app, create separate user for it, and run it in chroot. Much safer than your method.

Respectfully, I don't think that's correct, or possibly I am misreading your comment. IIUC, placing a key in /usr/share/keyrings does not allow those keys to sign any package, only the packages designated with "signed-by" in the apt list.

Sadly, plenty of applications still take the old "apt-key" approach of adding the keys globally (e.g., installing keys to /etc/apt/trusted.gpg.d), but I think Signal's installation process is the correct/recommended approach for distributing apt packages securely.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#404
post #399
post #252

Earlier quoted context omitted.

To be honest I don’t see a strong reason to trust signal either except better marketing. There are so many scandals that come to mind, like not updating the FOSS code for years. I’m no fan of Meta, and they have incentive to hoover up data. But I don’t have a good reason to trust signal other than that everyone on hackernews seems to love them.

You mix up concepts. The client app is responsible for e2ee, you don't have to care about the server. So you can actually audit the client code and make sure it is e2ee, which you cannot do with WhatsApp. In other words, for e2ee you must trust WhatsApp, not Signal. I presume that for the outdated code, you think about the server code. That's different and would imply metadata, not message content. Signal is e2ee, an…

> Signal is e2ee, and you don't have to trust them for that.

Only if both sides are using clients that are self-compiled, independently-compiled (and audited), deterministic/reproducible or third-party.

The problem is that the network and the app are the same people, and worse than that; they send binaries and expect you to trust them.

I know lip service is paid to reproducibility but afaik the instructions for doing that are 404ing.

I just get a greasy feeling from the lock-in, the heavy marketing, the fact that everyone refuses to speak critically of them unless it’s about anonymous usernames.

A truly good secure client would have worked on any network, it wouldn’t rely on transporting your data over their servers, it would be a protocol that was open to third parties to implement, it would also be reproducible or independently compiled by trusted third parties (like OS maintainers, who already audit a lot of the code that gets built and signed).

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#405
post #395
post #380

Earlier quoted context omitted.

Yeah, it's possible for a web server to detect and change the returned data maliciously. Even with user agent and all other factors changed to match, it's possible to detect even the difference between being piped into another command vs being redirected to a file.

It's also possible for a web server to selectively serve you a backdoored .deb or git repo

It helps that Signal uses an HTTPS apt repo and includes "signed-by=/usr/share/keyrings/signal-desktop-keyring.gpg" in the apt list entry. If their download server were compromised, (and assuming the hacker didn't also get the private gpg key) the attacker would have to provide malicious archives selectively to avoid detection. Anyone who installed the old key (e.g., me) would notice the key validation errors.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#406
post #350

Earlier quoted context omitted.

Correct. We spoke to our attorneys and found the breakdown in communication. We are working to rectify and reinstate signal-desktop ASAP. Sorry for the confusion.

Why is Signal, a company that prides itself in being tech-centric, allowing lawyers to send DMCA requests without consulting anybody?

Because when you ship a security product it's important to control who distributes it under the official name.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#407
post #385

Earlier quoted context omitted.

Signal isn’t saying no one can use the word signal. The problem arises when you use all of their branding together in such a way that could plausibly fool someone into thinking it’s their software, which very much appears to have happened here (see this entire thread full of people who installed this trademark violating build thinking it was legit)

Signal is not saying this, as evidenced by the cofounder saying that this is all a misunderstanding and that they're working to undo what's been done.

yeah I noticed that. Quite a reversal from their previous position, which was incredibly clear. I wonder if they'll extend this policy to other groups that have previously been shut down for doing the same thing (F-Droid being the obvious one here).

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#408
post #231

Earlier quoted context omitted.

That is what a DMCA takedown is. You contacting the people involved to get something taken down.

No. A DCMA takedown is your lawyers contacting their lawyers and saying that you're invoking a law which forces them to immediately take something down or risk severe legal ramifications. Isn't it better to reach out without invoking a DCMA and see if the other party is willing to cooperate first?

>Isn't it better to reach out without invoking a DCMA and see if the other party is willing to cooperate first?

That would still be your lawyers talking to their lawyers. The channels for handling DMCA takedowns are much more efficient than channels for handling something custom.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#409
post #219

Earlier quoted context omitted.

Backups work fine on my Android phone. They consistently go to a folder and Syncthing backs them up from there. Also no problems with it not ringing, Signal is actually the primary way that my family calls each other now and no one has experienced it not ringing when expected. The rest I admittedly dont use or arent impacted by. While its not perfect in all ways, I disagree with the "alpha" quality sentiment. Especia…

>Backups work fine on my Android phone. They consistently go to a folder and Syncthing backs them up from there. I never said backups don't work, I said they're not easy to do and restore compared to other apps where it's much more seamless and hands-off. No average user knows what Syncthing is and how to set it up. People expect the messaging app to have its own backup-restore system compatible with the cloud storag…

It takes a few clicks and entering a password to enable backups. Restore also worked fine the one time I needed it. They can go to Google Drive just fine, Syncthing is only so I have the backups going to my NAS instead.

As to ringing, it seems that the six people with six different phones (mostly Pixels, one iPhone) in my circle mean that it isn't good luck on my part...

It's end to end by default vs Telegram which is well known to be end to end maybeish if it's explicitly setup, for private chats only. WhatsApp is WhatsApp. Maybe it's a low bar, but Signal beats those others pretty easily. And refusing to use Signal over those two due to lack of a security audit is a bit absurd... All you're getting from Telegram and WhatsApp is "trust us bro" as well.

It's not an excuse. But considering it IS transparent for many users, me included.... Not everyone is having the issues you are.

Re: Snap Store administrators removed signal-desktop from Ubuntu Snap

#410
post #237

Earlier quoted context omitted.

Moxies always been fairly dictatorial about Signal. no third party clients, no decentralization. im not surprised to see a DMCA at all. So far Signal is a centralized encrypted messaging app that includes its own cryptocurrency and wallet no one asked for, shills me for donations every other release, and begs me to invite new users despite deprecating regular SMS message support. if youre a threat-actor the most male…

> no third party clients Isn't their client open source? If I compiled it myself, is that a third party client? If they don't let me compile it myself, how can I trust their official version is using the source they published?

They don't want people distributing unofficial builds that claim to be Signal due to the risk of supply chain attacks against users.
Post reply on HN