Live data from Hacker News

I don't trust Signal

drewdevault.com

411–420 of 473 posts

Re: I don't trust Signal

#411
post #42

The article actually proposes an alternative: Matrix, and Matrix is, in fact, a good piece of software, with federation options. I tend to agree with most parts of the article, especially the lack of federation options. My real pain point with Signal is that there is no real desktop application for it - no, a connected web interface is not a desktop application. For example, XMPP with OMEMO can be used simultaneously…

> My real pain point with Signal is that there is no real desktop application for it

Signal is open source, you can write your own -- just kidding. Moxie Marlinspike wants to lock you into his client as Facebook, Google and their ilk lock you into theirs.[1]

[1]https://github.com/LibreSignal/LibreSignal/issues/37#issueco...

Re: I don't trust Signal

#412
post #326
post #52

Earlier quoted context omitted.

That ticks me off too. I'd rather suggest Tox. For all the hate it gets, it does only have mode of communication: End-to-end encrypted, for your contact (as people's addresses are pubkeys) and with forward secrecy. Most "secure" IM systems fail this basic test. When proper end-to-end encryption is optional, guess what happens.

Well. I'd rather not have anyone suggest tox. The whole "we use nacl so we are safe" attitude from a couple of years ago seems to still be around. Good on them for using nacl. A shame they don't seem to realize that you can write bad crypto with it. The whole forward secrecy seems to be unresolved still. They have session keys,but other than that there is no rekeying. And then we have the whole issue with it relying…

>The whole "we use nacl so we are safe" attitude from a couple of years ago seems to still be around.

Citation needed.

>Well. I'd rather not have anyone suggest tox.

I'm repeating myself, but for all the hate it gets, I'm unable to come up with a better suggestion than Tox. There's always some kind of flaw: Centralized, no forward secrecy, end to end encryption optional, no way to verify contacts and so on.

Re: I don't trust Signal

#414
post #153
post #100

Earlier quoted context omitted.

What do you mean by a "connected" web interface? And what would being a desktop application bring it? Signal Desktop is somewhat buggy, not that full-features, and doesn't integrate that well with the rest of my OS, but otherwise it's working fine, and I can use it simultaneously with my phone. (But I can also use it with my phone turned off, which I love.)

> but otherwise it's working fine It doesn't work at all for me, because it requires a mobile phone number, which I don't have (a phone + any monthly subscription fee doesn't fit in a tiny fixed income budget).

Google Voice numbers are free.

Is that perfect? No, but if you want another unambiguous identifier, it's going to cost. Moxie does not have a lever that can move the world; if you think you do, you are probably well invited to haul on it.

Re: I don't trust Signal

#415

Drew DeVault doesn't trust Signal because its Android incarnation uses the Google Play Store --- the app market virtually all of its real users use --- and not F-Droid. DeVault would also like it if Signal would interoperate with other chat programs. Instead, DeVault would prefer that you use Matrix, a system for which end-to-end encryption is (according to its own website) "in late beta", offered on a select subset…

If people are on a centralized service it will be much easier censor, surveil and kick out undesirables. And as we saw on the Gab thread, these are things you want to enable. You want a strong leader to say what goes and doesn't and you hope that Moxie will become that leader.

I think I will stick with matrix.

Re: I don't trust Signal

#416

Earlier quoted context omitted.

> You have to root your device to run it wtf. I have been using F-Droid for many years, and this has not been the case. as far as I know, this has never been the case, as Android has always had functions for third party app stores. in fact, even today, F-Droid recommends not using root for installs, since then you don't get the screen showing permissions. > allow third party code that's called running apps. tl;dr nic…

'allow third party code' means code which is not signed. Once you tick that any unsigned code can run, not only the app you downloaded. Makes exploitation significantly easier. It would be better if Android forced you to explicitly select which code could run, but too hard for most users.

Then you "untick" it until the next time you need to install something.

This is what I do on lineageOS. I don't regularly install new apps.

Side rant: This marketer-driven "install an app for everything" is a threat to the open internet and privacy. Usually the only reason is to extract more personal info.

Already, young people barely use a web browser. That appears to be the future. Now get off my lawn or I'll start talking about the war.

Re: I don't trust Signal

#417

Earlier quoted context omitted.

Agreed, though personally I find any support of animated gifs in the year 2010 and beyond to be counterproductive.

How much non-geek non-privacy-activist socialising have you done via Signal? Without emoji and animated gifs, I suspect 70% of my Signal contacts wouldn't use it at all. It's hard enough to convince some of my friends to use it at all, "Can't I just Facebook message you?" For me, amongst my group of friends - it seems Moxy is making all the right security/usability tradeoffs. If you don't trust PlayStore, it seems no…

>I wonder what it is you're up to that makes you more of a nation-state target than him

I don't know what it is you're talking about. The entire point of my comment was that I don't like animated gifs. They're distracting, bandwidth intensive, and could be easily replaced by a dozen better image formats.

Re: I don't trust Signal

#418
post #241

Earlier quoted context omitted.

Evidently Facebook themselves don't agree with you, since their "Secret Conversations" feature uses Signal's protocol (many other systems also have equivalent features built out of Signal Protocol, Skype, Google Chat, XMPP ... it's a sort of trend) In terms of how Signal compares to something like Facebook Messenger using HTTPS that's an actual technical question that's worth talking about (whereas "Oh no, Moxie Marl…

> although TLS _can_ authenticate both parties, on the Web today we rarely do that. Instead the web server is authenticated using TLS but the client (a Facebook user) has some crummy HTTP layer authentication, maybe a password like "1LvUrDog" filled into an HTML form field. I would love to see more use of client certificates, but assuming good password practice is there a real security difference? Either way both par…

OK, so yes, if you steal Alice's credentials AND have control over the co-ordinating server you can trick Alice and Bob into continuing to communicate with you in the middle, and so long as you keep this up it's relatively undetectable.

I think I can see how to repair this (Alice doesn't know Bob's private key, but she does know a long term public key for him, as a result she could periodically and automatically re-verify that she's still talking to Bob and not just someone who has her short term keys and is actively conducting a MITM) but Signal doesn't attempt such a repair and maybe I'm wrong.

Re: I don't trust Signal

#419

Earlier quoted context omitted.

But that's not the argument the author makes. He is worried about the apps getting compromised at the platform level.

That's a security concern he feels he can address for himself if Signal is made available to him on F-Droid. But for the overwhelming majority of Signal users, there isn't even in theory a security benefit, because they're exposed to their platform vendor no matter what Signal does. Signal has decided --- sensibly, I think! --- to focus on the needs of the "normie" users. DeVault disagrees with that decision. He is w…

He is indeed welcome to do so. It is perfectly rational for him to choose some other software.

Far from not something that warrants a character assassination. Specifically, it's not something "clownish" that we should be "ashamed" to have on the front page. We get the community we deserve.

Re: I don't trust Signal

#420
post #153

Earlier quoted context omitted.

> but otherwise it's working fine It doesn't work at all for me, because it requires a mobile phone number, which I don't have (a phone + any monthly subscription fee doesn't fit in a tiny fixed income budget).

Google Voice numbers are free. Is that perfect? No, but if you want another unambiguous identifier, it's going to cost. Moxie does not have a lever that can move the world; if you think you do, you are probably well invited to haul on it.

> if you want another unambiguous identifier, it's going to cost

Nonsense - my XMPP addresses are free, globally unambiguous, federated, and support 3 types of end-to-end encryption. A phone number is patently unnecessary. The only reason to require a phone number is to tie the encrypted packets to a known identity.

Post reply on HN