Live data from Hacker News

I don't trust Signal

drewdevault.com

441–450 of 473 posts

Re: I don't trust Signal

#441

Earlier quoted context omitted.

'allow third party code' means code which is not signed. Once you tick that any unsigned code can run, not only the app you downloaded. Makes exploitation significantly easier. It would be better if Android forced you to explicitly select which code could run, but too hard for most users.

Then you "untick" it until the next time you need to install something. This is what I do on lineageOS. I don't regularly install new apps. Side rant: This marketer-driven "install an app for everything" is a threat to the open internet and privacy. Usually the only reason is to extract more personal info. Already, young people barely use a web browser. That appears to be the future. Now get off my lawn or I'll start…

You might do it, but thousands wouldn't.

Android could undoubtedly be stronger in this regard, and in permission control, firewall, ad blocking etc, but it's not going to happen.

Apps wouldn't be so bad if they were actually sandboxed properly, but yeah, they suck.

I was interested in Copperhead OS as an alternative, but it seems to have fallen into a greed induced mess.

Re: I don't trust Signal

#442
post #387

As a Signal user, I just wish I could make my own personal fork of the desktop app and still talk to everyone without having to use the beta servers and fear of having access cut off, because the visual design and UX of the desktop app is absolutely atrocious. And the latest update that was pushed a few days ago was a massive step back; the bloated UI now looks like some iOS app from 2007. It's just embarrassing. And…

Hmm, if you can improve the UI by yourself, could you not submit a pull request to do that? That would probably still allow you to use the improved UI without fear of having access cut off.

(I wasn't aware of a redesign - just updated, and I don't really like it either, but ah well.)

Re: I don't trust Signal

#443

Earlier quoted context omitted.

'allow third party code' means code which is not signed. Once you tick that any unsigned code can run, not only the app you downloaded. Makes exploitation significantly easier. It would be better if Android forced you to explicitly select which code could run, but too hard for most users.

Then you "untick" it until the next time you need to install something. This is what I do on lineageOS. I don't regularly install new apps. Side rant: This marketer-driven "install an app for everything" is a threat to the open internet and privacy. Usually the only reason is to extract more personal info. Already, young people barely use a web browser. That appears to be the future. Now get off my lawn or I'll start…

We're about to see what happens with APK side loading at scale... Fortnite is bypassing Play store. I predict massive pwnage.

https://twitter.com/APKMirror/status/1027580291374702592?s=1...

Re: I don't trust Signal

#444
post #193

Earlier quoted context omitted.

> Moxie forbids you from distributing branded builds of the Signal app ... Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction. > ... and if you rebrand he forbids you from using the official Open Whisper servers. This seems pretty fair to me. Not only could you abuse their resources, it would greatly hinder their ability to make changes and respon…

The F-Droid argument is the strongest and most evident among all. I don't trust Google, I don't trust Play. The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't. This alone is enough for me to lose trust in Signal.

Nah, people will just accuse him of publishing different binaries, or find something else to be upset about. You can't win against concern trolling by giving in to their demands. They just manufacture new demands, and all you do is waste your own resources. Haters are gonna hate, so you're better off ignoring them and focussing on your own vision.

Re: I don't trust Signal

#445
post #420

Earlier quoted context omitted.

Google Voice numbers are free. Is that perfect? No, but if you want another unambiguous identifier, it's going to cost. Moxie does not have a lever that can move the world; if you think you do, you are probably well invited to haul on it.

> if you want another unambiguous identifier, it's going to cost Nonsense - my XMPP addresses are free, globally unambiguous, federated, and support 3 types of end-to-end encryption. A phone number is patently unnecessary. The only reason to require a phone number is to tie the encrypted packets to a known identity.

An identity that everyone else already knows, yes. I figured that was so obvious as to not require elaboration.

Re: I don't trust Signal

#446
post #432
post #394

Earlier quoted context omitted.

Prekeys are to start a session with someone, it's basically a public key. You generate a new public private keypair, do a DHE to establish the session secrets, send your new public key along with the encrypted message. If you send more messages to the same person, they use the same session. TLS is fine enough for messages in flight, but a lot of messengers store message archives on their servers, and there may be ten…

> Prekeys are to start a session with someone, it's basically a public key. You generate a new public private keypair, do a DHE to establish the session secrets, send your new public key along with the encrypted message. At which point you have essentially decayed to conventional PKI and don't get any the security properties that you were supposed to get from the fancy Signal protocol (i.e. PFS).

Well, you always have to verify keys. No security is guaranteed without it. That is the case everywhere. Those pre-keys are just there to start a session, which in my communication with my brother case has lasted for as long as I had my phone (about 3 years). That session creates new key material with every message, providing forward secrecy.

I think it is a pretty elegant solution to key distribution, even though I wouldn't plan any bomb attempts without first validating the fingerprints.

Re: I don't trust Signal

#447
post #439
post #423

Earlier quoted context omitted.

Regarding the citation, it is just a matter of reading how the core devs reply to potential security issues. Sure, it has gotten better, but it is not too far from the good old https://github.com/irungentoo/toxcore/issues/121 The fact is we mostly know what kind of attacks are possible on signal. We know metadata is a potential problem. We know what kind of tradeoffs we get with a centralised architecture. We know ho…

>Sure, it has gotten better, but it is not too far from the good old So your citation for sticking to their old ways is pointing to some old example? That's not what I was looking for. >Why aren't the devs clear about using a less distributed architecture for mobile clients? Because it's not a priority to them; Or to me, for that matter. (I don't IM on the phone) >I would not recommend it for secure communication unt…

Signal is better because people who knows their shit has vetted the design and quite a bit of research on the protocol has been done. We a quite certain of the security properties of the signal protocol.

Tox has not had this amount of attention and it is written by people who seemed to sincerely believe that using nacl/libsodium made tox safe. If that is not a huge red flag, then I don't know what is.

Telegram is not encrypted by default and when it is it uses a weird protocol, which people warned about from the beginning. The devs were cocky even after a probably unintentional backdoor was found that would have let the server mitm every encrypted communication.

The difference between these three for secure communication is huge.

Re: I don't trust Signal

#448
post #343

Earlier quoted context omitted.

The problem with that is assuming they will have internet connectivity always on when you want to contact them. Which I never found true even for the few people I regularly communicate over Signal. Most people turn off data and only turn it on somewhat regularly over the day to check stuff. Older people (like family) have no idea or barely know what internet is or even the button for that does and just expect communi…

Which country are you speaking of where people turn off data (to save money presumably)? Signal used to be TextSecure, and there is a fork which still supports encrypted SMS.

To save money, battery and potentially protect weird apps trying to abuse the use of internet on background. Have heard and seen so many justifications for it. Barely know people that have internet 100% of time on. Somewhere in Europe ;)

Re: I don't trust Signal

#449

Earlier quoted context omitted.

google, facebook, whats app, microsoft. Basically the companies that pay for signal end to end encryption in their chat apps. There are, I'm sure, apps that are better, and that's never been moxie's goal. He's said it over and over that he'd rather have encryption for the masses than the perfect messaging app. It seems disingenuous to assume that he's acting in bad faith when he's clearly doing exactly what he said h…

Pushing an app out to F-Droid is trivial. There is literally no defense for only using Google Play and unsigned binaries on his own website.

Build the code yourself

Re: I don't trust Signal

#450
post #299

Earlier quoted context omitted.

It seems pretty odd to me to distrust someone because they aren't using the platform that you'd like them to use. Aren't there other issues with f-droid? You have to root your device to run it, allow third party code. Those are all security concerns too. It was posted elsewhere but here's Moxie's take: https://github.com/signalapp/Signal-Android/issues/127#issue...

> It seems pretty odd to me to distrust someone because they ... ... are using a platform "you" don't trust. Really? That's not really odd. At least, it's not odd, if that usage and what it entails is the denominating part of the persona in this question.

The application uses google play, which almost every other android application in the world uses by default. And somehow that makes them untrustworthy?
Post reply on HN