Live data from Hacker News

Why I won't recommend Signal anymore

sandervenema.ch

51–60 of 350 posts

Re: Why I won't recommend Signal anymore

#52
post #51

Signal is a honeypot, it was marketed as anti-mass surveillance, but depends on freaking Google for even functioning.

Even if you knew what you were talking about here, you can't make accusations like this on HN. You've been here for over 3 years now, and should know better.

Re: Why I won't recommend Signal anymore

#53

Can't wait for moxie to jump into the commentary. :) >Lack of federation Moxie's pissy because he trusted the kangbangers at Cyanogenmod to to keep in sync with his development. They didn't. Someone will need to volunteer to run their own server that's kept updated, then buy Moxie a Snickers and hope he stops being moody. >Dependency on Google Cloud Messaging Fun fact: The iOS client doesn't use GCM, it uses Pushkit.…

Layoff the personalised attacks on the psychology of someone who has helped increase the security of hundreds of millions of people for free, on basically a shoestring. Making pro/against arguments about Signal is fine but Moxie is genuinely a nice person (as are the rest of the former and current OWS team), so let's keep the argument civil.

Re: Why I won't recommend Signal anymore

#54
> Another issue, and a plus for using usernames, is that you may want to use Signal with people you don’t necessarily want to give your phone number to.

So, how do you know that the Edward.Snowden@signal you're communicating with is the same Ed Snowden that we all know about, and not some TLA stooge?

Re: Why I won't recommend Signal anymore

#55

I highly recommend Conversations (disclaimer: I've worked on it in the past, although I'm not a project "member" per say): https://conversations.im/ It's open source, uses a federated, open protocol, and can do multiple types of encryption including OTR and OMEMO (an XMPP wire format that uses the Axolotl ratched devised for signal). It does not do VoIP, so it would just be for chat (although there is a large bounty…

Conversations is great, but there's nothing comparable on iOS except Chatsecure which isn't yet beta quality. Then you need to pair it with a server that actually has all the recent XEP's installed (for push is XEP357, usually missing), see: https://gultsch.de/compliance_ranked.html

My current 'solution' is to use ZNC connected to Bitlbee (supporting OTR). On Bitlbee I use the jabber.fr service. ZNC has a push script for Mutter (great iOS IRC client) that I modified to redact my notification content from Apple's push service. I connect to the ZNC with TLS, so in theory everything should be ok.

NOT USER FRIENDLY but allows me to keep all my chats in one client and not tied to some shitty walled garden. Everyone less savvy I just tell them to use Signal.

Re: Why I won't recommend Signal anymore

#56

Can't wait for moxie to jump into the commentary. :) >Lack of federation Moxie's pissy because he trusted the kangbangers at Cyanogenmod to to keep in sync with his development. They didn't. Someone will need to volunteer to run their own server that's kept updated, then buy Moxie a Snickers and hope he stops being moody. >Dependency on Google Cloud Messaging Fun fact: The iOS client doesn't use GCM, it uses Pushkit.…

Layoff the personalised attacks on the psychology of someone who has helped increase the security of hundreds of millions of people for free, on basically a shoestring. Making pro/against arguments about Signal is fine but Moxie is genuinely a nice person (as are the rest of the former and current OWS team), so let's keep the argument civil.

I actually insulted the Cyanogenmod team and I think it's funny you missed that.

I don't have an issue with Moxie except that he's been pissy over this and a few other issues. I don't think anyone is going to argue that he isn't. Why not check the first link to the Libresignal thread and read his comments on the topic?

(EDIT: I get the downvotes on this comment, but like Moxie, I too am seriously annoyed that Cyanogenmod dropped the ball so bad with them. Moxie would need to get over it if there's a new solution in the future and HE ALREADY VOICED HIS OPINION THAT FEDERATION IS UNLIKELY. If that's not being pissy, I don't know what else is. I used to run Libresignal on BB10 and now I can't because of this policy of being anti-federation and no work moving forward on websockets fallback. He'll likely say no to approving the fallback on Replicant/Sailfish/BB10 because he doesn't get version reporting through analytics and is concerned about disturbances of the signal server.)

Re: Why I won't recommend Signal anymore

#57

I highly recommend Conversations (disclaimer: I've worked on it in the past, although I'm not a project "member" per say): https://conversations.im/ It's open source, uses a federated, open protocol, and can do multiple types of encryption including OTR and OMEMO (an XMPP wire format that uses the Axolotl ratched devised for signal). It does not do VoIP, so it would just be for chat (although there is a large bounty…

I tried Conversations but I couldn't for the life of me get message history to work. There's just so much stuff you have to do when it comes to XMPP to get things working. Perhaps if I used someone else's server it wouldn't be a problem but I'd prefer not to do that.

Re: Why I won't recommend Signal anymore

#58

Like a lot of crypto-puritanism it is rather mixed up. He says he recommended Signal because it was easy to use (more consumer friendly I guess) and secure, then says he wouldn't have gone in the direction of making it easier to use and criticises the things that make it user friendly, like using phone numbers instead of usernames. He says he thinks the protocol is secure, then says he doesn't want it to use GCM beca…

There is a coherent argument which you just refuse to see.

Signal was marketed as anti mass surveillance secure messaging system. It is but a mere user friendly email+gpg alternative. It actively avoid anti-mass surveillance methods and does the opposite - encourages centralization and collection of user statistics.

Even Telegram is better, as people arent fooled by what it is.

A better alternative is Ring.cx or Tox.im with for example Antox client.

Re: Why I won't recommend Signal anymore

#59
post #31

Earlier quoted context omitted.

Kind of tangential, but GCM is deprecated and you're supposed to use Firebase Cloud Messaging now: https://firebase.google.com/docs/cloud-messaging/ It's still just a JAR (no native components), so AFAICT there's no technical reason someone else couldn't do a similar thing with their own servers.

> It's just a JAR (no native components) I’ve reversed it, and rebuilt an alternative The jar you include actually opens just an IPC channel to the Google Play Services framework, which runs with system permissions, and handles the actual stuff. You can’t implement your own FCM without having root access on EVERY Android phone out there.

Maybe not. Although there's this guy: https://eladnava.com/pushy-a-new-alternative-to-google-cloud..., it seems like his library doesn't work very well after Nougat.

Re: Why I won't recommend Signal anymore

#60

> Another issue, and a plus for using usernames, is that you may want to use Signal with people you don’t necessarily want to give your phone number to. So, how do you know that the Edward.Snowden@signal you're communicating with is the same Ed Snowden that we all know about, and not some TLA stooge?

You're missing the point. Neither Phone number of Email address/username solve the problem you're proposing. But an email address/username is a lot more transient than a phone number.

I can change emails/usernames very easily and with little effort, and while burner numbers and applications that help that exist, changing phone numbers is not as easy and thus a significant percentage of users are unlikely to do it regularly. So you have a pseudo real ID that to the end user FEELS like it isn't you, but is a very strong (no pun intended) signal that it is to anyone looking in.

The phone number grants no you special verification of identity over an email address that doesn't involve an external verification mechanism (i.e, talking to the identity in person.)

Post reply on HN