Live data from Hacker News

A Statement on Recent Events Between Signal and the Anti-Censorship Community

github.com

51–60 of 290 posts

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#51
post #28
post #25

Earlier quoted context omitted.

> Sometimes I really wonder the motives and identities behind the people causing such massive and unnecessary drama In this case, it's pretty boring. They are just a group of "your average power users" or "wannabe programmers" in their highschool or junior years who happened to be born in China so had some exposure to anti-censorship. Being in their overconfident period of life, they pass by various myth they don't r…

I've seen a growing number of anti-Signal posts and activism lately, mostly surrounding the (well-documented) design tradeoffs that Signal makes for usability and privacy (such as opting to use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers), or their famous decision not to federate/interoperate. Perhaps it's just criticism growing in lockstep with Signal's overall…

One major reason for the push back against Signal promotion is that it does not represent any sort of federated protocol. It is a complete silo. So if it did become popular it would eventually be a serious problem and would need to be fought against.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#52
post #31

Moxie - and the Signal team - seems to have a real issue taking feedback from outside experts. See the way he has been completely dismissive of the IME vulnerability highlighted by Naomi Wu and others. I remember back when it was TextSecure - I tried to raise some usability and security issues. First I was ignored, then dismissed, then - a few years later - they implemented some of the changes. I still use Signal. Bu…

What should Signal do about "the IME vulnerability"? They can't possibly defend against compromised phones.

Why call it "the IME vulnerability" anyway? This isn't about a vulnerability, we're discussing compromised phones. "IME vulnerability" seems designed to make this sound like a Signal issue, which it isn't.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#53
post #21
post #8

It seems that a couple of security researchers from this community felt that Signal's implementation of a TLS-in-TLS proxy to allow its use in censored Iran didn't live up to their standards (it can be detected by censors and blocked). However, after Signal rejected this issue, they turned toxic and were prevented from posting anymore [1]. The above post is their reaction, which feels more like them lashing out rathe…

It's more important how we all feel about each other and our drama than the fact there isn't a currently easily available obvious way to have private secure conversations. Your "they are not being constructive enough" is actually very unconstructive, because it drags the conversation into more drama. The tone is not more important than the facts. It never is. Im not suggesting you have some alternative motive to defl…

Tone can often be more important than facts.

At one point in my career I had a somewhat public facing role. I made a tough decision that aggravated a user, who decided to send me several death threats. Suddenly that tough decision wasn’t so tough anymore. Any possible resolution was gone.

These situations involve people. We aren’t fact machines.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#54
post #3

As I wrote in a comment[1] in their other attention-seeking post[2], they keep talking about "risks" and "vulnerability". There's no exploit or vulnerability here (despite their use of the "PoC" and "responsible disclosure" terms that apply to such things). The fact that you can detect a Signal proxy as a Signal proxy isn't a vulnerability; if it gets censored you're no worse off than you were if that proxy didn't ex…

> The fact that you can detect a Signal proxy as a Signal proxy isn't a vulnerability; if it gets censored you're no worse off than you were if that proxy didn't exist: the main Signal servers are censored in Iran already. Indeed, this is the Signal circumvention proxy working precisely as designed.

There is more risk than just "if it gets censored". If the proxy can be detected, so can users of that proxy. If users of a proxy can be detected, they can be punished for that.

To what extend this actually happens, I am not sure of. So the severity of this vulnerability is unclear to me. What is clear, is that this is a vulnerability. Circumventing blocks tends to be illegal. If we want to help people circumvent such blocks, we need to help them from being caught as well. After all, we want to help against the blocks because we believe the blocks to be immoral.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#55

What interests me more, is Signal's principal stance about censorship. If non-tech people ever come to Signal in numbers, the moderation problem will inevitably arise. Would they censor things that we currently have public consensus about? Like CP, terrorism etc.

I doubt that this will ever be an issue, because Signal is a messaging application, on which censoring/moderation is thus irrelevant. It's not a social network (contrary to e.g. Telegram which has tons of SNS features). Let's hope it will remain just a messaging/videocall app.

They would have no other choice but add group and social features. That's what non-tech people come for.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#56
post #28

Earlier quoted context omitted.

I've seen a growing number of anti-Signal posts and activism lately, mostly surrounding the (well-documented) design tradeoffs that Signal makes for usability and privacy (such as opting to use phone numbers for usernames, to avoid having to store contact lists/social graphs on Signal servers), or their famous decision not to federate/interoperate. Perhaps it's just criticism growing in lockstep with Signal's overall…

One major reason for the push back against Signal promotion is that it does not represent any sort of federated protocol. It is a complete silo. So if it did become popular it would eventually be a serious problem and would need to be fought against.

That isn't a reason to push against Signal, it is a reason to push for a federated solution.

Not your point, but federation is often heralded as some must-have feature for communication around here, but we already have that: XMPP does that, even with encryption. Or Email with PGP. Or even the old Textsecure code, as Signal/Textsecure started out federated, but, surprise, that didn't help adoption.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#57
post #45
post #13

Earlier quoted context omitted.

What could have been the more productive way? If their issues are closed (and Signal does not seem interested in discussing this) and they feel like this is actively putting peoples lives in danger I feel they should call this out.

Start their own app that's better. The fork option is there and always has been.

It would take years of effort and years of time to get people to switch to $BetterSignal. It is a last resort.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#58

Earlier quoted context omitted.

I doubt that this will ever be an issue, because Signal is a messaging application, on which censoring/moderation is thus irrelevant. It's not a social network (contrary to e.g. Telegram which has tons of SNS features). Let's hope it will remain just a messaging/videocall app.

They would have no other choice but add group and social features. That's what non-tech people come for.

Group feature is already present and is a different thing than Telegram's channels or Facebook's groups.

On Signal it is a group of your contacts, so it remains private conversation.

There is nothing publicly said, and it is not open for strangers to participate.

I don't see any compelling reason for Signal to evolve towards more SNSish groups, to the contrary, by remaining in the current state they avoid the costly conundrum of moderation.

> That's what non-tech people come for.

I disagree, people come to Signal for what it is. Arguably even more people would come if there was SNS features, but on the business/feasibility aspect (Signal is still an open-source based modest-size project), it would not be worth the cost and endless legal trouble of moderation in all the different countries with all the different laws.

Most importantly, introducing SNS would entail moderation which would fail the very purpose of Signal's existence (since the contents of the messages is ciphered and private).

In the end, actually less people would maybe come to Signal if it launched SNS features.

Re: A Statement on Recent Events Between Signal and the Anti-Censorship Community

#60
post #52
post #31

Moxie - and the Signal team - seems to have a real issue taking feedback from outside experts. See the way he has been completely dismissive of the IME vulnerability highlighted by Naomi Wu and others. I remember back when it was TextSecure - I tried to raise some usability and security issues. First I was ignored, then dismissed, then - a few years later - they implemented some of the changes. I still use Signal. Bu…

What should Signal do about "the IME vulnerability"? They can't possibly defend against compromised phones. Why call it "the IME vulnerability" anyway? This isn't about a vulnerability, we're discussing compromised phones. "IME vulnerability" seems designed to make this sound like a Signal issue, which it isn't.

There are two practical options.

1. Bundle an Open source IME to be used when in incognito mode. 2. Warn users when they switch to incognito that their IME may still be recording the words they type.

This isn't just about compromised phones. A 3rd party keyboard doesn't have to respect the incognito flag.

Post reply on HN