The line about F-Droid doing no automated scanning is particularly troubling. Since he can't possibly imply that a Signal compromise would be detected this way, Moxie is making a political argument against the way people are using F-Droid to install other applications . He refuses - on principle, no less - the right for users to control their hardware and have full control over the software they install, and thinks t…
Does F-Droid support reproducible builds now? Or does it offer any other kind of assurance that the software downloaded actually comes from the purported origin?
I don't trust Signal
61–70 of 473 posts
Re: I don't trust Signal
#62Re: I don't trust Signal
#63Earlier quoted context omitted.
If Open Whisper Systems had received a national security letter requiring them to collect more information and keep it secret that they were doing so, how would you expect them to have responded to that subpoena?
NSL can't require to collect new business records. They can only compel you to disclose business records that you already have. This is beyond the legal authority of an NSL.
Re: I don't trust Signal
#64I don't know anything about Moxie derailing threads or anything like that but if we just listened to critics all the time then we just wouldn't have anything. Signal is better than a lot of what is out there and being used as scale and that counts for something. More secure is always better than not secure at all.
Read the end of an article as well. We have solutions like Matrix, and like XMPP with OMEMO.
Re: I don't trust Signal
#65Earlier quoted context omitted.
A Matrix server can force E2E on all messages passing it?
https://blog.cryptoaustralia.org.au/2017/03/21/run-your-end-...
Re: I don't trust Signal
#66>Google Play use yalp store > Packages on F-Droid are reviewed by a human being and are cryptographically signed >The app has to update itself, using a similarly insecure mechanism. F-Droid handles updates and actually signs their packages so are all android APKs. granted it's trust on first use: it accepts any signature for the first install, and only enforces the signature if you try to install an update. >A checks…
Re: I don't trust Signal
#67Earlier quoted context omitted.
NSL can't require to collect new business records. They can only compel you to disclose business records that you already have. This is beyond the legal authority of an NSL.
I’m pretty sure that isn’t true. They can be used to compel you to build interception capabilities.
Re: I don't trust Signal
#68> P.S. If you’re looking for good alternatives to Signal, I can recommend Matrix. Yes, if you're looking for alternatives to Signal, you should totally use a solution that hasn't rolled out end-to-end encryption by default[0]. /s ...and that only two clients have implemented so far, out of 50ish that they list on their website. [0] https://matrix.org/docs/guides/faq.html#what-is-the-status-o...
Author here, this is a fair criticism. Other alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring (not an endorsement of any of these). I'm an old curmodgen who just uses IRC+OTR and GPG, though, so I have to depend on others for recommendations. Also, Matrix enables end-to-end encryption by default on clients that support it.
Re: I don't trust Signal
#69But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…
The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.)
I admire Wire for a number of reasons, but certainly FOSS'ing all their code is one the main reasons. (The other is... Haskell! And also Rust.)
And just to point out, not only Wire bug-fixed the library implementation of the Signal protocol, as they use the Signal protocol. And their web interface is very good!
Oh, yes... And they are not based in USA.
EDIT: I am not affiliated with Wire, but just a happy customer. :)
Re: I don't trust Signal
#70> P.S. If you’re looking for good alternatives to Signal, I can recommend Matrix. Yes, if you're looking for alternatives to Signal, you should totally use a solution that hasn't rolled out end-to-end encryption by default[0]. /s ...and that only two clients have implemented so far, out of 50ish that they list on their website. [0] https://matrix.org/docs/guides/faq.html#what-is-the-status-o...
Author here, this is a fair criticism. Other alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring (not an endorsement of any of these). I'm an old curmodgen who just uses IRC+OTR and GPG, though, so I have to depend on others for recommendations. Also, Matrix enables end-to-end encryption by default on clients that support it.