Live data from Hacker News

I don't trust Signal

drewdevault.com

61–70 of 473 posts

Re: I don't trust Signal

#61
post #46

The line about F-Droid doing no automated scanning is particularly troubling. Since he can't possibly imply that a Signal compromise would be detected this way, Moxie is making a political argument against the way people are using F-Droid to install other applications . He refuses - on principle, no less - the right for users to control their hardware and have full control over the software they install, and thinks t…

Does F-Droid support reproducible builds now? Or does it offer any other kind of assurance that the software downloaded actually comes from the purported origin?

Yes, they only publish the signed binaries produced from public sources according to a recipe anyone should be able to follow.

https://f-droid.org/en/docs/Reproducible_Builds/

Re: I don't trust Signal

#62
I have recently switched to Riot (built atop Marix, which the author endorses at the end) for some family communications and yeah, I think I do prefer it to Signal.

Re: I don't trust Signal

#63
post #41
post #26

Earlier quoted context omitted.

If Open Whisper Systems had received a national security letter requiring them to collect more information and keep it secret that they were doing so, how would you expect them to have responded to that subpoena?

NSL can't require to collect new business records. They can only compel you to disclose business records that you already have. This is beyond the legal authority of an NSL.

I’m pretty sure that isn’t true. They can be used to compel you to build interception capabilities.

Re: I don't trust Signal

#64
post #49
post #38

I don't know anything about Moxie derailing threads or anything like that but if we just listened to critics all the time then we just wouldn't have anything. Signal is better than a lot of what is out there and being used as scale and that counts for something. More secure is always better than not secure at all.

Read the end of an article as well. We have solutions like Matrix, and like XMPP with OMEMO.

Signal did what those things failed to do which is to actually gain some popularity outside of HN. I hope Matrix takes off! In the meantime if people are convincing their families and friends to get on Signal then that's a net positive to me.

Re: I don't trust Signal

#65
post #57
post #51

Earlier quoted context omitted.

A Matrix server can force E2E on all messages passing it?

https://blog.cryptoaustralia.org.au/2017/03/21/run-your-end-...

That looks like a no given the article has a "Create a new secure room" section where you have to explicitly enable encryption for that specific room.

Re: I don't trust Signal

#66
post #27

>Google Play use yalp store > Packages on F-Droid are reviewed by a human being and are cryptographically signed >The app has to update itself, using a similarly insecure mechanism. F-Droid handles updates and actually signs their packages so are all android APKs. granted it's trust on first use: it accepts any signature for the first install, and only enforces the signature if you try to install an update. >A checks…

This doesn't even touch on the fact that Signal depends on Play Services. It has a websocket option, but the setting is actually not in the GUI

Re: I don't trust Signal

#67
post #41

Earlier quoted context omitted.

NSL can't require to collect new business records. They can only compel you to disclose business records that you already have. This is beyond the legal authority of an NSL.

I’m pretty sure that isn’t true. They can be used to compel you to build interception capabilities.

source?

Re: I don't trust Signal

#68
post #40

> P.S. If you’re looking for good alternatives to Signal, I can recommend Matrix. Yes, if you're looking for alternatives to Signal, you should totally use a solution that hasn't rolled out end-to-end encryption by default[0]. /s ...and that only two clients have implemented so far, out of 50ish that they list on their website. [0] https://matrix.org/docs/guides/faq.html#what-is-the-status-o...

Author here, this is a fair criticism. Other alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring (not an endorsement of any of these). I'm an old curmodgen who just uses IRC+OTR and GPG, though, so I have to depend on others for recommendations. Also, Matrix enables end-to-end encryption by default on clients that support it.

You suggest Telegram over Signal? Now we know you're spreading FUD.

Re: I don't trust Signal

#69

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

I am happy to see I am not the only person in the world that feels like this about Signal.

The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.)

I admire Wire for a number of reasons, but certainly FOSS'ing all their code is one the main reasons. (The other is... Haskell! And also Rust.)

And just to point out, not only Wire bug-fixed the library implementation of the Signal protocol, as they use the Signal protocol. And their web interface is very good!

Oh, yes... And they are not based in USA.

EDIT: I am not affiliated with Wire, but just a happy customer. :)

Re: I don't trust Signal

#70
post #40

> P.S. If you’re looking for good alternatives to Signal, I can recommend Matrix. Yes, if you're looking for alternatives to Signal, you should totally use a solution that hasn't rolled out end-to-end encryption by default[0]. /s ...and that only two clients have implemented so far, out of 50ish that they list on their website. [0] https://matrix.org/docs/guides/faq.html#what-is-the-status-o...

Author here, this is a fair criticism. Other alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring (not an endorsement of any of these). I'm an old curmodgen who just uses IRC+OTR and GPG, though, so I have to depend on others for recommendations. Also, Matrix enables end-to-end encryption by default on clients that support it.

Let's also not forget XMPP+OMEMO.
Post reply on HN