Live data from Hacker News

I don't trust Signal

drewdevault.com

71–80 of 473 posts

Re: I don't trust Signal

#71
> Off the bat, let me explain that I expect a tool which claims to be secure to actually be secure. I don’t view “but that makes it harder for the average person” as an acceptable excuse. If Edward Snowden and Bruce Schneier are going to spout the virtues of the app, I expect it to actually be secure when it matters - when vulnerable people using it to encrypt sensitive communications are targeted by smart and powerful adversaries.

I'm not so sure about this. I don't think Snowden and Schneier are praising it because it is the most secure application available that works for every threat model; I think they're doing it because it's the best attempt to up the security of the masses. In other words: there's a limit to its threat model. Signal makes it harder to do mass-scale surveillance, and allows e.g. whistle-blowers to contact journalists without standing out because they're using an encrypted messaging app.

Yes, it's important to highlight those trade-offs, and one can always do better, but as far as I can see Moxie has always justified the trade-off with arguments that were not based on being self-serving. You might not agree with his conclusions, but I think it's unfair to accuse him of being self-serving. (Unless you mean "thinking about the consequences for the success of Signal" by "self-serving". It's not really clear how it serves Moxie otherwise, and the author doesn't go into detail about that.)

In the end, I think it comes down to the author expecting different goals from Signal than the project itself has - as implied by his disdain for GIF search. Obviously Signal isn't only implementing features just to get more secure - it also wants to be widely adopted. It's just that the author apparently doesn't consider that as important.

Re: I don't trust Signal

#72
post #28

Is there a preference of Telegram over Signal or vice versa?

Apart from not being encrypted by default, Telegram uses its own homegrown crypto instead of a tried and tested one for its secret chat feature. That itself is a red flag.

Technically, Signal also uses homegrown crypto.

The difference here was it was endorsed by Moxie's acquaintances from the crypto circles, followed by a very loud and aggressive disparaging campaign against Telegram led by some of these people. I've been on metzdowd list for a very long time and while cryptographers aren't the chummiest people in the slightest, there's always an underlying mutual respect. The Telegram bashing was the first time I've ever seen geniuenly vicious behavior and hate displayed towards a project that not even remotely deserve it. Almost as if the goal was just to bury the competition.

Re: I don't trust Signal

#73
OWS's staunch refusal to permit anything other than phone numbers as identifiers should tell you everything you need to know about Signal.

It is an authenticated, nonrepudiable communications platform using identifiers that are very difficult (possible, yes, but most people will get it wrong) to comprehensively anonymize.

The ability to present nonrepudiable communications to a judge is precisely the wet dream of law enforcement officers, ambitious prosecutors, and despotic regimes everywhere. All they need to do is flip the people you're communicating with, and you're done.

Re: I don't trust Signal

#74
post #41
post #26

Earlier quoted context omitted.

If Open Whisper Systems had received a national security letter requiring them to collect more information and keep it secret that they were doing so, how would you expect them to have responded to that subpoena?

NSL can't require to collect new business records. They can only compel you to disclose business records that you already have. This is beyond the legal authority of an NSL.

> This is beyond the legal authority of an NSL.

If the legal authority can't be challenged in public, how are you so sure this legal authority hasn't been skirted plenty? In an opaque system, what they can and can't do is only theoretical. Only sometimes are things disclosed well after the fact and often only in aggregate (such as numbers about how many NSLs are greenlit). This is what the author means by no trust required. They can't be asked to subvert it, even via extralegal means.

Re: I don't trust Signal

#75
post #68

Earlier quoted context omitted.

Author here, this is a fair criticism. Other alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring (not an endorsement of any of these). I'm an old curmodgen who just uses IRC+OTR and GPG, though, so I have to depend on others for recommendations. Also, Matrix enables end-to-end encryption by default on clients that support it.

You suggest Telegram over Signal? Now we know you're spreading FUD.

I don't actually endorse any of the alternatives, just listing them. I haven't had time to research them in depth. I have worked with Tox before and I know some of the guys behind it, though, but I think it's dead in the water.

Re: I don't trust Signal

#76
post #59
post #12

[flagged]

I don't think that is a fair summary of this critique at all. The author has laid out specific, actionable items, such as putting Signal on F-Droid and allowing federation. Maybe he doesn't like Moxie, but it's not so simple as attacking his character. Instead, this is a reasonable summary of steps Signal can take to win his trust (or, to give him a true impression that he needn't trust it).

I think it's fair.

He accuses Moxie of being deceptive and insincere:

"It can be hard to distinguish these from genuine positions held by the person you’re talking to, but when it conveniently allows them to make self-serving plays, it’s a big red flag."

He then admits it's "a strong accusation". Later he dismisses Moxie's reasonable stance re: federation with "Moxie can write as many blog posts which appeal to wispy ideals and “moving ecosystems” as he wants".

That's not a reasonable critique, that's pure vitriol.

I would love to see federation in Signal, but I can understand why OWS decided otherwise. The author is not able to distinguish between "someone has weighed the issue differently than I would have" and "he's doing that for his own personal gain".

Re: I don't trust Signal

#77
Signal is not for state-proof encrypted communication. Not large states like the USA or Russia. If you think it is, you've been misinformed. For state actor proof communications you need to evaluate every action you take and think:

"What are the assumptions that I'm making here?"

One assumption is that you're not currently on anyone's radar. Are you willing to bet the entire enterprise on this assumption? How certain are you? Are you 99.999% certain?

Another assumption is that the operating system you are running the app in is not compromised on either end of the communication. 99.99%?

Another assumption is that the screen isn't viewable by other devices. Another assumption is that the frequency of your key taps aren't picked up by a mic and then turned into intelligible letters.

Another assumption is that the encryption algorithms you're utilizing haven't been subtly chosen to be intelligible to a single actor or that they'll stay secure once we have quantum computers.

Etc. Etc. Etc.

Signal is good because it raises the bar. Stock traders buying black information probably won't get your communications. They won't be scooped up in a email server leak. They wont be visible to your wife when she enters your phone's unlock code because they auto delete, and they don't get pushed to your iPad, like FB messenger[0].

But if you want to go up against James Bond, and you're already on his radar, you need to give up the illusion that anything computer related is fully trustable. Just pre-arrange some code words or OTPs and meet in person in an area without electronics or go even more old school and use dead drops with hand written communication.

[0] I personally know 3 people that were caught cheating this way.

Re: I don't trust Signal

#78
post #39

Some version of this post seems to circulate every few months or so. This one is more direct in its accusations of Moxie acting in bad faith. I think this is disingenuous. Moxie has been very clear[0] about the tradeoffs that Signal has made and the reasons for them. It's fine to be dissatisfied with those choices. It's another thing entirely to accuse Moxie of dissimulating. Personally, I'd like to see Signal replac…

Completely agree, I have had several people move from various chat apps and texting to Signal largely because of the iMessage like features. Ultimately, I am now able to have more secure discussions with largely non-technical users which is good for everyone.

Re: I don't trust Signal

#79
post #57

Earlier quoted context omitted.

https://blog.cryptoaustralia.org.au/2017/03/21/run-your-end-...

That looks like a no given the article has a "Create a new secure room" section where you have to explicitly enable encryption for that specific room.

e2e, by nature, is client specific. So Matrix, as a connectivity glue protocol, has nothing to do with it.

Synapse, the reference server, can handle rooms, and force encryption on the rooms.

p2p is client side. Riot, as reference client, is the one that takes care of this, and, if I get everything right, it is on by default.

Re: I don't trust Signal

#80
post #40

> P.S. If you’re looking for good alternatives to Signal, I can recommend Matrix. Yes, if you're looking for alternatives to Signal, you should totally use a solution that hasn't rolled out end-to-end encryption by default[0]. /s ...and that only two clients have implemented so far, out of 50ish that they list on their website. [0] https://matrix.org/docs/guides/faq.html#what-is-the-status-o...

Author here, this is a fair criticism. Other alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring (not an endorsement of any of these). I'm an old curmodgen who just uses IRC+OTR and GPG, though, so I have to depend on others for recommendations. Also, Matrix enables end-to-end encryption by default on clients that support it.

According to friends in the cryptography space and from a cursory reading of wikipedia, Telegram is a shitshow compared to Signal.

It's one thing not to trust Signal. It's another to recommend alternatives that are far worse.

Post reply on HN