Live data from Hacker News

I don't trust Signal

drewdevault.com

91–100 of 473 posts

Re: I don't trust Signal

#91

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

I am happy to see I am not the only person in the world that feels like this about Signal. The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.) I admire Wire for a n…

> that's the unique instant messaging that has FOSS'ed both the server and the clients.

Signal's server code is open source as well: https://github.com/signalapp/Signal-Server

And apparently the client can verify that the server is running that code: https://signal.org/blog/private-contact-discovery/#trust-but...

Re: I don't trust Signal

#92
post #82

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

Is it even possible for the Signal servers to keep track of who you talk to, when, and how often? I was under the impression that those two data points they stored were the only thing they _could_ store, because the rest is sent to the servers encrypted. Edit: Yes, apparently they have a method of doing private contact discovery and, IIUC, even a method for the client to verify that the server is running the source c…

Signal has to be able to route messages from user a to user b through their centralized server, so at a minimum they are capable of logging "This user sent a message that we relayed to this other user".

Re: I don't trust Signal

#93
post #67

Earlier quoted context omitted.

I’m pretty sure that isn’t true. They can be used to compel you to build interception capabilities.

source?

It's complicated, but that's kinda what happened to the Lavabit "secure" webmail service. When the owner wouldn't install a backdoor, the FBI sought the private encryption keys so they could MITM the whole site.

https://www.newyorker.com/tech/elements/how-lavabit-melted-d...

Re: I don't trust Signal

#94

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

I am happy to see I am not the only person in the world that feels like this about Signal. The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.) I admire Wire for a n…

I was on Wire for a time and even got other people on board. Then the experience suddenly degraded out of nowhere. The desktop and web clients would never finish syncing. Some other stuff I don't remember. I really liked the app though.

I mean the unfortunate reality of chat programs is that there are so many that when I'm having weird problems I'm not gonna spend time opening issues on GitHub and sending logs; I'll just go back to what works. That's even more true for my non-technical friends.

Re: I don't trust Signal

#95
post #82

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

Is it even possible for the Signal servers to keep track of who you talk to, when, and how often? I was under the impression that those two data points they stored were the only thing they _could_ store, because the rest is sent to the servers encrypted. Edit: Yes, apparently they have a method of doing private contact discovery and, IIUC, even a method for the client to verify that the server is running the source c…

The signal server is responsible for doing the trust-on-first-use key exchange and letting you send offline messages to your counterparties. If your client could somehow be tricked into thinking that the other side was offline and you'd already sent them a large number of messages while they were offline, or that this was the first time you were talking to them, your client would leak a lot of metadata to the server. And given that the server is in charge of routing your messages to your counterparties, it seems like there's a lot of potential for a hostile server to trick the client in that way.

Theoretically it might be possible for a sufficiently paranoid client to cover all the bases. But it's certainly a huge attack surface.

Re: I don't trust Signal

#96
post #40

> P.S. If you’re looking for good alternatives to Signal, I can recommend Matrix. Yes, if you're looking for alternatives to Signal, you should totally use a solution that hasn't rolled out end-to-end encryption by default[0]. /s ...and that only two clients have implemented so far, out of 50ish that they list on their website. [0] https://matrix.org/docs/guides/faq.html#what-is-the-status-o...

Author here, this is a fair criticism. Other alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring (not an endorsement of any of these). I'm an old curmodgen who just uses IRC+OTR and GPG, though, so I have to depend on others for recommendations. Also, Matrix enables end-to-end encryption by default on clients that support it.

Why would you rely on others for recommending those, but not for Signal? Just don't recommend anything then, or don't criticise Signal. What's the point of convincing people to move to worse alternatives?

Re: I don't trust Signal

#97

But we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Mox…

I am happy to see I am not the only person in the world that feels like this about Signal. The interesting fact is that I "Ctrl+F" this page for Wire and I have seen nothing, even though this comment is about something that made me switch over Wire from Signal: to date, that's the unique instant messaging that has FOSS'ed both the server and the clients. (OK, the article also says about Matrix.) I admire Wire for a n…

An open-source server is certainly a step up from Signal, but since Wire doesn't support federation (either in their ToS or in practice) I'd favour Matrix.

Re: I don't trust Signal

#98

"The APK direct download doesn’t even accomplish the stated goal of “harm reduction”. The user has to manually verify the checksum, and figure out how to do it on a phone, no less. A checksum isn’t a signature, by the way - if your government- or workplace- or abusive-spouse-installed certificate authority gets in the way they can replace the APK and its checksum with whatever they want." This is true for just about…

And that's not even what Moxie meant by "harm reduction" - he meant that he wanted to stop people downloading APKs from random third parties, which has surely been pretty much accomplished.

Re: I don't trust Signal

#99
post #79

Earlier quoted context omitted.

That looks like a no given the article has a "Create a new secure room" section where you have to explicitly enable encryption for that specific room.

e2e, by nature, is client specific. So Matrix, as a connectivity glue protocol, has nothing to do with it. Synapse, the reference server, can handle rooms, and force encryption on the rooms. p2p is client side. Riot, as reference client, is the one that takes care of this, and, if I get everything right, it is on by default.

Regardless of the truth of your assertions, the article you provided as evidence does not support them. At no point does it demonstrate that a matrix server can force E2E on all communications, that synapse can be configured thus, or that riot can require that configuration.

Re: I don't trust Signal

#100
post #42

The article actually proposes an alternative: Matrix, and Matrix is, in fact, a good piece of software, with federation options. I tend to agree with most parts of the article, especially the lack of federation options. My real pain point with Signal is that there is no real desktop application for it - no, a connected web interface is not a desktop application. For example, XMPP with OMEMO can be used simultaneously…

What do you mean by a "connected" web interface? And what would being a desktop application bring it?

Signal Desktop is somewhat buggy, not that full-features, and doesn't integrate that well with the rest of my OS, but otherwise it's working fine, and I can use it simultaneously with my phone. (But I can also use it with my phone turned off, which I love.)

Post reply on HN