47 ms·
Why I won't recommend Signal anymore
- kingad 10y agoWhat are your views about VoIP with ZRTP?
- mtmail 10y agoThat's unrelated (off-topic) to Signal and what the blog post discusses, isn't it?
- fragmede 10y agoThough it wasn't explicitly mentioned in the blog post, Signal does support encrypted voice calls, so GP post isn't entirely off topic.
- fegu 10y agoNobody actually exchanges the initial words to avoid mitm. Hence, zrtp is actually no that secure in practice.
- draw_down 10y ago> The big question now... is what post-Signal tool we want to use. I don’t know the answer to that question yet Oh.
- wtbob 10y agoI am also very unhappy with the direction Signal has gone, but there's currently no alternative. I'd be interested in contributing to work attempting to replicate it, though.
- gst 10y agoWhy isn't there an alternative? Signal uses the Axolotl protocol for encryption. There are already several XMPP clients that support the OMEMO protocol which is based on Axolotl (https://conversations.im/omemo/ https://conversations.im/omemo/). And for Matrix (a modern alternative to XMPP) there's Olm which is also based on Axolotl.
- SamWhited 10y agoAt the risk of derailing this slightly, I wouldn't call Matrix a "modern alternative" to XMPP. The use cases are almost entirely different; Matrix isn't really suitable for realtime applications like XMPP is (because Matrix is all pull-based, so you have to query the server constantly to try and get messages in a reasonable time; this also means keeping the phone radio in active, high-battery-drain mode [pretty sure that's the technical term]). Disclaimer: I do a lot of work on XMPP related things and rather like the protocol, so maybe I'm biased. I'm sure there are things for which Matrix is a better fit that I wouldn't use XMPP for too though.
- Arathorn 10y agoAgreed that Matrix isn't a "modern alternative" to XMPP, but for different reasons. At its core, Matrix is a decentralised object database for conversation history (like NNTP). XMPP is a message passing protocol (like SMTP, but extensible). Matrix is not "all pull-based" - that's just the baseline implementation. Folks have already implemented push-based transports for Matrix - e.g. COAP or WS. edit: [Disclaimer: i work on Matrix]
- tptacek 10y agoYou mean the Signal Protocol. That's its name. Axolotl was a name for a major component of Signal Protocol. Moxie and Trevor Perrin designed the protocol for Signal, and it's under active development. They own the protocol, its direction, and its documentation. Other projects can adopt parts of the Signal Protocol, and doing that is certainly better than just making stuff up. But Signal owns the protocol, because the experts who own the protocol are attached to Signal.
- Arathorn 10y agoYeah, just to clarify: Olm (matrix.org/git/olm) is an entirely independent implementation of the Double Ratchet algorithm (based on Trevor's original public domain spec sketch, which was originally called 'axolotl'). It's not connected to Signal or Signal Protocol or Open Whisper Systems, and subsequently we've added an entirely different new ratchet (Megolm - https://matrix.org/docs/spec/megolm.html https://matrix.org/docs/spec/megolm.html) to handle Matrix's specific requirements for E2E.
- zanny 10y agoI have some friends in an encrypted riot room right now. The olm could use a real good audit, but otherwise it is working right now. Federation is working, bridges are working, voice and video are working, it has Android and iOS clients. The only problem is the encryption doesn't apply to the voice / video or shared files yet, but they have made huge progress this last year from basically nothing so far.
- heavenlyhash 10y ago+1. I'm super happy with the Matrix / Riot ("riot" is the client) crypto work over the last year. It's such a relief to have a modern chat system that's FOSS, federates, and offers a liiiiitle more advanced UX than irc...
- Arathorn 10y agothe Olm audit is done; we're hoping to publish it week of Nov 14 (alongside iOS & Android support). Encrypted attachments was PRed this week: https://github.com/matrix-org/matrix-react-sdk/pull/533 https://github.com/matrix-org/matrix-react-sdk/pull/533 (for the web; mobile will follow shortly)
- SamWhited 10y agoI highly recommend Conversations (disclaimer: I've worked on it in the past, although I'm not a project "member" per say): https://conversations.im/ https://conversations.im/ It's open source, uses a federated, open protocol, and can do multiple types of encryption including OTR and OMEMO (an XMPP wire format that uses the Axolotl ratched devised for signal). It does not do VoIP, so it would just be for chat (although there is a large bounty on Jingle-based voip support open). It has also had a public security audit, and is designed to be white labeled so you can tweak a few variables in the source and build your own hardended version or encrypted-only version, etc.
- giancarlostoro 10y agoCurious for next time I evaluate XMPP is there a list of servers recommended by the Conversations team that people could install themselves? My issue with XMPP is that on the same system I have at DigitalOcean where I could run: an IRC server, a Web Server, and a Mumble Server and extra goodies all together in one box, I couldn't effectively run a XMPP server that would stay up (it would crash). I would of kept at XMPP had I found a decent memory efficient server that didn't merely crash.
- SamWhited 10y agoI'm a big fan of Prosody (prosody.im); even the nightlies (what I run) are remarkably stable, and the memory footprint is tiny (they have some metrics somewhere if you ask in the chat; I can't find them right away).
- darklajid 10y agoTHE xmpp server I'd recommend is prosody[1]. Lua based, quite active, very friendly community and easy to set up/configure. 1: http://prosody.im http://prosody.im
- majewsky 10y agoI have a virtual server (1 CPU + 1 GiB RAM) running nginx, murmur and Prosody. free(1) reports 80 MiB used memory, thereof 10 MiB for Prosody. (I just have one active account, though: myself.) So unless you're planning on hosting hundreds or thousands of users, you should be fine IMO.
- reacharavindh 10y agoThis. I didn't know much of the insides of Signal. But, When WhatsApp decide to go in bed with FB to share my contacts and usage, one of the alternatives I explored was Signal. Threw it out the moment it asked for ownership of my contacts (no way to opt out). I for one am not going to trust a guy's pinky promise to be good with my contacts and meta-data. If I'm going to give up the convenience of reaching anybody by WhatsApp, it is going to be at least worth it in the sense of privacy. Still hoping for a GNU project that garners enough interest to be technically strong, and used universally. One can dream.
- Joeboy 10y agoI doubt you'd want to use it if it didn't use your contacts, though. Not many people are prepared to deal with a whole separate set of contact ids for the sake of a small amount of arguable extra privacy.
- tdkl 10y agoWhat's wrong with having options ?
- reacharavindh 10y agoDiscoverability is complicated issue. If I want someone I don't know yet to reach me, I expect them to Google search my phone number/email to make initial contact. For those I already established initial contacts with, I'd like an account on a service that knows practically nothing about me other than my username(like coolkid654) and lets me send messages to others(coolkid655). Given the state of data leaks[data snooping by the Gov or anyone else], and spam, it wouldn't be a terrible idea for someone to have a username that they reveal to only the people they trust(are worth). More like a Blackberry key. If packaged well, and made to look 'cool', it could even catch on and everybody would create one(or many).
- resonanttoe 10y agoSure, most won't right. But clearly in this thread some people are willing to do that and I'm not convinced that there is a large burden/cost to signal to allow this. The problem for me is that my contact list of Signal users is quite small (1 or 2 people) and everyone else isn't using it. I don't see the reason to allow Signal access to that list of people "Just in case" they decide to. It's incredibly unlikely bordering on near impossible. This isn't the golden bullet of reasons that it should be this way, but the fact that in design Signal has made the choice to force access to contacts to me, says one of two things. 1. We haven't thought about cases outside of our own experience and expressly reject those as being outside of the market we're interested in. "You're not the user we're looking for." 2. There is value/commoditisation in that contact list that signal is interested in and this is the price to play in their system. The problem is that either of these two options run pretty counter to the idea of secure privacy focused messaging client designed to be seperate from the user. People's value of privacy is nuanced enough that making broad scoped decisions like this can run afoul of their expectations. Considering that Signal is aiming itself at the privacy conscious (Over-conscious in a lot of instances I'm sure), it's very weird that they would forgo this obvious affordance of information.
- clumsysmurf 10y agoUnfortunately, Google has made it (almost) impossible to wake up the phone via some external event without using its proprietary GCM. Even though GCM is not part of AOSP, it has unique status on the platform that can't easily be replicated (without recompiling the kernel, etc like the article mentions). Before the days of doze mode & other battery optimizations, you could just listen & block on a socket, then let the phone go to sleep. Incoming 3G packets would wake up the phone, you grab a wakelock, then start doing things. From what I remember, at least a while ago Facebook Messenger did this using MQTT. But this is not possible any more.
- chimeracoder 10y ago> Before the days of doze mode & other battery optimizations, you could just listen & block on a socket, then let the phone go to sleep. Incoming 3G packets would wake up the phone, you grab a wakelock, then start doing things. From what I remember, at least a while ago Facebook Messenger did this using MQTT. But this is not possible any more. It's not a coincidence that the Facebook app was known for being an absolute battery killer. Go to any android forum post about battery life from a year or more ago and you'll see that the first suggestion is always "have you tried removing Facebook?"
- Mathnerd314 10y agoKind of tangential, but GCM is deprecated and you're supposed to use Firebase Cloud Messaging now: https://firebase.google.com/docs/cloud-messaging/ https://firebase.google.com/docs/cloud-messaging/ It's still just a JAR (no native components), so AFAICT there's no technical reason someone else couldn't do a similar thing with their own servers.
- qwertyuiop924 10y agoThere are several projects moving toward this. Matrix is probably the most well-known project, but its crypto isn't actually operational yet, AFAIK. Tox works now, but for all their talk of trying to be user-friendly, asking users to exchange long alphanumeric sequences inherently isn't. Psyc, maybe?
- SamWhited 10y agoMatrix's protocol design is terrible for realtime messaging though (I'm sure there are other uses for which it's more adept); it's effectively a giant, inefficient, JSON datastore that syncs data everywhere. It's also pull based so it consumes battery like crazy. If that's what you need, fine, but for realtime messaging I'd argue that it's really unacceptable.
- qwertyuiop924 10y agoOkay. Tox, anybody?
- SamWhited 10y agoI haven't looked into Tox, but I'd be curious to find out the highlights. Really I've just never understood why people complain about XMPP; yes, it's XML which is ugly, but it's also the right tool for the job (easy to stream, very fast SAX-style parsers, event based, etc.), it certainly has its warts, I won't pretend it's perfect, but for the most part it's been around for 20+ years getting the kinks worked out. If we just keep creating new protocols because it's not perfect, we'll never get a more or less universally federated chat protocol like we have for more long form messages (email). I don't know anyone who would say email was the most wonderful modern thing in the world, but they still use it because it's good enough and was lucky enough to become ubiquitous. Similarly, I feel like people should just use XMPP even if they don't like it for that reason (although I'd still love to find out more about Tox, what it's strengths and weaknesses are, etc.)
- qwertyuiop924 10y ago
- empath75 10y agoAny service that owns valuable user data is going to get compromised eventually, whether they do it themselves, or are the victims of an attack. I feel like the only way to not get swept up in the surveillance state is to never put your data on one of these services at all.
- raverbashing 10y ago- Lack of federation Use a federated secure protocol. Oh wait, there are none. Because if a problem appears you just can't fix it without breaking all federated clients. And then they will whine. - Dependency on Google Cloud Messaging Fair enough - Your contact list is not private Fair enough - The RedPhone server is not open-source While it would be nice that it was Open sourced I can understand them not releasing it (might be for IP issues) tl,dr: "Signal does not work the way I wanted"
- SamWhited 10y ago> Use a federated secure protocol. Oh wait, there are none. Because if a problem appears you just can't fix it without breaking all federated clients. And then they will whine. That's why you have to design your protocol with backwards compatibility and versioning in mind, ala XMPP. I'm not going to pretend its perfect, but it works pretty well 90% of the time. It does mean clients have to implement versioning and feature negotiation and not just blindly assume everything else supports all the features they do; convincing client authors to do this is the tricky part.
- nickik 10y agoThere are really two federated protocols, xmpp and matrix. Matrix is pretty young but looks good, they just added e2e encryption. Check out the Riot client, web, android and ios. The apps are even native. Plus, you don't have to show your phone nr.
- antocv 10y agoRing.cx and tox.im work better. Signal is a honeypot by NSA/Google and the likes.
- qwertyuiop924 10y agoUmm... Tox?
- exo762 10y agoTox on mobile? Have you actually tried to use it? It drains your battery like crazy.
- walterbell 10y agoWire (http://wire.com http://wire.com) has worked well on iOS for encrypted text/files/audio/video. Open-source client, no contact sharing neeeded. No phone number needed, you can register with email by using a desktop browser at http://app.wire.com http://app.wire.com, then logging into the mobile app. Group chat for text only. Timed/ephemeral messages for 1:1 text/files. Feature matrix, https://wire.com/privacy/ https://wire.com/privacy/. Could use more documentation (e.g. on retention of encrypted data) but a lot of questions are answered on Twitter or Github issues.
- tdkl 10y ago> Don't know whether it needs GCM on Android. The .apk on the site uses websocket, no GCM required.
- Siimteller 10y agoTimed coming to groups in couple of weeks. Documentation is also getting a refresh in 2 weeks.
- heavenlyhash 10y agoEDIT: this isn't a response to most of the article, but specifically to the "Moving Forward" section, asking about alternative tools. Come to the matrix! https://matrix.org/ https://matrix.org/ It's free -- all FOSS, including the entirety of the server -- and yes, all of it: proof by existence: several of my friends run their own. It federates. I regularly join channels hosted on several different servers, and exchange messages without issue. It's on every platform. I use it on the desktop, my android (cyanogen, without gapps, none the less!), and my ipad, every day. It even has voice and video calling built in, using webRTC. This feature has been a little rough while it was in development, but I used it last week in a 1-on-1 call and had an effortless experience. The audio and video quality was on par with Google Hangouts. Crypto is hard, but it's coming. The Matrix developers have huge respect for the axolotl ratchet design used in Signal. They've worked on making another implementation (in C, for easier linking in various languages, ostensibly) here: https://matrix.org/git/olm/ https://matrix.org/git/olm/ The deployment of that code to give full End-to-End encryption is a work in progress, but the beta is roughly functional. It includes everything you'd expect: communication works by default, but in an encrypted room, messages are flagged yellow if you haven't explicitly verified the sender's key. There's a key per device; it doesn't leave the device; and as soon as you verify that device/key, messages from it are green, and you're E2E secure. Disclaimer: I have no direct association -- I became a Matrix convert after trying to write some XMPP client code about a year ago. I'm just really enthusiastic about recommending it because the tech is solid, the sync is good, it solves a problem, and the team hasn't stopped either: they been firing on all cylinders constantly since I started using Matrix. I love Signal for their dedication to getting encryption right and the security of their users. But yes, I also share a lot of the concerns listed in this article. Most of all, I honestly believe federation is an imperative. So, while acknowledging Signal's history of outstanding security work... Hey, let's celebrate there's more than one game in town working on alternatives.
- Veratyr 10y agoI'm also a Matrix convert. Tried getting Conversations + Prosody running for me and my wife but just couldn't get it to work properly. XMPP has so many XEPs (like MAM - XEP-0313) that you need to get things working nicely and there are very few clients (Conversations only afaik) that actually support them. We also found that Conversations just wouldn't send/receive messages sometimes and that when there was no connection, it'd pretend everything was fine and dandy but not actually send. Switched to Matrix and setting up my own homeserver took about half an hour, comes with everything I need (history, "Carbons", notifications, attachments, voice/video) built in. Plus it's federated and has support for bridges so I can interact with pretty much anything else through it if I like.
- SapphireSun 10y agoEssentially this guy is saying, Signal is secure, it's mostly easy to use (with the exception of multiple phone numbers), and the only alternative he mentioned is a half broken clone. Is he seriously going to stop recommending it to people whose lives depend on secure communications because of some abstruse ideological point? In any case, Moxie's position is a reasonable one even though there are some arguments for federation. While my current phone doesn't support Signal, once I get a new one I will continue to use it. You might opine that allowing Signal clones would allow me to use the app, but they would almost certainly be maintained by people who aren't really crypto experts, and so it's better to operate as though I am broadcasting in cleartext than to pretend that I'm not and get burned.
- kuschku 10y agoThe biggest argument is that there is little of a difference between Signal and Telegram or Signal and WhatsApp for the user if they are forced to use the official servers, and those servers get to store their entire social graph.
- SapphireSun 10y agoHere's what Moxie said about this issue: https://whispersystems.org/blog/contact-discovery/ https://whispersystems.org/blog/contact-discovery/
- wtbob 10y agoAnd here's my write-up of how a private set-intersection protocol could be used to enable users to securely swap contacts: https://news.ycombinator.com/item?id=11289223 https://news.ycombinator.com/item?id=11289223 It's a solved problem, but Signal doesn't implement it.
- bascule 10y agoThe protocol you describe is a synchronous online protocol where Alice and Bob have to be online at the same time (and if they're doing this at Charlie's behest, so does Charlie). Signal is designed for asynchronous communication where both participants don't have to be online to discover each other or send each other message. Also, how does this protocol even help? What's the use case? It allows participants to discover mutual contacts, but what then? Do we use Bob as a web-of-trust style introducer? What if Alice doesn't even want to talk to Charlie? Do we do this for all the friends Alice has in common with Bob? Do we do this for all the friends Alice has in common with everyone? Does Charlie initiate the process, only to have it only work if all three of them are online at the same time? Who kicks it off and why, and what would the user experience be? You end your last post with "So, problem solved" but I'm not sure this protocol even solves any practical problems for the Signal use case, and seems like a mere first step of solving a much more complicated problem of actually trying to turn this into a useful feature with good UX.
- codemac 10y agoSignal is to get people from SMS and iMessage -> Signal. This means that cross platform communication becomes secure in transit. Once Signal and others have really wiped out all the insecure messaging people are doing, then we can start with the identity problem with phone numbers. GCM, Contacts, etc are all related to this "phone number as identity" problem. RCS is an unfortunate grab in this space, and we need to move fast before RCS is the default, and we're back to insecure messaging. Email addresses are the best form of "federated identification" but are wildly insecure for communication. Here's to hoping we can get some better ones.
- EugeneOZ 10y agoAny messenger, tied to phone number, is not safe. possible attacks are: 1) create copy of sim-card; 2) force mobile operator to intercept password-code, sent to your number, and "restore" password this way. It may sound ridiculous for you, but in Russia it's reality (both vectors), it's real cases from life. And when user really need safe messenger, all of them are too careless to implement really safe way of messaging. And if you think these vectors are not possible in your country - be sure, we were thinking the same way.
- trimbo 10y agoThis is why there is a fingerprint ("Safety Numbers" in Signal), and a warning on every message when that fingerprint changes.
- codedokode 10y agoWarning still does not fully prevent the attack. The attacker can still access the account and obtain the data stored at a server (like contact list if it is stored there).
- majewsky 10y ago> like contact list if it is stored there The only thing that we know they store is the creation timestamp and last-seen timestamp for each account: http://arstechnica.com/tech-policy/2016/10/fbi-demands-signal-user-data-but-theres-not-much-to-hand-over/ http://arstechnica.com/tech-policy/2016/10/fbi-demands-signa... Reading over the article again, though, it neither confirms nor denies where these timestamps are the only thing stored about an account. They explain these are the only data matching the concrete subpoena they received.
- deleted 10y ago[deleted]
- lawnchair_larry 10y agoWhich everyone, including myself, clicks through.
- nickik 10y agoI have started to read about matrix a lot. - It now supports e2e encryption. - It has a nice web and mobile client, called riot.im - I has many other client options - You don't need to show any phone numbers. - Federated, you can host your own server
- secfirstmd 10y agoI've trained hundreds of human rights defenders and journalists over the last 10 years and I will continue to recommend Signal. For too long the community has placed perfect security over usability - there are slightly more secure ways to communicate than Signal but they are far too disruptive to peoples work flows to actually be implemented.
- tptacek 10y agoThe author of this post believes that by making a stand over Signal policies he doesn't like (the superficial GCM dep, the OWS-only server policy, the contact list discovery system), something more like LibreSignal will grow to take Signal's place. The author is wrong. LibreSignal won't replace Signal. Something like Telegram will: an "open source" messaging system with inferior cryptography, "opt-in" end-to-end messaging, a long-term dependency on the telephone system for authentication, and a far "cuddlier" personality with its users and, more importantly, with people from the app development community (like the author). Telegram will continue to gain adoption, because sexy beats sound in every end-user match up. Signal is the closest thing sound cryptography has to a palatable solution for end users. Iran has already compromised Telegram users, because it systemically trades security off for user adoption. They'll get more of them, and people will hang from cranes as a result. It's not wrong to criticize Signal. Signal does things I don't love, too! But we should be clear-eyed about the market.
- venomsnake 10y agoJust a question - is Telegram secret chat after you verify keys still with inferior cryptography? And why?
- joecool1029 10y agohttps://news.ycombinator.com/item?id=10713064 https://news.ycombinator.com/item?id=10713064
- sandervenema 10y agoHi, author here. I don't think LibreSignal or indeed Signal will ever be the dominant mobile messenger out there. There's simply a lot of inertia to fight against. It's the same reason why it's hard to convince e.g. Facebook friends to move to a different social network, why Google+ failed, etc. Whenever the social aspect gets involved, companies can very easily create lock-in by being early, and then the social aspect will prevent the majority of people from considering changing, because 'it works'. I never said that LibreSignal will replace Signal, and frankly, LibreSignal itself is not the solution either. But maybe LibreSignal will be the catalyst to a better solution. We all want to prevent people hanging from cranes, but crypto alone does not equal privacy, does not keep you safe, especially not in those countries, where rubber hose cryptanalysis (https://xkcd.com/538/ https://xkcd.com/538/) is much more common. In those dangerous situations/countries, good operational security practices are better to avoid detection/suspicion than using any 'magic' crypto messaging app.
- zabuni 10y ago"Also, there’s the issue of integrity. Google is still cooperating with the NSA and other intelligence agencies. PRISM is also still a thing. I’m pretty sure that Google could serve a specially modified update or version of Signal to specific targets for surveillance, and they would be none the wiser that they installed malware on their phones." Isn't part of the reason that Moxie went with the Google Store is that he gets to sign the god damned binaries, making it impossible for Google to modify the app.
- antocv 10y agoGoogle has root on your phone. That is enough for them to replace any signatures, steal keys, replace apps without you knowing etc.
- majewsky 10y agoThis. If Google controlling your phone via a remote backdoor is part of your threat model, you better start shopping for a different operating system anyway. That's not an issue with any particular Android app, it's an issue with Android.
- sandervenema 10y agoHi, author here. Yes, my point with that sentence was that the average (non-technical) user (to which Signal is marketed btw), is not going to check signatures. Google has root on the phone, the user is using their app store to install the Signal app that comes up in the store, and basically Google has full control over this, and the user would be none the wiser. Of course, us more technical inclined people could then check the signature, or compare the apk with one built from the official sources, to see the difference and complain about it. But between those things is a time frame where this is possible.
- zigzigzag 10y agoDoes it, actually? I was under the impression that the Play Store doesn't run as root and the package manager API (controlled by the phone manufacturer) is what checks signatures. Can the Play Store override the signature checks on upgrade and if so, what codepaths is it using?
- zigzigzag 10y agoLike a lot of crypto-puritanism it is rather mixed up. He says he recommended Signal because it was easy to use (more consumer friendly I guess) and secure, then says he wouldn't have gone in the direction of making it easier to use and criticises the things that make it user friendly, like using phone numbers instead of usernames. He says he thinks the protocol is secure, then says he doesn't want it to use GCM because it routes messages via Google who he doesn't trust (fixing that is the point of the encryption) and then talks about an attack that'd apply to any app regardless of whether it used GCM or not. He finishes with a call to action: "We as a community need to come up with a viable solution and alternative to Signal that is easy to use and that does in fact respect people’s choices ... this tool should not have dependencies on corporate infrastructure" But like a lot of armchair moralising, he isn't willing to debate the hard choices that go into building successful software. He says it should "respect people's choices" as if Signal is built by people who are disrespectful, he says it should not have dependencies on "corporate infrastructure" as if volunteer run datacenters actually exist, and then says his motivation is avoided paywalls, ignoring that both Signal and WhatsApp are free. It reads like a collection of talking points rather than a coherent argument. Signal is unusual because it combines cutting edge cryptography with consumer friendliness and is actually successful. It's pragmatic, not ideological. Crypto-warriors have a long history of producing secure software that nobody uses and then blaming the general public for not getting it; this sort of blog post is just a continuation of this decades long trend.
- api 10y agoPeople need to get the fact that all traffic across the Internet traverses lots of people's systems. There is no difference between it relaying off Google vs Verizon, AT&T, Amazon, OVH, or dozens of other carriers and cloud providers. Like you say that is the point of end to end crypto.
- throwaway101416 10y agoThere is a difference, because these people in the middle don't have your contacts and don't have root on your phone.
- sctblol 10y agoHmm... he mentions the Giphy thing at the beginning of the article, then never again. The Giphy mention seemed really dangerous to me. Now I don't use Signal but I imagine it's 1) optional and 2) requests are proxified/anonimised through an intermediary (the Signal servers in this case). And why is this dangerous? Because this "don't build cool stuff on this serious app" is what makes people not use the app. It's creating boring, dull apps what stops them from becoming mainstream successes. If we are trying to make the public using secure apps because we believe in privacy, we have to make them appealing. This is similar to the case of how nobody uses PGP because how horribly bad it is, UX-wise. That said the rest of points he brings up are good. I just didn't like the Giphy mention, especially taking into account he didn't say anything else about it, he just brought it up.
- sandervenema 10y agoHi there! The Giphy thing is what set me off writing the blog post in the first place. Maybe I should've expanded a bit more on that in the article. As far as I can tell, the idea is that requests to the Giphy API gets proxied through Signal. I don't see anything in moxie's blog post about whether this is optional. If it isn't and it's sending everything you type to the Giphy API then we have a whole new problem. In the blogpost by moxie, there's the example of typing "Im excited", which then gets sent in multiple API requests to giphy (basically one of 'I', one of 'Im', one for 'Im+' etc.). Now, if this is an action you don't do explicitly (like pressing a button or something, to search for gifs), then it would basically send everything you type in order to continually search for gifs and then offer suggestions? It's not clear from the blogpost. I hope at least that this is not what moxie had in mind.
- sctblol 10y agoIt's not clear to me, but I assumed that that only happened if you tapped on a "search for gifs" button, which is something that can happen accidentally, but... that's unlikely.
- giancarlostoro 10y agoGiphy only occurs when you click on a button to add an attachment, and you have to click on Giphy, THEN you search for GIFs.
- joecool1029 10y agoCan't wait for moxie to jump into the commentary. :) >Lack of federation Moxie's pissy because he trusted the kangbangers at Cyanogenmod to to keep in sync with his development. They didn't. Someone will need to volunteer to run their own server that's kept updated, then buy Moxie a Snickers and hope he stops being moody. >Dependency on Google Cloud Messaging Fun fact: The iOS client doesn't use GCM, it uses Pushkit. GCM was chosen for Android because what else is as robust and doesn't eat battery? Moxie's voiced support of Websockets if someone implements it correctly and he can merge it as a fallback option when Play Services are missing. If you can't code and want it, contribute to the bounty on it: https://github.com/LibreSignal/LibreSignal/issues/37 https://github.com/LibreSignal/LibreSignal/issues/37 https://github.com/LibreSignal/LibreSignal/issues/43 https://github.com/LibreSignal/LibreSignal/issues/43 > Your contact list is not private https://whispersystems.org/blog/contact-discovery/ https://whispersystems.org/blog/contact-discovery/ TL;DR, it's a tradeoff because nobody has a better idea that works at scale and is usable. Redphone used to have a good way of blindly doing contact discovery but it would require too much data for their current userbase.
- secfirstmd 10y agoLayoff the personalised attacks on the psychology of someone who has helped increase the security of hundreds of millions of people for free, on basically a shoestring. Making pro/against arguments about Signal is fine but Moxie is genuinely a nice person (as are the rest of the former and current OWS team), so let's keep the argument civil.
- joecool1029 10y agoI actually insulted the Cyanogenmod team and I think it's funny you missed that. I don't have an issue with Moxie except that he's been pissy over this and a few other issues. I don't think anyone is going to argue that he isn't. Why not check the first link to the Libresignal thread and read his comments on the topic? (EDIT: I get the downvotes on this comment, but like Moxie, I too am seriously annoyed that Cyanogenmod dropped the ball so bad with them. Moxie would need to get over it if there's a new solution in the future and HE ALREADY VOICED HIS OPINION THAT FEDERATION IS UNLIKELY. If that's not being pissy, I don't know what else is. I used to run Libresignal on BB10 and now I can't because of this policy of being anti-federation and no work moving forward on websockets fallback. He'll likely say no to approving the fallback on Replicant/Sailfish/BB10 because he doesn't get version reporting through analytics and is concerned about disturbances of the signal server.)
- antocv 10y agoSignal is a honeypot, it was marketed as anti-mass surveillance, but depends on freaking Google for even functioning.
- tptacek 10y agoEven if you knew what you were talking about here, you can't make accusations like this on HN. You've been here for over 3 years now, and should know better.
- 1024core 10y ago> Another issue, and a plus for using usernames, is that you may want to use Signal with people you don’t necessarily want to give your phone number to. So, how do you know that the Edward.Snowden@signal you're communicating with is the same Ed Snowden that we all know about, and not some TLA stooge?
- resonanttoe 10y agoYou're missing the point. Neither Phone number of Email address/username solve the problem you're proposing. But an email address/username is a lot more transient than a phone number. I can change emails/usernames very easily and with little effort, and while burner numbers and applications that help that exist, changing phone numbers is not as easy and thus a significant percentage of users are unlikely to do it regularly. So you have a pseudo real ID that to the end user FEELS like it isn't you, but is a very strong (no pun intended) signal that it is to anyone looking in. The phone number grants no you special verification of identity over an email address that doesn't involve an external verification mechanism (i.e, talking to the identity in person.)
- Sylos 10y agoBy making user-names unique...?
- latkin 10y ago> this tool should not have dependencies on corporate infrastructure like Google’s (basically any partner in PRISM) Free yourself from the bonds of corporate infrastructure by installing this tool on your Google Android or Apple iPhone device (Microsoft Windows desktop version coming soon).
- joesmo 10y ago"Otherwise, we’ll be in danger of ending up in an neo-90s Internet, with walled gardens and pay walls all over the place. You already see this trend happening in journalism." The internet will never be less walled, more free, and more federated than it was in the 90's. With such a poor understanding of the internet and its history, even if he did make a compelling argument (he doesn't), it'd be hard to take seriously.
- qwertyuiop924 10y agoYou're forgetting about AOL and Compuserve. The Internet itself was federated. Networking really wasn't.
- joesmo 10y agoI forgot them on purpose because he's talking about the Internet, not networking, not BBSs (which AOL and Compuserve were just big versions of). AOL and Compuserve eventually made themselves just another part of the Internet, but before that, they were really irrelevant in relation to the Internet's federation. In fact, other than AOL being an ISP and a gateway to the Internet for many, the actual AOL service was completely irrelevant once Internet connections came along.
- Canada 10y agoNothing is stopping anyone from running their own servers, changing the username scheme, and implementing the voice signaling. Moxie doesn't complain about such usage. But that's more work than simply complaining and telling OWS what they should do. As far as usernames go, that would require the signaling key to be remembered by the user. That doesn't work well in practice. As far as contact sync goes, has anyone submitted a patch for the android client to add an advanced option to disable that? On IOS access to the address book is user controlled at runtime. destinations will be validated by the server at compose time. Regarding federation, let's see some code. It's ridiculous to demand the small team that is OWS solve every single problem.
- JupiterMoon 10y ago> Regarding federation, let's see some code. It's ridiculous to demand the small team that is OWS solve every single problem. Moxie has explicitly rejected federation. Anyone writing such code is wasting their time it won't get accepted.
- Canada 10y agoYep. You can run your own federation though. And maybe if it's really awesome he'll change his mind.
- qwertyhaze 10y agoThe code is already written and both the signal server and clients support federation. It's not enabled in O
- joecool1029 10y agoRedphone component. I don't know why it's closed source. It's been suggested elsewhere in this thread that it was potentially IP issues they kept it closed for. Is it possible loose US CALEA law interpretation influences the reasoning? Or a gag? I honestly don't know why they chose to do that but I wanted to comment in to see if a lawyer or someone from the project could hint at the reasoning.
- lisper 10y agoI'm working on a completely open secure communications suite based on TweetNaCl. Proof-of-concept prototype is here: https://github.com/Spark-Innovations/SC4 https://github.com/Spark-Innovations/SC4 Working on a better UI at the moment. Could really use help, especially beta testers.
- deleted 10y ago[deleted]
- HashThis 10y agoHow does Signal compare to Telegram? Would you recommend Telegram as better or worse then Signal.
- encryptawaa 10y agoOn Signal, every message uses end-to-end encryption. Signal's servers can't see the messages you are sending, only you and the recipient can read them. Signal's encryption protocol is carefully scrutinized and follows best-practices. Telegram sends messages in plain-text by default. Telegram servers have access to all plain-text messages that you send. Telegram's private chats use end-to-end encryption. But they use an encryption protocol that they invented themselves that doesn't follow best-practices. Encryption experts have been critical of Telegram's encryption protocol since it was released. So your private messages might not be so private, either. If you are doing something sensitive and want to stay out of prison, use Signal.
- majewsky 10y agoActually, always use Signal unless you have contacts on Telegram that refuse to migrate. Consider all communication via Telegram to be on public record.
- jhasse 10y ago> Consider all communication via Telegram to be on public record. Just because the protocol has flaws, doesn't mean everyone can exploit them. On the other hand it's possible for Google to read every communication because they have root on your phone. So using Telegram [1] with a custom ROM without Google services (e. g. [2]) will make it harder for Google at least. Not easily possible with Signal. [1] https://f-droid.org/repository/browse/?fdfilter=telegram&fdid=org.telegram.messenger https://f-droid.org/repository/browse/?fdfilter=telegram&fdi... [2] https://copperhead.co/android/ https://copperhead.co/android/
- jhasse 10y ago> Telegram sends messages in plain-text by default. This sounds like everyone has access to those messages. Better: Telegram sends messages client-server encrypted by default and since you can't run your own Telegram servers, this is a problem.
- richardwhiuk 10y agoIf you aren't going to recommend anything else then sit down and shut up frankly. The world is made of compromises and saying I don't like your choices is pointless if it's effectively impossible to choose differently.
- ttam 10y agofunny enough, I was going to try out Signal today but stopped right after seeing the permissions they request: https://pbs.twimg.com/media/CwhFsLzXcAIDcMH.jpg:large https://pbs.twimg.com/media/CwhFsLzXcAIDcMH.jpg:large
- codethief 10y agoWell, everything is there for a good reason. (Though it escapes me right now why it needs permission to access the calendar.) How are you going to call someone over Signal if Signal can't use the microphone? If in doubt you can always check the source code – it's open source for exactly that reason.
- cbsmith 10y agoThere's a fundamental assumption here: that there is a better way. I'm not saying there isn't, but there's a pretty good existence proof that Signal is the best combination of security & simplicity we can put together. I would agree with this statement from the article: "there should be a tool that is fully free software (as defined by the GNU GPL), that respects users' freedoms to freely inspect, use, modify the software and distributed modified copies of the software. Also, this tool should not have dependencies on corporate infrastructure like Google’s (basically any partner in PRISM), that allows these parties to control the correct working of the software." There are such tools. None of them are as easy to use as Signal. So for now, I recommend Signal. I can't, in good conscience, recommend anything else... and given the author doesn't speak to what they recommend, I'm curious about what their recommendation would be.
- deleted 10y ago[deleted]
- RustyRussell 10y agoFor me I won't recommend it because of the horrible lack of options when you replace your phone (let alone lose it). No encrypted migrate. No backup options. Unencrypted loses content (images). Plus there's no way to search old messages.
- majewsky 10y agoI guess these are all features. For example, how are you going to do a backup that restores when you lose the phone (and thus the private key)? In practice, you would encrypt the backup with a passphrase, and the user would choose "123". Signal aims to be the most usable secure messenger, not the most usable messenger that also happens to be secure.
- codewiz 10y ago"Also, there’s the issue of integrity. Google is still cooperating with the NSA and other intelligence agencies. PRISM is also still a thing." What's this based on? Google immediately denied any association with the NSA and PRISM: https://googleblog.blogspot.com/2013/06/what.html https://googleblog.blogspot.com/2013/06/what.html Google’s chief legal officer claimed that collection was being done without Google's consent: http://www.irishtimes.com/news/technology/google-outraged-at-nsa-interception-claims-1.1579245 http://www.irishtimes.com/news/technology/google-outraged-at... Evidence leaked by Edward Snowden also points in the direction of illegal infiltration of Google's private network without Google's consent: https://www.washingtonpost.com/world/national-security/nsa-infiltrates-links-to-yahoo-google-data-centers-worldwide-snowden-documents-say/2013/10/30/e51d661e-4166-11e3-8b74-d89d714ca4dd_story.html https://www.washingtonpost.com/world/national-security/nsa-i...
- sandervenema 10y agoOn this: https://wikileaks.org/Op-ed-Google-and-the-NSA-Who-s.html https://wikileaks.org/Op-ed-Google-and-the-NSA-Who-s.html there are links on that page that point out multiple e-mails from the STRATFOR leaks and other files that point to Google being deeply embedded with the U.S. security apparatus. Also: https://www.theguardian.com/world/2013/aug/23/nsa-prism-costs-tech-companies-paid https://www.theguardian.com/world/2013/aug/23/nsa-prism-cost...
- sandervenema 10y agoAnd Google became a PRISM partner in 2009, as the slides here from the Snowden collection prove: https://search.edwardsnowden.com/docs/PRISMUS-984XNOverview2013-06-06nsadocs https://search.edwardsnowden.com/docs/PRISMUS-984XNOverview2...
- codewiz 10y agoAnd Google became a PRISM partner in 2009, as the slides here from the Snowden collection prove Read those slides more carefully: they say that collection from Google began on 1/14/09, not that Google became a willful partner of the PRISM program.
- piotrjurkiewicz 10y agoAdd a lack of real desktop to this.
- piotrjurkiewicz 10y ago*real desktop client
- droopybuns 10y agoAnimated GIFS were the straw that broke the camels back? Let's throw the best available solution under the bus. This post will be my go to example of the myopia of some members of the security community. We have very few examples of well executed, consumer friendly privacy soloutions. Signal is the best for all possible scenarios: Open source, user friendly, buy in from a major Internet service. I like wickr, but it falls short due to the closed source nature of the project. Consumer friendly, usable security needs to be the number one priority for security advocates. We need to stop burning down houses because they are short a door or are the wrong color. The foundation is the hard part. Wait till there is a real alternative that can be used by people who are not c.s. majors before you argue that people should stop using the best available solution. I appreciate the authors perspective and I agree with some of their points. Then they fuck it up by demonstrating purist jackassery. Worth a read as a useful persuasion antipattern.
- droopybuns 10y agoAnimated GIFS? Let's throw the best available solution under the bus. This post will be my house to example of the myopia of the security community. We have very few examples of well executed, consumer friendly privacy soloutions. Signal is the best for all possible scenarios: Open source, user friendly, buy in from a major Internet service. I like wickr, but it falls short due to the closed source nature of the project. Consumer friendly, usable security needs to be the number one priority for security advocates. We need to stop burning down houses because they are short a door or are the wrong color. The foundation is the hard part. Wait till there is a real alternative that can be used by people who are not c.s. majors before you argue that people should stop using the best available solution. I appreciate the authors perspective and I agree with some of their points. Then they fuck it up by demonstrating purist jackassery. Worth a read as a useful persuasion antipattern.
- youdontknowtho 10y agoIf they are only using GCM as a queue (and the messages are themselves encrypted) I don't understand what the problem is. They could use anyone for that functionality. Even if the messages are given to an "adversary" what can they really get from that? Your phone app contacted the signal servers. That's really it.
- haffenloher 10y agoThey're not even using it as a queue, they're queueing and delivering the messages themselves. GCM messages are empty and are only used to wake up your device.
- angry_octet 10y agoIf wishes were fishes we'd all live by the sea.
- haffenloher 10y agoFrom the post: "The Google Cloud Messaging service basically handles message handling from/to the user’s devices to the Signal servers. The GCM service then handles all the aspects of queueing all messages and delivery from/to users." This is not true. Messages are delivered via Signal's own servers only. GCM messages are empty; their only purpose is to wake up your device. [1] "The phone component of Signal is called RedPhone. The server component of this is unfortunately not open source [...] this is also probably the reason why secure encrypted phone calls don’t work in e.g. LibreSignal" No. The reason for that is that the signaling for RedPhone calls is currently still done via GCM and not via Signal's own message transport. Regarding microg: I've never heard of the need to re-compile kernels for that. I think most people use it with Xposed (admittedly, a giant hack, but it works). [1] https://whispersystems.org/blog/goodbye-encrypted-sms/ https://whispersystems.org/blog/goodbye-encrypted-sms/
- sandervenema 10y agoHmm. You seem to be right. Article corrected there to reflect that Signal is using empty GCM messages. I must have still had the old situation of TextSecure in my head when I wrote that. Nice to know re the reason Redphone doesn't work, thanks for that insight!
- tptacek 10y ago(had suggested the author add an endnote; they did)
- sandervenema 10y agoYes, I agree that's more transparent. I've added an endnote, and linked to it from the place where the edit was made.
- deleted 10y ago[deleted]
- bitmapbrother 10y ago>I’m pretty sure that Google could serve a specially modified update or version of Signal to specific targets for surveillance, and they would be none the wiser that they installed malware on their phones. I'm not sure he understands how app signing works and why it would be impossible for Google to forge a developer's signature. He also seems to have a problem with GCM and Google in general. Perhaps he should look into writing his own secure chat application.
- throwaway101416 10y agoWhy would they have to forge it? They can simply install a version that isn't signed on your system via an update. Then later replace it with a signed version once they have the data they wanted. You would never know what happened.
- em3rgent0rdr 10y agoI didn't have to recompile my kernel to use microg...instead I used FakeGApps with Xposed framework. instructions: https://github.com/thermatk/FakeGApps https://github.com/thermatk/FakeGApps
- chrismartin 10y agoSignal may not transmit any payload via Google Cloud Messaging, but Signal's requirement to run Google Play Services compromises the user's privacy in ways that have nothing to do with Signal. If you run Play Services then you have a device which provides your communications metadata, whereabouts, and device usage habits to Google. I don't trust Google with this information and don't want to carry such a device, but a handful of friends and family use Signal, so I must choose between easy/secure communication with them, and reducing my exposure to corporate surveillance. Signal may be "pragmatic" among the current choices (just like the project's decision to use GCM is pragmatic), but OpenWhisperSystems absolutely deserves criticism for: 1. Tying secure communication to running what amounts to Google's spyware on your device 2. Offering no alternative for privacy-conscious users 3. Showing hostility to those trying to introduce such an alternative to the project I think those dismissing these concerns as "crypto-puritanism" will be on the wrong side of history.
- haffenloher 10y ago> 3. Showing hostility to those trying to introduce such an alternative to the project Quite the contrary, they're actively asking people to contribute code for an alternative push mechanism [1][2]: "I would consider a clean, well written, and well tested PR for websocket-only support in Signal. I expect it to have high battery consumption and an unreliable user experience, but would be fine with it if it comes with a warning and only runs in the absence of play services." [1] https://github.com/LibreSignal/LibreSignal/issues/37#issuecomment-226646872 https://github.com/LibreSignal/LibreSignal/issues/37#issueco... [2] https://news.ycombinator.com/item?id=12883410 https://news.ycombinator.com/item?id=12883410
- fiatjaf 10y agoThe Signal app is stupid. It doesn't work intuitively as WhatsApp. It's incomprehensible that you need a phone number, it's incomprehensible that you can't compile it yourself.
- lonelyw0lf 10y agoThe truth which a lot of Moxie fans don't want to admit is he thinks there is nobody better to be entrusted with this project. I don't think this was ever meant to be a community project -- he just opened some parts so he could pretend it is. Also he is a limelight hogging security diva who always wants to be in the news and have people talk about him. If he allowed others to contribute and be recognised, he worries they might overshadow him.
- gyey 10y agoI haven't actually worked with GCM so please forgive me if this doesn't make any sense. I suggest that, instead of routing all messages through GCM, what if Signal could send a "wake up" message via GCM, and then let the app pull the encrypted messages directly out of Signal's servers? A wake up message would only be sent by the server if the message could not be received by the client via normal means (implying that the device is asleep). An optional user preference could allow some dummy wake up messages to be sent at random moments during the day, to support plausible deniability, at the cost of slightly worse battery life performance. This would all happen silently and the user would only notice a message notification when the app successfully fetches a new incoming message.
- haffenloher 10y ago> I suggest that, instead of routing all messages through GCM, what if Signal could send a "wake up" message via GCM, and then let the app pull the encrypted messages directly out of Signal's servers? Yep, that's exactly how Signal has been doing it for >1.5 years now.
- gyey 10y agoahh. I just thought otherwise from some of the other comments here. Makes sense. Thank you.
- rstuart4133 10y agoI know the redphone is library is just a binary blob in the github repository: https://github.com/WhisperSystems/Signal-Android/tree/master/libs/armeabi But I always thought that .so was just a compiled version of this C++ source, which in the same github repository: https://github.com/WhisperSystems/Signal-Android/tree/master/jni/redphone I haven't compiled it myself so I can't be 100% sure, but the C++ entry points matches the API the Java code is using. I presume it's written in C++ for speed. There isn't much to the C++ bits. It just pumps data through an encrypted RTP connection - CPU intensive but not particularly complex. The server code is up there too - in fact it's all up there. AFAICT, Signal is completely open source.
- nopcode 10y agoWhy is the author asking for GPL? Wouldn't a ISC/BSD-like license be better for the federation aspect?
- argos-rho 10y agoThe author offers no better alternative so I think that means the article speaks for itself: there's not much to do but whine. These are problems, sure, but they're minor when you consider that Signal is the most secure and user-friendly messenger we have on the market right now. If something takes its place, then great. Otherwise, we just will continue to use what is secure and actually works.