6 ms·
Rather pointless to have a "trusted" application on an operating system you cannot trust – and not even the possibility to run the application on an even remote
by claudius 10y ago
Rather pointless to have a "trusted" application on an operating system you cannot trust – and not even the possibility to run the application on an even remotely trusted and private system, in particular without giving unaccountable root access to Google.
- tptacek 10y agoThis is more or less a way of saying it's "rather pointless to have secure messengers on iOS". I understand why open source advocates say that, because they've been saying it for 20 years now, but I'm not sure we need to litigate the point or pretend it's some great insight.
- jrcii 10y agoSurely the age of a problem doesn't necessarily diminish its significance?
- claudius 10y agoLet me put it like this – if OpenWhisperSystems had an explicit toggle in their protocol which, after flipping it, would allow them to access all future communications and where the user was unable to tell whether it had or had not been flipped, nobody would call the protocol "secure" or write a "Trust It" headline about it. However, if OWS only supports systems on which such a toggle exists via a third-party provider, that somehow makes them secure? I find this hard to understand. Yes, of course an app which encrypts data against some adversaries is nice, but it should definitely be called "secure-against-some-people", not "secure", and people shouldn’t write "Trust It" but rather "Trust It if you also trust X and Y and Z".
- tptacek 10y agoAgain: this is a point that can be made to sound interesting with lots of extra words, but all you're saying is that people run applications on operating systems you don't like. They're not going to switch.
- claudius 10y agoAnd the counterpoint is? ‘People should give Google/Apple root access on their devices to run this new secure messenger’?
- eganist 10y ago> And the counterpoint is? ‘People should give Google/Apple root access on their devices to run this new secure messenger’? I feel like you might've misstated your intended point, but in any case: - Most threat models exclude the situation which you're discussing here because risks are generally low and, in the event of such a threat becoming material, the entity is probably screwed regardless of whether that threat is considered due to the costs of mitigation. (Seriously -- how would a company or person mitigate this short of independently auditing the code for the OS? Or building their own? And what happens after you look at the code? Do you then look at the hardware too? How low would you go? How low would your attackers go, for that matter?) - If you're the target of attackers who would actually try to gain access to your device through compromising the device maker, you've got bigger problems. The philosophical argument doesn't really work here because there's no practical solution that anyone can (or would, really) adequately fund. P.s. just to clarify, I'm not tptacek.
- sseppola 10y agoSorry, I don't understand. What do you mean by "give Apple/Google root access"? I've always assumed they already have that.. if no, how does OWS give them root access?
- e12e 10y agoYou can compile Signal yourself, and install it on a rooted phone, running presumably a Linux kernel and some Android/ASOP sub-system. In that case, excepting base-band backdoors and a few other details, Google won't have access to your phone at all (assuming no Google services etc here). OWS doesn't then allow you to use their servers for routing/discovery etc - so you need to run your own servers, and set up a different network that cannot federate with the one users of the Google Play Appstore version of Signal use. If you do that, and install eg. the F-Droid store, you've now given another actor (the F-Droid store) access to your phone. OWS argues that in general you're less likely to manage to run a safe, patched system this way.
- mtgx 10y agoThe same can be said about a "trusted" OS like say Qubes OS, with untrusted hardware, like Intel's. Actually, that's what the developers of Qubes OS and other "free" operating systems have said as well. http://blog.invisiblethings.org/2015/10/27/x86_harmful.html http://blog.invisiblethings.org/2015/10/27/x86_harmful.html https://www.fsf.org/blogs/licensing/intel-me-and-why-we-should-get-rid-of-me https://www.fsf.org/blogs/licensing/intel-me-and-why-we-shou... If anything, I'm more frustrated with the Signal team that the app doesn't have as good call quality/performance as WhatsApp, nor does it have video call support, and that the Chrome desktop "app" doesn't seem to import my phone contacts for some reason - all of which is making me continue to mostly use less secure and less trusted alternatives. My point is we should aim for getting things "more secure" constantly, and I think we have in the past few years. So rather than just say "what's the point?", we should say "let's put more pressure on X company to open source/prove their system is secure" and hope that in time enough pressure is built that those companies actually agree to do those things. And since I was talking about putting pressure on companies, let me start: Where the hell is Google's End-to-End tool? It hasn't had any commits in over half an year, and we already know NSA's bestie, Yahoo, has given up on it. Should we start drawing some conclusions about the Google/NSA relationship, too? Did Google abandon the project? https://github.com/google/end-to-end https://github.com/google/end-to-end There - who's next?
- haffenloher 10y ago> the Chrome desktop "app" doesn't seem to import my phone contacts for some reason Have you tried re-importing them manually via the "Import now" button in the Desktop app's settings? Maybe that helps.
- lrk_sirius 10y ago> The same can be said about a "trusted" OS like say Qubes OS, with untrusted hardware, like Intel's. Actually, that's what the developers of Qubes OS and other "free" operating systems have said as well. If you're really paranoid, go for open hardware supported by libreboot [0] or the Talos Workstation and run a hardened "free" OS. However, I don't think Intel ME (or similar firmware in AMD and ARM) has ever been used to compromise user security and privacy. The threat probably exists and is real but has it ever been exploited? On the other hand, I suspect that there is no lack of zero-days and other vulnerabilities for iOS and Android. [0] https://libreboot.org/ https://libreboot.org/ [1] https://www.crowdsupply.com/raptor-computing-systems/talos-secure-workstation https://www.crowdsupply.com/raptor-computing-systems/talos-s...
- eveningcoffee 10y agoI think that you are displaying your arrogance. These open source advocates are fighting with peoples ignorance. People are known to be ignorant about deeper consequences out of the convenience and I do not believe that very sizeable amount of them are given a change to be more informed. I'll give you a different example. These are two positive reaction examples for the cashless society: 1) I pay with the card all the time anyway. 2) I do not like coins. These are naive reactions considering only personal convenience. If these people are guided to have a longer more focused thought about the issue then they are able to make more informed decision.
- throwanem 10y agoSo put your money where your mouth is and build something that can win in the market. Hectoring people and complaining that open source or free software is judged too harshly accomplishes nothing and benefits no one.
- eveningcoffee 10y agoIt is pointless to build something when there is no market for it. You can see this, as you call it, hectoring as a market generation. If the market is ready, a product will emerge for it. This process is also made more difficult by arrogant people like you who out of their ignorance or self interest actively work against it. Let me explain: saying put your money where your mouth is and build something that can win in the market is considerably arrogant position as it states that an argument is simply wrong just because current market will probably not sustain it. But it will not sustain it because the market is not informed enough and it is very difficult to campaign against actors with huge resources on the sea of ignorance. Besides, I am simple observer, not a one I was describing. But I am becoming to believe more and more that the basic infrastructure were are using must be open to reclaim the lost trust within the society.
- throwanem 10y ago> You can see this, as you call it, hectoring as a market generation. I've been seeing it for well over two decades now. That's more than enough time for a market to emerge, were it ever likely to produce one.
- VLM 10y agoFalse binary dilemma in that the insight is the statement is true. Both legal cases and excessive patting on the back are interesting to contemplate but irrelevant to the truth or falsehood of the statement.
- drvdevd 10y agoIt may not be a great insight but it is an important fact to be aware of, especially in the context of something like Signal. It does need to be drilled into our heads again and again that the weakest link breaks the chain. Lest we forget... and we will. Or at least, I know I will.
- xorcist 10y agoObvious arrogance aside, security is not a scalar value. A centralized service is a convenient stop for the three letter agencies to do their work. Multiple independent implementations of the protocol and interoperability is a much stronger ecosystem. Even if the security of one individual user might not be better. If you applied the argument to the web instead, it might be tempting to say the security of a single user would improve if Google just ran the whole web, instead of all of these small shops with shoddy security, but very few people would argue that it would improve the reliability and security of the system as a whole. "Just centralize it" is not some great insight either.
- tptacek 10y agoNo, I'm not going to let you pretend that we are on opposite sides of a "centralize" versus "decentralize" argument. Find someone else to take the "Google should control the web" side, and debate with them. What you're saying here has nothing to do with what I'm saying.
- xorcist 10y agoYou replied to a fictitious argument. What I said is that security is not that simple, it matters on your threat model, and things like resilience and platform diversity matter too. Crypto is not the weak link for Signal (nor is it likely to be for comparable products). What claudius said was that in essence was that a trusted application should not depend on giving remote root to Google, likely referring to not be able to compile and distribute the software in a useful way. That is worth a more meaningful answer. Distribution and the run time environment are central to any realistic threat model and reducing that to open source zealotry kind of misses the point.
- tptacek 10y agoCrypto has already been the weak link in other "secure" messaging applications.
- nullc 10y ago> This is more or less a way of saying it's "rather pointless to have secure messengers on iOS". No! that is not at all what is being said. There is no way to use signal that doesn't give Google or Apple remote code execution privileges in the process. This means that for people who aren't already exposing themselves to these companies use of signal is a step down in security.
- deleted 10y ago[deleted]
- Jtsummers 10y agoYour same logic means we shouldn't even bother trying to make safer languages (like Rust is attempting) to run on existing OSes and hardware. What's the point? We can't trust the underlying OS. The point is, it's a step towards a future where a much greater percentage of our systems is vetted, verified, and shown to be secure/stable (modulo external components beyond their control) and minimizing those external components.
- antocv 10y ago> and shown to be secure/stable For various definitions of "secure/stable". For me, anything which Google can reach and amass information from, and thus NSA, is not secure. Rust on Linux where I am playing with, is fine. And its not only the "conspiracy style" "why would Google put backdoors in its 'Play Services'", no its more like "oh Google receives and sends notifications for every Signal message sent and recieved, among other information, such as Device ID, phone number, android version" - in short who is using signal and when. Signal is amassing huge amounts of information for benefit of Google. Look at their github page, where they even say they want more to amass more data and to "annoy the hell out of users" to make them update - shove updates down their throat a la Microsoft style.
- tptacek 10y agoAgain: criticism of Signal is in-bounds, but outright allegations that Signal is a shill for Google is not. Moxie is a member of the HN community, and you cannot make these kinds of allegations about him here in this fashion.
- antocv 10y agoYou can not tell me what accusations to make, based on your seniority of having been here longer than me or for any other reason. Moxie is a member of HN and of Github, and I have read his posts and his discussions on github, his contempt for the common user is obvious and abundant. Signal is dependent on Google. That is a fact. It can be hard to swallow, but many people, just read the github issue page, consider that insecure. For many people security means not feeding their data into USAs corporations and intelligence services data centers. For many users, like me, if the choice is between USA and others, Id prefer in fact to feed my data to Russian or Chinese or Indian corporations and intelligence services. Then its not a matter of "oh my encryption is better", it doesnt make a difference, in that position, Telegram is for me a better choice even if its encryption is not as good - if it at least makes it more difficult for USA (but very easy for Russia) then its better than Signal. Both Signal and Telegram suck, to various degrees in different forms, but the choice is easy to stay away from Signal and similar Google-only "secure" apps.
- bench_soup 10y agoThe LibreSignal fork is available on sailfishOS.
- h4waii 10y agoYou can use Signal with MicroG[0] and "checkin" to GCM in order for notifications for queue wakeup to reach your device. GCM is only used for notifying the device there is a message on Signal servers. You can also disable permissions on the Google Service Framework and use something like XPrivacy for MUCH more explicit permission control (revocation, spoofing, etc...) if you still want GApps on your device. [0] https://microg.org/ https://microg.org/
- Strom 10y agoDo you personally review every bit of code that runs on your device? No? Then you're trusting someone else who claims it's secure. No different than trusting Apple/Google.
- lrk_sirius 10y ago> No different than trusting Apple/Google. It is different. I expect Apple and Google to insert backdoors deliberately into their operating systems for three letter agencies (it's easy to do it when you've got either a proprietary OS like iOS or a "technically open but practically closed" OS like Android). They've probably done it before and are part of the PRISM program either way. However, I don't expect the FSF or Linus Torvalds to do it. They haven't done it yet and they probably won't do it.
- Strom 10y agoIt's subjective opinion to trust Linus/FSF more. On top of that Linus doesn't review every piece of code that you run. Some random people vet plenty of code that the distro contains. In addition, I would say it's easier for the NSA to make subtle changes to open source software to sneak in heartbleed-style vulnerabilities under the guise of new unrelated features/bugfixes.