10 ms·
Egypt has blocked encrypted messaging app Signal
- lep 10y agoGeez, if only there were a protocol with as good encryption but federated so that everybody could host their own server which would make it way harder to block… https://xmpp.org/extensions/xep-0384.html https://xmpp.org/extensions/xep-0384.html
- trome 10y agoEh, you'd have to operate a server in the country, and TLS in and out of Egypt is MITMed and outright blocked in many areas from what I've seen when playing with VOIP over there.
- vog 10y agoAt least they would have proper encryption within their country. Apparently, depending on central services outside their country makes it too easy to block.
- trome 10y agoThen you have to deal with regulations inside the country itself, I doubt its a free for all inside Egypt network wise.
- mi100hael 10y agoE2E encryption via OTR would largely mitigate that as long as keys could be exchanged out of band.
- supergreg 10y agoOr just setup Tor and keep using whatever they were using before.
- JshWright 10y agoXMPP is really hard to scale. It's a very chatty protocol, with tons of XML overhead.
- davecridland 10y agoSure it is. https://xmpp.org/extensions/xep-0365.html https://xmpp.org/extensions/xep-0365.html
- SamWhited 10y ago[citation needed]
- padraic7a 10y agoIf countries will block messaging services why do you think they won't raid / shut down servers? I really don't understand the hating on Signal for not fulfilling all of everyone's use cases. There is an SMS/ MMS fork called Silence (available on F-Droid). If that's a feature users want they have an option.
- trome 10y agoI can't say this is surprising, I was talking about the potential of Signal to be blocked by regimes with my friends a few weeks back (both the initial verification text, and client to server communication), and here we are with Egypt being the first to block it.
- pjc50 10y agoAnd this is why in western countries the politics of encryption should be regarded as a stopgap only. It's better than allowing the police to opportunistically go fishing in your data, but it's no substitute for sound democratic rule-of-law culture. If politics gets to the point of having to rely on encryption as your only protection then it's simply going to get banned and/or blocked.
- trome 10y agoI'd argue that the politics of encryption should be regarded as a stopgap in every country, not just western countries. Even Singapore sees value in encryption, and they aren't exactly supporters of free speech.
- onion2k 10y agoThat's true, and I think it means encryption not only protects speech but also works as a simple test for flagging nation states who're failing to protect the basic human right of privacy for their citizens. If a country tries to stop the use of encryption by its citizens then it's failing to do a good job, and its citizens (and other nations) should be working to make them aware of the problem.
- zeveb 10y agoI think it's unwise to rely on a sound democratic rule-of-law culture to protect our right to encryption: there's nothing which says that a majority of people won't support a law banning strong encryption.
- fpp 10y agoadditionally relying on specific applications / services that can relatively easy singled out with DPI and by that also stick out their users for "further inspection". Their suggestion to use TOR does not really help - Turkey for example has today started to block TOR ( http://www.bbc.co.uk/news/technology-38365564 http://www.bbc.co.uk/news/technology-38365564 ). With DPI hardware having dropped substantially in price while at the same time expanded functionality, TelCom providers / gov. agencies can relatively easily / quickly deploy such censorship / surveillance at the edge or in the TelCom core.
- subliminalpanda 10y agoI'm curious as to how they intend to circumvent the censorship from their end.
- trome 10y agoPerhaps integrating DNS tests and pinning DNS entries in Egypt would be a short term solution, but long term they may need to start bundling orbot with unique bridges.
- aorth 10y agoMoxie just committed circumvention support earlier today. Here's the commit: https://github.com/WhisperSystems/Signal-Android/commit/541718fd114a6f2336222a571869e1056cd122dd https://github.com/WhisperSystems/Signal-Android/commit/5417...
- vog 10y agoWith XMPP and federated messaging servers they would have at least working infrastructure within their country. But ... What exactly happened that XMPP lost on mobile phones? What did they do wrong? XMPP was there before smartphones came, had working clients, and had (for that time) pretty decent encryption. While I understand that big players like WhatsApp want to bind all users to their own infrastructure, I don't understand why even the niche instant messangers go through the burden of creating their own infrastructure (or relying on Google's) instead of just concentrating on the client side to provide better XMPP clients. Is XMPP so bad that nobody wants to do that? If so, why?
- koolba 10y ago> Is XMPP so bad that nobody wants to do that? If so, why? No it'd be great but unfortunately the things that make something technically great don't align with the business of acquiring monetizeable users (either directly or indirectly by selling the resulting social graph). I'm convinced that the only reason we still have email is because it predates walled garden land grabs.
- sliken 10y agoNot to mention email isn't particularly distributed these days. I don't know the exact percentage, by yahoo, gmail, and microsoft definite host a large majority of the email accounts on the planet.
- koolba 10y agoAnyone can register a domain, stand up a server, and start receiving email on it. Sending it a bit trickier as to get past spam filters there's a bit more to it (DKIM, SPF, static IP, etc) but it's still doable.
- sliken 10y agoI do it, but do see regular complains that others try and fail. The main problem is getting black holed by the popular email providers.
- fgrte 10y agoThis wouldn't be such a problem if Moxie hadn't removed the ability to communicate using SMS. SMS is federated and very difficult to block without disrupting essential services. See: https://github.com/WhisperSystems/Signal-Android/issues/2818 https://github.com/WhisperSystems/Signal-Android/issues/2818 Of course going the route of using centralized services allows later monetization my Moxie and his brogrammers.
- jagermo 10y agoA little harsh, isn't it? They have several good arguments for ditching SMS, as explained here: https://whispersystems.org/blog/goodbye-encrypted-sms/ https://whispersystems.org/blog/goodbye-encrypted-sms/ Especially this one: SMS and MMS are a security disaster. They leak all possible metadata 100% of the time to thousands of cellular carriers worldwide. It's common to think of SMS/MMS as being "offline" or "peer to peer," but the truth is that SMS/MMS messages are still processed by servers--the servers are just controlled by the telcos. We don't want the state-run telcos in Saudi, Iran, Bahrain, Belarus, China, Egypt, Cuba, USA, etc... to have direct access to the metadata of TextSecure users in those countries or anywhere else.
- fgrte 10y agoNot such a problem if there is no real name attached to the phone
- sliken 10y agoJust because the government doesn't know your name doesn't mean they can't hurt you.
- kuschku 10y agoYet, Signal leaks the exact same metadata, if one serves an NSL to OWS. In a way, Moxie's argument (don't tie things to phone numbers, don't use a centralized system for message transport) is exactly why Signal itself is so problematic.
- aorth 10y agoIt's not clear to me why Signal was blocked, though. Other governments have blocked messaging and chat applications before, but not for the reasons you'd think. For example, UAE blocks access to voice and video chat applications to protect the commercial interests of the telecoms companies who offer similar services. I'd be curious to know if other messaging applications were blocked in Egypt too, and why. http://www.thenational.ae/uae/uae-telecoms-companies-told-to-free-up-internet-calling http://www.thenational.ae/uae/uae-telecoms-companies-told-to...
- dodyg 10y agoSkype voice over 3G is blocked here in Egypt.
- niksakl 10y agoIsn't it "weird" that they chose to block Signal app and not the signal-protocol based Whatsapp? If Whatsapp really implements the same kind of security and privacy measures that Signal does, why is Whatsapp allowed to continue operating? If signal is preventing them spy on users and they ban it, is in't it safe to assume that Whatsapp is NOT preventing them spy on users, so they let it operate? Wouldn't you expect Whatsapp to be also targeted, especially considering the broad user-base it has compared to Signal? Yes, I know they had blocked Whatsapp in the past, but they didn't block it now. Which means that something has changed in the relationship of the Egyptian gov and Whatsapp since 2015.
- runn1ng 10y agoI wouldn't read that much into it; WhatsApp is simply more popular so they would face too much of a backlash. That would be my guess.
- aluhut 10y agoIsn't that the point in all this? Blocking the popular messenger you can't spy on.
- niksakl 10y agoKeep in mind that Egypt is practically under a dictatorship. It is not like their gov really cares if their people gets pissed off... Their government is far from carrying about peoples liberties[1]. So, for me the question remains: If what the Egyptian government wants is to apply their surveillance policies and Signal is banned because it is preventing them, doesn't the continuation of operation of other "private and encrypted" messangers say something? Especially of Whatsapp that claims that it implements the same security and privacy oriented architecture as Signal does? [1] https://www.freedomhouse.org/report/freedom-world/2013/egypt https://www.freedomhouse.org/report/freedom-world/2013/egypt
- JumpCrisscross 10y ago> It is not like their gov really cares if their people gets pissed of No man rules alone. Even in a dictatorship, pissed off peasants mean an army that has to do horrible things to keep them in line. That costs a dictator money.
- madez 10y agoDue to cutting ties with Google and Facebook as much as possible I don't use Signal nor WhatsApp. What alternatives are there? I have been using Tox (qTox on Desktop and Antox on phone) and XMPP (Conversations on phone). I also tried Ring (Desktop and phone) My observation is that there is a lot of user inertia to make people use another chat app, and none of which I tried is in good shape to compete right now with WhatsApp/Signal. XMPP and Ring share the problem that encryption was an afterthought. That alone is enough to stop widespread adoption. There must not be unencrypted chats nor different security levels. Encryption must be transparent to the user. Tox doesn't share that problem, and is what I have the highest hopes for. The clients are not yet able to compete with WhatsApp. Antox crashes sometimes, gets reaaaal slow, and doesn't send pseudo-offline messages reliably. Multi-Device support and real offline messaging is still lacking in the protocol. Multi-Device support is not needed, see WhatsApp, but real offline messaging is a must-have. Also, messages must be reliably delivered and in the order they are intended. Tests of mine between qTox and Antox showed problems in that regard.
- akvadrako 10y agoMaybe you have reasons, but your comment doesn't make it clear why cutting your ties with Google and Facebook means dropping Signal. Google and Facebook started using the same protocol as Signal in the latest versions of their messengers, but they don't interact in any way. By the same logic you should also stop using HN because it also uses HTTP, just like those big guys.
- madez 10y agoYou can't use Signal without GCM or its siblings on other platforms. I don't have Google's Apps on my phone, so there is no GCM. Using GCM voids your contact privacy. So Signal right now is a no-go. I do care about whether Google knows who I contact and when. I don't want Google to know.
- sliken 10y agoMoxie is open to someone writing an alternative to GCM, but nobody has stepped up and do it. It's much easier to complain about GCM, then to replace it. Signal's use of GCM does NOT reveal who you are sending signals to, or what is in the message.
- HashThis 10y agoWhat do people think about Telegram's (https://telegram.org https://telegram.org) security vs Signal?
- distances 10y agoI'm not sure if you're joking, as the topic has been extensively discussed here in HN for the last six months, at least. Anyway, in short: encryption-wise Signal is considered to be the state of the art, while Telegram is sneered at due to their homegrown encryption that isn't even enabled by default.