4 ms·
Signal is told to be a secure crypto messenger everyone can use. This means that people are installing it on a usual Android device and assume that nobody is ab
by larma 10y ago
Signal is told to be a secure crypto messenger everyone can use. This means that people are installing it on a usual Android device and assume that nobody is able to read their messages without physical access.
Of course you are right, there are many black boxes in most mobile devices. But does this mean we shouldn't care about any of them? Most of these black boxes are not updated on a regular basis or the update requires user consent. This means that, if they don't allow arbitrary code execution now, it is hard to make them do evil things.
The mentioned issue with Google Maps integration (leave the GCM problems aside) however is a real possibility to silently drive targeted attacks on Signal - it's actually damn easy for Google to do this. If we'd be doing a proper analysis on all other black boxes (processor, modem, manufacturer extensions, etc), I doubt we'll find such kind of backdoors in most of them. And if I will find such a thing, be sure I'll be writing about it as well.
This backdoor is important for those that want to securely communicate and their adversary is for example the US gov. e.g. the next Snowden. Google can be forced by US agencies to use this backdoor and this renders Signal unusable for them. These people should know about the backdoor. If you know and don't care, that's your problem...
- arghwhat 10y agoIf you are running an Android version that legitimately bundles Google Play, the Android release itself was either directly shipped by, or shipped by someone controlled by Google. I am not saying we shouldn't care about problems because there are bigger ones. However, if the problem you are trying to fix is "Google is capable of poking around in your running instance of Signal" (That is, what the map trick is potentially capable of), then removing any Google integration from the Signal app will not help as long as you still run on a Google-controlled Android release. The only unique thing about this specific Google dependency is that it is more dynamic than the OS, but as long as Google owns your OS, they have every possibility of monitoring your process memory. That's before you start worrying about the black box proprietary drivers most ARM devices use and all that jazz. My complaint lies in that fixing this will not improve the security by any noticable measure (that is, no noticable reduction in Google's capability of reading process memory of your instance of Signal) for any of the current Signal users (which are implicitly Google Android users, although a some instances may be non-Google + google services manually patched in). The primary benefit is that some people that cannot currently run Signal due to the dependency can join while maintaining the non-Googliness of their system.
- larma 10y ago> someone controlled by Google Manufacturers that ship GMS are not controlled by Google. I think you don't know a lot about how to apply for GMS integration, it's as easy as filling a form and passing the CTS (compatibility test suite). Google is providing some non-free files (basically apps and libraries, all sandboxed) and configuration files to manufacturers that they apply on top of AOSP (or possible extensions they did). The only way for Google to break out of the sandbox is to make a backdoor in the AOSP code, that is openly available for review. To repeat what I said to the other guy here: If you are not on a Nexus or Pixel device, Google is UNABLE to look into private app data of third-party apps (if they correctly configure the backup feature). This is possible with Signal only due to the mentioned "backdoor", making this an important issue. You are however right that the manufacturer(s) might be able to look into app's private data, but that's another issue (especially as most manufacturers are non-US companies).