25 ms·
I don't trust Signal
- api 8y agoI trust it more than unencrypted SMS or Facebook Messenger. I trust it less than p2p chat over an encrypted network I control with layered defense in depth. Security is not a boolean.
- cntlzw 8y ago> Security is not a boolean. Very true.
- lmm 8y agoSecurity is not a boolean, but when your whole selling point is security you'd better be good at it. I trust Signal the same amount as Facebook Messenger or any other centralised messaging system that uses transport encryption (e.g. Skype, IRC+SSL, WhatsApp...). But what's the USP that means I should use Signal rather than any alternative?
- Vinnl 8y agoTheir USP is "security made simple", in other words: use Signal because it's as easy as the mainstream alternatives, but far more secure (but not perfect).
- lmm 8y agoThat only works if they're actually more secure than the mainstream alternatives. I don't think they are; Signal has transport encryption but the system probably isn't secure against Open Whisper Systems themselves or someone who controls the central server, which is the same security situation you'd be in with any of the alternatives I mentioned.
- jlund 8y agoEverything in Signal is end-to-end encrypted.
- lozf 8y agoNot giving all your metadata to Facebook (Messenger, WhatsApp) or Microsoft (Skype) for a start. The message may be e2e encrypted, but damn sure these companies are logging as much as possible about who's chatting with whom, when, & where each of them are, how much data is sent each time, etc. Some people trust Moxie / OWS more than the others, and with good reason.
- madeuptempacct 8y agoIs there a preference of Telegram over Signal or vice versa?
- mtgx 8y agoTelegram doesn't use end-to-end encryption by default and likely never will. Paul Durov has been quite hostile against that feature in the past. So yes, choose Signal over Telegram. I find that instead of trying to convince friends/family to use Signal I just tell them "use Signal as your default SMS app" or install it myself for them. This tactic worked well in the Internet Explorer/Firefox and then Chrome transitions, so I don't see why it can't work again. Then whenever I will be chatting with them, it won't matter if they try to send me a SMS, as long as I use Signal, their messages will be encrypted, as they will be data messages. I wouldn't trust the default SMS app/Android Messages not to steal your SMS texts anyway, especially on Chinese phones. Also, I can't wait until the Matrix-based Riot gets its redesign: https://medium.com/@RiotChat/a-sneak-peek-at-a-whole-new-riot-im-1114df653782 https://medium.com/@RiotChat/a-sneak-peek-at-a-whole-new-rio...
- L_Rahman 8y agoThis is good advice. I would to those following it that this advice is likely most useful if your family members are on Android devices. iOS does not allow you to change the default SMS application and if your family member is on iOS, the iMessage platform lock in is nearly impossible to break out of.
- angry_octet 8y agoI've convinced quite a few acquaintances using iOS to switch, or to use both.
- diaz 8y agoThe problem with that is assuming they will have internet connectivity always on when you want to contact them. Which I never found true even for the few people I regularly communicate over Signal. Most people turn off data and only turn it on somewhat regularly over the day to check stuff. Older people (like family) have no idea or barely know what internet is or even the button for that does and just expect communication to work like always: sms and phoning. But if people cam do the above approach good for them. I can barely convince anyone, even tech people from work or friends to install even more chat clients/services. Most are just fed up and feel tired of the whole thing.
- ryanlol 8y agoSecure messaging on android seems like an oxymoron.
- chinathrow 8y ago[] deleted
- masklinn 8y agoThat's a joke right?
- okatsu 8y agoYou could spend a few minutes on Google and find out he is Moxie Marlinspike: https://en.m.wikipedia.org/wiki/Moxie_Marlinspike https://en.m.wikipedia.org/wiki/Moxie_Marlinspike
- thinkling 8y agohttps://en.wikipedia.org/wiki/Moxie_Marlinspike https://en.wikipedia.org/wiki/Moxie_Marlinspike
- r3bl 8y agohttps://lmddgtfy.net/?q=moxie%20marlinspike https://lmddgtfy.net/?q=moxie%20marlinspike
- Tomte 8y agotldr: "I don't like Moxie and feel the need to character assassinate him on the Internet."
- draw_down 8y agoCome on.
- jMyles 8y agoI don't think that is a fair summary of this critique at all. The author has laid out specific, actionable items, such as putting Signal on F-Droid and allowing federation. Maybe he doesn't like Moxie, but it's not so simple as attacking his character. Instead, this is a reasonable summary of steps Signal can take to win his trust (or, to give him a true impression that he needn't trust it).
- Tomte 8y agoI think it's fair. He accuses Moxie of being deceptive and insincere: "It can be hard to distinguish these from genuine positions held by the person you’re talking to, but when it conveniently allows them to make self-serving plays, it’s a big red flag." He then admits it's "a strong accusation". Later he dismisses Moxie's reasonable stance re: federation with "Moxie can write as many blog posts which appeal to wispy ideals and “moving ecosystems” as he wants". That's not a reasonable critique, that's pure vitriol. I would love to see federation in Signal, but I can understand why OWS decided otherwise. The author is not able to distinguish between "someone has weighed the issue differently than I would have" and "he's doing that for his own personal gain".
- apeace 8y agoTL;DR he doesn’t trust Signal because he doesn’t trust the Android operating system, and something about federation. > No doubt these are non-trivial problems to solve. But I have personally been involved in open source projects which have collectively solved similarly difficult problems a thousand times over with a combined budget on the order of tens of thousands of dollars. Shut up and code then. I’ll personally review your fully decentralized and secure chat app which nobody uses because it’s not available on any app store. Let me know when it’s done.
- IshKebab 8y ago"It's easy! Just just generate a 2048 bit PGP key using this command (make sure you don't use the default insecure options) and then mail it through the post to anyone you need to communicate with."
- jMyles 8y agoThe author expressly endorses Matrix.
- apeace 8y agoAnd which operating system does the author expect people to use Matrix on? The one he personally wrote and reviews every commit to? Does he expect everyone to only chat on "trusted" open-source desktop operating systems and not their phones? The F-Droid argument is a really empty one. Packages are cryptographically signed? Are you verifying those signatures? In an article about "trust", can you explain how exactly you trust F-Droid packages and not Google Play ones? What about iOS? The whole article is extremely vapid and lacks any compelling argument. Signal has introduced state-of-the-art encryption to millions of people in an accessible way. The author goes on to poke fun at the animated GIF feature of Signal as if it is a waste of time compared to working on an F-Droid distribution, but neglects to address five of the seven points written by Moxie (which he links to) about why they chose not to do that.
- jhasse 8y ago> In an article about "trust", can you explain how exactly you trust F-Droid packages and not Google Play ones? It's easier for Google to manipulate a package on Google Play than on F-Droid. > Signal has introduced state-of-the-art encryption to millions of people in an accessible way. WhatsApp has done that to even more people, so what's the point of Signal?
- LaGrange 8y ago"If Edward Snowden and Bruce Schneier are going to spout the virtues of the app, I expect it to actually be secure when it matters - when vulnerable people using it to encrypt sensitive communications are targeted by smart and powerful adversaries." Because if the adversary is, say, an abusive ex that happens to work for the telco, for example, then it doesn't matter. Unless you're actively hunted by a G7 country your problems are inconsequential.
- threatofrain 8y agoHow do you defend abused spouses in discourse by comparing their needs to people hunted by the most powerful political forces? Surely these two cases ought not be on the same table for comparison.
- JasonFruit 8y agoI think the top-level comment is unfair, but I also think you're misreading it. It's not defending abusive exes, but saying they are, though a lesser threat than major governments, still a threat worth defending against.
- LaGrange 8y agoThe original autor outright dismissed the entire class of threats, which, while they may seem "lesser," are also far more common. And it's not just abusive exes, not even every state actor has access to an NSA. Neither Signal nor any other existing application based by the same protocol (which exist and are _more_ popular than Signal itself — What's App is one, for example) are sufficient, but on the other hand, it requires far less knowledge to operate. Signal comes from recognition that very few people can practically operate high-effort tools, and if the effort to operate a fancy tool distracts them too much from the things they actually aim to do (it's rare that someone's goal in life is "using Matrix"), they'll fall back on something that doesn't distract them. For example, even when facing a state actor — if training your cadres to securely operate an encryption tool takes away too much from the core activism of your organization, the tool is no longer helpful. Same applies if the actual overhead of using it ("both have to be online" requirements, for example, or for somewhat lower threat profiles, "no emoji") makes it impractical. For most people the threat is going to be someone they know, or high-volume-low-effort attempts. Whether it's an ex or a boss or even most states, it's unlikely they're facing NSA. They often have a lot of other things to do, and neither their ability nor want to enforce technical solutions on others are high. That's the range Signal-backed apps generally target.
- hprotagonist 8y agoBut we have to trust that Moxie is running the server software he says he is. We have to trust that he isn’t writing down a list of people we’ve talked to, when, and how often. We have to trust not only that Moxie is trustworthy, but given that Open Whisper Systems is based in San Francisco we have to trust that he hasn’t received a national security letter, too (by the way, Signal doesn’t have a warrant canary). Moxie can tell us he doesn’t store these things, but he could. Truly secure systems don’t require trust. We have at least one data point that says that Signal stores exactly two integers about you, or did when the subpoena was issued: https://www.aclu.org/open-whisper-systems-subpoena-documents https://www.aclu.org/open-whisper-systems-subpoena-documents things can always change, but that’s evidence submitted in court under the penalty of perjury, which is a fairly strong claim.
- lmm 8y agoIf Open Whisper Systems had received a national security letter requiring them to collect more information and keep it secret that they were doing so, how would you expect them to have responded to that subpoena?
- dannyw 8y agoNSLs don’t allow that.
- hprotagonist 8y agoprecisely the way they did, which was to challenge the gag order, and win. That’s where the documents above come from, in fact.
- zmanian 8y agoNSL can't require to collect new business records. They can only compel you to disclose business records that you already have. This is beyond the legal authority of an NSL.
- lawnchair_larry 8y agoI’m pretty sure that isn’t true. They can be used to compel you to build interception capabilities.
- distantsounds 8y ago"The APK direct download doesn’t even accomplish the stated goal of “harm reduction”. The user has to manually verify the checksum, and figure out how to do it on a phone, no less. A checksum isn’t a signature, by the way - if your government- or workplace- or abusive-spouse-installed certificate authority gets in the way they can replace the APK and its checksum with whatever they want." This is true for just about every single piece of software that one downloads. But nice job deflecting it onto Signal to solve for you. Installing an APK by hand is not difficult either, you transfer it to your phone and open it. I don't see how Signal is doing any better or worse of a job from similar apps. Also, Signal's checksum verification is SHA-256 which I'd say is "good enough." It's also being served from an HTTPS webpage. Is there something missing here?
- jhasse 8y agoSignal doesn't need to solve it, because F-Droid would.
- shittyadmin 8y agoAdditionally with Android APKs, the APK has to be signed and additional updates will be verified to match the same vendor.
- Bartweiss 8y agoWhich as far as I can tell is what Marlinspike meant by harm reduction. It's not preventing anyone from hijacking your encrypted session and serving you a bad app, I'm not sure how it could. ("How do you secure your connection given that your security has already been silently compromised?" isn't a question I really understand.) But it helps ensure that people are at least requesting the genuine app, and if they get it then they'll get signature verification for future versions.
- Vinnl 8y agoAnd that's not even what Moxie meant by "harm reduction" - he meant that he wanted to stop people downloading APKs from random third parties, which has surely been pretty much accomplished.
- gruez 8y ago>Google Play use yalp store > Packages on F-Droid are reviewed by a human being and are cryptographically signed >The app has to update itself, using a similarly insecure mechanism. F-Droid handles updates and actually signs their packages so are all android APKs. granted it's trust on first use: it accepts any signature for the first install, and only enforces the signature if you try to install an update. >A checksum isn’t a signature, by the way - if your government- or workplace- or abusive-spouse-installed certificate authority gets in the way they can replace the APK and its checksum with whatever they want this is probably the only legitimate concern, to use f-droid so you have a permanent anchor of trust (f-droid, rather than whatever CAs you have installed) for the first install. this isn't even that big of an issue when you can install using yalp store. google might be a rootkit or whatever, but at least you can be reasonably sure that the apks are the originals.
- stratosmacker 8y agoThis doesn't even touch on the fact that Signal depends on Play Services. It has a websocket option, but the setting is actually not in the GUI
- Vinnl 8y agoHmm, how do you configure it? IIRC it just automatically used it because I don't have Play Services.
- craftyguy 8y agoAFAIK it's not user configurable, and the only way to enable it is to have a device without play services installed.
- UncleMeat 8y agoSo? Only an incredibly tiny population of android users aren't running play services. If your goal is to get as many people as possible to use e2e messaging, why spend time designing for the 0.001% of people who aren't running play services?
- wildchild 8y agoAny messaging app if it requires a phone number is a BS.
- bumholio 8y agoThe line about F-Droid doing no automated scanning is particularly troubling. Since he can't possibly imply that a Signal compromise would be detected this way, Moxie is making a political argument against the way people are using F-Droid to install other applications. He refuses - on principle, no less - the right for users to control their hardware and have full control over the software they install, and thinks the walled garden approach should be forced on every Signal user. Sorry, there is no excuse for Signal not to be available on F-Droid. I understand the automatic updates argument if it was valid at the time, but Signal has no right to impose what other applications I run and how I get them.
- Arnt 8y agoDoes F-Droid support reproducible builds now? Or does it offer any other kind of assurance that the software downloaded actually comes from the purported origin?
- bumholio 8y agoYes, they only publish the signed binaries produced from public sources according to a recipe anyone should be able to follow. https://f-droid.org/en/docs/Reproducible_Builds/ https://f-droid.org/en/docs/Reproducible_Builds/
- Arnt 8y agoThat's what Moxie does too, and F-Droid won't trust that. So what's different? Why are F-Droid's builds trustworthy?
- okatsu 8y agoI don't know anything about Moxie derailing threads or anything like that but if we just listened to critics all the time then we just wouldn't have anything. Signal is better than a lot of what is out there and being used as scale and that counts for something. More secure is always better than not secure at all.
- pmlnr 8y agoRead the end of an article as well. We have solutions like Matrix, and like XMPP with OMEMO.
- okatsu 8y agoSignal did what those things failed to do which is to actually gain some popularity outside of HN. I hope Matrix takes off! In the meantime if people are convincing their families and friends to get on Signal then that's a net positive to me.
- g_sch 8y agoSome version of this post seems to circulate every few months or so. This one is more direct in its accusations of Moxie acting in bad faith. I think this is disingenuous. Moxie has been very clear[0] about the tradeoffs that Signal has made and the reasons for them. It's fine to be dissatisfied with those choices. It's another thing entirely to accuse Moxie of dissimulating. Personally, I'd like to see Signal replace WhatsApp. That's why I support the path Signal took, and why I also have a distaste for the author's snarky dismissals of features like GIF search. [0] https://signal.org/blog/the-ecosystem-is-moving/ https://signal.org/blog/the-ecosystem-is-moving/
- djcrayon 8y agoCompletely agree, I have had several people move from various chat apps and texting to Signal largely because of the iMessage like features. Ultimately, I am now able to have more secure discussions with largely non-technical users which is good for everyone.
- lowry 8y agoI would agree with you if only Signal would not ask for so many permissions on my phone.
- tekromancr 8y agoCan you elaborate? I just set it up on a new phone yesterday and all it asked for on mine was; contacts (makes sense) files (to send pictures, files, etc) receive and send texts (if you want it as your default texting app/validating phone number via sms) Access to camera and microphone (for calls and in app photography) These all seem like reasonable permissions for the features available.
- staticautomatic 8y agoIs sharing your contacts mandatory in Signal? I don't use WhatsApp because I can't without sharing them.
- r3bl 8y ago> P.S. If you’re looking for good alternatives to Signal, I can recommend Matrix. Yes, if you're looking for alternatives to Signal, you should totally use a solution that hasn't rolled out end-to-end encryption by default[0]. /s ...and that only two clients have implemented so far, out of 50ish that they list on their website. [0] https://matrix.org/docs/guides/faq.html#what-is-the-status-of-e2e%3F https://matrix.org/docs/guides/faq.html#what-is-the-status-o...
- pmlnr 8y agoNonsense. You can run your own Matrix server and set whatever defaults you want.
- detaro 8y agoA Matrix server can force E2E on all messages passing it?
- pmlnr 8y agohttps://blog.cryptoaustralia.org.au/2017/03/21/run-your-end-to-end-encrypted-chat-server-matrix-riot/ https://blog.cryptoaustralia.org.au/2017/03/21/run-your-end-...
- masklinn 8y agoThat looks like a no given the article has a "Create a new secure room" section where you have to explicitly enable encryption for that specific room.
- pmlnr 8y agoe2e, by nature, is client specific. So Matrix, as a connectivity glue protocol, has nothing to do with it. Synapse, the reference server, can handle rooms, and force encryption on the rooms. p2p is client side. Riot, as reference client, is the one that takes care of this, and, if I get everything right, it is on by default.
- pmlnr 8y agoThe article actually proposes an alternative: Matrix, and Matrix is, in fact, a good piece of software, with federation options. I tend to agree with most parts of the article, especially the lack of federation options. My real pain point with Signal is that there is no real desktop application for it - no, a connected web interface is not a desktop application. For example, XMPP with OMEMO can be used simultaneously from Android Conversations AND Pidgin - same account, same messages (yes, it needs XMPP Carbons on the server), e2e.
- Vinnl 8y agoWhat do you mean by a "connected" web interface? And what would being a desktop application bring it? Signal Desktop is somewhat buggy, not that full-features, and doesn't integrate that well with the rest of my OS, but otherwise it's working fine, and I can use it simultaneously with my phone. (But I can also use it with my phone turned off, which I love.)
- pdkl95 8y ago> but otherwise it's working fine It doesn't work at all for me, because it requires a mobile phone number, which I don't have (a phone + any monthly subscription fee doesn't fit in a tiny fixed income budget).
- Vinnl 8y agoI don't think that has anything to do with the desktop app specifically?
- ezoe 8y agoSeriously, why do they use the smartphone in the first place? The smartphone ecosystem, be it Android or iPhone, is not secure. It can not be trusted. Even if we avoid Apple and Google's software distribution platform, Your smartphone still has binary blob kernel module, baseband processor and the OS runs on top of that. People who claims secure and trust on top of smartphone are all liar, idiot or both. Don't use the smartphone.
- kvark 8y agoUnless it's Librem-5 (https://puri.sm/shop/librem-5/ https://puri.sm/shop/librem-5/), although we've yet to see what comes out of it
- nickpsecurity 8y agoStill not secure. I describe the risks here: https://news.ycombinator.com/item?id=10906999 https://news.ycombinator.com/item?id=10906999
- craftyguy 8y agoMaybe not perfectly secure, but it's a big step up from the current devices. Being able to physically separate devices (e.g. baseband/modem) and toggle them off would allow you to obtain a much more secure environment.
- snikeris 8y agoIf your goal is to make secure communication possible for as many people as possible, you need to create an Android and iPhone app.
- UncleMeat 8y ago"Don't use smartphones" is not an effective method of getting people to communicate securely. We've had GPG forever. How many people used it? Also, for the large majority of people their smartphone is going to be more secure than their laptop.
- pron 8y ago> Truly secure systems don’t require trust. This is a chat app so, by definition, security requires trusting at least one other person. Also, I think experience shows that secrets can often be least trusted to those who have some interest in/use for them, with the secret owner often being the least trustworthy of all. So I'd say that if you trust yourself you're already probably trusting one of the weakest links in whatever chain of trust you would have. But seriously, pretty much every secure system requires trust, and the more it relies on technology, the more trust is required. You need to trust there are no backdoors or holes in a long chain of hardware and software that no one person can possibly verify, and if they hypothetically could, they could only hypothetically do so with the help of verification software that they could not themselves verify, at least not without dedicating a lifetime to that goal. Trustless security does not exist, and attempting to achieve it by adding more technological layers and more complexity reduces rather than enhanced security. We should make it easy for us to choose whom to trust, not work on a futile attempt to take trust out of the system.
- baby 8y agoI like Linus' argument, if you don't work with a web of trust then you're doing it wrong. In the context of mobile secure messaging the web of trust includes: I'm trusting every hardware component on my phone, I'm trusting Apple, I'm trusting the iOS code, I'm trusting the TLS protocol, etc.
- Boulth 8y ago> I like Linus' argument, if you don't work with a web of trust then you're doing it wrong I can't find the source for this, could you tell where did you take this from? (not saying it's not true, just curious to read the full text)
- baby 8y agoIt was a video on him talking to students and asked about security in the kernel IIRC. I'm on my phone now but if you find it please post the link :)
- 8y ago
- bilbo0s 8y agoPeople should just know by now, if you need to communicate something in private, you should just never use any electronic device that uses public networks. All of these "secure" tools that are being used must be understood in that context. They are "secure" against honest people. What I mean by that is that it's a lot like your home or apartment. Sure, you should lock your door and turn on your alarm system when you leave. At the same time, if you know there are three letter agencies surveilling you, it's probably wise to go ahead and assume they broke into your home and placed bugs in it despite your security precautions. Because they have.
- tabletopneedle 8y agoPeople still need to communicate with their peers in insecure networks. Now you need to compare the nitty gritty details and choose the most secure one for your needs. If you need content protection to keep dick picks out of NSA office circulation, Signal is probably the best. For metadata-free chat, Ricochet and Briar are currently the top duo.
- cwmma 8y agoFederation is not some sort of magic dust that would fix signal, you'd be just exchanging one problem (centralization) with another (spam). Plus in all likelihood even if they did federate, it would just be like email with gmail that the Open Whisper Systems is the dominant player so most conversations have at least one party running on Moxie's hardware.
- craftyguy 8y ago> one problem (centralization) with another (spam) I'd take the risk of possibly receiving more spam over the risk of depending on yet another walled garden.
- jMyles 8y agoI have recently switched to Riot (built atop Marix, which the author endorses at the end) for some family communications and yeah, I think I do prefer it to Signal.
- Vinnl 8y ago> Off the bat, let me explain that I expect a tool which claims to be secure to actually be secure. I don’t view “but that makes it harder for the average person” as an acceptable excuse. If Edward Snowden and Bruce Schneier are going to spout the virtues of the app, I expect it to actually be secure when it matters - when vulnerable people using it to encrypt sensitive communications are targeted by smart and powerful adversaries. I'm not so sure about this. I don't think Snowden and Schneier are praising it because it is the most secure application available that works for every threat model; I think they're doing it because it's the best attempt to up the security of the masses. In other words: there's a limit to its threat model. Signal makes it harder to do mass-scale surveillance, and allows e.g. whistle-blowers to contact journalists without standing out because they're using an encrypted messaging app. Yes, it's important to highlight those trade-offs, and one can always do better, but as far as I can see Moxie has always justified the trade-off with arguments that were not based on being self-serving. You might not agree with his conclusions, but I think it's unfair to accuse him of being self-serving. (Unless you mean "thinking about the consequences for the success of Signal" by "self-serving". It's not really clear how it serves Moxie otherwise, and the author doesn't go into detail about that.) In the end, I think it comes down to the author expecting different goals from Signal than the project itself has - as implied by his disdain for GIF search. Obviously Signal isn't only implementing features just to get more secure - it also wants to be widely adopted. It's just that the author apparently doesn't consider that as important.
- eighthave 8y agoI think Signal does a very good job at providing easy security for the masses. But for journalists and sources it can be dangerous since it is based on real phone numbers, and those phone numbers are sent to the server to be matched up. It is especially dangerous if the journalists and sources believe Signal is protecting them in that use case.
- daxorid 8y agoOWS's staunch refusal to permit anything other than phone numbers as identifiers should tell you everything you need to know about Signal. It is an authenticated, nonrepudiable communications platform using identifiers that are very difficult (possible, yes, but most people will get it wrong) to comprehensively anonymize. The ability to present nonrepudiable communications to a judge is precisely the wet dream of law enforcement officers, ambitious prosecutors, and despotic regimes everywhere. All they need to do is flip the people you're communicating with, and you're done.
- deleted 8y ago[deleted]
- 3pt14159 8y agoSignal is not for state-proof encrypted communication. Not large states like the USA or Russia. If you think it is, you've been misinformed. For state actor proof communications you need to evaluate every action you take and think: "What are the assumptions that I'm making here?" One assumption is that you're not currently on anyone's radar. Are you willing to bet the entire enterprise on this assumption? How certain are you? Are you 99.999% certain? Another assumption is that the operating system you are running the app in is not compromised on either end of the communication. 99.99%? Another assumption is that the screen isn't viewable by other devices. Another assumption is that the frequency of your key taps aren't picked up by a mic and then turned into intelligible letters. Another assumption is that the encryption algorithms you're utilizing haven't been subtly chosen to be intelligible to a single actor or that they'll stay secure once we have quantum computers. Etc. Etc. Etc. Signal is good because it raises the bar. Stock traders buying black information probably won't get your communications. They won't be scooped up in a email server leak. They wont be visible to your wife when she enters your phone's unlock code because they auto delete, and they don't get pushed to your iPad, like FB messenger[0]. But if you want to go up against James Bond, and you're already on his radar, you need to give up the illusion that anything computer related is fully trustable. Just pre-arrange some code words or OTPs and meet in person in an area without electronics or go even more old school and use dead drops with hand written communication. [0] I personally know 3 people that were caught cheating this way.
- lmm 8y ago> Signal is not for state-proof encrypted communication. Not large states like the USA or Russia. If you think it is, you've been misinformed. Ok, but in that case what does Signal offer that any random messenger with transport encryption doesn't? If your threat model doesn't include state actors then you can probably trust a) the HTTPS certificate infrastructure b) an international corporation like Facebook, so you can probably assume that no-one would tap your FB messenger messages in transit. "Not pushed to your iPad" sounds more like a bug than a feature - I want to be able to read my messages anywhere that I'm logged in as me (at least while I have my yubikey or what have you plugged into that device). Automatic deletion... eh, I would rather make a deliberate decision about when to delete things, personally.
- nailer 8y agoIs the .apk reproducible from the source?
- lorenzhs 8y agoIt is. https://signal.org/blog/reproducible-android/ https://signal.org/blog/reproducible-android/
- skywhopper 8y agoThis is a really poor post. Lots of in-the-weeds long-running-feud grudge holding snark, but no real examination of the issues at hand. And his assertions don't make sense in any case. You can't trust the Google Play store because a malicious actor might have swapped out the trusted roots on you. But then why should we trust F-Droid's signing infrastructure? Then he gripes that the posted APK has to be manually checksummed to use it. If you are truly paranoid, trusting a checksum you get from the same page you get a binary is as secure as ignoring the checksum altogether. But why would you trust a hidden signature process you can't see any more? How do you know your F-Droid binary was secure? But worst of all is this pointless assertion: "Truly secure systems don’t require trust." There are no truly secure systems. Malicious actors could replace your Matrix app with a lookalike clone. Your phone could have a hidden keylogger built into the OS. Or the hardware. The person's phone on the other end of your communication could have been compromised. You could be being monitored by all sorts of undetectable means. Perfect security is an unattainable goal, but good security requires acknowledging and enabling trust to play a role in the protocols and systems we develop.
- innerspirit 8y agoThe post is literally responding line by line to a post from 5 years ago. Very poorly thought out article.
- 4684499 8y agoSeriously, if Signal become decentralized and doesn't require a phone number to use, I'd switch to it without hesitate. Call me lunatic or whatever, all the court related news, security analysis only makes me feel Signal is just another honey trap or will become one eventually, because none of these positive reviews solves trust issues existed long ago. There are better models out there, they just don't want apply, I can't stop asking why. You'd think they'll re-consider the options after so many users expressed their concerns, or at least provide multiple choices, but no, it's been years, nothing has changed. I'd keep using Riot until then, even it's less secure and less user friendly, but it's good enough for me.
- JustSomeNobody 8y agoWhat's wrong with using Google Play Services? Correct me if I'm wrong, but I assume it has to do with message notifications. So, by using GCM, Signal would be leaking some metadata about when and who, etc. I assume. But wouldn't someone be able to get that same information from your ISP (with a little more work)? You're losing the benefits of longer battery life for basically nothing. Security isn't absolute. I don't know why this blogger has the attitude that there is such a thing.
- jhasse 8y agoIt allows Google to easily circumvent any end-to-end encryption since it's a rootkit.
- JustSomeNobody 8y agoHow? What mechanism? Does it access the plain text from the keyboard before the app encrypts it?
- jhasse 8y agoIt could do that.
- auslander 8y agoGoogle, APK ... if you're concerned about security, you would use Apple iOS only.
- jhasse 8y agoApple has root access to every device just like Google has to Android phones running Google Play Services.
- auslander 8y agoSecurity wise, Apple iOS is superior in any possible aspect to Android. Forensics people never complain how hard it is do Android, never :)
- jhasse 8y ago> Security wise, Apple iOS is superior in any possible aspect to Android. One aspect where Android is superior is that more of it is open-source.
- UncleMeat 8y agoGreat. Nobody cares. There are way more android users than iphone users. If your goal is to improve the security for the most people possible, you make an android app.
- 8y ago
- phyzome 8y ago« those are all really convenient excuses for an argument which allows him to design systems which serve his own interests. » I wish the author would actually lay out what they think Moxie's interests are.
- oyebenny 8y agoDoes Signal work in foreign countries? Like South America & Middle East for example.
- anderber 8y agoFor those looking for an open-source, private and secure messenger take a look at Adamant: https://adamant.im/ https://adamant.im/
- vectorEQ 8y agomost of these services aren't allowed to grow (i.e. not heavily invested in by the people with actual money) if they dont have some form of data mining or things like 'oops we facilitated key generatyion and kept all the keys' etc. If you want to securely communicate, either be smart about it outside of the app you chose. (encrypted or encoded with your own keys / tools where an app is just a medium of transfer) or create your own secure channels (not too difficult these days with good vetted open source implementations of crypto on multiple platforms...) I would say anyone who fully trusts any of these apps, and is worried about their privacy, is contradicting their worries with their behaviour. just google 'signal vulnerabilities' or that for any other of these apps... even if they have some good form of archntecture it's riddled with bugs... people can access your data. live with it, avoid it, or make the actual data incomprehensible for any 'eve' yourself instead of trusting another to do it for you.
- kup0 8y agoI don't prefer messaging apps that require phone numbers, they always feel less trustworthy to me because that one aspect of privacy isn't there
- alexnewman 8y agoWant to lose all faith in signal, try filing a bug fix as pull request - It probably will be ignored forever or shouted down - wanna notify the mailing list. Guess what you have to join rise up! Aka if you wanna file a patch to signal I hope you are ok with Joining an “anarchist” mailing list - Then when you are approved to make noises on the mailing list, it still gets ignored, no explainatiob 1 year later I removed the obvious bugs in the base64 implementation of signal
- throwawaymath 8y agoThe blog post states the following: > [Moxie] makes arguments which don’t hold up, derails threads, leans on logical fallacies, and loops back around to long-debunked positions when he runs out of ideas. Can anyone provide examples of threads where Moxie is acting like this? The blog post didn't give any.
- amai 8y agoIf you prefer obscure alternatives try: https://vsee.com/messenger/ https://vsee.com/messenger/ https://zangi.com/ https://zangi.com/
- trumped 8y agoSignal is at least as good as all the other cloud messaging apps... (privacy wise)
- lucb1e 8y agoSure but I think that is a given. The fact that it's "at least as [secure]" as something that stores chats in plaintext on their servers (Telegram) is not exactly news...
- deleted 8y ago[deleted]
- trumped 8y ago> The fact that it's "at least as [secure]" as something that stores chats in plaintext on their servers (Telegram) is not exactly news... probably news to most people... because most people appear to be trusting it....
- toast0 8y agoAFAIK, Signal has an open source client, and an open source server. If you want federation, you can go ahead and build it, and find users, and you can start from a reasonably well working base. Moxie isn't going to build it, because he doesn't think federation works; to convince him, you'll need to show him it works, not just tell him. Is there an example of a federated chat service which has end to end encryption that just works? Peer to peer chat is interesting, but it means that IPs of communicating users are more widely exposed -- now anybody in the network path between two users can see they're communicating with each other, not just that they're both communicating with Signal. I may not want to share my IP with some (or most) people I communicate with. Additionally, there's a lot of hard work around actually getting a peer to peer connection on today's internet, for a large fraction of connections, you're going to have to proxy packets for them anyway.
- dTal 8y ago> Is there an example of a federated chat service which has end to end encryption that just works? Yes. SilenceIM is a fork of Signal that maintains only the SMS implementation of the Axolotl ratchet. It works perfectly. For that matter, every other chat network does too, if you use Pidgin and the pidgin-otr plugin. End to end encryption is a property of the clients, not the network, practically by definition.
- toast0 8y agoSilenceIM and pidgin-otr add e2e over existing networks. That means I can attempt to send messages to people who won't be able to receive them. That is the opposite of 'just works'. With Signal, or other services, where e2e support is a mandatory part of the client and is the only way to send messages, if someone is available on the platform, I know that I'll have a e2e message stream. (subject to MITM of key exchange, of course)
- wpdev_63 8y agoIf signal was somehow federated(without a central server) and open source(which it is) then there's not much to not to trust. When they figure out a way to make signal serverless, then the only thing you would have to worry about is the OS of the phone and its underlying architecture... I have no doubt we will reach that point but I wish we get there sooner rather than later.
- qznc 8y ago> Truly secure systems don’t require trust. Security is something which only makes sense in relation to an attacker model. Only after you specified that, then we can discuss if something is secure or not. Signal is not secure if the NSA is after you. Signal is secure if your Chinese competitor is after your business data. Signal is secure if you are a journalist in Turkey.
- tabletopneedle 8y agoRemember that OTR, Cryptocat and PGP were secure enough when Snowden was agreeing about handing data to Greenwald and Poitras. So while Signal isn't secure if you're NSA's target, it might be secure enough to protect you from passive threat scanning.
- mnm1 8y agoIf the consequences of sending messages are torture and death, I wouldn't trust any form of electronic communication. That's what face to face meetings are for and have always been for. I did not think signal is insecure, but either party could be compromised in other ways like a key logger or other local software that intercepts messages on the device they are composed on. I certainly wouldn't trust any mobile os based app although desktop ones might not necessarily be better even if they both run on a Linux os that's fully open source. Most people are not up against such threats, so in most cases it doesn't matter. For the people that are, they are brave in using such software. I would never place my life in the hands of such software. I simply wouldn't trust any such software with my life. By comparison, the software in my car or on a plane is a different matter but it's also engineered to different standards and has proven itself in a verifiable manner--I haven't died after much driving and many flights.
- angry_octet 8y agoI would trust Signal on iOS, depending on who I was messaging. I'd turn on timed messages though, and the signal number wouldn't be my main phone number. Far less likely to be key logged on iOS. If you don't browse websites on the device that helps. You have to consider that face to face meetings are often observed by third parties, you can be tracked easily, extremely incriminating generally. The other person can talk, and provide evidence of your location. In comparison, sending a signal message is comparatively covert.
- mnm1 8y agoThe other person can show your signal messages to the wrong people just as well as they can talk about the conversation. At least with a conversation, you have plausible deniability although that may not count for much. You do also have to be careful of being recorded. Still, the point is, I would not trust a software platform. Ios or Android doesn't make a difference. They are both easily exploitable and have tons of security bugs no doubt, many that the biggest state actors are likely hoarding as 0 days for just such an occasion. There is no perfect solution.
- 8y ago
- noncoml 8y agoYou don't need to have absolute trust in Signal, you just need to trust it more than WhatsApp.
- INTPenis 8y agoI agree that Tox is better but at the same time I know people who truly need to stay hidden and they use Signal on a burner phone with a cash sim-card. That way it doesn't matter which medium the messages are transmitted over because it still can't be traced back to them. And as far as I know the encryption is solid. Unlike some other alternatives like Wickr Signal actually open sources their app and their communication protocol.
- tabletopneedle 8y agoUntil Tox defaults it's communication through Tor, it doesn't offer any notable differences. Sure, there is no central server, but intelligence agencies can see who you talk to without compromising server just by looking at the destination IP address of packets. Tox suffers from same MITM problems if the ToxID is changed e.g. on Twitter page of your contact, the same way the author of the article claims the "checksum" of Signal's APK can be changed by NSA, your employer or angry spouse.
- londons_explore 8y agoThis article is entirely about the Play store and F-droid. As a user, when an app claims to be 'secure', I expect the app itself to have made reasonable security tradeoffs. I don't however expect them to change my OS, my package manager, or anything else. The security of those other components isn't their concern.
- darklajid 8y agoI personally don't distrust Signal. I just refuse to use it. This comes up on HN a lot and everytime I have to admit that I am kinda unfair here: Signal is heralded as the nice and secure solution - but seems incomplete to me. I don't doubt all the more clever persons that tell me that Signal is the best choice for encryption right now. But as long as it doesn't support federation (I miss XMPP) and as long as it does require a phone number (None of anyone's business, not required for my contacts, a baaaad way to handle identification) it is utterly broken for me. I'll continue to use Telegram for family, friends and casual business stuff. The applications are awesome across platforms, I can initiate conversations with people without using a phone number. Worse encryption? Probably. Likely. Just as centralized? Yes - hate it there as well. But I hoped that Signal would be the solution. I'm unfair. Signal gets judged for NOT being open (federation, phone number). Telegram is just a random service that I use instead then - works better anyway.
- catdog 8y ago> But as long as it doesn't support federation (I miss XMPP) and as long as it does require a phone number (None of anyone's business, not required for my contacts, a baaaad way to handle identification) it is utterly broken for me. Why not simply use XMPP then? https://conversations.im/omemo/ https://conversations.im/omemo/
- leshow 8y ago> This is a strong accusation, I know. The thing which convinced me of its truth is Signal’s centralized design and hostile attitude towards forks. The thing that convinced you that Moxie feels a certain way is that Signal has a 'centralized design'. Please, if you're going to accuse someone of acting in bad faith with no evidence the least you can do is be honest about it. You have nothing but your feelings for proof of anything.
- topkeks 8y agohttps://twitter.com/matthew_d_green/status/1027566578559270912 https://twitter.com/matthew_d_green/status/10275665785592709...
- jmarinez 8y ago+1 I agree wholeheartedly wiht the concerns and complaints in this post. Even if you were to have the most trustworthy person leading a system like this, who is to say that this person's mind won't change. Or worse, a different successor could redefine the goals - this is created under a company after all. What's the solution? Trust in design.
- tptacek 8y agoDrew DeVault doesn't trust Signal because its Android incarnation uses the Google Play Store --- the app market virtually all of its real users use --- and not F-Droid. DeVault would also like it if Signal would interoperate with other chat programs. Instead, DeVault would prefer that you use Matrix, a system for which end-to-end encryption is (according to its own website) "in late beta", offered on a select subset of clients, and "not enabled by default"†. This argument is clownish and we should be embarrassed it's on the front page. There are people in the world that want to sysadmin their phones. It's a life choice they are free to make and I don't hold it against them. But the vast, overwhelming majority of users do not want to make the app market on their phone work more like Debian and less like the Play Store. Signal, to put it bluntly, does not care about the desires of the phone sysadmins. Even if they caved to the sysadmins, the application would, for virtually all its users, be no more secure. This bothers DeVault a lot, enough that he's constructed an entire psychoanalysis of Moxie Marlinspike to explain to himself how it could possibly happen that someone else on the Internet doesn't agree with him. Also, just as a note to DeVault: the point of end-to-end encryption is that you don't have to trust Signal's server. All it does is arrange for the delivery of messages, which are secured client-to-client. Compare Signal's server to Wire's, which --- last I checked --- retains a record of every pair of users who have communicated in the past. † When this was pointed out downthread, DeVault responded: "[o]ther alternatives (which I have not reviewed in depth) include Tox, Telegram, Wire, and Ring". Telegram is a particularly funny reference to make, because not only is E2E not the default there, but --- last I checked --- it can't even do E2E group chat. Telegram's owners are adamant that TLS is adequate for group secure chat.
- bufferoverflow 8y agoAdditionally, I'm pretty sure it's trivial to verify the APKs that Google Play serves are identical to the ones the devs published.
- xorcist 8y agoThat's not the interesting question. How easy is it to verify that the APKs are built from the published source code, without any added funny business? The F-Droid devs put a lot of work on reproducible builds. Not all software complies, but with an interest in information security there's no exucse not to. That's the use case of F-Droid, and comparing it to self publishing APKs without even as much as a GPG signature is so beside the point it borders on deceptive.
- syngrog66 8y agoSignal immediately asks for your phone number. Dead giveaway that they are not about privacy. So I assumed its a honey trap.
- bArray 8y agoTo be completely honest, Android should be considered as "insecure" for the same reasons. It's binary blobs that are hacked around by distributors with limited support after a year or so (when phones stop being manufactured and widely sold). Can we just get a proper Linux OS running on mobile devices already that's properly open source and easily re-flash-able? It's clear that ARM is here to stay and if Linux is to stay relevant, it needs to move towards support for one of the most popular computing devices on the planet. Desktops made their way into each home and mobile have made their may into each pocket. That way, running something like Signal would be more trust-able coming from a package manager, especially with something like Debian's reproducible builds.
- tabletopneedle 8y ago"Google Play Services lets Google do silent background updates on apps on your phone and give them any permission they want. Having Google Play Services on your phone means your phone is not secure." Yes, Google can install a backdoored version of Signal. This is bad. But if you can't take that risk, you can install e.g. LineageOS without Google Apps, download the source code, reproducibly compile the apk, and install it on your android. If you have a better idea, maybe it can be implemented. "A checksum isn’t a signature, by the way - if your government- or workplace- or abusive-spouse-installed certificate authority gets in the way they can replace the APK and its checksum with whatever they want." If they can add a certificate on your smartphone/PC, why can't they replace Signal with malicious one? Why can't they replace F-Droid? There is no 100% method to solve this issue, unless perhaps if you can meet with F-Droid developers, obtain the authentic public key from them to verify the F-Droid client's signature. Calling SHA256 cryptographic hash a checksum shows slight dishonesty on your side. The differences in connotations between the words are significant. F-Droid doesn't magically solve this problem. The root of trust comes from another SHA256 hash -- 61:DB:51:32:39:47:61:C4:D4:3F:8A:9B:AE:72:B0:2E:B0:8D:F3:B5:ED:F2:92:1C:7B:14:7E:2F:29:30:83:03 -- that authenticates the certificate of f-droid.org. Or it comes from the hash F3:33:D2:E7:FA:A3:68:7F:B2:99:3E:6D:F6:9D:EE:1D:DA:77:36:11:DD:CA:B3:3A:B6:79:87:AA:40:56:94:22 that authenticates the MIT's PGP key server that has the signature verification key for F-droid clients: https://pgp.mit.edu/pks/lookup?search=f-droid&op=index https://pgp.mit.edu/pks/lookup?search=f-droid&op=index All your suggestion does is, it adds a layer or two where we hope the NSA doesn't compromise them in case you'd want to use that chain to install and validate Signal. And even if you personally verify the authenticity of public key, you haven't solved the issue of private key exfiltration via hacking. You need expensive HW like HSMs to even start combatting exfiltration. And Google can afford those. "...centralized servers and trademarks." Of course you can't call a fork with the same or similar name as the original. You don't want malicious entities to create projects with names like "Signal Official Client" etc. Having distinct name helps both the fork and the original one. Centralized servers fix a crucial issue, shitty designs that linger forever. It also fixes the issue of having to deal with backwards compatibility indefinitely. Moxie can actually see what versions are still deployed, and push updates to most users. The idea here being, you don't have to support older protocols (e.g. the group chat had a big issue that was or is currently being worked on), implement backwards compatilibity that risks downgrade attacks etc. Let me give you an example. Riot decided to go with stupid, stupid base64 public key fingerprints. What happens here the only way to jump to smart choice of base10, is if all clients switch at the same time. If one client shows fingerprint in different base, it's not compatible. Sure, you can add a feature that lets the clients negotiate which fingerprint to use but then you need to get that deployed to every client. This happens really slowly, and it must usually follow the waterfall model with first deciding about these things on future revisions of Matrix protocol. And if you want to know how that will turn out, take a good look at OpenPGP research group: since SHAppening, they haven't even been able to agree on a new hash function for fingerprints. And once decided, that hash function will wait for years before the next revision of protocol is ready. Then you wait for it to be implemented in upcoming reference libraries and forks of those. And then you wait for them to be deployed in clients. Moxie changed all users' fingerprints from Base16 to Base10 -- my guess -- within a week by pushing the update. The advantage of agility is obvious. "But we have to trust that Moxie is running the server software he says he is." For content encryption, we absolutely don't have to trust him. For metadata, yes, we must trust the server runs the version that only collects registration date and some other minor detail, I forget. If you want to remove metadata, use Ricochet or Briar. Because Signal isn't lying about being anonymous by design, the only thing I think we can agree is, it should be stated in clear on their front page: "End-to-end encrypted, but not anonymous, we know your phone number and IP-address, and can see who you talk to, when and how much". "We can stop Signal from knowing when we’re talking to each other by using peer-to-peer chats." Yes, but that doesn't prevent global passive adversaries from seeing who we connect to directly. In some authoritarian country, the government could see Alice and Bob talk to each other. With centralized design, they only see connection to service providing domain fronting, or connection to Signal server at most. If you really wanted to solve this, you would run Ricochet or Briar. Federation is a horrible idea. I trust they are not interested in my metadata personally. I won't trust metadata of all my chats to a friend of mine who runs personal instance of Signal Server. He watches porn on that same computer. He downloads Russian game cracks to that computer. He has friends who are my enemies and vice versa. He has repressed personal grudges, reasons to fuck me over, or he doesn't have 50M in foundation money (and he'd prefer $5k over our weekend hang-outs that admittedly are getting boring) or strong cypherpunk ideology to prevent corruption. He's a chinese refugee who has relatives he loves in political prisons, waiting to hand out their organs to rich members of the political party, and he's being extorted for my metadata on his computer. His computer isn't patching itself automatically so there as RCE vulnerability that got him compromised by our common adversary. He clicked on wrong link, once. The number of threats is endless. Federated system doesn't distribute risks across hundreds of operators, it increases the attack surface tremendously, while dropping the number of targets the metadata of which is compromised at the moment. But I don't care about others, I care about the fact my friend doesn't have as good security as Google and Signal devs. Government agencies are really, really, really, really good at hacking and the trend is towards mass hacking. Having shitty servers makes that free because you can use exploits that should already be useless due to system updates. "Federation would also open the possibility for bridging the gap with several other open source secure chat platforms to all talk on the same federated network -" Yeah let's talk about that. Currently many Matrix channels lack end-to-end encryption because there is a backdoor: an IRC-bridge bot that leaks all conversations to non-end-to-end encrypted environment. Like you said: "Tradeoffs are necessary - but self-serving tradeoffs are not.", the possibility of having bots is extremely dangerous. The fact Matrix isn't end-to-end encrypted by default is horrible. The E2EE is in beta, and the fingerprint verification in clients suck. For the past three years I've been complaining about this, every time there is a developer assuring this will be fixed. This bug should never have existed in the first place. Now the users have come to accustomed to having the possiblity for briges to insecure systems. "but those are all really convenient excuses for an argument which allows him to design systems which serve his own interests." You should not make such generalized defamatory claims if you want to be taken seriously. I took this seriously at start but your arguments really lost their traction. It was another badly thought post that didn't show understanding of design choices and that hurt more than in helped: People might now switch to less secure Matrix protocol. Or they might even go with unaudited Tox, designed by non-experts.
- angry_octet 8y agoThe author is a delusional crank. He is very deliberately ignoring the very cogent arguments for the Signal architecture in favour of some specious moaning about how play store is subverted by the NSA. If you want a federated / onion-routed message transport, start coding. You can use the signal ratchet mechanism if you want, you just can't call the resulting shibboleth Signal. Distribute only by obscure methods, easily subverted by users installing malware versions with higher search rankings. Then stand back and watch as hardly anyone used your app.
- moogly 8y agoAs a Signal user, I just wish I could make my own personal fork of the desktop app and still talk to everyone without having to use the beta servers and fear of having access cut off, because the visual design and UX of the desktop app is absolutely atrocious. And the latest update that was pushed a few days ago was a massive step back; the bloated UI now looks like some iOS app from 2007. It's just embarrassing. And don't even get me started on the lack of a search function -- something the mobile client has.
- Vinnl 8y agoHmm, if you can improve the UI by yourself, could you not submit a pull request to do that? That would probably still allow you to use the improved UI without fear of having access cut off. (I wasn't aware of a redesign - just updated, and I don't really like it either, but ah well.)
- moogly 8y agoIn theory yes, but I don't think the team would appreciate any old random schmuck to change their product's look-and-feel :)
- sbmthakur 8y agoSlightly off topic: How do you convince your friends & family to switch to Signal from WhatsApp?
- sodosopa 8y agoWhere's the "This Post is Bullshit" button?
- r3vrse 8y ago> There’s an alternative to the Play Store for Android. F-Droid is an open source app “store” (repository would be a better term here) which only includes open source apps (which Signal thankfully is). By no means does Signal have to only be distributed through F-Droid - it’s certainly a compelling alternative. This has been proposed, and Moxie has definitively shut the discussion down. Adjunct to the rest of this discussion: just read through that GH issue and came away with markedly different conclusions than the author of the blog post. It reads like someone who is trying hard to justify and prioritize dev time/resourcing in the face of what is a demanding and vitriolic minority. No evidence of disingenuous intent or desire to push a particular agenda. I see nothing that would have prevented the old OSS adage: "if you want to see it, do it". Drew, I don't know you, or the background for the argument you're making, but it seems like you have something stuck in your craw here. Maybe take a little time and try to view the situation with fresh eyes? You're obviously passionate about this subject -- and the unique perspective is appreciated -- but it devalues the rest of the info presented, and I don't buy the precept you're proposing.
- alexnewman 8y agoAlthough signal has cash they need a lot more support. It’s a good time to remind people they are hiring