10 ms·
Some version of this post seems to circulate every few months or so. This one is more direct in its accusations of Moxie acting in bad faith. I think this is di
by g_sch 8y ago
Some version of this post seems to circulate every few months or so. This one is more direct in its accusations of Moxie acting in bad faith. I think this is disingenuous. Moxie has been very clear[0] about the tradeoffs that Signal has made and the reasons for them. It's fine to be dissatisfied with those choices. It's another thing entirely to accuse Moxie of dissimulating.
Personally, I'd like to see Signal replace WhatsApp. That's why I support the path Signal took, and why I also have a distaste for the author's snarky dismissals of features like GIF search.
[0] https://signal.org/blog/the-ecosystem-is-moving/ https://signal.org/blog/the-ecosystem-is-moving/
- djcrayon 8y agoCompletely agree, I have had several people move from various chat apps and texting to Signal largely because of the iMessage like features. Ultimately, I am now able to have more secure discussions with largely non-technical users which is good for everyone.
- lowry 8y agoI would agree with you if only Signal would not ask for so many permissions on my phone.
- tekromancr 8y agoCan you elaborate? I just set it up on a new phone yesterday and all it asked for on mine was; contacts (makes sense) files (to send pictures, files, etc) receive and send texts (if you want it as your default texting app/validating phone number via sms) Access to camera and microphone (for calls and in app photography) These all seem like reasonable permissions for the features available.
- staticautomatic 8y agoIs sharing your contacts mandatory in Signal? I don't use WhatsApp because I can't without sharing them.
- degenerate 8y agoIt would be great if it asked for those permissions when it needed to do something - for example ask for mic permission at the point you want to make your first voice call. I see some apps going that direction and it's refreshing. edit: Apparently, Signal does this for some things? See comment-replies.
- tialaramex 8y agoOn Android that's version dependant. Older Android versions only had the idea of the app declaring "I need to be able to use your Camera, read your Contacts, and make $$$ phone calls" and then you pick "No" and don't get the app or you pick "OK". This more or less railroads users into pressing "OK", except for the most security conscious, who go without the app. A few releases back Google had an unofficial feature that let you switch off features an app had, and it would get some dummy replacement, e.g. if it had Contacts access but you switched that off, it would see no Contacts at all. If it had Camera access, but that was switched off, it would always be told your Camera was busy in another app. Once word about this hidden feature got out, Google disabled it. Recent releases (Certainly on my Nexus 5X for example which is a while back) enable an app to ask at runtime. If you said "No" the app gets a second chance to explain itself, and then if you keep saying "No" the feature is just disabled and Android stops prompting you. The app might not work after that of course. Like the disabled older feature, the Settings pages for apps let you undo previous authorizations, again this may make certain apps malfunction - a map app with no GPS is merely crippled, but a "barcode scanner" with no Camera access is junk. However of course apps for an older phone don't prompt, the older Android can't handle it, so for them you still have to make the decision at install time.
- mrguyorama 8y agoThe permissions system that android apps use is entirely dependent on which API version you target. Last I understood, if you made a new app today and purposely chose to target an old API version, you could force it to use the "all or nothing", user hostile permissions query you described
- 8y ago
- dleslie 8y agoLast time I had it installed it scanned my contacts a half dozen times while I slept. I removed it in the AM.
- balladeer 8y agoTo be fair it does that to map you with the contacts who also are on Signal just like WhatsApp or Telegram does. Though you could also use Telegram just with user_names w/o phonebook permission but for signing up you need to use your actual phone number.
- jlund 8y agoThe Contacts permission is completely optional, and contact information is never stored: https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/
- ppjet6 8y agoThis seems like smoke and mirrors to me: Traditionally, in Signal that process has looked like: The client calculates the truncated SHA256 hash of each phone number in the device’s address book. The client transmits those truncated hashes to the service. The service does a lookup from a set of hashed registered users. The service returns the intersection of registered users. The phone number space is really not this big.
- hutzlibu 8y agoBut in the linked post he does not explain, why he does not maintain a F-Droid repository for people who do not trust google, nor why the original Signal Client does not connect to Signal Forks, even if they use everything the same. Security reasons? Ordinary smartphones are full of rootkits anyways, so someone using a forked Signal version probably is better of anyway, as he knows a bit more what he is doing. So the base argument holds in my opinion: Moxies main focus is Moxie in control. And not making Signal the best and securely possible. So I also use Signal, but as soon as Matrix gets stable, I am gone
- move-on-by 8y ago> Moxie forbids you from distributing branded builds of the Signal app ... Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction. > ... and if you rebrand he forbids you from using the official Open Whisper servers. This seems pretty fair to me. Not only could you abuse their resources, it would greatly hinder their ability to make changes and respond to protocol-level security threats. They aren't in the API business, controlling their ecosystem allows them to make forward progress without concern for 3rd parties that they have no control over. And still there is the issue of 3rd parties abusing their server resources.
- hutzlibu 8y ago"Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction" In this particular case, not likely. People who are into more secure communication do not randomly click on anything. They know what they are doing, or get it installed from people they trust. And if they don't - their fault. Not Signals. And Signal can continue to work and introduce breaking changes whenever they want. They simply only support the official build of Signal. Any person using anything different, cannot complain, if things stop working. (they will anyway, sure) And the ressouce-abuse. Can this really be a thing? I don't know in detail how the protocol works, but what can I do with the servers, I can't do with Signal anyway? Sending (encrypted) data from A to B. I can allready abuse that today, if I want.
- m-p-3 8y agoI am not willing to support Signal if they are unwilling to federate the system. Sure, it doesn't allow them the flexibility they'd like to have to move forward but in a way it won't be their fault if federated servers aren't keeping themselves up to date when there's a major protocol change and they get temporarily splitted from the pool.
- Tomte 8y agoYour „in a way“ is totally opposed to what normal users see. They will blame OWS when their Signal client that hasn‘t been updated in two years won‘t work.
- wrs 8y agoIt doesn’t matter whose “fault” it is — the issue is the practical effect that will result. This is exactly his point with the SMTP and GitHub analogy from the “moving ecosystems” post. Why do you think the split would be “temporary”? As long as “email” is a thing, as in “just send me an email”, and it’s a federated set of randomly updated servers, “email” will never have end-to-end encryption, because the first version of SMTP didn’t have it, and the user will still expect to send messages to a server running that version. Similarly, if “Signal” is going to be a thing, as in “contact me on Signal”, the entire network effectively has to operate at the level of the least up-to-date server — otherwise it’s not one network, and the product is therefore unreliable. But there’s no way to enforce that all the federated servers update themselves in any amount of time.
- x0x0 8y agoAlso, it's not like Moxie hasn't discussed this. At length. GP deliberately ignores Moxie's reasoned responses to exactly this issue.
- thecrash 8y agoTry to look at it from a user perspective, though. It's not a question of whose fault it is when something doesn't work, it simply doesn't work. Signal is successful in large part because it provides complex functionality (secure messaging) in a package that "just works". Federation complicates that significantly.
- balladeer 8y ago> I'd like to see Signal replace WhatsApp And one day we realise it was indeed something nefarious, let's assume something of this sort happened in the future, and then we rue that we didn't act when people used to say something was amiss. There is one line in the article that says it well: > Truly secure systems don’t require trust. edit: I have supported Matrix and Firefox among others (both in code as an Android dev and with modest donations - stopped using Firefox after Pocket). But no, not Signal. I'd wait for federation (if at all).
- SquareWheel 8y agoAgreed, though personally I find any support of animated gifs in the year 2010 and beyond to be counterproductive.
- bigiain 8y agoHow much non-geek non-privacy-activist socialising have you done via Signal? Without emoji and animated gifs, I suspect 70% of my Signal contacts wouldn't use it at all. It's hard enough to convince some of my friends to use it at all, "Can't I just Facebook message you?" For me, amongst my group of friends - it seems Moxy is making all the right security/usability tradeoffs. If you don't trust PlayStore, it seems not much of a jump to say you also shouldn't trust Android. If you're _rightly_ that concerned (and I'll note that Snowden recommends Signal, so I wonder what it is you're up to that makes you more of a nation-state target than him), I don't have a clue what your options are - I suspect they start with "don't use the internet at all"...
- SquareWheel 8y ago>I wonder what it is you're up to that makes you more of a nation-state target than him I don't know what it is you're talking about. The entire point of my comment was that I don't like animated gifs. They're distracting, bandwidth intensive, and could be easily replaced by a dozen better image formats.
- bigiain 8y agoSorry - I hadn't intended to aim that accusation at you specifically, but at people who are "more of a nation-state target" than Snowden. Poor sentence construction on my part there... And while I agree with you about animated gifs, I understand WhisperSystems reluctance to try and become the force that turns non-geek non-privacy-activist users (which they and I are hoping will widely adopt Signal) to find WebP or flif or whatever alternatives to giphy or where ever else they're finding their reaction gifs and topical memes and funny cat-riding-a-roomba animations from. That's how a _huge_ percentage of users want to communicate with each other. Moxy is trying to give them a secure way to communicate how they want to, not attempting to force them into new ways of communicating that have boring justifications like "bandwidth saving" or "animation format technical merit" as the only reasons why they can't have vast libraries of funny animations to send their friends... If they can't quickly reply with Ru Paul doing fingersnaps in Signal, they'll go do it on Facebook instead. For that reason, I'm of the opinion that _not_ supporting animated gifs is significantly more counterproductive, if you're trying to become "the secure messaging mechanism the whole world will use" or if (like me) you'd like more and more personal communication to be exclusively between the participants, and not include advertising networks and data miners and sentiment analysers (and, yeah, law enforcement and government bureaucracy)...
- ggg9990 8y agoIt’s not surprising. The people most interested in encryption want to trust nobody. That’s the goal of strong encryption, but as Ken Thompson says it’s not possible. Between the US Government and Moxie I’d trust Moxie but I’d rather trust neither.