6 ms·
Sometimes you just feel like using Signal instead
by cloudyo 7y ago
Sometimes you just feel like using Signal instead
- maxton 7y agoWho's to say Signal will protect you any better against targeted remote-code-execution attacks from well-funded cyber mercenaries like NSO?
- stjohnswarts 7y agoHow many people actually worry about these spy agencies? If a state actor wants you or your information they'll just pull up in a black van and take you and use a $5 wrench to beat it out of you.
- criley2 7y agoI get the implication but America isn't Russia and they just don't do it, too big of a headache, too easy to blowback into political realm. Officers hate when clandestine work erupts into public political drama. Plus, why would you hire a team of people to kidnap a citizen and beat them when you can assign a ticket to a government blackhat at the NSA who will run the commands against your devices and take what they need without you ever knowing. Even then, there is substantial risk of whistleblowing for illegal data collection against citizens (Snowden et al) so they would instead in a clandestine manner ask a fellow member of the Five Eyes to perform the surveillance "legally". Our society has known about Five Eye roundabout spy agreements for a long time and has largely shrugged, so the risk of public political blowback doing this would be minimal.
- lashkari 7y agoI get your point that a highly-motivated attacker has other, less sophisticated, ways of getting to your data. However, if we're playing poker and I learn your tell, it's in my best interest that you are naive to that fact. While not the best analogy, I would think that the same concept would apply to state actors.
- goatsi 7y agoThe state actor will have a more difficult time doing that if you are living in a different country. Exploits don't care about borders: https://www.voanews.com/africa/ethiopia-accused-using-spyware-against-citizens-living-abroad https://www.voanews.com/africa/ethiopia-accused-using-spywar...
- roywiggins 7y agoMuch of what NSO Group does is sell to smaller despotic regimes who then use them to spy on dissidents who live abroad and would be quite hard (and embarrassing) to black-bag. Not everyone can send a murder team to Stockholm (or wherever). Some despotic regimes do have large kidnap-and-murder programs (ex Rwanda) but if you just want to keep tabs on exiled dissidents and learn exactly who they're talking with back home, NSO Group has a product for you.
- JohnFen 7y ago> How many people actually worry about these spy agencies? I don't really worry about the spy agencies themselves -- I am not of any interest to them. However, I worry a lot about the likes of NSO and the tools they produce. They are likely to end up being used, in one form or another, by criminals and corporations.
- wp381640 7y agoThese tools keep authoritarians in power and indirectly impact hundres of millions of people. It's like saying you don't care about pacific ocean plastic because you live on the east coast.
- heavenlyblue 7y agoHow’s that different from selling weapons to them, though?
- wp381640 7y agoIt's not - we shouldn't be selling weapons to them either. Ditto with sharing intel. Sanctions on selling exploits seems easier to achieve though since there is less of a conflict with economic interests
- JohnFen 7y ago> These tools keep authoritarians in power Indeed. I think I covered that in "criminal" category, but perhaps I should have been more explicit.
- peatmoss 7y agoYeah, I pretty much assume that targeted attacks will always succeed when a well-funded state actor is involved. For me, I look at encryption as a mitigation for surveillance. Anything that increases the marginal cost to monitor an individual makes broad surveillance less economic. Signal will always have the edge for surveillance due to the relative difficulty of hiding a back door. Whatsapp will always be suspect in that they could easily be forwarding everyone’s messages to third parties.
- blotter_paper 7y agoI mean, Signal is open source and not owned by Facebook, so I'm not sure why anybody uses WhatsApp instead.
- vocatus_gate 7y agoIt's a much better app, user experience-wise. I prefer Signal for obvious reasons, but WhatsApp is easier to use (and has a much better web interface).
- Canada 7y agoI agree, but when the people you want to talk to are on WhatsApp already...
- maximente 7y agothey have features signal has not yet copied and probably won't (statuses e.g.)
- dylan604 7y agoThe main one being actual users
- shantly 7y agoLast I checked Signal's UX was worse enough that I'd be fighting a real uphill battle to get my friend group to switch.
- blotter_paper 7y agoThat's reasonable, I suppose I'm lucky to have a friend group that universally prefers open source sorftware to good UX -- there was never really a question for us.
- smeyer 7y agoIt's a little eye opening to me that anyone could have a friend group that "universally prefers open source software to good UX". I have and use Signal with some friends, but there are also loads of people I communicate with who couldn't even tell you what open source software is, let alone articulate a preference for it over good UX. Are all of your friends software engineers and/or technophiles?
- godelski 7y agoNot that I'm dissing Signal (it is my preferred platform, sadly not most used), but don't both WA and Signal use Open Whispers systems? So isn't there the potential that the same exploit might work on Signal?
- vocatus_gate 7y agoWhatsApp allegedly uses an implementation of the OpenWhisper encryption system that Signal created (and still uses). However as there is no source code available unlike Signal, there's no way to verify if WhatsApp "really" is using it (or using it correctly).
- kingbirdy 7y agoCouldn't you determine by looking at the code in the APK, at least for Android?
- e12e 7y agoYes, "no way to verify" is a bit strong. Not as easy to verify is true (but: if you review the source, you'd also have to build the app yourself).
- mosburger 7y agoIt might be a bit difficult (but not impossible) to do that... the APK you download is not the APK that the developer uploads to the Play store. Usually, developers upload a "bundle," and then Google optimizes it by stripping out irrelevant media, i18n, etc., to deliver a smaller optimized APK to the end user. So you can't just generate an MD5 of your APK and match it against the store description like the good old days when you could make sure your Linux ISO was legit, but there's probably some way to make it work? EDIT: It might be possible to circumvent Google's bundling/optimizing by just uploading a regular old APK, but IIRC that was becoming more difficult these days. Unfortunately I'm not an Android dev expert.
- godelski 7y agoThis is true, but that also doesn't answer the question. It still leads to a possibility. The hack could also sidestep OW in some other way and only be WA specific, but still begs the question. Security is a constant cat and mouse game, so if someone says: "well, that only affects WhatsApp, it won't affect us -- even though we use the same underlying structure." sounds kinda naive.
- milofeynman 7y agoWould this attack have been preventable with signal?
- nullc 7y agoSignal's software is timebombed to force you into taking automatic updates. These updates could be used to force targeted users into backdoored builds. Additionally, the signal has had a long history of being feature hostile to strongly secure use, through things like making it very difficult to cryptographically verify the identity of the party you're talking to... or automatically resending the last message you sent when the far end merely claims its key has changed. I recommend people treat signal as unencrypted communications-- _actually_ unencrypted private communications are too absurdly insecure to use. But in practice signal does not provide the kind of strong security that we would associate with 'encrypted communication', and maybe UI considerations make that an unrealistic goal. Instead signal provides the kind of security we should expect from _ANY_ communication, but which isn't actually provided due to pervasive surveillance.
- dependenttypes 7y agoThere have been a few electron vulnerabilities that affected signal. Plus signal demands that you have a phone number in order to use it. Also the fact that each device has its own key promotes the users to just blindly accept new keys.