5 ms·
What happens to Signal when the EARN It Act passes? I assume that eventually the Apple App Store and Google Play Store will just stop allowing it to be download
by DaftDank 6y ago
What happens to Signal when the EARN It Act passes? I assume that eventually the Apple App Store and Google Play Store will just stop allowing it to be downloaded if they do not add the backdoor in? Is there a workaround that will allow people to use it still? I've heard people mention locating the servers in other countries, but wouldn't the various App stores be bound by US law and still not allow them?
- EGreg 6y agoWhen? Or if?
- s17n 6y agoI don't think that the earn it act will affect Signal - they aren't a publisher by any reasonable standard so they don't need the 230 exemption in the first place.
- chrononaut 6y agoAs I don't know much of the details of the legislation, or more importantly its references or modifications, can you elaborate more on what "they don't need the 230 exemption" means in the context that this act would likely not apply to them? Are you implying that the EARN IT act focuses on publishers of content and thus it less likely apply to Signal?
- Skunkleton 6y agoDisclaimer: IANAL, an not really well informed on these subjects. I think with sufficient funding for a legal department, Signal could work without the section 230 exemption. In practice, they don't have that money and would be forced out of business long before they were able to prove their case.
- billme 6y agoSignal’s official statement on the EARN It Act is here: https://signal.org/blog/earn-it/ https://signal.org/blog/earn-it/
- nickthemagicman 6y agoThanks for the link. There's a subtle threat in there, that they'll move out of the country if they have issues which I think a lot of tech companies would. This bill is so stupid in that tech companies can relatively easily move.
- m52go 6y agoThe legal entities can move to other jurisdictions, sure, but it doesn't matter because app distribution still occurs primarily through USA-based Google Play and USA-based Apple App Store—both of which can easily geofence apps as they please (or as they're required). This is one of the reasons I've started to appreciate Matrix a lot more lately. https://matrix.org/blog/2020/01/02/on-privacy-versus-freedom https://matrix.org/blog/2020/01/02/on-privacy-versus-freedom
- billme 6y agoPutting aside Signal officially declining to the add option to discover or manually add a server via the client, theirs nothing stopping anyone from going to GitHub, downloading the code for the server and client, editing the code however they see fit as long as it follows the legal guidelines.
- CGamesPlay 6y ago> long as it follows the legal guidelines. So like, as long as they add in the backdoor?
- deleted 6y ago[deleted]
- jayp1418 6y agoNope. But following GPL open source license guidelines and releasing your changed codes. And not using signal name and their copyright materials.
- solinent 6y agoSignal started open-source, it was TextSecure, I'm sure there'll be an open-source alternative if the commercial entity fails, though I hope they do not.
- billme 6y agoAs far as I know, while the DevOps code is not open source, the server and app code are on GitHub; that is you’re able to roll your own version however it defined by the licensing; recent attack on Signal by security researcher used a self-compiled app as a proof of concept; Signal patched the issue.
- jlund 6y agoJust to clarify, the bug you're talking about was in WebRTC. We submitted a patch upstream: https://webrtc-review.googlesource.com/c/src/+/175960 https://webrtc-review.googlesource.com/c/src/+/175960
- billme 6y agoRight, here’s another comment on the topic by Signal staff too: https://news.ycombinator.com/user?id=pthatcherg https://news.ycombinator.com/user?id=pthatcherg
- solinent 6y agoI didn't mean to imply Signal wasn't open-source, just that it was based on TextSecure and can be forked. If the commercial entity fails or is held liable, we just need a distributed profile system, should be easy enough.
- loeg 6y agoSignal is still open source and is not a commercial entity.
- solinent 6y ago> Signal Messenger, LLC, is a software organization that was founded by Moxie Marlinspike and Brian Acton in 2018 Did you google it? You're simply wrong. It is open-source as it was, I didn't dispute that, but they are liable for their users if this bill passes, and they will easily go bankrupt. If there's no commercial entity, then liability falls to the developers most likely--whose identity can be obscured since they're developing Signal hopefully. https://www.corporationwiki.com/p/31jiai/signal-messenger-llc https://www.corporationwiki.com/p/31jiai/signal-messenger-ll... They have a standard corporate structure--based in Delaware, registered as a Foreign entity in California.
- graham_paul 6y ago> the Apple App Store and Google Play Store will just stop allowing it to be downloaded Time for a privacy focused app store!
- bilal4hmed 6y agoat least on Android you can sideload it
- Mediterraneo10 6y agoI recall reading something recently about how in a coming release, Android will disable sideloading. The sole permitted way to sideload will be to enable ADB and then install the app with adb install. Some techies will continue to do that, just like some people unlock the bootloader and install LineageOS on their device, but removing Signal from the Play Store would make it as good as dead for the general public. (Even Signal’s website discourages people from downloading the APK from them, and prefers that people use an app store instead!)
- trishmapow2 6y agoSome googling leads to this [1]. From what I read it seems to be an opt-in program (for now). Was initially very concerned when I read your post, especially because Google recently broke Magisk (likely forever). [1]: https://www.xda-developers.com/google-advanced-protection-play-protect-sideloaded-apps/ https://www.xda-developers.com/google-advanced-protection-pl...
- Multicomp 6y ago> Google recently broke Magisk (likely forever) Can you give more details on this? I wasn't able to find anything with google-fu except this post, which is surprising.
- trishmapow2 6y agoBasically Google has actually implemented remote attestation properly (using hardware) so Magisk can't hide unlocked bootloaders anymore unless someone finds a crypto flaw. It's slowly being rolled out to Play Services but I believe cts still passes for now. https://www.xda-developers.com/magisk-no-longer-hide-bootloader-unlock-status/ https://www.xda-developers.com/magisk-no-longer-hide-bootloa...
- tssva 6y agoNo work around needed on Android. It allows installation of apps outside the Google Play Store.