11 ms·
I don't trust Signal (2018)
- bitxbitxbitcoin 6y agoI'd love to hear/see the 2020 reasoning for not being on F-Droid.
- Pick-A-Hill2019 6y agoNot relevant but since F-Droid has been mentioned in the context of it. F-Droid is based in the UK and their accounts are over-due. 'Free' does not exist forever. https://beta.companieshouse.gov.uk/company/08420676 https://beta.companieshouse.gov.uk/company/08420676
- Pick-A-Hill2019 6y agoOriginal from 2018, 467 comments https://news.ycombinator.com/item?id=17723973 https://news.ycombinator.com/item?id=17723973. Not commenting as snark (reposts are ok after all) more to save Dang digging out the link and also to see how many more or less duplicate sentiment comments are made and / or how perceptions have changed.
- ColanR 6y agoI thought that first comment had some inappropriately personal things to say about ddvault and his article. It also seemed like they didn't really respond with substance to the what the article said.
- tptacek 6y agoWhat substance in the article did I miss? Unlike the author, I stand by what I wrote originally. I'll note the irony of calling my critique overly personalized, when the original article is based on the logic that Moxie's disagreement with DeVault's opinion about F-Droid --- a controversy that is meaningful to less than 1% of Signal's Android user base --- implies inexorably that Moxie is untrustworthy and disingenuous.
- 4ad 6y agoAfter the PIN/Intel SGX debacle, I trust Signal even less.
- AnonHP 6y agoSeems like I missed this a month ago. I'm now catching up from Matthew Green's blog post. [1] [1]: https://blog.cryptographyengineering.com/2020/07/10/a-few-thoughts-about-signals-secure-value-recovery/ https://blog.cryptographyengineering.com/2020/07/10/a-few-th...
- codethief 6y agoThanks for posting this! I had been waiting for Matthew Green's reaction.
- codethief 6y agoFor anyone who doesn't know what this is about: https://community.signalusers.org/t/dont-want-pin-dont-want-anything-stored-in-cloud/14057 https://community.signalusers.org/t/dont-want-pin-dont-want-... https://community.signalusers.org/t/mandatory-pin-without-clear-explanation-within-the-app-might-cause-significant-number-of-users-to-quit-using-signal/11597 https://community.signalusers.org/t/mandatory-pin-without-cl... TL;DR: - Signal introduced mandatory PINs to store certain user information (profile, contact list) on their servers in an encrypted fashion (protected by the user's PIN and, if the user chooses a short PIN, Intel SGX enclaves that Signal uses) - PIN UI was/is exceptionally bad, didn't explain what PIN was for and came with annoying Do-you-still-remember-your-PIN popups which made zero sense when user chooses long passphrase. - Most importantly: If user chooses a short PIN, protection of their information will hinge purely on Intel SGX enclaves. But: The PIN UI didn't recommend choosing a long passphrase and also didn't explain this point. - Lots of users didn't want any of their information on Signal servers to begin with, were annoyed by popups and/or didn't trust SGX and ran amok (see the above two links) - It seems PINs can now be disabled[0] [0]: https://support.signal.org/hc/en-us/articles/360007059792-Signal-PINs#pin_disable https://support.signal.org/hc/en-us/articles/360007059792-Si... For more details, see the post by Matthew Green that was posted in a sibling comment.
- shakezula 6y agoWhat's the alternative to Signal then? For iOS users?
- sneak 6y agoThere is no alternative that provides the ease of use and privacy guarantees. I think the OWS/Moxie hate is misplaced. They’re competing with iMessage and WhatsApp and Instagram and Facebook, and Signal is a much better option than all of those. Let’s be honest: the alternative is that Facebook gets all of our chats in cleartext.
- ColanR 6y agoI think Drew responded to that. I thought this was a key quote: > Off the bat, let me explain that I expect a tool which claims to be secure to actually be secure. I don’t view “but that makes it harder for the average person” as an acceptable excuse. If Edward Snowden and Bruce Schneier are going to spout the virtues of the app, I expect it to actually be secure when it matters - when vulnerable people using it to encrypt sensitive communications are targeted by smart and powerful adversaries....it’s your responsibility to clearly explain the drawbacks and advantages of the tradeoffs you make. If you make broad and inaccurate statements about your communications product being “secure”, then when the political prisoners who believed you are being tortured and hanged, it’s on you.
- tptacek 6y agoWhich is pretty rich, because in the post where that quote originally appeared, the author recommended as an alternative to Signal a tool that wasn't even end-to-end encrypted by default.
- Shared404 6y agoA) I see that nowhere in this post, so the author must have retracted it when he found that out. B) Matrix has always been very easy to set up E2E C) Matrix is now E2E by default, at least with the client non-technical users will be using. I think it is for the other clients as well, but I do not know for sure.
- sneak 6y agoI really don’t think OWS has the authority to stop forks from using the Signal servers, any more than YC has the authority to dictate that I use Chrome to view HN. There is, of course, the vague language of the CFAA, so I’m not sure I’d want to test this theory, but his demands that forks not use the main centralized servers are, in my opinion, unenforceable bluster.
- myrion 6y agoMight be unenforceable, but they don't have to cater to them and can and will break forked clients for however long it takes those to catch back up. And then Signal gets flak for not hobbling their development processes to the speed of the slowest (somewhat popular) fork.
- ddevault 6y agoThis doesn't have much value without federation, which would require active support from OWS.
- tptacek 6y agoYou can literally just look at Matrix, the tool you recommended, to see the problem with federation, fragmentation, and market demands to support lowest-common-denominator security. It took years after your recommendation for Matrix to have universal default E2E, the table-stakes feature of a secure messenger.
- ddevault 6y agoAre you going to back this up with evidence, or is it okay when you use axiomatic arguments? "It took a while" is not actually an argument that the procedure is wrong or less correct, in case you were unsure.
- tptacek 6y agoIn fact, it is an argument that you were wrong, and the evidence for that is that when you made the argument, and for two whole years afterwards, your recommendation would have put vulnerable users on a platform that was for many users default-plaintext.
- deleted 6y ago[deleted]
- f0ff 6y agoAs to the interjection that Signal is lacking a FBI canary - Moxie was clear on the subject: https://web.archive.org/web/20141027143819/https://github.com/WhisperSystems/whispersystems.org/issues/34 https://web.archive.org/web/20141027143819/https://github.co...
- LinuxBender 6y agoThe lawyers at my workplace have the same opinion as the lawyers Moxie spoke with.
- ColanR 6y agoThe EFF reference at the bottom of that link provides a useful alternative position: > What’s the legal theory behind warrant canaries? > The First Amendment protects against compelled speech. For example, a court held that the New Hampshire state government could not require its citizens to have “Live Free or Die” on their license plates. While the government may be able to compel silence through a gag order, it may not be able to compel an ISP to lie by falsely stating that it has not received legal process when in fact it has. > Have courts upheld compelled speech? > Rarely. In a few instances, the courts have upheld compelled speech in the commercial context, where the government shows that the compelled statements convey important truthful information to consumers. For example, warnings on cigarette packs are a form of compelled commercial speech that have sometimes been upheld, and sometimes struck down, depending on whether the government shows there is a rational basis for the warning. > Have courts upheld compelled false speech? > No, and the cases on compelled speech have tended to rely on truth as a minimum requirement. For example, Planned Parenthood challenged a requirement that physicians tell patients seeking abortions of an increased risk of suicidal ideation. The court found that Planned Parenthood did not meet its burden of showing that the disclosure was untruthful, misleading, or not relevant to the patent’s decision to have an abortion. > Are there any cases upholding warrant canaries? > Not yet. EFF believes that warrant canaries are legal, and the government should not be able to compel a lie. To borrow a phrase from Winston Churchill, no one can guarantee success in litigation, but only deserve it.
- ncmncm 6y ago
- ncmncm 6y agoI reacted to previous posts about this by installing Element (was Riot.im; search for both words) matrix client, setting up a periodic donation to privacytools.io, and making accounts with that as homeserver (chat.privacytools.io) for me and for the rest of the family. (Previously, I had a Librem.one account, but they don't maintain their server, so I dropped it.) It works... Still waiting for anyone else I know to come over. Element really needs to set up as an optional SMS handler, on phones. Probably building in a Signal gateway is needed too. Signal would be nowhere today if it didn't also do SMS. Separate gateways are too clunky.
- ddevault 6y agoMatrix does pretty well in terms of privacy these days. As for privacytools.io, I can't really agree. They have made a number of suggestions which are less about actual privacy and more about a trend I've come to think of as "privacy roleplaying" - trendy software & services which use privacy and security as a selling point but whose implementation doesn't back it up. An example is Protonmail. When it comes to the privacy vs usability debate I come down hard on the side of privacy. Doesn't matter how pretty it is if it's going to get you rubber hosed.
- ncmncm 6y agoThis is useful information. So, not librem.one, not privacytools.io, then... Maybe that leaves a homeserver of my own? I guess I am glad no one has picked up my current address. But it doesn't bode well for adoption. I had thought that parking on a homeserver was not trusting them.
- Funes- 6y agoI only use phone calls (sync) and e-mail (async) nowadays.There's no other communication channel I would need. I'd only be willing to substitute them with their encrypted, P2P, and open-source counterparts, if they ever come into existence. Texting, on the other hand, used to be the bane of my existence, as--especially in its current form (free, nested layout, etcetera)--it's one of the most distracting, inefficient, absurdly redundant and useless communication mediums I know.
- core-questions 6y agoYou could have substituted email for its encrypted, P2P, open-source counterpart for almost 30 years now. It's called PGP / GnuPG. What more do we really need? It actually has more legal protection and formality, and way more clarity, than any centrally managed "E2EE" chat platform. We just need a really good app that uses SMTP as the underlying protocol to send messages that aren't MIME / HTML email, but rather are a simple new format for chat, and then start using email as a chat mechanism. There's no real reason why it can't be fast enough.
- frabbit 6y agoSignal falls into an uncomfortable place for me. I like pre-paid cellphone plans which give me a small number of text messages, a small amount of airtime. Using these I can communicate with people when I am not near a WiFi AP. I do not want to pay for data and would prefer to use my and my friends' access points and the free wifi in the small number of commercial locations that I visit. In Canada all of the major carriers disable WiFi Calling² on pre-paid plans. They essentially only enable it as crutch to leach off public infrastructure to take up the slack on their insufficient private infrastructure. So I infrequently (but enough to be annoyed) find myself in the situation that I am not near a WiFi access point and wish to communicate with someone else. Currently Signal will only allow me to do this via insecure SMS messages. I read their original explanation in 2015 for disabling this functionality. Namely SMS leaks too much metadata¹ and we are only catering to needs of real-activists in real-dictatorships, and anyway SMS is too expensive there so this is a 1st World Problem. As an explanation it leaves me wondering why I would bother with Signal: if I bite the bullet and sign up for a circa CA$50/month plan with data I may as well just use Element Matrix over WiFi. Signal brings nothing to the table except the possibility of accidentally sending an insecure SMS message and incurring a 30c charge for it. 1. https://signal.org/blog/goodbye-encrypted-sms/ https://signal.org/blog/goodbye-encrypted-sms/ 2. https://support.signal.org/hc/en-us/articles/360007321171-Can-I-send-SMS-MMS-with-Signal- https://support.signal.org/hc/en-us/articles/360007321171-Ca...
- redthrow 6y agoIn Canada, Fido has $10/m + tax "Tablet Plan" which can be used on phones and gives you 4GB/m data
- frabbit 6y agoI appreciate the suggestion but had already experienced the issue that WiFi Calling did not work with my unlocked Nexus5, similar to this: https://forums.fido.ca/t5/General-Support/Wifi-Calling-worked-amp-stopped-working/td-p/98186 https://forums.fido.ca/t5/General-Support/Wifi-Calling-worke... As noted on this article, your compatible device must have been purchased from Fido. If you have a non-Fido device and no conflicting services, Wi-Fi Calling may work, but we can’t assure that the feature will work properly! Without WiFi Calling enabled sending Secure Signal messages will not work. The only option left is sending a normal insecure SMS to which the message text has been input using the veneer of the "secure" Signal app.
- daneel_w 6y agoI trust Signal's end-to-end encryption promise, but I have a problem with the application not offering anonymity or privacy. By demanding users to provide a cell phone number to enable their accounts, they are connecting actual people to the Signal accounts and consequently also allowing them (or someone else) to visualize social networks; in intelligence gathering, data such as who speaks to whom, at what hours, with what message frequency etc. is highly valuable. It's also important that users ask themselves how Signal manages to finance all the SMS costs and the infrastructure when the application is gratis and free from ads.
- daneel_w 6y agoJust to add... yes, I know it's possible to register a Signal account with a disposable VLN, but how many Signal users can be expected to be "tech literate" to this level? Practically none.
- msy 6y agoGiven the demographic Signal attracts that seems like an unsafe assumption.
- Shared404 6y agoI would guess that a significant portion of Signal's users are non-technical people dragged there by their technical friends that couldn't get them onto Matrix. I would still guess that none is a bad assumption, however. Edit: Spelling
- daneel_w 6y agoPractically none. I think it's safe to assume it's not even 1 in 1000 who have registered with a VLN, or even know what one is.
- Shared404 6y agoYou raise a valid point. I would think that probably more than 1 in 1000 would know, but suspect you are right about how many actually would do it.
- jszymborski 6y agoI love Mr. DeVault's work, and think he consistently shows integrity in his work, to say nothing of his incredible productivity and engineering. That said, in my time following his blog and Mastodon toots, he's prone to making these hot-takes that take down successful projects that do a lot of public good, but don't tick every check. His repeated criticism of Mozilla is a good example of this. It often feels like cutting off ones nose to spite the face. Without the Mozillas and OpenWhispers of this world, we've no hope for the DeVaults which create incredible feats of engineering that tick all the ideal boxes but lack some of the creature comforts (e.g. sr.ht, wayland, etc..) I'm optimistic for the future, and the projects started by Moxie and DeVault are a large part of it.
- ddevault 6y agoI appreciate your feedback, and I try to be more balanced with this kind of article these days, and publish them less often. However, I'd like to point out that I've always strived to find other resolutions to these problems first - I spoke with Moxie and others involved in Signal at length before writing this article, and only wrote this as a last resort. With organizations like Mozilla, I have also spoken directly to some of those responsible, though it's more difficult with a larger organization, and waited until a long-term pattern of bad behavior had been established. I make these criticisms because I want them to live up to the ideals they proclaim - it's with the hope that they'll change for the better.
- ColanR 6y ago> I make these criticisms because I want them to live up to the ideals they proclaim - it's with the hope that they'll change for the better. Thanks. It's important that projects are held to high standards, even if they're hard to achieve. Otherwise there'd be no pushback against pure pragmatism.
- jszymborski 6y agoI'm sorry you're getting downvoted. Though I disagree with some of your stances on OWS and Mozilla, your articles are always thoughtful and there is never a doubt you're earnestly fighting for a better world w.r.t software.
- tptacek 6y agoThis post has been on Hacker News several times. For instance: https://news.ycombinator.com/item?id=17723973 https://news.ycombinator.com/item?id=17723973. When it was first published, it included an emphatic recommendation to use Matrix, and, later, Tox --- in fact, the post even included a changelog at the bottom recording the inclusion of Tox. After it was pointed out to the author that Matrix didn't even do E2E by default, the recommendations (and the changelog) were ghost-edited out of the post, but you can still see them on Archive.org. I don't understand why people take this post seriously.
- ddevault 6y agoAh, once again with the insubtantive rebuttal of the last point in the article, the point which has the least relevance to the meat of the article. And this time, your rebuttal is out of date, because Matrix does have end-to-end encryption by default for all chats! Always lovely having you around on HN, tptacek.
- tptacek 6y agoRecommending a tool that wasn't even end-to-end encrypted over Signal because you didn't like the way Signal's leadership responded to your demand to support F-Droid is the most relevant thing you wrote. Just because it was malpractice doesn't make it out of bounds.
- ddevault 6y agoLook at this guy, he was wrong! Wrong wrong wrong WRONG! Look, he retracted his statement, that's how WRONG he was!
- tptacek 6y agoOnce again: you did not retract your statement. You ghost-edited it out of your post. The purpose of a retraction is to inform your readers of your mistake, and a retraction would be a good thing to add to your post. The distinction is especially germane in a thread on a post that purports to discern how trustworthy someone else is. You set the bar, now clear it.
- etaioinshrdlu 6y agoI'm so proud that a family member managed to get all of my extended family on Signal. My grandparents are even on Signal. I wouldn't trust such an app for anything actually secret due to the mentioned issues (and phone number req), but I think it's great that we're using high grade encryption to talk about what we had for dinner. Encrypted and private should be the default no matter what!
- Cactus2018 6y agoPlus cross-platform video chat and nice (large) multimedia attachments.
- motohagiography 6y agoTrust it to what? I use Signal because I think it protects my SMS messages from: a) being harvested and read by other apps on my phone b) being read by someone who unlocks my phone c) being passively intercepted and stored by carriers and their snoopy employees d) opposition researchers or private investigators targeting my friends, acquaintances, and business associates. For anything targeted and state level, all bets are off anyway, so it's not a solution for people who have that problem. What am I missing?
- frabbit 6y agoI use Signal because I think it protects my SMS messages It depends. I think calling them simply SMS messages instead of being more precise is misleading because: Text messages sent through your mobile SMS/MMS plan are insecure and need your phone to be connected to your mobile network. and Signal Desktop does not send or receive SMS/MMS messages. Only Signal messages will be sent or received. The desktop app is an independent client that works whether or not your mobile device is present or online. We also want to encourage users to move away from insecure legacy protocols. https://support.signal.org/hc/en-us/articles/360007321171-Can-I-send-SMS-MMS-with-Signal- https://support.signal.org/hc/en-us/articles/360007321171-Ca... I find it very confusing.
- motohagiography 6y agoIt has other features, but the main point of using Signal is to send encrypted messages to people using the PSTN directory service (e.g. phone numbers). You are still in that sandbox. The secondary feature it it ostensibly encrypts messages at rest on your device so they cannot be decrypted and read by other apps. (Assuming that's true.) If you want a more secure messenger, use Wickr, Riot/Matrix/whatever it's called now, or protonmail or something similar, as these don't depend on the phone directory for identity and so they resist some traffic analysis and contact tracing as well. The threat model is both the business model and use case for security products, so talking about the features or implementations outside the context of the threat model is going to just add uncertainty, imo.
- 6y ago