4 ms·
Friendly reminder that reproducible F-Droid builds of Signal are still rejected for weak reasons [1]. You must trust the Signal binaries on popular app stores [
by mechnesium 6y ago
Friendly reminder that reproducible F-Droid builds of Signal are still rejected for weak reasons [1]. You must trust the Signal binaries on popular app stores [2][3].
Don’t worry though; the Signal devs assure you that signed Android binaries from their website are reproducible [4]. As if checksum collisions aren’t something that state actors could trivially create [5].
I don’t trust Signal.
[1] https://github.com/signalapp/Signal-Android/wiki/F-Droid https://github.com/signalapp/Signal-Android/wiki/F-Droid
[2] https://play.google.com/store/apps/details?id=org.thoughtcrime.securesms https://play.google.com/store/apps/details?id=org.thoughtcri...
[3] https://apps.apple.com/us/app/signal-private-messenger/id874139669 https://apps.apple.com/us/app/signal-private-messenger/id874...
[4] https://signal.org/blog/reproducible-android/ https://signal.org/blog/reproducible-android/
[5] https://shattered.io/ https://shattered.io/
- gruez 6y ago>As if checksum collisions aren’t something that state actors could trivially create [5]. >[5] https://shattered.io/ https://shattered.io/ Collision attacks are an issue when using md5/sha1, but I don't see how it's relevant in this case. If state actors wants to replace the signal apk with a backdoored one, they'll need to pull off a preimage attack, not a collision attack. A collision attack wouldn't be useful because you still need the original publisher to sign the apk for you, which seems unlikely considering OWS isn't a CA or anything. If OWS was compromised by state actors into signing, then they can just sign the backdoored version directly, no need for a collision attack.
- mechnesium 6y agoThanks for pointing out collision vs. preimage. Interesting distinction.
- h_anna_h 6y agoI presume that the idea is that the compiled binary from the source and that the binary distributed by signal would be different but have the same sha1s. It does not make a lot of sense though because one could simply use another algorithm.
- gruez 6y ago...or just compare byte by byte, since reproducible builds provides you with an .apk to compare against, not just a hash.
- mechnesium 6y agoAFAIK, you cannot view applications on iOS unless your device is jailbroken. Apps are completely opaque since there is no traversable filesystem. On Android, it is a little simpler. The vast majority of non-technical users have no knowledge about hexadecimal file comparisons or checksums. They see an app that promises privacy, and they click download.
- NikolaeVarius 6y agoYes, the collided MD5 that looks like gibberish because a phone would have no clue wtf to do with a ranom blob of data?
- j-james 6y agoSignal's reasons for not wanting to maintain an F-Droid repository are terrible, but that doesn't in any way compromise their security. As others have pointed out, reproducibility goes farther than just checksums.
- hjek 6y ago> You must trust the Signal binaries on popular app stores. Or you can just run Signal Desktop exclusively without the hassle of smartphones[0]. Audio / video calls recently landed in Signal Desktop too[1]. [0]: https://ctrl.alt.coop/en/post/signal-without-a-smartphone/ https://ctrl.alt.coop/en/post/signal-without-a-smartphone/ [1]: https://signal.org/blog/desktop-calling-beta/ https://signal.org/blog/desktop-calling-beta/
- cyphar 6y agoYou can download the APK from their site[1] and have been able to for several years, that's how I install it on my devices (and it does autoupdates). As for hash collisions, as far as we know SHA256 hasn't been broken yet and even if it were broken you would need to be able to create a valid APK with Signal's code and the backdoor which hashes to the same thing as Signal. [1]: https://signal.org/android/apk/ https://signal.org/android/apk/