15 ms·
Ask HN: How do we know Signal or Telegram don't store our data on their servers?
I'm just curious how we trust companies such as Signal, Telegram, Mozilla, that claim they don't store and sell our data?
Thank you
- chimeracoder 6y ago> I'm just curious how we trust companies such as Signal, Telegram, Mozilla, that claim they don't store and sell our data? These are three very different companies with very different security processes and trust profiles. In the case of Signal: if you trust that the source code they distribute is the same as the app available in the Play Store, then it's pretty easy to verify that the messaging data is end-to-end encrypted in a way that prevents Signal from having much metadata that they even could store. With "sealed sender", they don't even know who's talking to whom: https://signal.org/blog/sealed-sender/ https://signal.org/blog/sealed-sender/ There's the possibility that Signal could ship a different app in the Play store, but that would require active malice to do in a way that would not be trivial to discover[0], and at some point you do have to trust someone. It's not impossible, but it's hard to imagine a world in which Signal is compromised but other links in the chain aren't, because quite frankly, there are far more easily corruptible or hackable links in the hardware/software stack that you use, so Signal would make a pretty inefficient target for someone who wants monetizeable data. [0] ie, an accidental divergence between the two would be more conspicuous
- kitkat_new 6y agoyou don't know if they know, because you can restore that meta data
- jolmg 6y ago> trust that the source code they distribute is the same as the app available in the Play Store And, of course, one has the option to build the source and install that.
- theshrike79 6y agoTelegram has reproducible client builds.
- d1sxeyes 6y agoI had to scroll down a shockingly long way to find this. The point is that even if Signal permanently stored everything you ever sent them, then they wouldn't be able to read it. - You can build the client yourself per Signal's reproducible builds, so actually, they could not ship a different app to the published source without it being immediately detectable - You can validate the source code does not send any unencrypted data to Signal - You can validate that your private keys used for encryption are stored locally on the device and not transmitted to Signal Theoretically, anyone who has the corresponding private key could decrypt the message. So if your contact uses an unofficial client which does share their private key with a third party, then that third party could unencrypt that message, however by that point, the app creator has compromised the device anyway, and could do something as naive as take screenshots of all of the messages in the background after Signal has done the work of ensuring the secure transmission of the message. Note, I haven't actually done all that, because I do trust Signal. But I could if I wanted to. And obviously, this assumes that all the cryptographic standards used in Signal are still unbroken - but if they were, then you're screwed either way.
- baggy_trough 6y agoThe same way that we trust that Apple doesn't log our keystrokes and send them back to the mothership.
- kitkat_new 6y agoGet hired and sign NDA
- beamatronic 6y agoYou don’t. Everything is about trust.
- skzv 6y agoYes, and I trust Durov.
- dylkil 6y agoSignal is open source, you and anyone else can inspect the code. You can then build it from source and install on your android directly avoiding the play store.
- kitkat_new 6y agoand how does this proof that they don't save what you send them?
- dylkil 6y agowhat use are my encrypted messages to them?
- cygx 6y agoBuilding social graphs and activity logs, for one.
- kitkat_new 6y ago1) Meta data 2) Decrypt in case of security breach or more advanced computing
- theshrike79 6y agoSo how do I build the Signal server and confirm it's identical to the one they're running?
- jolmg 6y agoIt doesn't matter if it's not. Security should depend completely on the clients. Public-key crypto allows private communication through insecure channels.
- genghizkhan 6y agoThat's not going to be true of metadata, though. A malicious server could keep a lot of valuable metadata about you.
- bzb6 6y agoTelegram stores your data by default in their servers. You have the option of removing single messages or conversations but there’s no way of knowing if they really do so. Also if you remove your account without removing your conversations first they stay there forever (others can see the messages)
- Akcium 6y agoAt first I wanted to write about client-side app verification, that we can prove that the apps we have and the open-source complied app would be the same. Which does not prove that if the app sends your phone number or location (for example), they don't save it in database. Indeed, interesting question
- pdevr 6y agoAs long as it is stored on the server and the transmission is encrypted, we will never know for sure. Especially in cases where the company "controls" the encryption and decryption.
- faitswulff 6y agoSignal’s claim to fame here is that they were subpoenaed in 2016 and could only supply account creation and last connection times: > The American Civil Liberties Union announced Tuesday that Open Whisper Systems (OWS), the company behind popular encrypted messaging app Signal, was subpoenaed earlier this year by a federal grand jury in the Eastern District of Virginia to hand over a slew of information—"subscriber name, addresses, telephone numbers, email addresses, method of payment"—on two of its users. > ... “The only information responsive to the subpoena held by OWS is the time of account creation and the date of the last connection to Signal servers,” Kaufman continued, also pointing out that the company did in fact hand over this data. https://arstechnica.com/tech-policy/2016/10/fbi-demands-signal-user-data-but-theres-not-much-to-hand-over/ https://arstechnica.com/tech-policy/2016/10/fbi-demands-sign...
- argggg 6y agoThis, more than anything, is why I trust them and recommend them to others.
- deleted 6y ago[deleted]
- Kuraj 6y agoIs it possible that they could in fact produce this data but were prevented from publicly saying so due to a gag order? I'm asking specifically because I remember Private Internet Access, a VPN provider, also being tested in court in the past [1], and because of this I've chosen to trust them despite them falling under Five Eyes jurisdiction. [1] https://torrentfreak.com/private-internet-access-no-logging-claims-proven-true-again-in-court-180606/ https://torrentfreak.com/private-internet-access-no-logging-...
- sithadmin 6y agoPIA used to be my go-to, but I immediately ceased using PIA after the 2019 acquisition by Kape Technologies, which has a rather foul track record.
- hutzlibu 6y agoWell in the case of Telegram, you can trust, that they store your data on their server, because they say so. And it is convenient, because you can just switch your smartphone and still access all your chathistory, without having to manually backup/restore. But Telegram in general does not have a business model yet, so just assume, that one day, they want(or have) to cash out. Signal on the other hand is a non-profit foundation and pretty open on what they are doing. That creates trust for me.
- iamben 6y agoIIRC the business model was going to be the GRAM coin/TON network, which was P2P transactions, dropbox style storage etc.
- SulfurHexaFluri 6y agoI thought that got shut down by the US government for being a scam.
- jakub_g 6y agoDurov wrote his thoughts on monetization lately here: https://t.me/durov/142 https://t.me/durov/142
- hprotagonist 6y agoSignal and the ACLU sued and were granted permission to release sealed warrant data from a previous law enforcement request for user data. As of mid-2016, and trusted as much as you feel like trusting something attested in a court of law, Signal stores: a bool (is this phone number a user) and two ints (epoch of signup, epoch of last transmission). https://www.aclu.org/open-whisper-systems-subpoena-documents https://www.aclu.org/open-whisper-systems-subpoena-documents
- waschl 6y agoTelegram is storing your message content in their cloud for „cloud chats“ (default), as those are not end-to-end encrypted. Telegram‘s „secret chats“ and signal chats are end-to-end encrypted. The servers still may store metadata, and there is no way to tell if they do than either joining them or let a trusted third party verify that. To check if e2e encrypted message content cannot be encrypted via backdoors on their servers, you need to ensure they use proven encryption schemes and the client encryption does correspond to those algorithms.
- 7v3x3n3sem9vv 6y agoIt's important to note that Telegram does store all your data by default as they do not enable E2EE for everything like Signal does. So if you're under the assumption that they don't, this is incorrect. Telegram, for all intents and purposes, is about as secure as using Facebook. The best you can do with Telegram is hope they don't sell out or get compromised at some point in the future, because all your private communications are stored on their servers forever. Telegram does have "secret chats", which from what I can gather, don't even work for group chats, only one-to-one messages. My general advice is to treat Telegram like a new Facebook if you have to use it, assume everything may by read by everyone, don't treat it like it's private and secure. For "text messaging" friends and family use Signal. Everything is end-to-end encrypted by default, so you know nobody is collecting your data.
- juniperplant 6y ago> Everything is end-to-end encrypted by default, so you know nobody is collecting your data. I think it's wise to remember that what happens on the other "end" is outside of your control. If the other person in the conversation stores chat backups unencrypted you're still at risk, and there's not much you can do about it.
- saladgnu054 6y agoI believe you have self-destroy timers in Signal. Perhaps those help.
- idlewords 6y agoOne reason you can believe the claim is that there's no real market for personal data, despite the folk belief that everyone's data is somehow worth a fortune.
- chrisco255 6y agoNot everyone's personal data is worth a fortune. Specific persons of interest, however, their personal data IS worth a fortune.
- joshka 6y agoNo real market is an easily disprovable claim. While not worth a fortune in the small, in bulk it's worth a imperial butt load. Attention is what you're able to sell. That's advertising and sales. E.g. do you think that those associated with others in right wing militia would be more or less sensitive to advertisements for gear for prepping? How big is that market?
- joshka 6y agoAround 6 hours later... https://www.buzzfeednews.com/article/ryanmac/facebook-profits-military-gear-ads-capitol-riot https://www.buzzfeednews.com/article/ryanmac/facebook-profit...
- tptacek 6y agoWe don't know that Signal doesn't store data about users on its servers. Even the source code can't tell us that, because we don't run the servers. What we do know is that programs like Telegram have to store data about users on their servers, by design. A big difference between the two projects is that Signal is carefully designed to minimize the amount of data the service needs to operate; it's why identifiers are phone numbers --- so it can piggyback on your already-existing contact lists, which are kept on your phone. By contrast, other services store, in effect, a durable list of every person you communicate with, usually indexed in a plaintext database.
- shabda 6y agoSignal has reproducible builds for Android. https://signal.org/blog/reproducible-android/ https://signal.org/blog/reproducible-android/ Does that help in any way to verify that they do not store data on their servers?
- deleted 6y ago[deleted]
- evanreichard 6y agoMy understanding: If you verify the safety numbers in person, then I believe you can be confident that it's E2E encrypted for that conversation. If the safety numbers are different, then there could be a nefarious actor listening in. Someone please correct me if I'm wrong. Edit: That being said, I believe they could still record IPs, as well as the destination and timestamps of each message.
- spullara 6y agoIf they were storing that it would have been produced when they were forced to produce all data relevant to the case.
- evanreichard 6y agoAgreed. Just pointing out what information they have access to if they wanted to start logging as much as they could.
- sjaak 6y agoIn the case of Signal, I imagine people assume all of the following: 1. the protocol between client and server is setup in such a way, even if Signal wanted to store interesting information, they could not access anything interesting even if they wanted to (for example, messages), thus they don't store anything since it's useless 2. the app implements the protocol faithfully and this has been checked by people perusing the source code 3. the binary downloaded from the app/play store phone is compiled from the sources listed on github
- rozab 6y agoThis might seem like a naive question, but how is it possible to verify that 3 is true? I get how it might be done in theory but real life is complicated. Has anyone attempted to do this?
- tdons 6y agoI imagine it's non-trivial. I think it would involve (in case of iOS): 1. downloading the binary 2. jailbreaking the phone to extract the binary (pretty sure this is necessary on iOS) 3. check the version of the binary, then compile the original sources of the version 4. ??? compare the two binaries, this is likely the most difficult part, they won't be identical because of things like codesigning (and build flags, timestamps, ...) I know noone that does this.
- evgen 6y agoYou don't compare builds because you probably don't actually have sources. What you do is use a special iPhone (a Security Research Device) that Apple grants some researchers or you use an emulator like the one from Corellium (to whom Apple recently lost a lawsuit over this emulator) to probe and step through the code. Find the key sections that do the real crypto work and make sure that they do what they are supposed to do and that they are getting the correct inputs. There is a large group of people who do this sort of research, and some fraction of them do this research and actually talk about it or publish papers. If you could find a deliberate weakness in the security of an app like what we are talking about (or WhatsApp or iMessages) then you have just printed your own golden ticket to whatever mobile cybersecurity job you want for the next decade or two, so there is a bit of an incentive to publish if something like this was discovered...
- titzer 6y agoHello, future? Yes, this is Richard Stallman calling from the 1980s. I think what you might be looking for is the source code to the entire software stack.
- qchris 6y agoPerhaps a little pedantic, but I don't think this is technically correct, since Stallman and the GPL wouldn't really apply here for server-side code, since it doesn't seem like the client-side application code is being questioned regarding trust, but rather the intermediary code on Signal's own servers. In that case, Affero GPL would be the answer. And that license was first published in 2007, which is something like 18 years after the initial GPL release. I don't think that actually detracts from gist of your point, but just wanted to point it out in case anyone was interested.
- johnchristopher 6y agoWhat prevents Google from replacing Signal on the Android Application store with their custom and backdoored version ? Can we check a hash or something ? Does the signal foundation do that on a regular basis ?
- paulgb 6y agoIf Google wanted to read your messages and were willing to use malware to do it, there’s little to stop them on Android. Even if Signal checked the apk regularly, there’s no guarantee that the apk served to them is the same one served to everyone else. They could also push an update to the OS that recognizes the Signal apk and applies a patch after downloading but before installing. That said, Signal does apparently support reproducible builds so that people can check that the apk matches what’s on GitHub (though this is more of a way to detect malfeasance on Signal’s part rather than Google’s) https://signal.org/blog/reproducible-android/ https://signal.org/blog/reproducible-android/
- johnchristopher 6y ago> They could also push an update to the OS that recognizes the Signal apk and applies a patch after downloading but before installing. Ah, right, there's also that.
- jrockway 6y agoNever forget to reflect on trusting trust, of course: https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_ReflectionsonTrustingTrust.pdf https://www.cs.cmu.edu/~rdriley/487/papers/Thompson_1984_Ref...
- oneplane 6y agoNothing, because they can also just read it off of your phone and don't need to 'break' Signal.
- mjg59 6y agoSignal is signed with a key that's held by Signal, not Google. Android won't install app updates unless they're signed with the same key as the currently installed version. (I work at Google, but not on Android)
- Yoric 6y agoIf you wish to be more certain, use something open-source. For instance, Matrix has many clients made by different teams, in the open, and several of these are part of e.g. Debian, so you should be able to find at least one you can trust. What about Mozilla? What could they store?
- adsharma 6y agoIf this is a concern for you, consider using the signal protocol without a server. CLI prototype. Can be generalized into a nice phone app. https://github.com/adsharma/zre_raft https://github.com/adsharma/zre_raft https://twitter.com/arundsharma/status/1348718596415918080 https://twitter.com/arundsharma/status/1348718596415918080
- adsharma 6y agoBetter quality video: https://drive.google.com/file/d/1lmMgj76IpsX_YN4lNgqwKLexZDSGAsK5/view?usp=sharing https://drive.google.com/file/d/1lmMgj76IpsX_YN4lNgqwKLexZDS...
- alexbiet 6y agoSignal was created by one of the founder of WhatsApp which was sold to Facebook. Is there a guarantee that Signal won't have the same fate?
- tapoxi 6y agoYes, Signal is a nonprofit charity.
- fsflover 6y agoIf you don't want to trust anyone but to verify instead, consider running Matrix with your own server. In this case you still can talk to anyone else on Matrix, because it' federated.
- bigiain 6y agoI'm not familiar enough with Matrix, but I'm curious about how/if it can protect against malicious federated server operators? Does that just boil down to needing to trust they are not running modified code?
- fsflover 6y agoYour own Matrix server does not spread any information unless you allow it or unless you message other servers. Now, concerning the other servers, it may be a problem, just like Gmail is a problem for everyone running their own email server. However, it's a much smaller problem and at least theoretically everyone who cares can escape the walled garden. You can create a server for all your friends and you will always know exactly which information is shared with others and which isn't.
- upofadown 6y agoWhich data? We can be somewhat sure that they don't have access to the content of Signal or Telegram secret chats as long as we have verified the identity of our contacts. After that, what data do you care about? Neither Signal or Telegram is intended to provide complete anonymity. That is a much harder problem. For Mozilla that would involve Tor. I don't think that Mozilla really has "servers" in the sense you mean.
- bluefox 6y agoThere's no need to trust them. You assume they log everything that your device sends them, as well as the time, IP address, etc. and infer all they can from it. Then you act accordingly. You can apply similar conservative assumptions to your device and the programs it runs, but for practical purposes you may want to relax them somewhat.
- orblivion 6y agoIf you trust the source code of the software you're running, you can at least get a sense of what data they're getting in the first place. You know, at least, that they're not getting the content of your communications if you verify safety numbers. You can also prove that they're not getting the contents of the gifs you're grabbing for your conversation, because the client makes a secure connection to the gif service using Signal's servers as a proxy. As far as promising not to store your metadata, or promising not to deliberately give the gif service information about your account because they hate you, or promising not to store your contacts when you search for other friends with Signal, then yeah you have to just take their word for it. Though, they may over time look for ways to put some of those guarantees on the client side as well with some clever engineering, so you could prove it.
- ajsharp 6y agoThere's a lot about Signal in particular that they get right. AFAIK: (1) All Signal messaging is E2EE; (2) they don't store messages on their servers; (3) the client code is open source, and it seems like a good portion of the server code is open source. Where I think Signal could go further on being the most secure, useful, and privacy-conscious messaging app/company in the world: 1. Open source ALL of the server code. They have something called Signal-Server (https://github.com/signalapp/Signal-Server https://github.com/signalapp/Signal-Server) on their Github, but it's unclear if this is the server they use, or simply a server one could theoretically use to run a private Signal server. 2. Open source all server-side services/infrastructure code that doesn't compromise security in some way. 3. Better features. Signal is currently the most secure and privacy-conscious of the messaging apps, but solidly the worst overall user experience. It's not that it's bad, it's just that the other apps are much better. People like gifs and giphy and emojis and a fast-feeling interface. This is important, because it's hard to be a privacy-conscious individual when all your friends want to text on other apps. At least in my social circle, Signal is still the thing that people jump over to when they want be extra super sure they're not leaving a paper trail, but not the default messaging app they use. 4. Introduce a user-supported business model. This probably makes a lot of people uneasy, and while I appreciate the current grant and donation-based business model (the Wikipedia model), that model comes at great cost of efficiency. By operating effectively as a non-profit, you are inherently in a less competitive position relative to your competitors (the best product and engineering people are more likely to go competitors who can pay more), and you're persistently in fund-raising mode (again, see: Wikipedia). There are lots of ways to skin this cat, maybe the easiest is to ask power users to pay like $5/mo. Or just give people the option to pay with absolutely zero obligation. Some non-zero cohort would inevitably take them up on this. Most of these suggestions, of course, especially 1-3, are very very hard and come at an enormous cost. Building in public as an open source business seems to massively slows things down and introducing a huge amount of community management overhead. That said I'm sure there are ways to manage/mitigate those costs.
- _rohan 6y agoIt's cool that Signal is open source, that's a big source of confidence for me. Is there some way for me to verify that the app in the app store is actually built from the OSS code on github?
- dredmorbius 6y agoFor that matter, what is Zoom's architecture and dataflow?
- cschmidt 6y agoWhile not directly about data storage, I loved this tweet [1] from Edward Snowdon this week: > do we really trust signal? cause i see zero reason to. Here's a reason: I use it every day and I'm not dead yet. [1] https://twitter.com/Snowden/status/1347217810368442368?s=20 https://twitter.com/Snowden/status/1347217810368442368?s=20
- Lendal 6y agoI like this reason because you don't need to know anything about tech at all to be able to understand this. You also don't need to trust or like Snowden. If you view Snowden as a hero or a traitor, it changes nothing. All you need to trust is that he's got no reason to lie about using Signal, and neither does Elon Musk.
- superdisk 6y agoUnless he's an NSA operative who's promoting a honeypot.
- paxys 6y agoThat's a stupid reason. He's not dead (or at least imprisoned) yet because USA doesn't have an extradition treaty with Russia. What does a chat app have to do with it?
- ohthehugemanate 6y agoSignal: operations that involve sending your contacts (like contact discovery) use a pattern Signal invented where the client can validate the software running on the server. The server runs inside the SGX secure enclave. Before your client sends any data, it performs remote attestation on the running server code to ensure it matches the published open source code. See the full explanation at https://signal.org/blog/private-contact-discovery/ https://signal.org/blog/private-contact-discovery/ (starts part way down, with "trust but verify"). Or check the client source code yourself! Telegram: I dunno, they.re closed source, don't encrypt by default, and have shady ownership. I don't trust them at all, personally.
- coolspot 6y agoKeep in mind that SGX is not as secure as advertised[1][2]. Also whole security dangles on Intel to be trusted to not give its private keys to anyone. Which is a big ask for any company. NSA/CIA likely can get those keys legally via FISA court order or illegaly via hacking and/or insider. [1] - https://arstechnica.com/information-technology/2020/03/hackers-can-steal-secret-data-stored-in-intels-sgx-secure-enclave/ https://arstechnica.com/information-technology/2020/03/hacke... [2] - https://www.theregister.com/2020/06/10/intel_patches_sgx_again/ https://www.theregister.com/2020/06/10/intel_patches_sgx_aga...
- ohthehugemanate 6y agoSure, but the question wasn't "does the NSA have access to data", it was "how do we know that information isn't stored." The answer is that signal includes an industry-leading attestation process using CPU security features. If the CPU manufacturer is compromised that would compromise anything running on it, including attestation. But that's not a flaw in Signal's implementation, and it is out of scope of the question.
- ohthehugemanate 6y agoSure, but the question wasn't "does the NSA have access to data", it was "how do we know that information isn't stored." The answer is that signal includes an industry-leading attestation process using CPU security features. It's true that if the CPU manufacturer is compromised that would compromise anything running on it, including attestation. But that's not really to do with Signal's implementation, and it is out of scope of the question.
- sunstone 6y agoTelegram is very clear that they do store our stuff on their servers. And in clear text unless you choose end-to-end encryption. My concern is not about my data being stored on their servers. My concern is about having having marketing data being sold to third parties in order to target advertising at me, just as when you leave "third party cookies" active on your browser. That is creepy and invasive. Would Zuckerburg ever do such thing?
- greattsclerouse 6y agoUse Matrix or KeyBase and self host. Im shocked how much people still trust these shady companies.
- SLHyR82 6y agoTelegram stores all data on own servers. Just try the following trick: - in a private Browser window open web.telegram.org - enter your phone number, receive the code - turn on flight mode on your phone - now enter the identification code in your browser - access your whole chat history while your smartphone can definitely not act as a source Even WhatsApp is better in this regard. Article in German: https://www.heise.de/hintergrund/Telegram-Chat-der-sichere-Datenschutz-Albtraum-eine-Analyse-und-ein-Kommentar-4965774.html https://www.heise.de/hintergrund/Telegram-Chat-der-sichere-D...
- i_r7al 6y agoTelegram is based on the UAE. The UAE is known of their very strict monitoring practices of their citizens. Not until recently they allowed FaceTime to work there. I honestly doubt that Telegram does't give the UAE government access whenever they need it's a monarchy government.