5 ms·
It's been like this for a while, and the project owner's attitude is pretty negative overall. I do use signal daily, but I believe it's likely compromised ala l
by ndiscussion 5y ago
It's been like this for a while, and the project owner's attitude is pretty negative overall. I do use signal daily, but I believe it's likely compromised ala lavabit.
- morelisp 5y agoWhat's in the Signal server to be compromised?
- corty 5y agoList of phone numbers? Pairs of communication partners? Timing and size of messages? Metadata about transferred media? There is still a lot, sufficient for targeting a drone strike as the usual wisdom goes.
- tptacek 5y agoSome of that information you don't even need a backdoor to collect; the rest is stored in plaintext by Signal's competitors.
- corty 5y agoSignal claims to specially protect some of that data, such claims need verification. Storing or not storing that data needs verification, without the trust that they do what they say they are no better than their competition. Trust is earned e.g. by openness about the source code. And that a server backdoor isn't strictly necessary is also beside the point because the server is the easiest and most obvious way to get at all that data. Also, there is competition like Briar which has less of those pesky metadata problems (but some other problems instead)
- tptacek 5y agoI don't recall Signal ever having made implausible claims about traffic analytic attacks. I also don't buy into the idea that platforms are as trustworthy as their source release policies are orthodox.
- corty 5y agoIt isn't advanced difficult traffic analysis if it is all your servers. Or all your logs landing in one logstash.
- tptacek 5y agoWhat difference does this make? In your threat model the only serious countermeasure between you and state-level adversaries is a Logstash implementation?
- morelisp 5y agoThe goalposts now seem to be at "someone might subpoena Signal's logs for some metadata", having moved pretty far from the original claim of "Signal's server code hasn't been updated because it has been secretly backdoored or intentionally weakened." It's difficult to see this as good faith security analysis rather than fearmongering.
- ViViDboarder 5y agoSignal doesn’t store lists of phone governments have lists of phone numbers. Comunication partners are hidden from the server using Sealed Sender for many conversations. The rest of this could possibly be obtained, it it wouldn’t require a patch to the server as message sizes and timestamps likely appear on disk somewhere. Though the data is encrypted, you could tell “x received a message from some party (sealed sender prevents knowing who) at y time of roughly z size”.
- corty 5y agoSignal still uses and verifies phone numbers, so at some point they will pass through their infrastructure. They could still save them, knowing the source code they use gives at least at hint that they don't. Sealed sender also is based on the pinky-swear that the infrastructure distributing the sender auth certificates doesn't correlate identities and connections with the messaging infrastructure. And that the server receiving the enveloped messages doesn't log. So all based on trust based on believing the right source code is running somewhere. When access to that source code is restricted suddenly, of course people are worried.
- pvarangot 5y agoBeing able to hide from a government that wants to drone you while still being in the cellphone network requires much much much more OPSEC than just using Signal. For an average user Signal is about protecting the content of your messages, not your network, and it's good at that.
- corty 5y agoYes, that "drone strike" thing is actually a stupid saying. I'm sorry to have used it because it is somewhat distracting from the actual points.
- ndiscussion 5y agoIf you use the Signal app from the app stores, and communicate with the server, you are using 100% closed source software. They could easily add a backdoor in the client despite the fact that it's "open source", because no one builds it from source.
- morelisp 5y agoAre Signal's Android builds no longer reproducible?
- ndiscussion 5y agoIt looks like they are, but there might be a minor issue in verifying the content: https://github.com/signalapp/Signal-Android/issues/10476 https://github.com/signalapp/Signal-Android/issues/10476 But despite best efforts by the community to verify builds, Google and Apple can be forced to upload a malicious app to a particular user, meaning they aren't using the same app at all.
- morelisp 5y agoIf your threat model includes the ability to force Apple to do X, then Signal is irrelevant.
- ndiscussion 5y agoThat's probably a good point, I'm using GrapheneOS which is not identifiable to Google/Apple and can't be singled out for updates.
- greysonp 5y ago> But despite best efforts by the community to verify builds, Google and Apple can be forced to upload a malicious app to a particular user, meaning they aren't using the same app at all. Hi there! Signal-Android developer here. App signing verification is done at the OS-level, and Google does not have our signing key, so they wouldn't be able to give an existing user a different APK and have it successfully install.
- gruez 5y agoI thought they were never compromised? They shut down rather than comply with the order >The service suspended its operations on August 8, 2013 after the U.S. Federal Government ordered it to turn over its Secure Sockets Layer (SSL) private keys, in order to allow the government to spy on Edward Snowden's email
- ndiscussion 5y agoLavabit was never compromised, I'm saying that Signal may have been compromised by the feds, instead of choosing to shut down. Feds may have learned their lesson and not provided an option this time.
- notjtrig 5y agoThe chance that a small nonprofit with so much traffic is not leaking/providing data to the feds is astronomically slim imho, there are so many actors who would love to there hands on it. Maybe it thwarts some inteligance services but not those with unlimited resources.
- 2OEH8eoCRo0 5y agoBased on what information would you draw such a conclusion?
- notjtrig 5y agoI would point you towards Stuxnet and take a look at how sofisticated a state level attack can be and the fact that today Iran still can not keep us (America/Israel) out of it's centrifuges. Everything you type online is being stored by multiple actors, to think they can't access a small company with limited resources is wishful thinking. If no one in Signal's 180 employees is working for the feds I would be embarrassed to be an American.
- coolspot 5y agoAdd easily-bruteforceable PIN-codes forced on users, protected only by vulnerable Intel SGX. Add requirement of a phone number to create an account.
- rOOb85 5y agoThat's a bold claim with 0 data to back that up. What are your sources for believing it's received a love letter?