8 ms·
Exactly, using lawyers first is a very bad sign. I don't know why often people say "oh it was just the lawyers" like that makes it okay. No, those lawyers are
by hyperhopper 4y ago
Exactly, using lawyers first is a very bad sign. I don't know why often people say "oh it was just the lawyers" like that makes it okay.
No, those lawyers are paid for by and directed by signal. Signal is responsible.
- dheera 4y agoHey signal, maybe fix this $ sudo apt-get install signal Reading package lists... Done Building dependency tree... Done Reading state information... Done E: Unable to locate package signal and we don't need to resort to unofficial snap packages
- nsxwolf 4y agoOh, snap!
- tssva 4y agoThe name for the Signal Desktop package is signal-desktop and Signal provides instructions on their website on how to add their deb repository.
- dheera 4y agoToo difficult. Their install instructions are also too complicated and involve reading about 5 lines of comments and 4 shell commands. It should NEVER be more than 1 line of shell or 2 mouse clicks to install anything. This is 2022, not 1995. It's faster to just search for "signal" in the snap store and hit "Install".
- iakov 4y agoAll that time you've gained on the installation will be lost during the lethargic start of snapped application :P
- tssva 4y agoUnfortunately, this is the world Signal lives in. For binary debian packages to be installed securely directly from a vendor requires the installation of gpg keys which is what 2 of the 3 commands are regarding. If Ubuntu had spent resources to develop a convenient way for developers to directly provide binaries to the users of their OS instead of developing a system where they are gatekeepers and distribute all packages Signal would now be able to provide an easier secure method of installation. If you were providing a privacy focused product which in some uses that privacy can be the difference between life and death, would you want to turn over supply chain protection of that product to a 3rd party?
- turminal 4y agoYou're already trusting debian/ubuntu maintainers with your entire system. Why would trusting them with one particular app make any difference?
- drran 4y ago> If Ubuntu had spent resources to develop a convenient way for developers to directly provide binaries to the users of their OS No way. I will never trust your binary.
- mechanical_bear 4y agoLol, like you audit the thousands of lines of code when you compile from source.
- 411111111111111 4y agoWhat made you think they'd be willing to compile from untrusted sources? There are a lot of users that prefer the established trust model of a Linux distribution. They're willing to trust the mostly unpaid debian maintainers for example... but not John Doe, the temporarily set back billionaire who's just about to make it big
- drran 4y agoYes, I look at code. I'm professional developer. I will spend 1-2 minutes at scanning per thousand of lines.
- irthomasthomas 4y agoIt's 5 lines. Took me 30 seconds. Well worth it for the performance gains. wget -O- https://updates.signal.org/desktop/apt/keys.asc https://updates.signal.org/desktop/apt/keys.asc | gpg --dearmor > signal-desktop-keyring.gpg && cat signal-desktop-keyring.gpg | sudo tee -a /usr/share/keyrings/signal-desktop-keyring.gpg > /dev/null && echo 'deb [arch=amd64 signed-by=/usr/share/keyrings/signal-desktop-keyring.gpg] https://updates.signal.org/desktop/apt https://updates.signal.org/desktop/apt xenial main' |\ sudo tee -a /etc/apt/sources.list.d/signal-xenial.list && sudo apt update && sudo apt install signal-desktop
- marginalia_nu 4y agoYeah, let's teach users to paste sudo commands into the terminal. That's great.
- rosnd 4y agoWhat alternative do you propose?
- marginalia_nu 4y agoWhat if there was some sort of a store of snaps where you could download vetted packages with a graphical interface. A snap store, if you will.
- cyberphobe 4y agoSounds great as long as they get proper permission to distribute the software they’re distributing. Otherwise it’s just another untrusted party in the supply chain
- hsbauauvhabzb 4y agoUnless you audit every line of code the one liner executed, reviewing that one line doesn’t add much value.
- ChuckNorris89 4y ago
- cyberphobe 4y agoIt’s true, they should distribute a .deb that ensures the repo and key are installed so it gets updates. However, your suggestion that they should just capitulate and allow 3rd parties to violate trademark seems like a pretty bad take.
- politelemon 4y ago> It should NEVER be more than 1 line of shell or 2 mouse clicks to install anything. If it is critical or has the potential to compromise security, it should take however many lines that are required to ensure a safe installation. The landscape today is far too complex to expect simple deployments (one liners) to be safe. A few extra lines is a small tradeoff in that case. I shudder when I see curl|bash type installations being normalized.
- galgalesh 4y agoI don't think there is any reason for publishers to force users to download their software from the internet now that the Snap Store and Flathub exists. I've had so many bad experiences with broken third party packages or worse, "installers".
- irthomasthomas 4y agoI just expunged the snap system entirely from my ubuntu. It feels much snapier without it. I've never tried flatpacks, my preference is to AppImages, they seem to perform much better than other systems I've tried.
- tssva 4y agoI can think of a lot of reasons why publishers of privacy and security related software would want to direct distribute their software rather than relying on 3rd parties if it is avoidable.
- jcastro 4y agoThere's also just as many reasons to not give Signal root on my PC by installing their .deb package.
- cyberphobe 4y agoNo one is forcing you to use their deb
- michaelmrose 4y agoSignal is secure communications used not only by nerds but in situations in which privacy is a requirement for safety. In this singular case do you think its a greater security risk that someone may compromise signal and ergo your computer or that one or more of 97 different stores/repos with a multitude of different maintainers get attacked and used to first compromise your communications and then probably your computer as well? Remember you are expecting the maintainer to not only be honest you are expecting them to secure his own machine as well.
- turminal 4y agoWhy doesn't signal have a package in the official debian repo? I don't want to add random deb repositories for software like that.
- michaelmrose 4y agoPresumably for the same reason they don't want someone else packaging snap for them its another party to attack in order to attack their users in a way that would destroy trust in their product given its sensitive nature.
- turminal 4y agoI'm already trusting debian to provide the rest of the system without backdoors. Why would getting signal from somewhere else help in any way?
- michaelmrose 4y agoIt's presumably signal not trusting 97 different stores not Debian's in particular not to get compromised.
- woodruffw 4y agoIt's not a "random" repository, it's their official repository. They seem to be doing everything right (or as right as possible), including providing a signing key (which you can independently verify) and using an HTTPS host. What's your threat model here? Trusting Signal to provide the binary and host the servers, but not distribute the binary that connects to the servers?