5 ms·
Kind of a good sign for signal's security that this is the best Russia has got!
by advisedwang 2y ago
Kind of a good sign for signal's security that this is the best Russia has got!
- yellowapple 2y agoYeah, this just gave me the last nudge I needed to give Signal a go.
- DemPartyPooper 2y ago[flagged]
- autoexec 2y ago[flagged]
- abuani 2y agoObligatory request to provide a source to backup some serious claims?
- autoexec 2y agoIf you're a signal user and didn't know about this already, that should tell you everything you need to know about signal. See https://community.signalusers.org/t/proper-secure-value-security-pins-are-too-easy-to-brute-force-sgx-is-not-reliable-enough/15096 https://community.signalusers.org/t/proper-secure-value-secu... Then read the first line of their terms and privacy policy page which says: "Signal is designed to never collect or store any sensitive information." (https://signal.org/legal/ https://signal.org/legal/) Signal loves to brag about the times when the government came to them asking for information only to get turned away because Signal never collected any data in the first place. They still brag about it. It hasn't actually been true for years though. Now they're collecting the exact info the government was asking for and they're protecting that data with a not-very-secure/likely backdoored enclave on the server side, and (even worse) a pin on the client side.
- gtvwill 2y agoAlso signals spam folder isn't open source on server side. They literally have code that reads your messages and checks if spam or not and you cant see what it does or how it's written. Couple this with signal being the preferred messaging app for 5 eyes countries as advised by their 3 letter agencies and well if you think those agencies are going to be advising a comms form they can't track, trace or read you obviously don't understand what they do.
- alwa 2y agoWhile it seems to be true that it’s not open-source, they claim (in strong terms) that they use techniques other than reading the message to make that assessment: https://signal.org/blog/keeping-spam-off-signal/ https://signal.org/blog/keeping-spam-off-signal/ They point out that the protocol’s end-to-end cryptographic guarantees are still open and in place, and verifiable as ever. As far as I can tell, they claim that they combine voluntary user spam reports and metadata signals of some sort: > When a user clicks “Report Spam and Block”, their device sends only the phone number that initiated the conversation and a one-time anonymous message ID to the server. When accounts are repeatedly reported as spam or network traffic appears to be automated, we can issue “proof of humanity” checks to suspicious senders so they can’t send more messages until they’ve completed a challenge. For example, if you exceed a configured server-side threshold for making requests to Signal, you may need to complete a CAPTCHA within the Signal application before making more requests. This approach slows down spammers while allowing regular messages to continue to flow. Does that seem unreasonable? Am I missing places where people have identified flaws in the protocol?
- deleted 2y ago[deleted]
- alwa 2y agoI see a link to a forum where an anonymous participant says “Since a recent version of Signal data of all Signal users is uploaded to Signal’s servers. This includes your profile name and photo, and a list of all your Signal-contacts.” They then link to a Signal blog (2019) explaining technical measures they were testing to provide verifiably tamperproof remote storage. https://signal.org/blog/secure-value-recovery/ https://signal.org/blog/secure-value-recovery/ I’m not equipped to assess the cryptographic integrity of their claims, but 1) it sounds like you’re saying that they deployed this technology at scale, and 2) do you have a basis to suggest it’s “not-very-secure or likely backdoored,” in response to their apparently thoughtful and transparent engineering to ensure otherwise?
- andrepd 2y agoCan you elaborate? I'm semi-familiar with the Signal protocol but I'm not sure what you are referring to here.
- autoexec 2y agoSee https://community.signalusers.org/t/proper-secure-value-security-pins-are-too-easy-to-brute-force-sgx-is-not-reliable-enough/15096 https://community.signalusers.org/t/proper-secure-value-secu... Then read the first line of their terms and privacy policy page which says: "Signal is designed to never collect or store any sensitive information." (https://signal.org/legal/ https://signal.org/legal/)
- codazoda 2y agoI was going to discount most of this. It appears this link is missing or private now. What did it say?
- autoexec 2y agofixed the link. Just to be safe, here's an archive of the page: https://web.archive.org/web/20210109010728/https://community.signalusers.org/t/proper-secure-value-security-pins-are-too-easy-to-brute-force-sgx-is-not-reliable-enough/15096/2 https://web.archive.org/web/20210109010728/https://community...
- loufe 2y agoI'm a big signal user yet skeptical that it's not directly involved with intelligence agencies. That's all to say, this sounds like FUD but I think it should be taken seriously. Out of curiosity, where have you read this?
- autoexec 2y agoIt was a bit of a controversy when the change happened: see https://web.archive.org/web/20210109010728/https://community.signalusers.org/t/proper-secure-value-security-pins-are-too-easy-to-brute-force-sgx-is-not-reliable-enough/15096/2 https://web.archive.org/web/20210109010728/https://community... https://www.vice.com/en/article/pkyzek/signal-new-pin-feature-worries-cybersecurity-experts https://www.vice.com/en/article/pkyzek/signal-new-pin-featur... Note that the "solution" of disabling pins mentioned at the end of the article was later shown to not prevent the collection and storage of user data. It was just giving users a false sense of security. To this day there is no way to opt out of the data collection.
- orblivion 2y agoFollowing the conversation down, it sounds like what you're really saying is that Signal stores sensitive information encrypted with PIN+SGX, which is controversial. And maybe you have a good argument for why it's bad (and I'm uneasy with it myself). But I think people don't like that you made the assumption for them that PIN+SGX is bad.
- autoexec 2y agoEven if everyone agreed that the system was secure, and they absolutely don't, see for example https://web.archive.org/web/20210126201848mp_/https://palant.info/2020/06/16/does-signals-secure-value-recovery-really-work/ https://web.archive.org/web/20210126201848mp_/https://palant... https://www.vice.com/en/article/pkyzek/signal-new-pin-feature-worries-cybersecurity-experts https://www.vice.com/en/article/pkyzek/signal-new-pin-featur... I think we should all agree that outright lying to users on the very first line of their privacy policy page is totally unacceptable.
- orblivion 2y agoYou cited this so I think this is what you mean: "Signal is designed to never collect or store any sensitive information." I interpret this, I think reasonably, to not include encrypted information. For that matter they collect (but probably don't store) encrypted messages. The question is, does PIN+SGX qualify as sufficiently encrypted? This line is a lie only if it does not. Sorry I skimmed those articles, I don't want to read them in depth. But it sounds like they are again ultimately saying "PIN+SGX is not secure enough".
- nightpool 2y ago"I interpret this, I think reasonably, to not include encrypted information" Why? Encrypted information is still sensitive information.
- orblivion 2y agoMaybe via metadata? The size of the information, etc. Do you mean that they should have a caveat about that? Or if you want to be literal, you have to say that they're storing sensitive information even if it's encrypted. But by connotation that phrase implies that someone other than the user could conceivably have access to it. So for all any user could care, they just as well are not storing it. Do you mean that they should rephrase it so it's literally correct? Or do you mean that it's actually bad for them to be collecting safely encrypted sensitive data? Because if so, you literally cannot accept any encrypted messenger because 3rd parties will always have access to it.
- teemur 2y agoInteresting. Could you provide a better alternative? Preferably even remotely as user friendly as signal/whatsapp?
- autoexec 2y agoI don't have a good answer. Personally, I'm using Jami for secure communications but I won't pretend it replaces signal in terms of user-friendliness especially back when signal allowed SMS and secure communications in the same app!
- hsuduebc2 2y agoThreema comes to mind.
- lcnPylGDnU4H9OF 2y agoI found SimpleX recently (https://simplex.chat/ https://simplex.chat/), which got my attention because it uses a unique account schema that doesn't have any individual account identifiers. It's got some interesting features. Not sure about user-friendliness since I don't use other messaging apps to know what to expect. It's mostly just interesting to me that they did away with the username entirely and they instead have users connect exclusively through shared secrets like they're Diffie and Hellman.
- saagarjha 2y agoI wouldn’t assume that but I also wouldn’t recommend against using Signal.
- aembleton 2y agoThat we know of