3 ms·
Maybe I shouldn't, but I stopped taking the author seriously for their lack of nuance/extremely biased views favouring Signal in every article about E2EE applie
by ezst 3mo ago
Maybe I shouldn't, but I stopped taking the author seriously for their lack of nuance/extremely biased views favouring Signal in every article about E2EE applied to IM. But I do agree that threat modeling is just a support to formalize and document the variables in the threat equation. It doesn't say anything about whether the threat is reasonable, legitimate and grounded in reality, so it's only knocking the subjectivity can a tad down the road.
- wizzwizz4 3mo agoDoes one have to be nuanced in everything one says? I'm not a fan of Signal's threat model, especially their historical threat models (e.g. acting like it's safe to link users to phone numbers, and then advertise which phone numbers are and aren't using Signal), but Signal's main protocol seems pretty solid, especially compared to some other systems.
- some_furry 3mo agoMaybe it's because I'm a bad writer, but I've heard from at least a half dozen people in recent years that they think I'm too pro-Signal when my actual stance wasn't "Signal is good" but rather "all these so-called alternatives suck ass when it comes to cryptography implementations". Signal pisses me off in a lot of ways. If someone joins a group chat and posts horrific content, the admins cannot clean it up. This extremely basic functionality doesn't meet the most basic bar for group moderation and safety tools. This means a troll posting a high-frequency flashing GIF to a group chat full of epileptic people is going to cause real harm. This means someone joining a chat and posting unsolicited CSAM will legally imperil everyone present and the admins are powerless to intervene at all. They seem really indifferent on fixing this. I would love for an alternative app to materialize that provided the same level of cryptographic excellence as Signal but without the enormous ego of their marketing teams or evangelists, which actually put a microgram of care into user experience and community safety. None of the alternatives people raise meet the bar, and I find it extremely disingenuous when people insist their privacy (which is a second-order property from their cryptographic implementations) is somehow "better than Signal". So when people do this, I tend to 0day their favored apps. https://soatok.blog/encrypted-messaging-apps/ https://soatok.blog/encrypted-messaging-apps/ We, collectively, as an industry, should be able to do better. That we haven't is depressing.
- wizzwizz4 3mo agoYou've written about the minimum bar before (https://soatok.blog/2024/07/31/what-does-it-mean-to-be-a-signal-competitor/ https://soatok.blog/2024/07/31/what-does-it-mean-to-be-a-sig...). Have you written up your Signal criticisms / desired features anywhere? (Or, do you know where anyone else has?) I have my own ideas about requirements, but they're not concrete enough to say "requirements analysis done, let's start programming"; and most people I talk to haven't thought about this enough to be helpful.
- some_furry 3mo agoI've posted on the Signal Discourse and even had a colleague ask the Signal devs at Real World Crypto this year about this missing feature. No dice on either approach.
- ezst 3mo ago> Does one have to be nuanced in everything one says? no, but unlike a computer, the real world isn't binary, and recognising that it's flawed and full of compromises generally heightens your chances of affecting it (by your ideas or actions). > I'm not a fan of Signal's threat model […] but Signal's main protocol seems pretty solid, especially compared to some other systems. My main gripe with Signal is that no amount of protocol sophistication can undo the problems linked to it being a centralised service. Soatok seems unable to acknowledge that centralisation is a real (privacy, security, reliability, political, …) concern here, nor to see value in the decentralised (federated/P2P) alternative protocols implementing the same double-ratched/PFS crypto primitives.
- some_furry 3mo ago> Soatok seems unable to acknowledge that centralisation is a real (privacy, security, reliability, political, …) concern here, nor to see value in the decentralised (federated/P2P) alternative protocols implementing the same double-ratched/PFS crypto primitives. I genuinely do not understand where this impression is coming fron. The only thing I've ever written about this topic acknowledges that centralization has risks, but a perfectly decentralized system that doesn't properly encrypt data end-to-end is bad for user privacy. The cryptography needs to be excellent. "But decentralization" doesn't cut it. https://soatok.blog/2025/07/09/jurisdiction-is-nearly-irrelevant-to-the-security-of-encrypted-messaging-apps/ https://soatok.blog/2025/07/09/jurisdiction-is-nearly-irrele... Disagreeing with me is one thing, but claiming I seem "unable to acknowledge" anytbing is dishonest.
- ezst 3mo ago> I genuinely do not understand where this impression is coming fron. I don't want to engage in a citation battle, I just can't care enough for that. Having read those posts about Matrix, XMPP (OMEMO) and a couple others, many months/years ago, they really came across as "screw those amateurs for even trying, Signal is great, and by my very definition of it, only Signal can be". Again, those are not your words, but something about the tone and the way you compare them made it sound that way. Also, even if that's besides the initial point, I firmly disagree with the premise of the post you just linked. For the same reason mentioned in a sibling comment stating that the real world isn't binary even though IP addresses might be: A centralised service is political no matter what. If not their admins, their hosing provider or executive power may decide to censor you based on your country of origin, political beliefs, ideological activism or any other reason out of your control. Signal's crypto protects what's in the envelope, but does little else (neither can it) against a motivated state-actor fingerprinting you beyond the service boundaries, and guess what, we know it to be a fact for the jurisdiction Signal is operating under.
- throawayonthe 3mo agoperhaps not the kind of nuance you mean, but this post criticizes signal for not having a threat model
- frmersdog 3mo agoThe author is an over-opinionated a*hole, so not taking him seriously is perfectly fine.