Top
Best
New

Posted by Cider9986 6 hours ago

Registration without a phone number on Signal will use zero-knowledge proofs(community.signalusers.org)
119 points | 63 commentspage 2
user3939382 4 hours ago|
I don't trust Signal. The device OSes and hardware are opaque, chatty, not private or trustworthy, the network backbone is completely owned by dragnet surveillance, Dual_EC_DRBG flavored shenanigans, so how could an app running on top of this suddenly be trustworthy? Especially one that's super high profile which signals inside a dragnet "someone is working especially hard to make this secret".
bawolff 4 hours ago||
Viewing any security thing as a binary is the wrong way to look at it. Figure out your adversaries, how much power they have and what they are willing to spend. Make your decisions from there.

I personally think signal is sufficient for the threats the average person is concerned about, but that is a decision each individual has to make for themselves.

420official 4 hours ago||
Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?

I concede that if you can't trust the device itself you can't trust anything running on it, but why have you resigned yourself to that? And how does that reflect on signal at all?

mmooss 4 hours ago||
> Is it your expectation that E2E is broken by these "dragnet surveillance" networks? Surely not?

While I disagree with these critiques of Signal, the surveillance networks can capture metadata - who talks to who and when - without breaking E2E. The metadata is as valuable as the data.

I think Signal has a feature to protect users, but I can't imagine how it works if the attacker can see all parties' Internet connections.

420official 1 hour ago|||
It's true someone snooping at either end of a conversation could over time correlate timing and sizes to show that two users are communicating, but that's the most they can do. Signal is not peer to peer so you're not connecting to your recipient, and signal itself has enough raw volume that simply correlating sizes and timing of a small number of messages wouldn't really be sufficient to know who is communicating with who.

I think they could make that significantly more difficult by adding csprng delays and padding to the messages. That way you can't really effectively correlate timing and sizes without direct access to signals inner workings. I'm not sure what signal's actual throughput is, but if think as a paid feature it could be economical.

Another crazier way would be to send every message to a large number random latched recipients. Good way to 1000x your bandwidth.

> The metadata is as valuable as the data.

This can be true if you are able to get ahold of a user's device and access their signal messages. It's not true in most other cases. I don't particularly care if you know that I am talking to someone specific as much as I care that you don't know what I'm saying.

ranger_danger 1 hour ago|||
> the surveillance networks can capture metadata - who talks to who and when

If this is part of your threat model then I would suggest a different tool such as SimpleX since it uses onion routing and can be configured to always use private routing/relays.

bawolff 52 minutes ago||
I'm not familiar with SimpleX, but keep in mind only some types of onion routing is secure against a global passive adversary. Famously Tor is not.
Cider9986 33 minutes ago||
Nym is apparently good against a global adversary.
atiq-ca 5 hours ago|
Signal still uses proprietary blob and uses google/apple service for notifications. Use molly.im instead which has solved these problems.
Cider9986 4 hours ago||
Molly is a security-hardened Signal client only on Android for people unfamiliar. They went through a period of not updating (there were no security updates during that time afaict), but now releases should happen faster on top of Signal.

In Molly there's three options. Google Play Services, WebSocket, and UnifiedPush.

I use the WebSocket and Molly has used >1% of battery since the last full charge so it doesn't seem like play services would improve battery but maybe if I had more apps depending on it..

Google and Apple can't see the notification content but they can see metadata. If you want metadata privacy you should use SimpleX instead anyway.

rkagerer 4 hours ago||
If you're using WebSocket, how do Google and Apple see metadata? Can someone explain why it's so difficult to make a decent chat app divorced from their ecosystems?
Cider9986 4 hours ago||
I'm talking about using play services or Apple's version. Signal falls back to a WebSocket if you don't have play services installed.
john01dav 4 hours ago|||
The native Signal android app delivers notifications just fine without Google play services on my degoogled android.
twothreeone 1 hour ago||
Same!
opan 4 hours ago|||
I was using Silence from F-Droid for a while back in the day because of these issues, but the lack of interop and needing to make everyone move again soured me on the whole thing. I would rather just get people on XMPP or Matrix and not use some sketchy phone-first app at all. For SMS I use Fossify Messages, which I think was a fork of QKSMS. I don't use SMS as primary or sensitive comms, only as needed. Same as email, basically, but less useful.
nosioptar 4 hours ago||
I really liked silence. I stopped using it when f-droid said the source code was no longer available. Fossify messages is the best replacement I've found.

(I dont bother with encrypted messenging apps. I prefer to assume that anything I do on my phone is doubleplus unprivate. If I want privacy, I head over to my computer.)

Cider9986 3 hours ago||
GrapheneOS is more well-roundedly private than any desktop OS.

Competition is Qubes but that has usability issues and does not have good hardware security.

wolvoleo 2 hours ago|||
The problem for me is writing on a mobile device is a terrible user experience.

When I'm at home I don't wanna use a virtual keyboard on a 6.3" (or 7.9 unfolded). I just want to use my triple monitor PC setup with a real keyboard and a wealth of display space.

Mobile is cool for on the go but a productivity killer.

nosioptar 3 hours ago|||
I'm not about to trust a google branded device. Even if the Graphene folks are on the up and up, google sure as hell isn't.
Cider9986 2 hours ago||
That's not based in reality. Why would Google have a hardware backdoor when 99.9% of their users run their software giving them the data they want.

Google Pixels have no evidence of a hardware backdoor when a desktop is proven to be much less secure against remote and local exploitation.

It has been shown through leaks that Pixels running GrapheneOS are the most secure against Cellebrite in AFU. GrapheneOS was the first to implement a reboot timer feature which brings the device to BFU (much more secure) and then Android and iOS copied it (with longer, non-customizable duration).

You can inspect network traffic to see that GrapheneOS phones only connect to GrapheneOS-run services.

Here's a team member's thoughts: https://discuss.grapheneos.org/d/10150-not-your-average-why-...

ranger_danger 58 minutes ago||
But GrapheneOS relies on a proprietary, black-box security chip from Google... who pinky-promised to open-source it but never did, and that just doesn't sit well with me.

I think it's entirely possible that a compromised Titan module (whether such code ships with the device or is updated at a later point) could leak keys via some covert method, and possibly transmit via the baseband or through some other application/method where the OS is not really aware of what's going on.

ranger_danger 5 hours ago|||
I tried it and it was fine while it worked, but eventually I had to go back to regular Signal because Molly's updates did not follow Signal's closely enough, and at some point the server code changed enough to where I was unable to use it for an unacceptable amount of time (after checking, it took them weeks to update). Something to keep in mind if you're not using a custom server.
blfr 4 hours ago||
Maybe it's because I use Molly as a secondary device (my tablet) but I never had an issue where it didn't work for weeks.
throwaway35435 4 hours ago||
[dead]