U.S. Senate staff can now use Signal
zdnet.com
zdnet.com
Con: The government does this while still insisting that encryption should have a backdoor in it, thus creating the impression that Government officials deserve bulletproof encryption, but private citizens don't.
It would be interesting to see what happens to Signal if encryption legislation is ever enacted, and/or if it would continue to be used.
* Have to use a government email for official business? Everyone else does but Congress
* Have to keep a record of all communications? Everyone else does but Congress
At least they passed a law that banned insider trading by Congress... but then they repealed the most important parts just a year later! [0]
So, I'm sure we'll see Congress enact a law that requires that all software have a backdoor, unless that software is used by a member of Congress, in which case the penalty for having a backdoor is life imprisonment.
[0] http://www.npr.org/sections/itsallpolitics/2013/04/16/177496...
Second poster up stated that Third poster up's note of "Congress does not have to abide by laws that they set", was separation of powers. Which is exactly what First poster up was talking about. That you say that nobody is saying anything of the sort, deliberately ignores the second post up, which does indeed claim that.
Then they turned around and surreptitiously passed a law allowing foreign funding for political parties (!). Such "nationalism" this. Similar stories are to be found on things like corruption/transparency/Biometric ID laws.
Frankly this is democracy in its true self; the self-righteous religion appears to share more and more in terms of theology with Communism and erstwhile utopian systems. I can't wait to see this whole (world) system go down the gutters, and when people open their eyes to this language game.
That I would agree with, but...
> I can't wait to see this whole (world) system go down the gutters, and when people open their eyes to this language game.
I do hope this is hyperbolic. I personally like our global technological civilization; with all its injustices it's still better than what we had in the past. Also, I don't like wars, and I definitely don't want to find myself in one.
They also require a management that is willing to iteratively rewrite core pieces of the software and release major versions with breaking changes. That is what is lacking in our government, and what fuels the frustration behind calls for revolution.
Right now we delegate it at best to a group of people that are already filtered by money or status, which is oligarchy. Not that I don't enjoy my life in the oligarchy, but it's not democracy.
Can you point me to a source where I can read more about it?
The reality right now is that most members of Congress either don't want backdoors, or don't hold a strong enough opinion to want to upset the status quo.
That can change, of course, and we should all be taking steps to let Congress know that we don't want backdoors, that they are a bad idea. But it's not ideal to start from an incorrect sense of that everyone wants backdoors.
You have to find out what your member of Congress thinks. Luckily it's easy--they have a form on their site for questions from their constituents.
proposes* law ftfy
This might already be the case and is much better then making senate use non-e2e secure communication software.
Whistleblowing and legal affairs come to mind -- whistleblowers need to feel secure in order to report misdeeds, and even elected officials have attorney privileges.
Those certainly aren't the only cases, but they're two examples where open probably isn't the right default for communications.
Governors, Politicians, etc. are public servants. They are not there for their own good, they are there to follow the law, and the serve the interests of their constituents, and only that. Therefore it stands to reason that any communications they have with other officials, about official business, should be recorded as it is a matter of public record. It stops "he said she said" disputes. It helps us know about underhanded deals, unfair advantages, and many of the other things that people do when given such powers with no oversight.
Even with perfect life recorders I think you'd end up with a moribund apparatus playing 5 dimensional tic tac toe (that is, sensible people would call for letting them turn the damn things off whenever they wanted to).
If anyone wants to help out in collecting government communications using FOIA, please let me know. It's surprisingly easy to get bulk communications data of cities, though it ends up being very time consuming with everything considered. I could definitely use the help, especially with a project beyond the city level that started just this week.
Here's [1] an example of a dataset of ~2mo of email meta - about six million emails - I recently received from Houston, TX. (Thanks to Jeff Reichman at januaryadvisors.com for cleaning the data up!)
[1] https://data.world/sketchcity/city-of-houston-email-metadata...
Like, they can use self-disappearing messages, but all messages are automatically archived and encrypted with a pre-set password. I guess this could still open the data to being stolen if the password is discovered, but I don't really see any other solution to making both self-disappearing messages and FOIA requests working at the same time.
Sometimes it's vital that people be able to communicate in private with their reps.
I'm a Signal user and hugely appreciate their push to bring encryption to the masses.
But when it comes to the government, I believe the ideal situation is that there is a literal live-stream of everything they are doing, at all times. Government officials are public servants. Sure, if you're discussing an ongoing military operation, keep it behind closed doors temporarily. But the vast majority of what they're doing should be made accessible to the public in real-time.
The only reason not to do so is to hide lobbyism, partisanship, and corruption from the public eye.
There's nothing wrong with putting public keys on an unencrypted site, though those retrieving the key may want to consider that their access of it may be visible.
If a quorum of some m < n keys can be used to reconstruct a key, and those n keys are distributed amongst a set of generally trusted and coercion-resistant entities, then the option exists for a quorum to be formed under specific protocols which would make the relevant decrypting key available.
In the case of PKI, there's the added twist that the sending party is encrypting to the recipient's public key. If no self-encrypted copy is retained, this means that an escrow policy on the sender need not make available any copies of messages sent -- say, a national legislator. The method would allow for accessing the messages received, however.
(And if the received messages referenced the sent ones, you'd have that content as well.)
Escrow could also be used for other purposes, such as allowing for key recovery, by the authorised keyholder, on appeal to the escrow authorities.
Given the risks and challenges of key loss in a PKI crypto context, these are options which might be worth considering.
Who do they think they are?
What's good for the goose is good for the gander, as they say.
Last year, I helped someone out, including dealing with their manipulative friend. Whose name and number ended up in my Android contacts db.
The other week, Signal pops a message: X has joined Signal. Be the first to send [them] a message.
Um...
If so, I probably wasn't overly worried. But now, seeing this... "unpleasant" person's name pop up, was a bit of a jolt.
Despite some prodding, none of my other contacts have switched over -- from Messenger or Whatsapp or whatever -- to Signal. So, I'm not... "used to" all its behavior, yet.
Yeah, I'm out here in the everyday boonies... ;-)
Also, IIRC Signal uses a hash of the phone number to display if one of your contacts is also using Signal. I understand how that notification might feel creepy at first, but if you understand what actually happens it de-escalates from "creepy" to merely "convenient".
Yes, discoverability...
I'd rather have that explicitly opt-in, not a default behavior.
I view my use of Signal as information I'd prefer not to share with some -- even if they are in my contact db and even if they use Signal.
P.S. Yeah, I see some discrepancy between this and the way Signal is designed and the goal to minimize metadata.
Ok. Still, it was a creepy moment for me, seeing this person's name pop up in a Signal alert.