Personally, I'd like to see Signal replace WhatsApp. That's why I support the path Signal took, and why I also have a distaste for the author's snarky dismissals of features like GIF search.
Personally, I'd like to see Signal replace WhatsApp. That's why I support the path Signal took, and why I also have a distaste for the author's snarky dismissals of features like GIF search.
So the base argument holds in my opinion: Moxies main focus is Moxie in control. And not making Signal the best and securely possible.
So I also use Signal, but as soon as Matrix gets stable, I am gone
Having multiple branded builds to choose from would be a terrible thing and would easily allow fake apps to gain traction.
> ... and if you rebrand he forbids you from using the official Open Whisper servers.
This seems pretty fair to me. Not only could you abuse their resources, it would greatly hinder their ability to make changes and respond to protocol-level security threats. They aren't in the API business, controlling their ecosystem allows them to make forward progress without concern for 3rd parties that they have no control over. And still there is the issue of 3rd parties abusing their server resources.
The main point is, Moxie could take the wind out of the sails of literally all arguments in this page by publishing Signal on F-Droid but he just won't.
This alone is enough for me to lose trust in Signal.
[0]https://signal.org/android/apk/ [1]https://whispersystems.discoursehosting.net/t/how-to-get-sig...
For it to be on F-Droid. I think that much was clear.
Or are we just going by the author's ignorant or disingenuous (depending on how you interpret his words) statements?
If you are so concerned about state-level actors that play store is untenable to you, signal and android on commodity hardware are probably not the solutions you want anyways.
Are there any identified, non-state-level actor threats here, or is this just an ideological rant against proprietary software? If state-level actors are your concern, using android means you have already lost.
It was posted elsewhere but here's Moxie's take: https://github.com/signalapp/Signal-Android/issues/127#issue...
wtf. I have been using F-Droid for many years, and this has not been the case. as far as I know, this has never been the case, as Android has always had functions for third party app stores. in fact, even today, F-Droid recommends not using root for installs, since then you don't get the screen showing permissions.
> allow third party code
that's called running apps.
tl;dr nice FUD.
This is what I do on lineageOS. I don't regularly install new apps.
Side rant: This marketer-driven "install an app for everything" is a threat to the open internet and privacy. Usually the only reason is to extract more personal info.
Already, young people barely use a web browser. That appears to be the future. Now get off my lawn or I'll start talking about the war.
Android could undoubtedly be stronger in this regard, and in permission control, firewall, ad blocking etc, but it's not going to happen.
Apps wouldn't be so bad if they were actually sandboxed properly, but yeah, they suck.
I was interested in Copperhead OS as an alternative, but it seems to have fallen into a greed induced mess.
I am arguing Play store is fine, and side loading is bad policy.
I argued that for every person who will take the time to micromanage permissions, thousands wouldn't.
So what are you talking about?
https://twitter.com/APKMirror/status/1027580291374702592?s=1...
And you accuse me of making things up? "Allow third party code" is not called "running apps"
Most likely one of those, yes. Though on Android 8+ you can only give that allow-install from unknown soures permission to F-Droid.
Also both Copperhead and Fairphone Open ship with the F-Droid priviledged extension by default allowing you to kee that setting entirely disabled.
... are using a platform "you" don't trust.
Really? That's not really odd.
At least, it's not odd, if that usage and what it entails is the denominating part of the persona in this question.
Here's a thought. If you are so concerned about the NSA that you think Google's cloud is a problem, why are you running the OS developed by Google?
I'm not, and I find that position naieve. For the overwhelming majority of people who are not a cross between Bruce Schneier and Linus Torvalds, a threat model that tries to protect against the NSA and GRU and MSS pretty much requires avoiding anything with a network connection. If you have a smartphone, you should probably just use its default application store.
I can trust people that I think made incorrect technical decisions, because I can see that they made a decision for technical reasons and have different priorities and reasoned soundly.
There are, I'm sure, apps that are better, and that's never been moxie's goal. He's said it over and over that he'd rather have encryption for the masses than the perfect messaging app. It seems disingenuous to assume that he's acting in bad faith when he's clearly doing exactly what he said he wanted to do.
If you want to make the prefect, self-hosted, chat eco system, fire up that matrix server and invite your non tech friends to join. I'm sure that will work out incredibly well.
In the mean time, Moxie seems to realize that to accomplish his goal and make communication incrementally more secure for average users, he needs to go where the users are.
It's crazy to me that people still think that secure communication is a technical problem. We've had GPG for the competent for a long time. The hard problems in secure communication are about using the eco systems that are available to large groups of average users and still being secure.
Am I missing something?
I donated some money to them a while back. How hard could it be to push the binaries out to a second app store?
I tried to publish my open-source game on F-Droid, but the build process involves building native components with a specific third-party version of the NDK toolchain, as well as shell scripts to move files around, so it never made it to the store.
In this particular case, not likely. People who are into more secure communication do not randomly click on anything. They know what they are doing, or get it installed from people they trust. And if they don't - their fault. Not Signals.
And Signal can continue to work and introduce breaking changes whenever they want. They simply only support the official build of Signal. Any person using anything different, cannot complain, if things stop working. (they will anyway, sure)
And the ressouce-abuse. Can this really be a thing? I don't know in detail how the protocol works, but what can I do with the servers, I can't do with Signal anyway? Sending (encrypted) data from A to B. I can allready abuse that today, if I want.
I think you overestimate people. I told my wife to install Signal because she needed a password for something and it was way to complicated for her to remember. I know what the signal app is and could likely avoid fakes - she would not. I think it is often the case that only one party of the conversation is security minded, while the others just trust that person.
> And the ressouce-abuse. Can this really be a thing?
You know NTP, the protocol for sharing what time it is? That gets abused badly [1]. If you have an open service, there are ways it can be abused. This would without a doubt lead to DDoS-like resource abuse where lazy clients don't cache things properly and just hog server resources. There are ways to limit things like that- but they aren't always simple. Also, like I said before, Signal isn't in the API business.
[1] https://en.wikipedia.org/wiki/NTP_server_misuse_and_abuse
Not limiting freedom of the user because they know what they are doing at the expense of others is maximizing the protection and freedom of a small group, not society as a whole.
Even if that wasn't wrong, it would be a fatal limitation for a social app which relies on network effects. Even if you were actually super-humanly capable of not making mistakes you'd end up using the apps that everyone else you know is actually on.
That's not the sole market of people who would try Signal, though.
Are you paying him to do that? No? Well, there you go. It's more work, for what appears to be very little benefit.
> The Signal Foundation has 50 million dollars.
Sure, it doesn't allow them the flexibility they'd like to have to move forward but in a way it won't be their fault if federated servers aren't keeping themselves up to date when there's a major protocol change and they get temporarily splitted from the pool.
As long as “email” is a thing, as in “just send me an email”, and it’s a federated set of randomly updated servers, “email” will never have end-to-end encryption, because the first version of SMTP didn’t have it, and the user will still expect to send messages to a server running that version.
Similarly, if “Signal” is going to be a thing, as in “contact me on Signal”, the entire network effectively has to operate at the level of the least up-to-date server — otherwise it’s not one network, and the product is therefore unreliable. But there’s no way to enforce that all the federated servers update themselves in any amount of time.
Signal is successful in large part because it provides complex functionality (secure messaging) in a package that "just works". Federation complicates that significantly.
Without emoji and animated gifs, I suspect 70% of my Signal contacts wouldn't use it at all. It's hard enough to convince some of my friends to use it at all, "Can't I just Facebook message you?"
For me, amongst my group of friends - it seems Moxy is making all the right security/usability tradeoffs.
If you don't trust PlayStore, it seems not much of a jump to say you also shouldn't trust Android.
If you're _rightly_ that concerned (and I'll note that Snowden recommends Signal, so I wonder what it is you're up to that makes you more of a nation-state target than him), I don't have a clue what your options are - I suspect they start with "don't use the internet at all"...
I don't know what it is you're talking about. The entire point of my comment was that I don't like animated gifs. They're distracting, bandwidth intensive, and could be easily replaced by a dozen better image formats.
And while I agree with you about animated gifs, I understand WhisperSystems reluctance to try and become the force that turns non-geek non-privacy-activist users (which they and I are hoping will widely adopt Signal) to find WebP or flif or whatever alternatives to giphy or where ever else they're finding their reaction gifs and topical memes and funny cat-riding-a-roomba animations from. That's how a _huge_ percentage of users want to communicate with each other. Moxy is trying to give them a secure way to communicate how they want to, not attempting to force them into new ways of communicating that have boring justifications like "bandwidth saving" or "animation format technical merit" as the only reasons why they can't have vast libraries of funny animations to send their friends... If they can't quickly reply with Ru Paul doing fingersnaps in Signal, they'll go do it on Facebook instead.
For that reason, I'm of the opinion that _not_ supporting animated gifs is significantly more counterproductive, if you're trying to become "the secure messaging mechanism the whole world will use" or if (like me) you'd like more and more personal communication to be exclusively between the participants, and not include advertising networks and data miners and sentiment analysers (and, yeah, law enforcement and government bureaucracy)...
And one day we realise it was indeed something nefarious, let's assume something of this sort happened in the future, and then we rue that we didn't act when people used to say something was amiss.
There is one line in the article that says it well:
> Truly secure systems don’t require trust.
edit:
I have supported Matrix and Firefox among others (both in code as an Android dev and with modest donations - stopped using Firefox after Pocket). But no, not Signal. I'd wait for federation (if at all).
These all seem like reasonable permissions for the features available.
edit: Apparently, Signal does this for some things? See comment-replies.
Older Android versions only had the idea of the app declaring "I need to be able to use your Camera, read your Contacts, and make $$$ phone calls" and then you pick "No" and don't get the app or you pick "OK". This more or less railroads users into pressing "OK", except for the most security conscious, who go without the app.
A few releases back Google had an unofficial feature that let you switch off features an app had, and it would get some dummy replacement, e.g. if it had Contacts access but you switched that off, it would see no Contacts at all. If it had Camera access, but that was switched off, it would always be told your Camera was busy in another app. Once word about this hidden feature got out, Google disabled it.
Recent releases (Certainly on my Nexus 5X for example which is a while back) enable an app to ask at runtime. If you said "No" the app gets a second chance to explain itself, and then if you keep saying "No" the feature is just disabled and Android stops prompting you. The app might not work after that of course. Like the disabled older feature, the Settings pages for apps let you undo previous authorizations, again this may make certain apps malfunction - a map app with no GPS is merely crippled, but a "barcode scanner" with no Camera access is junk.
However of course apps for an older phone don't prompt, the older Android can't handle it, so for them you still have to make the decision at install time.
https://developer.android.com/distribute/best-practices/deve...
@mrguyorama - this means you can force the old landgrab user-hostile permissions to people running old Android versions, but you cannot force them onto users running Android 8.
1: https://developer.android.com/training/permissions/requestin...
Traditionally, in Signal that process has looked like:
The client calculates the truncated SHA256 hash of each phone number in the device’s address book.
The client transmits those truncated hashes to the service.
The service does a lookup from a set of hashed registered users.
The service returns the intersection of registered users.
The phone number space is really not this big.