EU Commission to staff: Switch to Signal messaging app
politico.eu
politico.eu
Once all of the interns got invited to the U.S. embassy to meet the Ambassador (some guy who literally said he got the job because he was friends with Obama). On the way out the nice embassy staff gave us goodie-bags, complete with handy pen drives...
Basically everyone was giving away free pen drives in Brussels then. I would be surprised to find that the U.S. didn't already have access to a large number of EU institution computers.
I'm sure the NSA has implants in the EU systems but they're not dumb enough to just hand them out on USB drives that can be traced back to them.
Though even then, you have to have something to compare it with and also know what you are looking at and able to eliminate what should and shouldn't be there.
Though when you have multilayer flash, the possibility to have a nefarious layer, sandwiched between good layers, makes things way harder.
All that said, as a rule, I'd just downright ban any non-company/entity USB drive or any tech. Keyboards and Mice, more so.
Why not? The US was found to be spying on Merkel and nothing seemed to come from that.
There are two kinds of U.S. ambassadors:
1) Career foreign service people
2) Friends of the presidential administration at the time
Examples of the latter aren't hard to find. Off the top of my head I'm familiar with William Timken, a US businessman who was appointed Ambassador to Germany by George W. Bush because he was a huge supporter [0,1]. Colloquially we could say he got the job because "he was a friend of Bush."
I remember being surprised to learn that US Ambassadors were (maybe still are) individually responsible for paying for a good part of their formal duties as Ambassadors(eg throwing parties, travel, etc). So historically, having wealthy people in the role was a requisite. I gleaned this from reading "In the Garden of Beasts" by Erik Larson [2].
The bits I have cobbled together suggest there is an interesting history surrounding the practice of selecting and acting as a US Ambassador.
[0] https://2001-2009.state.gov/outofdate/bios/t/53349.htm
[1] https://www.spiegel.de/international/spiegel/us-german-relat...
[2] https://www.goodreads.com/book/show/9938498-in-the-garden-of...
The real work is done by the diplomats who are appointed through the US Foreign Service office. They do the actual work of the embassies.
Not really, a foreign service officer can be appointed by a president to be an ambassador. A recent example from the news is Marie Yovanovitch. In regular times, my impression was that foreign service officers were appointed to the more difficult and critical ambassadorships (e.g. Ambassador to the USSR), and friends of the president were appointed to "easy" ambassadorships (e.g. to a staunch ally with a fashionable capital).
Now, for sensitive countries you want a specialist. Like your probably not sending golfing buddies to broker Israel/Palestine peace agreements. But they'll probably do alright being the Ambassador to Belgium or Canada. Those embassies are practically on rails.
Nepotism is a problem, as is cronyism.
1. People the administration is paying to go out and brown-nose foreign leaders, or those leaders’ own ambassadors/diplomats, in a combination “outbound sales” and “customer service” sort of way;
2. People who presumably have the ear of the administration, where foreign leaders want to pay to impress them in order to access the administration through them.
Whether or not you call someone who’s a friend of the president an “ambassador”, foreign leaders are going to want to treat them as an ambassador, so you may as well give them the protections that playing that role requires—even if they never normally leave the country—on the off-chance that a foreign leader either runs into them or intentionally pursues and {hires through a proxy, seduces, coerces, etc.} them.
In this second sense, “ambassador” is short for “a person a state leader is worried about the welfare and mental sanctity of, in the face of global political machinery trying to manipulate the leader by any means necessary.”
Though it would be good if there was an open source communications platform that would allow the public to engage with politicians in a formal and constructive way. Alas, so much disparity in solutions that it often irks me.
https://ec.europa.eu/digital-single-market/en/projects Be great if the interface was better for that site, though google didn't find anything of note.
I can think of many comparable situations in other countries (some EU ones as well) in which the person finding the issue would of very easily been locked up.
The actual bug was thanks to a long-standing bug in python's standard email.utils library, which finally got fixed: https://bugs.python.org/issue34155, combined with insufficiently-defensive coding and testing on my side. (I wrote the auth code in question).
It does not really say that the app is "super not secure". Just that people make mistakes, and it's not even shameful the way they reacted to it.
My favorites was the "special email inbox for lawyers".
So, I am somewhat hesitant to let the EU develop a chat client.
I hated working there because I felt like a parasite just making the world worse. The in-hosue IT of our customer would probably have done a better job if they had just been allowed to hire some guys instead of having to go through an easily gameable procurement procedure. Not because they would have been more competent, but because they would have not have had perverse incentives.
I mean, we've got this nice secure login system for government sites: DigiD, which works fine. So you need that to submit your taxes. A few years ago, it turned out you needed any valid DigiD to submit your taxes, not necessarily your own. There are tons of other sites that cost many millions, and resulted in an atrocious user experience. And some projects simply failed after going way over budget.
Estonia has a similar solution, but "Smart-ID" was created after PKI was fully rolled out, it's terrible compared to that. Centralized, unverifiable, stores secrets insecurely, does some cryptographic bullshit. The two solutions somehow seem very related.
But my point is that even if DigiD is secure, that's still not going to help you when the tax service uses it incorrectly.
I haven't heard any such criticism about that system before, so it would be interesting to hear. I've been using it for years, it's easy to use and there haven't been any security problems with it. The company that developed it is trying to export it to other countries as well.
It doesn't utilize a hardware-backed secure secret storage on Android (~80% of marketshare in EE if I remember correctly). This means vital key material is unsafe from any compromise, just a plain file somewhere. This means that they have to go into a lot of effort to detect clones, which is also certainly not infallible. Cloning or compromising an ID-card of Mobile-ID is way way harder with it's audited security.
The technical overview describes how key is generated on the device and half of it is sent to AS SK's servers. There's no security benefit in that (they can't really verify you've deleted their half of the key from your device), except that now AS SK has half of your private key. In general their technical overview gives the feeling that like they want to pull wool over people's eyes, it's IMHO a bad sign.
It also totally lacks any privacy, every login you do is logged and counted. SK AS shouldn't mandatorily have that metadata.
It relies completely on their centralized servers, they go down, your authentication and signing goes totally down. Neither service owners or their clients can do anything about that. Identity mustn't be like that.
It's totally proprietary, thus their claims about security can't be easily verified, and it's limited to their blessed OSs (and versions). If they go bankrupt or similar, the identities of all those people are in jeopardy.
It's also expensive for server administrators and thus has a high barrier of entry. Identity and security shouldn't be behind a paywall for neither side. The web has LetsEncrypt and now a lot more sites are protected, the web is better off, SK AS has done the opposite.
In comparison, ID-card's PKI is usable for free, supported in every system (that can do TLS basically), entirely FOSS if you wish, the hardware is much more secure (EAL6+), it doesn't mandatorily leak metadata, doesn't rely on a centralized proprietary server to work.
Then use that for the competition to get the contract.
Preselection is hot garbage, as proven time and time again. Of course mechanism to mitigate the upfront cost of participating in such a competition should be implemented but in the end it should turn out cheaper/more worthwhile since a working MVP already exists by time of selection.
And anyway most costs are incurred during the lifetime of the project, after you proved yours is the best solution, with endless change requests, delays that require additional money, etc. The companies bidding usually have far more experience at syphoning money than the client has at holding on to it.
The development is also more expensive than in other areas since there is need for documentation.
And then there is a flaw in the process: Producing the software has to be done via some bidding process. For writing the requirements documents they already rely on companies, which can add clauses making it hard for competitors, after that the lowest bidder wins. In case there is a competitor and not some big player like T-Systems as the only one the offers typically are "optimistic" meaning that at some point in time the budget will run out and extra budget has to be granted (or the project would fail, which doesn't look good and they'd have to restart the whole process, thus wait another two years) and there a "smart" company can find quite a few extra costs. ("Oh wait, you updated from windows XP to 10, we have to redo a lot and then re-twst and re-certify")
It's a game some companies can play quite well.
That all said: Software is expensive. Gathering requirements is hard. Bureaucracy, which among other things tries to prevent corruption, causes extra work.
When, say, the national Police asks companies to come up with sofware to manage contact details for all employees, you could come up with "Install and Configure SomeOpenSourceCRM on a VPS" for €3000.
Whereas typically some Enterprise Consultancy quotes a factor hundred of that to "integrate" it in a crappy way.
I've worked in such projects, for governments. The overhead is ridiculous. the NIH-syndrome is rampant. The specs and "but this is how we do things"-requirements are cut in stone.
Very often a evening of tuning some Open Source tool could suffice; But either some rule disallowing the language/server/deploy-speed, or some manager disliking it because last year they decided that from now on everything must be Java+XML, or you need at least three weeks of meetings before you are allowed to even start.
This is not a joke. I've had a simple off-the-shelve Rails tool cut down, because "we don't allow dynamic languages". I've had projects delayed with 3+ weeks because "we require a deploy-window to be announced 21 days in advance" and I've worked as only developer on a project with four(!) managers managing me.
That is why government projects are expensive: a catch22: "Because they are".
> we don't allow dynamic languages
I would translate as "we have now experience in running and maintaining those platforms, which causes issues"
> require a deploy-window to be announced 21 days in advance"
This sounds a bit like ITIL or similar processes in oalce, which are there to ensure the systems are in defined state.
> with four(!) managers managing me.
Usually those should have different roles. Like technical oversight, communicating with the actual users and getting their requirements, then the IT management for operations and than oversight (variance exists, but lots of things, different stakeholders and as they spent public money they have to do extra documentation of processes for accountability reasons)
While I also feel the temptation to yell "I could do it for 1/100th of that" at a screen when I read/hear about these projects, just basic probability suggests that I'm probably wrong. It's me (with as little enterprise" experience as I could manage) vs a whole lot of people that don't strike me as particularly stupid and who have lots of incentives to keep costs down.
When you try to buy software like this through conventional state procurement mechanism you'll inevitably waste a lot of money, but it would be really cheap to "grow" it through supporting an environment where that can happen. Why doesn't Werner Koch have a position in academia? Third party funding of whole departments is commonplace and is always a blind bet trusting that the grantees will come up with something rewarding.
[0] (In German) https://www.heise.de/newsticker/meldung/Open-Source-Bundeswe...
Signal does the job, doesn't store data, not even metadata, and can be used immediately.
But the code is right there for you to read it and re-use it, you just won't get far building your own network with one user and demanding everybody else switch over.
Isn't that just a promise? Also, even then, it is based on your contacts, which are seen by google.
You can use a different contacts app, you don't have to give all your information to Google. My contacts are managed by a Nextcloud instance.
As far as I know OWS does not mention this anywhere on their site nor on their program -- aren't the issues with usability of other programs and lack of sane defaults (such as with gpg) often given as an argument by signal supporters on why you should prefer it?
That being said, is that even possible? I admit that I am not too familiar with how Android phones work. Signal requires the google play services in order to work, right? Is this not enough for google to see your information?
Signal also released a WebRTC version that doesn't depend on Google Play Services if that floats your boat.
Your phone number is sent to Signal's servers during sign-up and it uses the conventional SMS service to "close the loop" and prove this number is under your control. Having signed up you can use a PIN to lock the number to you so that anyone without that PIN can't do the "new phone" dance (this expires if you stop answering PIN questions correctly)
If you choose to do so a digest of your contact's phone numbers can be sent to Signal for them to match against the set of (also digested) numbers of Signal users so they can tell you who has Signal enabled.
Whether you choose to give your contacts to Google, to Facebook, to Apple or whoever is up to you and outside Signal's control.
Signal does let you create an encrypted profile, and then your device can tell other people's devices the keys to look at the profile if you want to allow that. You don't have to use a profile or trust anybody else if you don't want to. Signal doesn't learn the keys (unless I guess you deliberately sent them those keys) so they can't read the profile.
Unlike many of its competitors Signal's messages can't be read by Signal, in most cases this includes who sent them (Signal's "Sealed Sender" means in most cases if you correspond with someone the indication of who sent them a message will be encrypted such that they can tell you sent it but Signal only knows it was someone they authorised to send them messages). When you attach images Signal avoids learning how large the images are exactly, and if you use a service like GIPHY to add typical meme images like Stephen Colbert eating popcorn Signal double-proxies this so that they don't learn which GIF you used, and GIPHY doesn't learn who used it.
Edit: Fixed name of GIPHY. Huh.
I can look it out for myself but there won't be any point as they can simply run different code on their servers.
> If you believe that despite precautions the source code won't match what actually runs on your phone
On their servers
Also what precautions? As far as I know their binaries are not reproducible.
> this expires if you stop answering PIN questions correctly
After a week if I remember correctly.
> a digest of your contact's phone numbers
> also digested
A hash? This does not protect against anything. There are much less than 2^32 active mobile phone numbers per country. It would be trivial to brute-force it.
> Whether you choose to give your contacts to Google, to Facebook, to Apple or whoever is up to you and outside Signal's control.
The point is that someone* other than you will be able to see the metadata. It does not matter if it is Signal or not.
OK.
That's true for literally all services. Do you expect to be able to walk into the server rooms and dump the binaries to inspect them?
> Also what precautions? As far as I know their binaries are not reproducible.
The client builds are. Reproducible server builds don't tell you anything about what is running.
The point is that your client should not send any information which you expect to keep private to their services. It is the exact reason that we use e2ee rather than just tls for chats.
> The client builds are
Not fully, see https://signal.org/blog/reproducible-android/
> Reproducible builds for Java are simple, but the Signal Android codebase includes some native shared libraries that we employ for voice calls (WebRTC, etc). At the time this native code was added, there was no Gradle NDK support yet, so the shared libraries aren’t compiled with the project build.
> Getting the Gradle NDK support set up and making its output reproducible will likely be more difficult.
Yes. And Signal achieves this better than all the other major options, given the number of footguns in the other tools.
If you are concerned about the client builds then run a decompiler. It's not hard. People have been auditing binaries for ages.
https://www.aclu.org/open-whisper-systems-subpoena-documents
You can also disable contact backup on Android.
Forking a piece of software whose market moat is 100% network effects is not easy.
As a citizen within EU I would rather see them donate money to the Signal Technology Foundation instead. OTOH that could be controversial, so perhaps it would be better if citizens and companies would donate directly instead.
[0] Signal conducts the hiring and interviews, EU pays the salary
The EU's structure is also a bit different than that of nation states, with cabinet members and parliament rather limited in their ability to make spending decisions. Anything serious needs approval by the council, i. e. the heads of state.
And just now is probably a bad time for new expenditures, as Brexit will severely cut into revenue.
Developing a custom app would mean throwing tax money into a black hole, generating an inferior product that nobody would use (among other things due to the complete lack of network effect). Supporting an existing, good open-source product (and possibly spending grant money on _that_) makes a lot more sense, and is a practical solution.
The margins of law enforcement and intelligence can be blurry, but to the extent that they're antagonistic towards private communication as a whole... "law enforcement" is kind of a euphemism. The article should have said "could antagonize the intelligence community," whether it's police or whatever.
Over time this "antagonism" is growing, because intelligence is increasing its reliance on these data sources.
"What do you mean we can't analyse IM chats. How are we supposed to do our job?"
If you are interesting enough to be a target to the CIA's of the world then they will probably find a way to get at you, if not through your phone then through your spouse's or maybe your Echo or whatever. These people would do well to distance themselves from devices in general
For the masses who do nothing too wrong yet still engage in WrongThink(TM) (relative to the politics of the time and place) these apps are great because they astronomically increase the effort requires for law enforcement to rifle through your private communication which greatly reduces ability of police to have the power of arbitrary enforcement over the common man. A consequence of this is that tracking down drug dealers and other petty criminals requires "good old fashioned police work" as opposed to hooking their phone up to a black box like police have grown accustomed to.
I agree with you that the distinction between law enforcement and intelligence is blurry but it's the folks solidly on the law enforcement side that are hindered by E2E encrypted messaging because it diminishes their power over people who have done nothing wrong and makes their routine work marginally more difficult.
The big thing for intelligence is that now they track everybody. It doesn't matter if they think you are relevant or not, if at some time you become, they already have plenty of material to blackmail you.
I don't understand why there's so much publicity behind Signal, and Wire is never mentioned. I've been using Wire for years, and it doesn't require a phone number to setup.
I honestly don't see how privacy and security do not go hand-in-hand.
From Wikipedia[0]: "Wire stores unencrypted meta data for every user" ... "Wire changed its privacy policy from "sharing user data when required by law" to "sharing user data when necessary"." ... "Wire did not inform its users about this policy change, which makes it even more suspicious, considering that it is about a tool that promises privacy to its users."
I use to speak highly of Wire a few years ago but have not used their programs in a while. It's pretty clear that non-corporate users and their expectations of privacy are of little importance to them.
All the three-letter agencies already knew they had these tools available, GPG, veracrypt, Signal, etc.
Now it's just impossible for governments to whole sale eavesdrop on conversations. If they want access it now has to be targetted, and most likely device specific which is harder.
Moxie had better preemptively order up some new code reviews.
That phrase needs to be deprecated
It collapses to 'verify'. Just say that.
I'd be surprised if anyone has ever actually done this. It's a very obscure thing. But to their credit, it's possible.
SGX can't actually make you have secure end to end encryption though. The Signal protocol is necessary but not sufficient. The operators can always just push a software update that invalidates all the security guarantees. It's been a problem since the start but they never talk about fixing it, even though the issue is a glaringly obvious one.
What they could do is allow third parties to audit their software updates, and then cross-sign the binaries. Android allows this but there's no UI for it. It'd benefit from a collaboration with Google to allow multi-vendor apps.
After that comes sandboxing. Dalvik/ART doesn't support the Java SecurityManager API. However, for sandboxing software components cheaply it's hard to beat. If a component is sandboxed in a correct manner then the audit costs get much lower. You don't need to re-audit a component that's changed if the sandbox means it can't access keys or message data, for example (and if everything is memory safe: you'd have to do multi-process on iOS which is a lot more expensive).
Assuming that the sgx environment hasn't been tampered with. There have been several flaws in sgx, e.g. https://www.theregister.co.uk/2019/02/12/intel_sgx_hacked/
And so far these are not zero day bugs. The researchers work with Intel to only publish when there are fixes available, usually. It's not much different to any other security system in that sense.
Consider: how do you know the SSH server isn't tampered with? It could be feeding you an entirely fake session.
You might say, the sandbox. How do you know the sandbox isn't tampered with?
How do you know the hard disk or the RAM isn't tampered with? The third party owns the machine itself.
SGX is based on the insight that it's very, very difficult to tamper with a physical circuit as small as a CPU. The CPU is the root of trust in any machine. If a CPU can produce a report that says the moral equivalent of "I'm running an OpenSSH server version X" and the CPU itself is preventing the server owner from tampering with the software, then you have the ability to reason about what the server is doing with your data.
As for the actual client, see https://signal.org/blog/reproducible-android/
Right now signal is not fully reproducible so you can't trust that the binary that they distribute does not use a different code.
I would be more worried if only communist / socialist nations (you all know the ones I am talking about, not sure of a better name so calling them what they claim to be) were using it. If the NSA advises against Signal that might be another concern. It might mean a foreign intelligence has access somehow.
"Totalitarian" would be a better word, I think. This isn't specific to economic systems, it's about governments wanting to control the communication of their citizens (or subjects, I guess).
> "If the NSA advises against Signal that might be another concern. It might mean a foreign intelligence has access somehow."
Or it could mean the NSA does not have access. They do have a history of wanting access to encryption systems.
Totalitarian is probably closer to the word I was trying to think of.
ACAB
This is as secure as purchasing a machine from Crypto AG. [1]
For an individual that is obviously infeasible. For the continent of Europe as a whole, it obviously isn't. Why shouldn't they put some money into developing cellphone hardware with open source drivers?
Supply chain security is an independent problem. First you have to know exactly what the design is supposed to be, only then can you verify that it actually is.
Some forks of Signal are, though[2].
[1] https://community.signalusers.org/t/how-to-get-signal-apks-o... [2] https://forum.f-droid.org/t/signal-in-f-droid-in-2018/2847
Not sure how feasible this is on iOS (with Bitcode).
Just keep relying on some Californian dude that insist i give him my and my friends phone numbers?
And harass me so i give him more info to “personalize my profile” !?
session (very bleeding-edge p2p signal fork) https://github.com/Loki-project / https://getsession.org/
- There is a fixed pop under at the bottom of the screen asking me to confirm my profile name, with “Get Started” or “remind me later” (which is apparently every time i come back to the app), and no “never“ option. I had already put a first name but that’s not good enough. Had to do it again to confirm i don’t want to share a last name with him / them.
- why does he care about the distinction between a “first name” (mandatory) and “Last Name” (optional)
-> Only the user should care about the name.
=> Why should the app / he / them get access to my contacts list to update a contact name? I’m perfectly willing to have duplicate contacts siloed in a “secure messaging app”.
Also, could someone explain why the app need phone numbers ? They only send some initial token over SMS, which can be spoofed.
Looking at the other comments, the European alternatives don’t look very secure, so it looks like they prioritized security here.
In what way are Wire and Matrix not very secure, though?
A half-broken service would be better than one under US control as the US is the one doing the most snooping on EU. Getting everyone to switch if Signal ever stops being secure would be way harder than to pick a better service now and help secure it.
Matrix would be a better choice for one. Saying EU services isn't secure is hyperbole.
Signal might be open source but the servers are still run in the USA and thus are subject to the US "legal system" (which in turn is subject to the mood of its president).
Correction: The signal servers don't even have that bit of metadata. See [1], they only store the last time that a user connected to the server.
https://signal.org/bigbrother/eastern-virginia-grand-jury/
Signal turned over everything they had on this user (which was two time stamps: user creation and last access), and fought the gag order to be able to publish the subpoena and the response. Signal would have to be pretty stupid to lie to a federal court.
Think what you want, but Signal doesn’t have any metadata to turn over.
Even if I couldn't break the encryption I'd have timing and connectivity data.
So, if I were a user, I would always operate on the assumption that info would leak.
Getting people to use Tor for everything is hard enough, good luck getting people to use stuff even more obscure.
Note that it's what they claim at least. It's not verifiable client side, and to be honest, it's hard to come up with a scalable protocol where this is the case, but you should still not repeat their claim as a matter of fact while in reality we only have their word that the code actually matches what's deployed. And even if they don't store anything, AWS could still provide interested entities access to the infrastructure to capture what Signal doesn't want to capture. Yes, features like sealed sender are awesome and are an important step, but the service still gets ip addresses, which do provide hints about the sender. Again, likely Signal doesn't store ip addresses but people with access to their infrastructure could.
Furthermore, Signal's encryption doesn't help against people storing all of Signal's traffic and waiting until attacks on crypto algorithms become practical (quantum computers, theoretical progress on attacks). Some secrets become irrelevant with time, others increase in value. The best defense is never having the message leave your country's network in the first place.
And there's the DOS problem. What happens if the american president decides that the EU should be cut off from all US network connections? The EU parliament members can't even organize a good response to this because they use an american service...
As an EU citizen, I'm half puzzled and half horrified at how happy the EU institutions are to rely on foreign products: especially coming from a country that has a history of being trigger-happy and cutting people off in the name of a "trade war".
This also is not for official communication , it's just for any case where staff would currently use WhatsApp or similar spyware.
[] i.e. the build installed on my phone, not the build available no Google's server to download.
[2]: https://threema.ch/en/transparencyreport
Edit: Formatting
The BÜPF law in Switzerland requires any company that has more than 100 request per year to retain data. Threema reached this in 2019.
"Der Dienst ÜPF erklärt eine Anbieterin abgeleiteter Kommunikationsdienste als eine mit weitergehenden Auskunftspflichten (Art. 22 Abs. 4 BÜPF), wenn sie eine der nachstehenden Grössen erreicht hat:
a. 100 Auskunftsgesuche in den letzten 12 Monaten (Stichtag: 30. Juni);
b. Jahresumsatz in der Schweiz von 100 Millionen Franken in zwei aufeinander folgenden Geschäftsjahren, wobei ein grosser Teil ihrer Geschäftstätigkeit im Anbieten abgeleiteter Kommunikationsdienste besteht, und 5000 Teilnehmende, die die Dienste der Anbieterin in Anspruch nehmen." [1]
[1] https://www.admin.ch/opc/de/classified-compilation/20172173/...2. Threema is proprietary around open source library. It's trivial to add a backoor after any audit, and it's trivial to lie in your transparency report. Open source stuff is _obvious_ choice. There's no reason to open entire source for Threema (no ~one's making a profit copying other messengers) unless they're hiding something.
Given the problems ive experiences with the wickr app and lack of basic phone security ive seen this feels LESS secure to me.
Google put out research saying they had 0 successful phishing after mandated fobs. I guess there's a concern about forwards and that Wickr shows when someone screenshots but that doesnt stop anything...
I have seen lots of campaign staff that dont have passwords on their phone, or weak 4 digit ones. I use a password manager to store a long wickr pass but I think most just use a simple pass or re-use a password...
Wickr on my phone has render problems all the time and it has shown messages without me logging in at least twice.
It's also super inconvenient. if they really care about E2E - which doesnt even feel like the actual problem they are trying to fix (phishing/ability to read past messages when an account is compromised) - I'd rather have some enthusiastic outsiders develop an open source basic PGP chrome extension to sit on top of gmail or something (maybe that already exists)
The communications are encrypted, but my identity is public.
If you stop answering the PIN confirmations eventually it expires and somebody with that number can sign up (and if they want, set a new PIN).
Regardless of whether you use PIN locks your contacts will be shown that something about the other party in the conversation changed, if they use in-person confirmations of identity they'll be invited to perform that over again.
I might recommend Signal to them if they specifically ask for something encrypted, but if they just follow what I use they'll see no Signal.
Heck, whatsapp has gotten several orders of magnitude more people to use encrypted messaging than any other software, and techies hate it.
There's no requirement to be anonymous in this context. Metadata can be reduced via tech but it's not the top-priority -- quick fix to confidentiality problems OTOH is.
This is not about 'Signal' it's about why governments can't/won't deliver on so many issues they themselves deem to be very materially important to them, particularly in the area of IT.
It is true that they could throw a lot of money on the problem. But that in itself does not guarantee that they outcome would be a world-class communication system. So given that Signal already exists and is the gold standard for secure communications, IMHO it’s better to use that.
What the EU can do however is to fund cryptography research. (And it would not surprise me if they already do.)
From various comments in this discussion, I've discovered that Signal is open source and has reproducible builds, and the server is open source too. It would be possible for the EU to create its own "EU-Certified" Signal environment for use by people who wish to see their data remain in the EU.
I know this will never happen in real life but I think this is the only way to solve the problem of corrupt officials and revolving doors / lobbyist problems.
Edit: the book "Haze" by L.E. Modesitt Jr. has a good take on this.
Nothing stops you from explicitly publishing your communications. And whether you do it explicitly, or implicitly by using an insecure communication method, it's always a choice which you can revoke at any time.
It looks like the replies to this comment misunderstand the point.
It's not about one person choosing to make their communication public, but that there should be a record of government communication period. Have we not seen enough examples of our elected officials corruption in media that isn't encrypted? Now we want them to be able to communicate in all manner with no accountability?
I think you misunderstood my point, which was that they can always do that. You can't stop them from using Signal, if they want to do something nefarious. Hell, they can just meet in a dark alley if they want. Sure, you can make it against the rules, but we are already presupposing rule-breaking (or else we would not need oversight).
So, if there's going to be some kind of disclosure system, let's make it structured and explicit. Just requesting that they use unencrypted communications, and then having some sort of unaccountable gray-hat institution (i.e. intelligence services) snoop on those communications, is a bad system.
Interestingly, the EU's position on this looks really confused. SMS messages should (in theory) only transit their own local telcos. The USA doesn't get a look-in unless it hacks the telcos themselves.
What the EU is doing here is routing all Commission traffic through US based server farms and roots of trust. The phones are controlled from the USA, the comms services are too. So their own local firms can no longer see the traffic but US firms can (Signal claim this isn't the case but people are wising up to the fact that this can't be true until more infrastructure is in place).
What actual threat are they trying to block here?
A large powerful country ruled by a megalomaniac who has proved he isn't afraid to ruin his country's reputation by abusing his power.
Consider, the Signal threat model assumes that you can't trust telcos. That's usually based on the assumption that you're some ordinary grassroots citizen who might be spied on by the government. But the EU Commission is the government. It seems a bit odd for them to implicitly assert the national European telecoms companies are untrustworthy.
Anecdote: Personally, I’ve been using Signal for some years with a few different group chats. The number of times people in those groups talk about how bad Signal is and want to avoid it hasn’t changed much (these people use a mix of iOS and Android). All those groups are quite silent because people don’t want to use it.
Edit: Security without ergonomics doesn’t help. And Signal is still behind on that front. As someone else here pointed out, they could’ve chosen Wire, which has a better UX and has E2E chats syncing across devices.
[0] https://briar.app.
More info: https://code.briarproject.org/briar/briar/wikis/FAQ#will-the....
But I think you confuse the Commission and the Parliament.
The whole point of my comment is that two European bodies that work together closely have diverged in their IT policies.
All you need is a bow-and-arrow, a practiced hand, and your own raven to MITM the message.
https://support.signal.org/hc/en-us/articles/360007059752-Ba...
Are we going to get more features? Yes.
Are we confident the devs can deliver those features actually secure? Yes, these guys are the ones leading the industry at the moment.
Do we need to worry about long term future of the app being sold? No, the project is a non-profit, it's backed by a foundation, and it's an ideological app, not a for-profit app or con (startup)