So, IMO the barrier is, "actually working"
https://github.com/signalapp/Signal-Android/issues/5253 https://github.com/signalapp/Signal-Android/search?q=missing...
If they don't, anyone who has ever used Signal to communicate with them will be silently unable to contact them anymore.
Probably depends on the use-case, but as a normal user that lives in a non-repressive state, there is little value in using Signal. (FWIW Signal uses central servers, so in a repressive state it can just be turned off?) GPG based security is superior and not tied to a blackbox platform...
"[A correspondent's security code which is the only way to be sure you aren't MITM'd] can change repeatedly": It will tell you this happened, allowing you to take whatever action you think is appropriate. Also like modern TLS the behaviour is that you are always protected by the protocol from passive eavesdroppers regardless. Pervasive Monitoring Is An Attack and so protection against this is far more than "just Marketing".
"Most people install it through the Play Store": Play Store APKs are signed by their creator, not (only) by Google. If Open Whisper Systems says you're getting Signal, Google don't get to substitute something else except if you buy a Google phone and only then by replacing your OS.
"Phone number based apps are vulnerable to SIM hijacking". Signal users can choose to "lock" their account with a PIN so that an apparently new phone with that number doesn't get access unless its owner presents the PIN.
Assuming that you think the phrase "non-repressive state" includes countries like the US that spend billions of dollars to spy on their own citizens, just the first item is already a huge benefit.
Harvesting every single SMS message is trivial and so undoubtedly the NSA does it, they can run simple keyword matching an statistical analysis, and keep everything in case it's interesting. Each SMS message carries the sender, recipient and full text. In contrast harvesting even the encrypted Signal messages is difficult, and even with a successful (and relatively unlikely) breach of Open Whisper Systems itself neither the contents or in most cases senders are revealed by doing this. (Messages to friends or to those happy to receive messages from strangers don't need to reveal who sent them to Signal's own systems, only to the recipient). So instantly such government bulk collection isn't possible.
GPG's security is definitely not "superior" because it's based on the PGP hybrid crypto which is from last century. For example there's no Forward Secrecy, so it makes sense to steal encrypted PGP data on the expectation that you'll some day be able to decrypt it. In contrast old Signal encrypted messages are probably completely useless because the keys needed to decrypt them likely no longer exist anywhere. PGP offers only a signature mechanism, so a recipient can prove you sent a message, whereas in Signal the recipient only has their own certainty that it's not a forgery - nobody else could have forged it, but they easily could and so they can't use that as proof of anything.
But it's only OWS that control that check, right?
> Harvesting every single SMS message is trivial and so undoubtedly the NSA does it, they can run simple keyword matching an statistical analysis, and keep everything in case it's interesting. Each SMS message carries the sender, recipient and full text. In contrast harvesting even the encrypted Signal messages is difficult, and even with a successful (and relatively unlikely) breach of Open Whisper Systems itself neither the contents or in most cases senders are revealed by doing this. (Messages to friends or to those happy to receive messages from strangers don't need to reveal who sent them to Signal's own systems, only to the recipient). So instantly such government bulk collection isn't possible.
Comparing to SMS is a strawman. If the best thing you can say for your crypto is that it's more secure than SMS, it sucks.
Practically Signal offers little advantage over any messenger with transport encryption (e.g. Facebook Messenger): in both cases you pretty much have to trust the organisation itself.
> GPG's security is definitely not "superior" because it's based on the PGP hybrid crypto which is from last century.
It's based on a mature cryptosystem which we know the NSA tried and failed to break. That's better than using something novel and unproven.
> For example there's no Forward Secrecy, so it makes sense to steal encrypted PGP data on the expectation that you'll some day be able to decrypt it. In contrast old Signal encrypted messages are probably completely useless because the keys needed to decrypt them likely no longer exist anywhere.
True as far as it goes (though the PGP standard has good support for key rotation via subkeys - it would be good to improve the UX around this), but think about your threat model - reading messages from 10 years ago might not be the biggest vulnerability. In contrast, using Signal means an attacker who gains access to one person's phone has immediate access to phone numbers for all their contacts - which for a government means probably getting immediate access to their names, addresses, and real-time locations.
Signal does do a few good things that PGP-based cryptosystems don't. But the downsides massively outweigh the upsides in my book.
There's a critical difference you're papering over: the level of trust that is required is very different. With transport encryption you have to trust that the infrastructure is secured on an ongoing basis. With end-to-end encryption implemented in a real-world app (i.e. distributed through a walled garden) you need only trust that the version of the app delivered to you is based on the code it claims to be.
> Signal does do a few good things that PGP-based cryptosystems don't. But the downsides massively outweigh the upsides in my book.
One of the things Signal does well that PGP systems don't is actually being usable by real humans, which for a security system is everything.
If we're talking about a government bulk surveillance programme then not really - servers and infrastructure change all the time and sysadmins are naturally curious. An ever-expanding pool of people at Facebook (or wherever) would have to be on board with the surveillance programme for it to be worth setting up.
> With end-to-end encryption implemented in a real-world app (i.e. distributed through a walled garden) you need only trust that the version of the app delivered to you is based on the code it claims to be.
Those walled gardens don't let you pin a fixed version of that app, and OWS stops people from redistributing the APK or putting it up on open-source app stores, with their rationale being that they can't handle old versions of the app using their servers. So in reality you have to trust them on an ongoing basis.
> One of the things Signal does well that PGP systems don't is actually being usable by real humans, which for a security system is everything.
Being secure is everything. Usability is important, but better a secure system that only a few people can use than an insecure system that everyone can use.
This is moving the goal posts. Your quoted threat model was "SIM hijacking" not an insider attack.
> Practically Signal offers little advantage over any messenger with transport encryption (e.g. Facebook Messenger): in both cases you pretty much have to trust the organisation itself.
Only if you squint enough to believe that there's no difference in what you have to trust them to do and for how long which is a stretch.
You must trust Facebook to hold on to your messages without ever choosing to look at them for any reason even though they easily could, indefinitely. If you subsequently decide this trust was misplaced, too bad, they've got all your data.
Whereas you only have to trust OWS to not have hidden some backdoor in the software they publish, which they've no incentive to do, at the point where you use the software.
I can't understand why it requires ID/passport from you to use it. I guess if you want to use an encrypted messaging platform then you don't want it to be tied to the government issued ID.
p.s. you phone number is tied you your ID, so it's basically your ID
It may not be for you, but Signal does a very good job of solving the problems it does aim to solve for the millions of people who use it.
[0]https://medium.com/@mshelton/using-signal-without-giving-you...