Adding Encrypted Group Calls to Signal
signal.org
signal.org
The way that Arch Linux approaches packaging makes much more sense to me - a single bash-like PKGBUILD file that describes how the upstream source should be transformed into a package that the distro knows how to deal with.
It is the DEB format which is generally unlike most others in architecture and design, you cannot toss "Fedora/Ubuntu" into the phrase and be honest, they are quite different and have different design goals.
This is generally frowned-upon in Debian too. Upstream's effort are nearly always wrong from the distribution's point of view, and extra busywork has to be done to get rid of upstream's attempt.
Note also that making "a" .deb package is not the same as making an official Debian package that satisfies the Debian Policy and passes the automated linters (lintian, piuparts, autopkgtest, etc). The second will have the minimum quality that Debian expects.
Yes, I can `apt source foo` and then spend annoying painstaking time dumping in the new version of the upstream source, fixing any weirdness with the build system, updating dependencies, etc. I've done this every now and then and I hate doing it. It doesn't help that Debian's packaging tools have worse UX than git, inscrutable errors, and nearly nonexistent detailed documentation.
In contrast, if upstream has its own debian directory checked into their source repo, I can usually expect it to work; all I'll need is a `sudo apt build dep . && dpkg-buildpackage -uc -us` and it should build without any futzing on my part. And if an even newer version later ends up in the official Debian repository, it'll get seamlessly updated with no further work on my part.
(Meanwhile I also appreciate being able to grab upstream Linux kernel source, copy in my local config, and run `make deb-pkg` in its root to get a perfectly-functioning, updated kernel that installs things to the right places and properly integrates with dkms and update-initramfs. Even just rebuilding Debian's shipped kernel is usually not that easy.)
> Note also that making "a" .deb package is not the same as making an official Debian package that satisfies the Debian Policy and passes the automated linters (lintian, piuparts, autopkgtest, etc). The second will have the minimum quality that Debian expects.
I frankly do not care about that one bit. All I want is something that I can trivially build, installs on and integrates (reasonably) well with my system, will get upgraded automatically if a newer version shows up in an official Debian repo, and I can easily remove with `apt purge foo`. A debian directory checked into the upstream ticks all those boxes. Trying to shoehorn newer upstream source into an existing Debian-maintained debian directory usually very much does not. If your experience differs, all the more power to you, but this has been my experience using Debian for many years now.
As somebody who's used to 100KB snappy and fully featured IRC clients I'm always baffled when I use these modern clients that use 3 orders of magnitude more resource to look and behave like a cheap clone of a smartphone SMS app, but worse.
My own irc client I wrote when learning C and then re-wrote learning GTK+ is better than any of them in terms of doing what I want non-bloated as a client. But it doesn't quite match the whole signal thing somehow. :)
Signal is excellent software. Game changing stuff. Telegram (indirectly), Whatsapp (directly) owe signal a great debt. The reverse doesn't seem to be true.
End to end ecryption for the masses is a huge, huge win that Moxie can take a vast amount of credit for making happen, then improving and increasing. So there's a little hero-worship for Moxie, a man with whom politically I probably have very, very little in common. It's a good feeling when you can do that.
I do like Signal, otherwise I wouldn't put up with that software. But you can both enjoy the protocol and Android client and think that the desktop app is a pile a donkey dung.
And you can put the stated criticisms of it in proper context. Then assess the costs and risks to yourself. Compare its use along with the rest of signal to the alternatives. And examine the response of Moxies team to issues.
At least that's what I did and came up with a "Hard Disagree" on that statement. Signal desktop is pretty good. (And no I don't like electron apps as a rule - it's the only one I use).
Deviation from perfection is not donkey dung.
>Signal desktop was missing basic features like answering [voice] calls...
vs
Messaging on phone and internet everywhere was missing end to end encryption before Signal. (Yes I used OTR with like 3 people, now I encryption with almost everyone, thanks signal).
Advantage signal. By a huge margin, for mine. Picked the essential feature. Got it right. Expanded from there. I find it pretty hard to fault what they're doing. People who want to do it differently because they think it's "better" (eg federation), don't seem to actually get much done in comparison to signal's massive win they chalked up for all of us.
I find it kinda odd that here, where people understand tech, there is more sticking up for facebrick, goo, appletax etc when they screw their users yet again than there is for Signal doing the opposite. The contrast between how they view people who use their stuff is very, very stark. Signal are pretty great. We need more love for anyone who can achieve at a similar level to make computing better for us. To push competition toward being better at privacy, security and so on and away from the direction of turnkey totalitarianism surveillance that the Stasi could only have wet dreams about. Alarmist right? Could bad things really happen here? Are the interests of Cook, Zuck, Seregey, Larry, Jeff et al not precisely yours or a wider population's? They all do seem really quite friendly to despotic regimes. But I guess those reigimes are foreign?
So be it. But then when their software is crap I won't just accept the "well at least it's not Facebook" defense.
Somebody will make signal redundant one day. When I look at it I see that day has not come. When it does the world is a better place for the advances made by signal.
The decisions they've made are /why/ signal is the leader of the pack by a margin. But please do make better ones. Please do give us something better than signal. Their libraries are all capital F Free. Go for it.
Crapping on them from the sideline, sure, go ahead but acknowledge they've done rather better than /anyone/ else in this space. It's not even close. So maybe their decisions are worth considering as having some merit? Disagree sure, but really. They've done it. Well. I haven't. Nobody else has.
I don't like electron. The desktop client works well for me on linux and for non-techy family members on mainstream consumer machines. There's some merit there you're completely discounting which doesn't seem quite fair.
And it's not "At least it's not facebook"
It is: "Whatsapp now is end to end encrypted thanks to signal" and "new players have to match signal's encryption"
That's crap loads more than "at least it's not facebook" that's actually good as opposed less evil. Straight to heaven for achieving that, for mine.
I don't care about the blockchain tech in session but would session be a good candidate to a signal replacement ?
Telegram Desktop is a Qt app. Not that it offers E2E so not really comparable to Signal imo.
It's hard to call it useful when it's so unreliable and broken.
When I send a note to self on my phone and it never shows on my desktop.
Weird. I find the desktop app pretty good.
I see people complaining about it being slow, but that's not been my experience.
My main complaint with the desktop app is that I really want it to sync message history with the phone app. If you, for example, don't use your laptop for a while, you'll have to re-authorize it and it won't have any messages from when it was off. I realize all of that is a trade-off for their security design, but having access to all my messages and being able to search them is important to me.
Yes, it uses a server for media distribution and uses encryption keys that the server does not know.
Do you rotate the group key regularly and/or on group events (e.g. a person leaving the group call)?
What SFU do you use, and did it require custom modifications? Or is it even a fully custom server-side solution?
I don't think we've made the SFU repository public yet, so I don't think I can comment on that yet. Likely I'll be able to in the future.
Contact discovery can have a slight time delay, but so far it has worked very well after a while. (I don't use SMS)
I actually tend to prefer this style of dark mode for messaging or other short-term use apps on an AMOLED display because it's just "off" with no background, but I agree that there really should be another option. Plenty of apps I've seen have Dark and Dark (AMOLED) versions, or similar.
oh, and being beaten for having installed a vpn
https://scroll.in/article/952355/vpn-for-terrorism-in-kashmi...
https://www.kahawatungu.com/whatsapp-admins-in-kashmir-now-r...
Technological solutions only go so far when offline restrictions can be imposed. It's entirely likely that once Signal figures out username based registration & sees some traction in, Governments will just ban it.
> In March 2017, Signal was approved by the Sergeant at Arms of the U.S. Senate for use by senators and their staff. https://www.zdnet.com/article/in-encryption-push-senate-appr...
> The European Commission has told its staff to start using Signal, an end-to-end-encrypted messaging app, in a push to increase the security of its communications. https://www.politico.eu/article/eu-commission-to-staff-switc...
https://www.politico.com/story/2019/06/27/trump-officials-we...
https://www.eff.org/deeplinks/2020/10/urgent-earn-it-act-int...
http://cyberlaw.stanford.edu/blog/2020/06/there%E2%80%99s-no...
The US and cryptography have never really gotten along.
take for example matrix or discord. these services because of their non phone nature, it is very difficult for police to track down dissent. encryption is a fancy word when you are the only one using it.
i remember actively avoiding using tor back a decade ago because while it could be used to securely communicate online, i would have been the sore thumb.
mass adoption of encryption of all forms in all communications without leaving afk trails is the only way to keep internet safe from governmental control.
There are other of these style apps too, but fluffy is furthest along I think. https://matrix.org/clients/
> The Signal Protocol's development was started by Trevor Perrin and Moxie Marlinspike (Open Whisper Systems) in 2013.
From the WhatsApp Wikipedia page:
> After months at beta stage, [WhatsApp] launched in November 2009, exclusively on the App Store for the iPhone.
From my own experience, I was on WhatsApp back in 2009-2010 on my OG iPhone that I got as a hand-me-down from a friend who’d just upgraded to the 3G/3GS.
So the branding and history of WhatsApp is longer, but the core is Signal. Also if you used both apps and their desktop clients you can easily see how close these two are.
The front end, however, remains significantly better on WhatsApp than on Signal.
I continue to use both daily, and as much as I loathe Facebook, I still prefer the UX on WhatsApp way more than Signal. That they look similar is more down to the fact that messengers today all look the same (look at facebook messenger, iMessage) than that WhatsApp has taken Signal's front end. If anything, Signal is slowly trying to emulate WhatsApp features, in a more privacy-preserving way, which understandably takes time.
Once those points are addressed Signal would be great
I'm not sure how data protection works with Google Play and App Store payments, but I feel like this could be a potential privacy problem.
This app is the worst battery drainer I've ever seen on an iOS device, considering what it does.
On the desktop, I really wish that you could resize the contacts sidebar to just show the sender's icon, as you can in iMessage, but the maintainers don't seem to be particularly interested: https://github.com/signalapp/Signal-Desktop/issues/2510
Of course the app crashing during a call is an issue, but I don't see how the call could stay open with the app closed without security expectations breaking?
I wanted to be able to use Signal to replace whatsapp, telegram and FB messenger. I've convinced some of my friends to install it, but none of them are happy with it.
On both mobile and desktop sometimes messages take hours to appear and on mobile it reserves ~2GB of storage for no apparent reason.
I trust that people behind Signal are brilliant got the security right, but the UX is simply not there yet.
Your debug logs would also be welcome for messages taking hours to appear. For mobile it's usually something with battery savings or FCM. For desktop that's the first time I read about that, are you sure that the messages had actually been sent?
I feel that for mobile it is still not as reliable as WhatsApp, but for desktop it's nice to be able to get your messages without mobile connection.
Compared to other apps which offer group E2EE video calls:
Duo - 32 participants
Facetime - 32 participants
Zoom - 100 participants (or 1000 w/ a Large Meeting License)
Facetime is apple only.
Zoom is not even end to end encrypted (edit: now), and was built for businesses, and apps are close to malware installers
I'm probably out of the loop, do you mind expanding on this?
https://www.theverge.com/2020/4/2/21204648/zoom-macos-instal...
Zoom is not malware and never was malware, although Zoom did so some installer tricks to help computer illiterate users get into meeting more quickly, which coincidentally is their entire value-add.
Note I own no shares in Zoom, do not and never have worked for Zoom, and have no financial interest in Zoom.
https://www.theverge.com/2020/4/2/21204648/zoom-macos-instal...
> Zoom is not malware and never was malware
I have never said that. I said that installers are close to malware.
> which coincidentally is their entire value-add.
Yes. This also enabled full camera and mic access without user interaction. Entire value-add.
https://www.theverge.com/2019/7/8/20687014/zoom-security-fla...
https://blog.zoom.us/zoom-rolling-out-end-to-end-encryption-...
I don't think my phone would be able to receive 1000 different video streams simultaneously for instance.
> Your Legacy Signal Groups will be automatically upgraded to New Groups so they can get in on the new features we recently released, like admins, @mentions, group links, and more. Upgrades don’t happen all at once or instantly, and some groups may not upgrade for a while.
Signal will catch up soon.