Metadata can be as damning as the actual message data, and in a lot of places you don't want the authorities to know that you are even communicating at all.
- read the source code and are satisfied that it's secure
- compiled that version of the code
- installed it on your mobile or desktop
You're still only as secure as the client on the other side of the conversation.
If that one is compromised (has not gone throught the steps above) it could very well be sending all messages in clear text to a malicious party.
Edit: formatting
That doesn't mean I blindly trust them, only that despite seeing potential for abuse I judge that they have more incentive to be telling the truth than not.
Also check the comment by user faitswulff where they mention how they have been subpoenaed "and could only supply account creation time and last connection time".
>> There's no technical solution in any technology for preventing the other side being compromised, as far as I can see.
I don't know Matrix, but I can guarantee that it doesn't solve the problem of a compromised client obtaining the messages willingly sent to it.
If the NSA did have it backdoored somehow through the OS, it's a good bet they'd force LE agencies to use parallel construction to keep that information top secret.
That is why we really need open source hardware and OS's. A good (or even functional) open linux phone can't come fast enough.
Your solution?
* Magical amulets?
* Fake your own death, move into a submarine?
* YOU’RE STILL GONNA BE MOSSAD’ED UPON
The Google Play Services app/package? Heh...
It very much does matter if the server is malicious.
Signal also offers to label contacts for which you could verify the authenticity by another way.
Doing a video call with the contact can be a simple way to clear doubts, even if it is not a proper different channel.
This uses the fact that the client on each side is open source and inspectable, so that each side knows that they sent only the public key that they generated on their own device.
PS: to answer your last sentence, Signal allows you to flag specifically contacts that you managed to verify. Which is technically equivalent to say that you verified that the public key is theirs.
Indeed it is far from straightforward that merely doing a video call suffices to check the keys.
Signal is famously using a special protocol for secure key sharing through the server, which I have not studied.
But as said by another comment, there is no way around verifying explicitly the public key using an independent channel.
Signal does have the capability to have a verification phrase displayed, which is generated from the session key. Reading that off can make the video more difficult to MITM, because then they'd have to morph the audio to match the phrase, and if it's done after the video is setup, morph the video as well. Not impossible, but difficult.
Please don't spread this harmful meme.
It is hard enough to get my parents to use a secure messenger. If I told them they needed to do a key verification process for every person they ever communicate with... they'd just go back to facebook messenger or sms.
I think it is completely reasonable for somebody to say "I don't care enough to worry about validating public keys" while also educating people like journalists about how to do that correctly.
For Signal there is an open issue here for iOS [1] and some documentation for Android [2]
Some nice work about it has already be done by telegram https://core.telegram.org/reproducible-builds
[1] https://github.com/signalapp/Signal-iOS/issues/641
[2] https://github.com/signalapp/Signal-Android/blob/fab24bcd1e5...
Can you elaborate on this? That's exactly what I'd expect of an app I compiled from source.
To be secure you would HAVE to build and install it from source.
But then again your OS could possibly inject code to get the keys. Or a keystroke logger may have been installed.
not allowed to use VPNs because national security issues.
https://www.aa.com.tr/en/asia-pacific/india-launches-fresh-c...
"social media muisuse"
i remember last year this word was so much used, "misuse" which translates to criticizing the ruiling dictator government. it still is,
https://thenextweb.com/in/2020/01/08/kashmirs-police-want-pe...
here. a whatsapp group needs to be "registered" with police.
and lastly more recently, https://theintercept.com/2020/12/06/kashmir-social-media-pol...
this is a reason why i never signed up for whatsapp, havent joined signal, don't tweet or post on facebook. Why? because PII
the danger is real and i am living it. people better realize it
If the main danger is, police scanning the phone for compromised material (without a police spyware on it), then there are some ways to deal with it technically, by using services that don't leave a trace. Telegram for example has a "secret chat" function, which won't save the messages, meaning someone scanning your phone later, won't find them.
(which I head is also a main reason for many people to join telegram, because so they can chat with their affairs and not have their wifes read it)
Then there are simply private tabs of chrome or ff, from where you can use chat-services without trace. (if the chat services are not cooperating with the police, or are decentralised by default, I think in that scenario I would use matrix)
Anyway, you live in kashmir?
I know mainly of the conflict by reading Shalimar the Clown, from Rushdie. Just curious about your opinion, if you know the book. I heard it was not well received in Kashmir itself? I think it was very well written, but I don't know how accurate it is.
8 months or so ago I was stooped because it looked like I was "recording a video" on my phone when actually I was. Took a slow turn, double press power button and pickachu face that I wasnt. Still a couple guys around helped or I was history.
No. I havent read Rushdie. It has that whole demon verse thing around him, he isnt liked
The problem with telegram as with WhatsApp and signal is phone numbers. India has had this network analyzer on isp level for like 6-7 years, called "netra". So all unencrypted traffic goes through it. Same for all encrypted traffic. This is the reason why I stopped using tor, because my traffic would show up uniquely than rest and that gets them suspicious quickly.
There is a lot of text written on the conflict which actually is more than 500 years old. Kashmir has been under foreign oppressive occupation for over 500 years constantly and even today is under 3 nations. Its not like the occupation wont affect the people.
I am trying to get people I know on matrix because there is no PII, waiting for dendrite to come out of beta so that I can set up my own server and such.
The joys of living in an open air prison.
Well, he did made many people aware of the conflict, which created attention, which results in indian police having to give interviews to the intercept for example, which helps in some ways. Things would probably be darker without.
How is your opinion on a political solution?
Do you think independence would work out (if your big neigbhours would let you)?
My understanding is, that the kashmir population in itself is divided?
Anyway, hope you stay safe.
from what i have observed and from facts, at least on the indian occupied side, india spend like millions to convince entire generations about a local hero who happened to be pro india.
https://zeenews.india.com/india/at-2-3-per-cent-turnout-srin...
this was a couple years ago.
yeah so its not like people are not protesting, we just don't see a point in the conventional protests. kashmir has been fighting foreign invaders for over 500 years so its kinda in the system, to oppose.
as a kashmiri, i see no alternative other than complete independence. there is no other way forward, will that take 20 years or 500. Doesn't matter
personally i think all three of these nations have to let go of kashmir, not because of some altruistic reason but because of CPEC. india and pakistan "need" to pass through kashmir to access it. china cannot afford jeopardizing their project because of indo-pak squabbles. for them business is king and the sooner things settle down, the easier.
for us kashmiris, we could practically live off of port fees for all the goods passing through our borders so yeah, i am hopeful
I would be more afraid, that those big powers next to you don't want to let you go exactly for that reason. They want to use your land.
But yeah, I hope that they can settle for that. Leave you in the middle. A buffer between them.
Well a man can dream. Right?
Edit: see discussion here: https://news.ycombinator.com/item?id=25690036