https://twitter.com/RealSexyCyborg/status/119769537620088012...
https://twitter.com/RealSexyCyborg/status/119769537620088012...
That's hardly her main point:
> For Chinese who are used to a specific IME- like Sogou, trying to type on something else is a tiny bit like a QWERTY user suddenly faced with Dvorak- we can make it work, but it's slow enough day to day that 50/50 they just install Sogou because what's the big deal right?
> The Signal "fix" is "Incognito Mode" aka for the app to say "Pretty please don't read everything I type" to the virtual keyboard and count on Google/random app makers to listen to the flag, and not be under court order to do otherwise.
> Needless to say, Sogou/Baidu dos not respect the IME_FLAG_NO_PERSONALIZED_LEARNING flag. So basically all hardware here is self-compromised 5 minutes out of the box.
> so unless journalists tell them otherwise, which they have not been doing- users will install Sogou.
This is important.
Btw I agree that when Signal says your messages are secure, it should probably do something to warn about ways things still may leak.
I don't mind it at all. If someone uses "being called asshole" as a reason to not even inform anyone, they would have found another excuse. Some people simply register it as strong language and otherwise focus on the content. At any rate, it's very easy to judge what someone says in frustration when you yourself don't even suffer from the situation and/or don't care about those who do.
> But it's not like everyone tries to annoy other, it's more an issue of ignorance.
So she shed light on that, and instead of talking about the important bit, people think it's super important to teach a random person to not be rude, ever? That's what we're focusing on?
That's my point. By presenting the issue the way she did, people moved the conversation away from the issue and instead ended up in a meta-discussion about the discourse. If her points were laid out in a nicer manner, she would be closer to actually achieving her goal.
By HER doing A, OTHERS did B? That doesn't even parse as English, and betrays doublethink.
Let's be clear: the Chinese state detains people all the time, based on many sources of information, probably the least important being interception of keystrokes to Signal in an input method app. They own all the app makers and the app stores. They can push a specific version of an app to a specific person. Frankly it is meaningless to rely on Signal on a device like that.
The OWS team is small. They don't have a social media team like big corps do, tracking social issue engagement, what big accounts have tweeted etc, and it is ridiculous and counter-productive to be going off about it.
Yes OWS is small, but a major security vulnerability for a country with over a billion people seems worth addressing, no? Naomi Wu is certainly a big account on Twitter and we can see from TFA that Moxie and OWS are aware of this complaint. The question is what to do about it. If you read TFA you will see that the best suggestion seems to be a warning to users using any third party IME. Seems quite reasonable to me.
If the keyboard is leaking keystrokes or word searches on a wide basis it would be difficult to hide technically. DFIR techniques for this are pretty straightforward, I'm sure plenty of people in HK could do it. Why no details?
But ultimately this is a much bigger Android problem, and won't be solved by fixing the keyboard (which OWS is obviously unqualified and ill-equipped to do). A broad ranging device lockdown guide, and OPSEC training (like [1] but for protest groups), is necessary to have anything except illusory protection. I don't think OWS should get into the business of issuing security advisories for all the platforms that they port to.
The pro-democracy groups seem to have this stuff figured out as well as you can and still have a visible protest movement. Very much following Chairman Mao: "The revolutionary must swim with the fishes."
Should they be less minimalistic on their website? Probably yes. Would anyone read it? Geeks, yes. Maybe people who are worried. But I think it is a small win at a high cost.
Maybe it's possible to write a basic phone opsec guide and just stick it on medium or something. Rely on the magic of Google to help people find it. (Would Baidu index it? I wonder.)
Insecure IMEs exist everywhere and affect every app. Not just Signal, not just in China.
This is the operating system's job to tackle, not Signal's. And oh wonder: Android displays a scary reminder when you install an IME (of course they could and should disallow network access for IMEs as well).
Signal should show a reminder to help people be secure, but framing this as some kind of obligation towards the people of China is weird.
(ios makes the third-party keyboard ask the user for "full access" in order to hit the internet.)
EDIT: The specific request in TFA is to detect users using a third party IME and give them a security warning. Seems pretty reasonable.