Signal Is a Government Op
yasha.substack.com
yasha.substack.com
> I’ve written at length about the deeper history of Signal’s government backers and the way in which crypto fits into America’s imperial machine. In fact, I dedicated two whole chapters of my book to the subject. I won’t reprint it here. But if you want to know the whole story, you can pick up Surveillance Valley at your local bookstore. Or you can check out some of the articles I’ve…
> …This is a preview of a full letter that is only available to subscribers. To support my work and read the rest, sign up and read it here.
I was not under the impression that Parler was shut down by the government, but more by the "cancel crowd". Was it a government operation ?
As for the article, it seems the main arguments are that :
- Signal was financed by Radio Free Asia (US government propaganda operation), at least 3 million.
- If the crypto was effectively unbreakable, it would not be recommended by big companies like FB, Google, etc...
It's interesting and it's always good to be a bit paranoid, but the evidence is a bit thin for me.
> If the crypto was effectively unbreakable, it would not be recommended by big companies like FB, Google, etc...
This claim falls apart given that Google started encrypting traffic on private links after learning of us gov snooping on their traffic. Also, why would Google care about breaking signal traffic at all?
- OWS was disolved for one. Signal is now developed by the "Signal Foundation" which is a registered 501(c)(3)non-profit. - Brian Acton (ex-WhatsApp) paid $50m startup money also
> Moxie began partnering with America’s soft-power regime change apparatus — including the State Department and the Broadcasting Board of Governors (now called the U.S. Agency for Global Media)
- So what. The Senate has literally approved Signal for use as a means of communication. - The US Govt. is not unified by any stretch of the imagination, there are plenty of competing interests. Some agencies want to support freedom of information, some want to suppress it.
This smells like a hit-piece. Also, both the client and server source-code is freely available for review and has been reviewed independently.... https://proprivacy.com/privacy-service/review/signal Realistically only the client matters, as it promises end-to-end encryption regardless of how secure/non-secure transport is.
The NSA etc doesn't need to "buy" apps in this manner anyway. They just go to the manufacturer of the devices/chips/components, throw them a National Security Letter and get ring-0 exploits (or hack their way in).
So I suspect this post is really just an elaborate bit of spam.
This post can pretty much be boiled down to “Open Whisper Systems received 3 million in funding from Radio Free Asia, therefore its a government op.”
The argument is standing upon legs composed of two individual twigs, shaky and weak would be an understatement.
This article is waste of time.
His well known position (many years of pando) makes me think "yeah, right, just what we need: another conspiracy that convinces people that there's no alternative and therefore any effort to step away from silos does no good to them". Sigh.
The layperson only slightly interested in privacy does not want (or need) mathematical proofs: they operate by trust. Chains of trust in people, friends, activists, journalists or self-proclaimed "experts" that recommend tools or dissuade them from sharing too many data in the places where everybody of a certain age has to be to socialize. So this kind of gray insinuations, with big logical jumps and with zero consistent evidence (other than the US has an interest in promoting encryption and is pouring money on that horse too, probably orders of magnitude less than it pours in big monopolistic, closed source and privacy-mining tech companies) does more damage than good to the public it pretends to inform.
But hey, I guess that's the pitch from which he manages to make a living, and it must have his public, which I might not totally be getting.
Has anyone read his book by the way? Does he develop his "most of open source crypto project work for the CIA" in some interesting or novel way? Something that gets my attention is how he sells himself as unveiling the "secret" military history of the internet, when all that I read from him is public knowledge. I guess the wistleblower myth is quite attractive, even for him.
While I'm open for convincing, I'll chalk it up as FUD until convinced otherwise.
This op-ed speculates that the CIA has somehow compromised Signal by merely funding it. There's no there there, at least not without some more compelling evidence that the CIA and Silicon Valley are colluding to spy on all the recent Signal converts. I don't know enough about Signal and e2ee, but I'm guessing more evidence would have to be supplied to cast doubt on the robustness of Signal's code.
Enough said
Also why would Snowden continue to use (and support it) it if it was the case?
It doesn’t necessarily compromise Signal, but simply highlights that government isn’t always internally efficient or consistent.
I am from Ireland, i've worked my entire life in human rights, including campaigning against CIA black sites, Iraq, NSA/GCHQ spying etc (along with the global range of issues from China to migrants). Why would I or anyone of the other hundreds of projects, work with OTF if somehow it was a CIA front? In our case, the linking of projects like ours to stupid conspiracy theories like this has endangered myself and some team members. We've had doxing and death threats from people from countries as varied as Ireland to Vietnam trying to say we are CIA/US stooges because of this crap.
>Why would I or anyone of the other hundreds of projects, work with OTF if somehow it was a CIA front?
Im not saying they are or aren't (I have no idea) but how would you know if the CIA were behind something if they didn't tell you?
Whether it’s true or not, it makes me question what I’m using for conversations. I suppose it doesn’t matter anyway.
Is there something I can self-host for just my family? The issue of having them commit to another chat program isn’t a problem.
That's even before we get into their past security issues / breaches. From security/privacy point of view it's really not better.
Now, -that- would make it an interesting "experiment" ...
For the sake of the downvote: Note the tentative nature of my giving this any credence - "were this to have any truth".
The point still holds: It'd be interesting ...CALEA legally obligates Signal to provide the government a lawful interception methodology.
https://en.wikipedia.org/wiki/Digital_Collection_System_Netw...
If Signal is a government op or not is unclear but it's also unnecessary. All Americans by definition do not have privacy because the government can snoop. Signal pretty much doesnt need to be a government OP.
Common misunderstanding but incorrect.
https://www.pcmag.com/news/the-real-reason-the-feds-cant-rea...
" Soghoian explained that communications, "encrypted with a key not known to the company […] cannot be intercepted." So in a situation where the decryption keys are handled on the device, and not by whomever is delivering the messages, then law enforcement must ignore the message entirely. "
Even if the article isn't factually correct or even clickbait it can still be food for thought and a good starting point for a discussion?
> …This is a preview of a full letter that is only available to subscribers. To support my work and read the rest, sign up and read it here.
Says it all really. PSA's aren't supposed to be behind paywalls.
The problem is that if you are actually using signal to transmit sensitive (as in worth a lot of money,peoples lives, state secrets) information you are making a huge mistake.
Sure no one is going to break your communication on the network. But what they are going to do is use a zero day, get into your phone and extract the signal message db and listen in on your mic and keyboard.
Signal has been promoted all over the place but no one mentions this fact, and when someone does it is dismissed.
There are better solutions out there but they cost money.
The reason it is in all these places because it is free, easy to use and supposedly secure. That the information contained can be exfiltrated would be news to them. All they know is that security proffessionals recommend Signal so that is what they use.
Just use Signal has been a mantra in tech circles for a long time. This obvious fact I am bringing up is always obvious yet no one mentions it.