Why Not Signal?
dessalines.github.io
dessalines.github.io
What I believe they're referring to is a project that OTF (under, IIRC, the Broadcasting Board of Governors) ran for several years that funded audits for all online privacy technology. I'm aware of it because Matasano, the firm I helped run for 10 years, took (as I recall) several of these OTF projects.
Notably, these projects included all sorts of random privacy tech tools. It was clear at the time, to me at least, that anything anybody was using (or, in some cases, even talking about using) was eligible for funded audit projects.
This is a little like suggesting that because companies like Google fund critical internet infrastructure audits, the projects that get those audits are somehow compromised by Google.
I get that it's very difficult to disentangle the US IC from online privacy technology (this is a much bigger issue with Tor), but in this case, there is just nothing to the story, except maybe that people might want to know that there was at least one good thing, among a zillion bad things, that the US IC actually funded.
PS
The OTF projects I'm aware of all reported directly to the projects involved, not to OTF, and were totally standard software security assessments, with rules of engagement set by the projects themselves and results reported directly and exclusively to the project. It was just money OTF was shoveling into getting audits done for open source projects.
Like em or not, OTF funds a ton of great privacy-augmenting shit.
[0]: https://www.opentech.fund/results/supported-projects/prepari... [1]: https://www.opentech.fund/results/supported-projects/the-gua... [2]: https://www.opentech.fund/results/supported-projects/dark-cr... [3]: https://www.opentech.fund/results/supported-projects/reprodu...
Traditionally, this has been explained by saying that the feds have defensive and offensive strategies, but I have to wonder if there are certain federal agents that lean toward one end of the spectrum or the other.
More importantly, he's possessed by the fallacy that governments have agendas rather than people within governments having agendas. This is important because he uses it to say that nothing downstream of the CIA can ever have the goal of promoting anonymity. The most obvious contradiction to this within the domain of US intelligence agencies is NSA's freelance tool Ghidra, but hopefully that concept is amply clear when mentioned, even without examples.
It's especially bizarre since the author's only reference to the founder's "confused and useful idiot politics" is that the founder claims that regimes in Belarus, Russia, Venezuela, China are authoritarian and that there are human rights abuses elsewhere. That claim seems not only reasonable, but also perfectly consistent with still being suspicious about US surveillance policy.
In particular, operating a large enough fraction of the exit nodes would provide quite a lot of intelligence, and we know spooks of various stripes do operate a lot of them. Just being seen in contact with a known exit node might be enough to draw unwelcome attention.
That said, the public evidence I know of seems to suggest the spooks' main interest in Tor is actually in having their own assets able to use it.
https://www.washingtonpost.com/graphics/2020/world/national-...
Or more recently RSA:
https://signal.org/blog/private-contact-discovery/ https://medium.com/@maniacbolts/signal-increases-their-relia...
> Signals database, which we must assume is compromised due to its centralized and US domiciled nature, has a few important pieces of data;
> Message dates and times > Message senders and recipients ( via phone number identifiers )
Since Sealed Sender[0] in 2018, Signal messages only have the sender available under encryption, in other words the signal server can't store the sender. Conceivably it could store metadata about the sender, but such data isn't authenticated. The article fails to mention sealed sender at all.
As a consequence of this, and the way signal bootstraps contacts from phone numbers, you can't actually build any sort of social graph from signal. The signal server doesn't know my contacts on signal. It never has. It knows phone numbers with signal, and I know phone numbers and contact names, and you can join those things to get that my contact, Fred, uses signal. But that's all done on my phone, the signal server never knows that [1].
On the other hand, any system that uses a system of contacts managed within the application (e.x. you have a username and contacts tied specifically to the communication protocol) must maintain a contact graph. It's actually worse from this perspective. I think with a system like Keybase you could attest to having an identity on the platform, and use that to bootstrap but this is no better, and arguably worse, since you still need to publish that identity on the attestation platform.
[0]: https://signal.org/blog/sealed-sender/
[1]: Implementation detail I don't know here: whether or not you are sent all signal phone numbers, or if you reveal the contacts you know to the server. The first is obviously more private.
My litmus test is simple on if Signal is good enough. It's banned in most totalitarian nations. It has to be more secure than iMessage, and it's not like I use it for criminal activity so I'm happy with it. If that's peoples idea, you'd want to avoid all-things-convenient (the internet) and use intermediaries, deal in cash only, etc. For simple messaging without the government cataloguing your every word, Signal works great.
The biggest threat to privacy is probably every device sold today having a microphone in it. Misuse for passive listening. Not the actions purposefully taken for communication like a text message.
Hard to know what to trust these days. "Nobody" I guess.
that said the clients do leak a lot of metadata when compared to signal.
This is not a character attack, it is pertinent information. The author does not actually value individual liberty or privacy from state apparatus, quite the opposite, and it would not be a stretch to call this article agitation.
Edit: Sorry, the answer was yes to both.