MLAT order from Luxembourg for Signal user data
signal.org
signal.org
Maybe there's some sort of cryptographic attestation out there which could fulfil such purposes but quite sure it's not that practical.
There are a few reasons why I would prefer them to provide source code that they claim is running in the service due to the metadata issue:
a) if it's actually running there, people can find simple bugs in it that could allow that metadata to be stored or revealed by accident,
b) if it's not actually running there, but something very close is (i.e. that code with small amount of patches), then the advantage above still applies and if those patches come to light, they can be easily evaluated for intent and effect,
c) if they're running something completely different (which would be very weird), it'd be noticeable and it would be an obvious lie once exposed.
Ever since that, I don't think you should consider Signal's server "open source" at all. They've shown they'll conceal, diverge and cover up for their own enrichment. What will they do when they're threatened? Cave.
>Last commit 7 Days ago
>AGPL-3.0 License
That's the present
If there's a single piece of closed source code running on the servers, it ceases to be open source.
Yeah no that's not the definition of opensource, if my opensource mailserver has a closed source spam-scanner, my mail server is still opensource - the spam-scanner
phone_home_to_nsa(metadata, ip_address, sender, recipient);
Are you still comfortable with this 'open source' project?
They are not perfect, but I can't see anyone who does better overall.
>iCloud backups are turned on by default
I believe it is good default, as 90%+ of their users (would) care more about accidental data loss than privacy. When that changes, Apple will change the default.
>client-side detection system for "child pornography"
Yes, that's a very controversial move. But they made it client-side because it's more private than server-side.
I think you're right about the numbers, but I don't understand why that justifies the default. Why even have a default? Why not just ask users what they want? It's not a hard question, and it even has the benefit of helping inform users about the feature.
> Yes, that's a very controversial move. But they made it client-side because it's more private than server-side.
So? Either it respects privacy or it doesn't in this kind of discussion. Lauding them for violating your privacy but not as much as they could otherwise is like lauding a mugger for only taking half of the cash in your wallet. Yeah it could have been worse, but that doesn't change the nature of their actions.
I've never seen anyone ask for Signal to remove the ability to use phone numbers. People ask Signal to add the ability to use something other than a phone number, as well.
There are different ways to achieve that, all of which have drawbacks. They chose one.
Do you have some examples of the sort of "heroism" you think is involved here?
It's pretty clear that governments around the world (including many western countries) have decided that online services must take full responsibility for everything their users say and do on the platform. Regulation is coming hard and fast. It's not subtle and some of it will inevitably be inconsistent with E2EE.
Anyone running a popular service of this sort is going to be under huge pressure - political pressure, expensive legal pressure and presumably the sort of pressure exerted by police and intelligence services that the rest of us are fortunate not to know very much about.
Signal's structure, the tight link between the org, the people and the centralised operations focuses all the pressure on this small group of people. They are going to be an absolute lightning rod as soon as WhatsApp has given up.
I don't want to be in their shoes. I fear they will have to make very difficult decisions pretty soon. I find it puzzling that they're making themselves the target of further powerful opponents by adding cryptocurrencies to the mix.
I think Matrix has the better structure for what's coming. It distributes the pressure. It's not either on or off. It's not just some specific app that can be banned.
Your theory is that, seeing this, US politicians will decide priority #1 is to re-write the US constitution in order to go after a completely different service? Sure, they can't find a bare majority of votes for cheap, easy fixes that are broadly popular, but repeatedly getting super-majorities for the lengthy and expensive process of tearing down the fundamental principles of the country to go after an outfit few voters have even heard of it will be easy? I don't buy it.
One of the most awful things about the "better structure" of Matrix is that if you make any use of this "better structure" you eliminate Don't Stand Out which is an essential characteristic of Signal. Yet, to enable that "better structure" to even exist Matrix already makes you give up some of the privacy you have on Signal anyway. So you're losing some privacy to have the option of giving up even more privacy.
Several of the sub-threads in this discussion mention metadata. Don't Stand Out is crucial because of metadata. The Secret Police can raid all sixteen users of "Jim's Black Pill Matrix Server" and if two of them are innocent bystanders too bad, all fourteen members of the Conspiracy To Do A Naughty Thing are known to use Jim's server, and so they Stand Out and were caught. In contrast, using Signal the Conspiracy To Do A Naughty Thing are disguised by the presence of Sarah's Hen Night Planning DO NOT TELL SARAH, Smith Family Group, and LOL Funny Cats!!!! among many more. Signal doesn't know, or care about any of these groups.
If you think that E2EE is not under heavy political fire then please read what our governments are demanding from tech companies. This is not limited to companies that are "choosing what is communicated and by who". On the contrary, governments are demanding that companies monitor what is communicated and by who:
International statement: End-to-end encryption and public safety
https://www.gov.uk/government/publications/international-sta...
Writing long letters deploring the rules might work if you're up against the resident's association, local town council, or even a court of law, but Mother Nature couldn't give a shit what you think about her rules.
Is it normal for Signal to have waited 10 months before responding?
The initial confirmation was an oral one during a committee meeting. They also confirmed it to the press. (Cf luxtimes.lu behind a paywall)
The fact that a Luxembourgish MP is on Hacker News commenting intelligently on a topic in a way that I would frankly do myself just makes me want to emigrate.
I’m a hacker at heart so it’s my pleasure to lurk here and comment on an issue I’m actually involved in.
one of my first jobs working as a dev for what was back then the largest email provider in Germany was a system that would automatically extract all email correspondence from user-accounts that were demanded (via fax) and fax it back to them. we received only a few per week and it was a manual process at LEA's s. there was no law that required this to be automated and we could have done this manually but we wanted it to scale so that we could serve the same answers not per week but per second if we had to (at least that's how I implemented it because I was young, and keen and not thinking). I have no idea how many requests they answer today but if I'd have to guess it would be a lot more because these processes today are also automated at the LEA. It's no longer a deputy that prints it out and manually sends a fax.
also LEO's are just people. there are plenty of cases where they are totally happy to use the system to their advantage, and well beyond making speeding tickets disappear.
Signal is there. And you can also install it on private devices, that's what politicians like even more. That even their own intelligence agency can't read the messages.
A lot of politicians are corrupt, and they don't like laws that make it harder for them.
citation please
This was the beginning. I know from corruption cases in Austria, that a lot of politicians were using Signal. You can find it in the documents of the prosecution.
Edit: changed a word
Can you explain this further?
https://www.atlanticcouncil.org/in-depth-research-reports/is...
Of course TPB were also enabling the sharing of masses of copyrighted material. But what Signal is doing, in the eyes of police and intelligence community, is almost the same.
I honestly see a bleak future where the development of secure applications is forced underground. And the next step would be total control of the internet so no anonymous networks can exist. And after that we'll just use radio, so really there is no way to stop people wanting to be private.
Because the Stasi searched for pirate radio stations with vans.
And no way to break the https encryption in advance without also making all online banking vulnerable to hackers.
Perhaps they’ll try to get around that by van Eck phreaking everyone’s phone/tablet/vr/computer screens. That will explode in the faces of both law enforcement and politicians when the fantasies in table 2 of this paper have official faces attached to them [link is research paper titled “What Exactly Is an Unusual Sexual Fantasy?”]: https://oraprdnt.uqtr.uquebec.ca/pls/public/docs/FWG/GSC/Pub...
(Before anyone thinks of the obvious fantasy on that list “good, I don’t want such people in power!”, the egg will still be very much on the face).
And last I checked, unlawful drug use is sufficiently common[0] that actually trying to enforce it fairly would bankrupt the nation[0], so same applies to other types of naughty.
[0] (in) the UK
edit : root -> route :)) talk about a freudian slip :)))
They do have a registry, but it's not relevant to this order. When you send me a message, your phone sends Signal my phone number and an encrypted blob. Signal routes that to my phone and the server doesn't keep a long-term record of that. Thus, Signal-the-server has a record for the next many seconds at least containing the destination of a messsage. It does not have my profile name, your profile name or any way to connect your phone number to that message.
Signal running on my phone has enough state concerning you to decrypt the encrypted blob and see that it's from you.
Signal, the organisation, is in control of all the source code and could change the code to gain control of all the information Luxembourg is asking for. But the past is immutable. Noone can go back in time and retroactively store more data. Signal didn't log the destination phone number at the time and so it's not available now, Signal didn't transmit the profile names to the server and so it never arrived and could not be stored.
Luxembourg has the legal right to forbid people in its territory from using apps like Signal, though. But I doubt it would even try to that, because it's really difficult to write a scope that includes things like Signal messages and yet excludes things like messages that instruct and authorise your bank to transfer money.
You're never going to make abstract metadata like volume of messages and relationships completely anonymous, but that's essentially an opsec issue which Signal is trying to solve by normalizing it anyway: if all your communications are always encrypted all the time, and you constantly use them, then there's no discontinuity if you go from "I don't like advertisers" too "I am in possession of the panama papers" - it all looks the same.
Even here Signal works very hard. Signal doesn't know group memberships, all the group metadata is encrypted and acted on based on cryptography, so somebody who is apparently authorised to administrate a group kicked somebody out of it, and then they sent a message to the group. Who was that admin? What's the group's name? Who is in it? Who did they kick out? What was the message? All deliberately unknown to Signal.
Also all messages to people who agree to accept your messages in advance (so, most people's friends, and those whistleblower hotline type setups at newspapers) are anonymous to Signal. You've got proof you're authorised to send this message, so they don't need to care who you are and they don't ask your client who it is. They need to know who the message is for to deliver it, but that's all.
So all they have is your phone number, date when you've registered, and last time you've used it. If someone took over their servers, all they'd see are encrypted blobs and their destination. They have no reason to keep those blobs after they've been delivered.
This is exactly all the info they've previously reported to the courts. Example: https://signal.org/bigbrother/cd-california-grand-jury/
Last connection date: 1634169600000 (unix millis)
Account created: 1606866784432 (unix millis)People are killed over metadata.
An encrypted blob also isn't nothing. Encryption is not a silver bullet. With a stream of encrypted blobs, you can ascertain:
- Connections
- Frequency of communication
- Volume of communication (length of the blobs)
- IP addresses
- Receipt time on the target number
Etc.
1. You can see that my wife sends someone a message via Signal. 2. You can see a stream of data from Signal to Google. 3. You can see that an app on my phone receives a small amount of data from Google.
You can still pick out something, but the architecture tilts the statistics and widens the error bars on your results.
> Signal still knows nothing about you
they do have the means to push an app update that uploads decrypted messages somewhere, and I wonder to what extent governments can force them to do so. Signal users should not enable automatic updates, that's for sure.
The transparency is rather nice, too. Reminds me of Njalla, but without the children's pictures.
Does this mean that Signal (and other open-source E2EE apps) is a great hiding place for the 'lost and banned', and 'bad' actors?
EDIT: Judging from the responses, it is admittedly a "Yes" then.
In the case of Signal unfortunately for everyone else, the service is centralised and some governments can and may get the ISPs to block Signal's servers instead.
PGP enables people like... well, not her, and not me either, to be frank. I tried and failed. PGP did that for a definition of "people" that excludes most people.
That is good to hear. Unfortunately for now, there is no iOS app which is a serious limitation in order to get others to move off from the alternatives.
Until then, no thanks and no deal.