If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead.
This alone is bad enough to abandon Signal but then consider they have centralized control of client binaries, and metadata protection anchored on centralized SGX they can trivially access. This negligent design makes them vulnerable to coercion or even court orders if any judge realizes they actually -can- decrypt messages and dump metadata.
Matrix supports Signal crypto but in a federated network with no PII requirements like Signal. Also no lock-in or central control of apps.
I understand your concerns, and if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either.
But, like the vast majority of us, I am not any of those things. As such, for my (and most others) use case, Signal is great.
For those at risk from highly motivated and/or state-level actors, Signal isn't nearly enough. Nor, unless you build and run your own servers and clients (and never screw up your OpSec), is Matrix.
Signal isn't perfect. However, for most people, it's good enough.
Don't make perfect the enemy of the good. Because perfect doesn't exist.
We also have a responsibility to favor tools and practices that make those that really need privacy not stand out.
Element or other Matrix clients are easy to use and lack the serious flaws I outlined for Signal.
When it comes to that sort of messaging ("I'm running a few minutes late and will meet you inside the restaurant," or similar) I don't (and won't) separate those out. I just use Signal for all such messages.
Which makes for inconvenience when (especially iPhone users) install Signal and still use iMessage.
I'd add that if I have something to discuss that I don't want recorded (don't forget that it's not just your device that puts you at risk, anyone who's received such messages do so as well), I'll use encrypted voice calls (with the assumption -- valid or not -- that the other participant(s) aren't recording that conversation) with Signal or Matrix.
In both my personal and professional life, I've always made sure to only put in writing that which I wouldn't care if it was shared with the world.
Which is no different than it's ever been. I'm not sure why anyone thinks this is a new thing or that somehow "technology" obviates the need for good OpSec. It never did and still doesn't.
I mean that's really bad, right? Supposedly Signal is the go-to alternative to doing things the hard way (e.g. GPG over email), but apparently it's just not good enough for those with the highest security needs. Given that the alternative is that these people go back to using extremely brittle software, shouldn't someone do something about that?
The implication of course is that Signal should do something about that, because they already have the user base and are in a position to adopt user identifiers that are not based on phone numbers.
Is it? If that's what you got from my comment, then I certainly didn't communicate my thoughts clearly.
Signal is great for what it is. And that's as a centralized encrypted messaging platform that's easy to use.
Have some tradeoffs been made (e.g., not strictly p2p, some data is stored, in encrypted form, on their servers, etc.) in making Signal easy to use? Yes.
For the majority of folks, Signal is more than good enough.
AFAICT, Signal has been quite successful in that space.
However, if you're the target of motivated folks and/or state-level actors, any product that relies on third-party interaction of any kind is suspect. For that use case, you need more.
Why is it Signal's responsibility to do that? Should they be held responsible for the (lack of) OpSec[0] of others, whether they're Signal users or not?
I mean, I get it. Why should you (or anyone else) have to do any work (other than download this handy app) to protect yourself, especially if your communications are of interest to motivated hostile adversaries?
The whole "telephone number as identifier" bit, and the network discovery it provides, is the primary reason Signal has had the level of adoption it has. And is something of a red herring in this case, IMHO[1].
And Signal is a centralized service. All messages (stored until they're delivered) and metadata (the stuff that Signal stores for each user) are stored on Signal's servers.
Storing anything on systems accessible to the Internet is risky. Plain text is much worse than encrypted blobs, but there's definitely still a non-zero risk.
That alone makes it unsuitable for those whose life may depend on their ability to maintain secure communications.
There are other tools that folks can use (a bunch of folks have mentioned Matrix, which is great too), but which should be either fully p2p or privately hosted/managed on hardware under one's physical control, again assuming that you might be harassed, imprisoned or killed for your communications.
But for most of us, myself included, Signal is more than good enough.
[0] https://en.wikipedia.org/wiki/Operations_security
[1] Since Signal is a centralized service, they need a mechanism(s) to identify their users. In some respects, using a phone number for that purpose is sub-optimal, but it doesn't really impact the security of messages sent through the service, nor does it attach (other than an optional photo and other information voluntarily provided by the user) any information that could be used to personally identify the user in question. A such, even if the encrypted blobs were to be accessed and decrypted, they wouldn't be all that useful anyway, except as a self-selected list (those who have registered with Signal) of phone numbers. I'm not sure how much of an issue that is for most folks, given that dozens, perhaps hundreds of other organizations (almost all of whom don't give a rat's ass about your security) have your phone number associated with your name, your address, your shopping/browsing/travel habits and a raft of other PII.
I agree. Signal absolutely should not abandon this. Rather, it should add other user identifiers that can be used alongside phone numbers.
> Storing anything on systems accessible to the Internet is risky. Plain text is much worse than encrypted blobs, but there's definitely still a non-zero risk. That alone makes it unsuitable for those whose life may depend on their ability to maintain secure communications.
I strongly disagree. A lot of critical work has been done with email + PGP, and that's about as leaky (in terms of metadata) as it gets. Obviously there are use cases where you do worry about this, but "storing data on the Internet" is not as such always a problem for those who need the highest security guarantees. Signal adopting alternative user identifiers would open it to use in some of these extreme cases, but would not (of course) make it usable in every situation - and that's okay.
I'm old school. If it's connected to the Internet, eventually it will be compromised.
Yes, strong encryption can (and does) make data compromise immensely more difficult in terms of time and resources (much longer than our star will exist -- about five billion years -- which isn't really that big a deal, since the Earth will be uninhabitable in a billion years or so), but once that centralized server(s) is compromised, all bets are off.
I don't disagree that strong encryption is a valuable tool for maintaining data privacy and integrity, but it absolutely does not reduce the risk to zero.
I'm not saying "don't use Signal", in fact I still recommend it to non technical people, since it's just much simpler. But pointing at the flaws is a necessary requirement for them to be fixed
And why should I trust F-Droid's build of Matrix over Signal's build of Signal?
Please understand, I agree with your point. Mine was orthogonal: If you are under threat from motivated and/or state-level actors, using someone else's servers (or clients, for that matter) is a bad idea.
And that includes Matrix. I run my own Matrix server and the users of that server can interact (especially via voice/video) without any fear of being intercepted -- even by me.
What's more, I can't decrypt the conversations folks have in Matrix "rooms" that don't include me without a long process of brute-forcing.
No one is coming to my house to confiscate my server. That scenario is much more likely with a public/commercial service hosted at a data center/cloud provider.
So yes, Matrix is likely more secure than Signal if, and only if you build and install your servers and clients from source with a compiler/linker you built yourself using a trusted tool chain on hardware whose components you've personally confirmed to be free of compromise[0].
[0] https://users.ece.cmu.edu/~ganger/712.fall02/papers/p761-tho...
With matrix at least you can pick a server operator you trust to provide your metadata to, or host a server yourself.
Should I? What specific features of Telegram make it superior to Signal?
1. generally, a certain phone number uses signal
(1) happens once, upon registration of your phone number. You don't see history of which phone numbers are communicating, do you?
In other words, you don't need Signal to buy someone's location history. You just need their phone number and Signal doesn't particularly provide that to you.
Per my understanding, Signal provides subpoena/nation-state resistant level security and is in fact used by many people with high security needs.
1. Google, Apple, or Signal could, compile a malicious Signal binary that generates weak keys and deliver it to specific users, or all users, via app stores.
2. Signal sysadmins or third party datacenter techs could use any of a pile of SGX exploits to dump all their centralized metadata in plain text.
3. Signal aggregates all IP metadata to one place making it easy for their cloud providers and ISPs to work out who is talking to who.
4. Carriers see SMS activations and know who uses Signal. They also know all of the cellular data IPs. An entity that buys this along with data from other ISPs would quickly learn the identities of most conversation participants and their current locations. Enrich that with data widely sold from drivers license office and you also get race, home address, etc, etc.
Centralized PII requiring services that claim to be promoting security and privacy should be met with extreme scrutiny.
(1) is abstractly possible for any software and always has been. Signal cannot directly send my phone a bespoke binary... I got it through the app store. If that was allowed it would be Apple or Googles breach of the model, not Signal.
(2) there were SGX vulnerabilities, yes, but they've been patched and Signal is no longer vulnerable (in the one instance where they were), no?
(3) citation please, these are IP logs for conversations?
(4) this is not Signal's problem to solve. If you buy into what Signal offers, you're saying it's okay that my carrier knows that I registered with Signal because that's all they know. Being able to inspect IP headers for traffic on the internet is possible regardless of the software you're using. If you don't trust the internet with your communications then you need to take them off the internet... I don't know what else to say.
Further, typically companies can't be compelled to do something like (1) because it represents an undue burden on operation of their business. This is why Apple refused to give the FBI a bespoke build of iOS that bypassed the pin code. Not to mention the loss of business when people find out that a breach of trust had happened. Also I thought Signal had reproducible builds in every instance possible.
Idk, it sounds like you really shouldn't use any software you didn't write yourself and hardware you didn't build yourself and network where you don't trust every single node if your threat model involves IP logs and hardware tampering and targeted malicious software... that is hardly practical by any stretch of the imagination.
Bottom-line, despite Signal's issues it is still the #1 IM app that I recommend to "normal people" seeking to have private conversations. No, it's not perfect, yes, it's a massive improvement over facebook/instagram/whatsapp/telegram/etc.
Also facebook/instagram/whatsapp/telegram/etc are not trying to advertise themselves for the high risk use cases Signal is actively promoted for. I obviously do not recommend anyone use those either, regardless.
Matrix is all I suggest for most people.
I'd be curious to see stats on this. At least in the US, it is very easy to buy a SIM and sign up for a pre-paid plan with zero KYC.
And that's a quite high regulation part of the world, I'd be surprised if South American or African countries were stricter.
https://www.comparitech.com/blog/vpn-privacy/sim-card-regist...
But it looks like the official answer is 36:
> Those without any SIM-card registration requirements are Bosnia and Herzegovina, Canada, Cabo Verde, Comoros, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Iceland, Ireland, Israel, Kiribati, Latvia, Liechtenstein, Lithuania, Maldives, Malta, Marshall Islands, Micronesia, Moldova, Namibia, the Netherlands, New Zealand, Nicaragua, the Philippines, Portugal, Romania, Serbia, Slovenia, Sweden, the United Kingdom, the United States, and Vanuatu.
What app do you recommend to HN types? (I'm getting ready to switch messaging platforms. All my friends use iMessage and I'm so tired of typing on my phone at them. They can be lured over to something else with the promise of encryption.)
Effectively the same crypto as Signal but you can be anonymous as needed. Also decentralized with many app options.
...Of course, Element remains the oldest and likely still most feature-full app.
Mind you, the last time I looked there are not alternate implementations of the signal protocol and even the usage of libsignald was frustrating due to continuous backwards compatibility breakage. I would love for a proper libpurple implementation.
Uhhh, not sure what koolaid you've swallowed, but including them in that list is almost laughable.
Irrelevant of your position, please read the entire article that you referenced for facts (pre-RvW overturn, pregnancy at 23~28 (?) weeks, took Pregnot, buried in back yard, Nebraska law was at that time 20 weeks).
The Vice article seems to have quite a lot more facts and references. https://www.vice.com/en/article/n7zevd/this-is-the-data-face...
The point is that the mother is being charged with aiding her daughter to have an abortion due to evidence collected from chats they thought were secure, but which were still susceptible to a warrant.
Now, there are other charges. And the time the abortion happened it occurred while the 20 week ban wasn't being enforced, because the state knew it wouldn't hold up under Roe (and is only illegal and chargeable now, with the court having overturned Roe). So, yes, it's super interesting.
But the point is that police are charging someone for aiding an abortion due to texts the sender thought were secure. That's the entire relevancy. Anything else about this particular incident isn't germane.
In other words I'd suspect the classification of "self defense advocate" to be a self serving branding effort since there are legal ways to accomplish the same, but I wouldn't doubt the need of this person for a secure messaging platform.
Outside of the United States, that's usually not the case. Even if countries do allow private gun ownership, the restrictions on how to obtain them (and what they can legally be used for, what kinds are available, etc.) are exceptionally onerous.
And even within the United States, there are individual states that have attempted to severely curtail private firearm ownership. Were it not for certain Supreme Court decisions, handgun ownership would be outright illegal in the District of Columbia and likely in several other states.
Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally onerous". And i think most non-Americans would agree that adding some friction to a fringe case (owning a personal firearm for protection or fun is not something most people do, even in the US) is worth it if it nearly eliminates blatant misuses of firearms - either making suicides easier and more terminal, enabling easier revenge murders, or making your average school/public place shooting easier.
What would you consider a just middle ground between "onerous requirements" and "everyone can buy any weapon without any requirements but paying for it"?
Just because you've accepted the boot on your neck doesn't make it not a boot. When (not if) a currently free and democratic Western nation decides to be not so democratic anymore (whether due to invasion, international pressure from economic partners like Russia and China, or just that the assholes in power decided to seize even more power) the citizens (or rather subjects) of those countries will have no means of fighting back. You can already see it with several countries' response to covid.
>What would you consider a just middle ground between "onerous requirements" and "everyone can buy any weapon without any requirements but paying for it"?
My feelings on gun control can be summed up as "I want mail order rocket launchers delivered to my doorstep." The state should fear its people, not the other way around, and the best way to ensure that is to give the people the means to put a bullet (or several) into any would-be tyrants.
And, regardless of what "the majority of citizens" feel about bootlicking and trampling on their own natural rights, advances in home manufacturing are quickly making any efforts to do so a pipedream.
You should look into France and it's protest culture. When the people are unhappy with the government's action, they go out on the street and protest. Without any weapons, this being a civilized country where violence is only a last resort. And you know what? Governments listen and adapt, even without the fear of direct death.
So i find your premise wrong to begin with. There is no natural right to murder, so i disagree that owning a weapon is a natural right.
And i find it extremely funny that the country that is so proud in their "everyone should be armed so the government is afraid of the people" culture has such shitty dysfunctional governments that act against the people's interests extremely often. Where are the armed uprisings against the Patriot act, civil asset forfeiture, racist abuse, abortion restrictions, failures to combat climate change or wasting money in useless wars abroad? No? When then?
I don't know. I'm a believer in extreme gun rights as well, but giving people the power to have rocket launching systems like MANPADS just seems a bit, dangerous.
It's not a "permit", though. And there are no special limits on who can own one - if you can legally own a gun, you can legally own a DD or any other NFA item. One doesn't even need to be a US citizen or a permanent resident for that, even people on student and work visas can do it.
ATF can be more thorough with NFA items because the law doesn't have a limit on how long they can look at you, unlike those regular NICS checks which have a hard limit - but the list of things that makes one ineligible to own is the same.
As far as residency, you have to be a resident somewhere in US, but you don't need to be a permanent resident / green card. A student or a work visa is good enough, combined with proof of current residency (such as utility bill with your name and address).
This isn't quite what OP asked for, of course - you can't have one "shipped to your doorstep" - but this is also true for most regular firearms (there's a collector license that enables this for some old guns).
So...I guess my point is that you don't _have_ to choose between masks and gun rights. I'm unsure of why you would bring it up.
> You can already see it with several countries' response to covid.
Perhaps the commenter was going for something else, but at least where I'm at we've had two straight years of people insisting they are muzzles, an infringement on our god-given rights, and the beginning of a slippery slope to tyranny. Perhaps the commenter meant something else, but since they didn't spell out what specifically about the "response to Covid" they intended to solve with a mail-order rocket launcher of all things, I was left to interpret for myself.
I also take issue with the idea of gun (or rocket launcher ownership) ownership as a means of prevention. I mean look at the top countries for (citizen) gun ownership. Sure you've got the US, Serbia, Canada, Uruguay, Finland up there, not bad, But you've also got Yemen at #3 and Lebanon and #11. If that's the kind of "freedom" private gun ownership ensures, then I'm not buying.
And again I'm not even that pro gun control. I think you should be required to get a background check to get one, I think you should be required to be trained on their use and safety, and I think you should be required to take reasonable measures to protect your firearms against theft. I'd say that's it, but I suppose I'm also against mail order rocket launchers. But for the most part, having met those requirements I think you should be able to buy what you want (within reason, again let's skip the rocket launcher). But as protection against government tyranny? Doubt.
A good and fair point. I'd fallen into the trap of being too US centric on HN.
> Were it not for certain Supreme Court decisions, handgun ownership would be outright illegal in the District of Columbia and likely in several other states.
Sure, were it not for the Supreme Court. But as there remains plenty of ways to legally obtain guns in the US, I'm still going to doubt that you've resorted to gun smuggling for "self defense"
There are almost always reasonable uses of many services and tools we tend to have knee-jerk-ban reactions to as a society.
Google Play services are still required for the official builds because of the (unverifiable to be really) encrypted backups.
> everything is client-side
Signal's FOSS fork developers would disagree. They got outright legal problems after they wanted to implement an open source alternative. Most APIs in regards to contact management are server-side. There's Molly as a younger fork but I'm waiting for Signal to write them also a cease and desist letter.
Honestly this is why I think that Signal should be treated the same like WhatsApp. Supposedly end to end encrypted, but only until you suddenly have the FBI with printed out chats in front of your door.
As long as Signal uses proprietary services and contains proprietary blobs in their (default aka Play store-provided) app we have to treat it as an unsecure messaging system.
Especially given the RCEs that it had in the past, where it was as simple as injecting an HTML with a script tag to install malware on your system.
??? I use the official build with encrypted backups without Google services, and have been doing so for at least 3 years. I've been forward-carying my backup since 2016, too.
I still prefer Matrix, but Signal is clearly the next best thing for chats. And it also has quite a number of non-HN users :)
Does the app get just name and phone numbers or all the meta data like address and personal notes that I put into my contacts ? I haven't been able to figure this out - does anyone know what Apple's policy is on this ?
All other fields, for all contacts, are accessible once Contacts access is granted.
[0] https://developer.apple.com/documentation/bundleresources/en...
That doesn't make any sense. Signal did the total opposite. It started keeping sensitive user data in the cloud including your name, your photo, your phone number, and a list of your contacts. It stores that data on their servers permanently.
Signal has always kept your name/pic/etc on their servers I believe, because otherwise you turn signal into a P2P application, which it is not. It's a fully encrypted application that stores minimal information. It is NOT P2P.
For example, your messages are stored on their servers until they're delivered.
You are wrong and your blog post from 2014 doesn't take into account their new data collection practices. See: https://community.signalusers.org/t/proper-secure-value-secu...
If this is the first time you're hearing about the data collection, that should tell you everything you need to know about how trustworthy Signal is.
> Signal has always kept your name/pic/etc on their servers I believe
Wrong again I'm afraid. There really was a time when Signal didn't collect and store any user data on their servers. They've repeatedly bragged about times when governments have come around asking them for data and they were able to turn the feds away because that data was never collected in the first place. That changed with the update which added pins. Today, Signal now collects that very same data.
They store registered users phone numbers and allow discovery by making a request with a hashed version of the phone numbers on your contact list. They add an extra layer to allow attestation of the software doing this using Intel's secure enclave. They give many examples of responding to warrants with only whether the number has been registered and the timestamp of registration, which they explain is the only information they hold.
Private Contact Discovery: https://signal.org/blog/private-contact-discovery/
See:
https://community.signalusers.org/t/can-signal-please-update...
and
https://community.signalusers.org/t/dont-want-pin-dont-want-...
See here for a discussion on how Intel's 'secure' enclave won't save you: https://community.signalusers.org/t/proper-secure-value-secu...
When people talk about cloud services, they generally mean part of an application that runs on the cloud that participates as a trusted actor in the application's trust model.
What people in the linked thread are realizing is that "signal has a server" and they are confused because they thought signal didn't have a server, or something.
So, what's important about Signals servers is that, outside of initial key exchange which is verified by two parties out of band, they are not a trusted entity, ever. When you send a message it goes through signals servers. When you sync your profile picture with other devices, same thing. The data transits signals servers. This is made possible because of cryptography. By encrypting the data in a way that is indecipherable by 3rd parties (Signal's servers included) your data is isomorphic to random noise. So, the only thing Signal needs to do is route the random noise to the right place. If it doesn't do that, it's a denial of service and about the only attack you're vulnerable to if you use Signal. Otherwise, the receiver gets the exact random noise that you sent, but only they can make sense of it because of the miracle of cryptography.
If you're really doing to throw a fit because Signal syncs a profile picture between your devices using the same level of crypto as is used for messaging then you're honestly crazy.
No. Signal did not "not have a cloud" and now they "have a cloud". Not by any reasonable interpretation of the events.
The justification for it was so that you could get a new device and have Signal download all of your info from your Signal's server down to your device. The data collection first takes place as soon as you set a pin or opt out of setting one (at which point a pin is assigned for you automatically).
The data is encrypted, but that does not make it impossible for signal or for 3rd parties to access it. see: https://community.signalusers.org/t/proper-secure-value-secu...
If you're a whistleblower or an activist, a list of every person you've been contacting using Signal is a highly sensitive data. No matter how you want to spin it, Signal is hosting that highly sensitive user data on their servers where Signal and 3rd parties alike could possibly gain access to them.
Thus, we have to trust the cryptography itself. Sending an encrypted message to a peer is no different from sending an encrypted message to yourself (other than the use of symmetric vs asymmetric crypto). The fact that you send a message to yourself which is stored persistently on signal's server doesn't change anything (and it's even opt in AFAIU). Sure, there are concerns about the implementation, but until someone can decrypt the blobs in storage (the crypto is broken) I don't see reason for outrage.
Pretty simply, if you don't trust the crypto then you have a very different threat model to pretty much everyone else. If you don't trust crypto you can't use the internet because you can't use TLS. You're relegated to networks where you trust every single node (where you don't need crypto) and other such stuff. Most of us trust the crypto because it's really the only practical option. I don't see the problem.
Leaving aside the whataboutism here, you shouldn't assume that when you're using a secure messaging app that claims to be designed to never collect or store user data. Signal makes that claim at the start of their privacy policy and it is a lie. It started out true, but they begain colleting data and they refuse to update their policy.
> Thus, we have to trust the cryptography itself.
No one is suggesting we can't trust cryptography. The fact is that doesn't matter how strong your algprythm is when you're encrypting that data with a 4 digit number. You can 100% "trust the cryptography" and still acknollege that it won't take very long for someone to brute-force your pin and get your data plain text.
> Sending an encrypted message to a peer is no different from sending an encrypted message to yourself... (and it's even opt in AFAIU).
This has nothing to do with "sending data to yourself" and everything to do with Singal collecting data from you and storing it for itself. There is a massive difference between encrypting something yourself and sending that data to yourself and someone else copying data from you, encryping it, and saving it for themselves.
This data collection is also not opt in. At all. You can opt out of setting a pin, but if you do one will be automatically generated for you and your data still gets silently uploaded to Singal servers to be stored. The community spent months begging for Signal to add a way to opt out of this data collection, but they were ignored.
See:
https://community.signalusers.org/t/dont-want-pin-dont-want-...
https://community.signalusers.org/t/mandatory-pin-without-cl...
> Pretty simply, if you don't trust the crypto then you have a very different threat model
"The crypto" isn't the problem here. The problem is Signal collecting sensitive user data and permanently storing it on their servers in a manner that could allow it to be accessed by third parties and then not clearly disclosing that to their users and refusing to update their privacy policy to reflect the change.
You can prove it to yourself. Go take one of Signal's servers and try to find someone else's data there. You won't.
Why would Signal update their privacy policy to reflect the desire of misguided fear mongers? I certainly wouldn't do that if I were them.
They literally can. If you can brute force a 4 digit pin, you can access any of the data protected by a 4 digit pin. Some pins are longer, but it's notable that even after a lot of backlash they continue to push for "pins" and not "passwords" knowing that many will continue to use a simple four digit number.
> You can prove it to yourself. Go take one of Signal's servers and try to find someone else's data there. You won't.
um... what?
> Why would Signal update their privacy policy
To accurately reflect the data they collect and how it is used? So that they don't lie to their users by making claims that are demonstrably false? To notify whistleblowers and activists that their information and the information of those who they are in contact with could be discovered by state actors who can force Signal to give them access? There's three good reasons right there.
I'm sorry you're so upset by this. I know the reality is uncomfortable but that doesn't make it "fear mongering". I honestly wish it wasn't true. I wish they weren't collecting user data, I wish they were doing more to secure what they do collect, and most of all I wish they were honest and forthcoming about what they are doing, but wishes can't change what is. I hope that regardless of if you use Signal or not, you'll try to accept facts even when they aren't easy to accept.
This term isn't just some loose word to be thrown around and abused on message boards. If we take your definition of collected where handling encrypted data is collecting it, then "the internet" collects all data. Uh oh.
What signal does is route encrypted messages between principals in a system. That's all they do. They don't collect personal information. Read their subpoena responses, they publish all of them.
I think this is misguided, and confuses the truth. Data collected and stored remotely is being "collected and stored remotely" regardless of how well protected it is.
I will however concede that it is possible to design a system where data is encrypted on a device and then uploaded to the cloud in such a way that simply having that encrypted data on a remote server doesn't put that data at risk. Signal did not design their system in that way.
> If we take your definition of collected where handling encrypted data is collecting it, then "the internet" collects all data. Uh oh.
Again, this isn't about handling encrypted data - it's about the long term storage of highly sensitive but encrypted data - and as I said above, even that is fine if it's done correctly. Signal has done a poor job of designing their system which leaves user's data at risk.
> What signal does is route encrypted messages between principals in a system. That's all they do.
That used to be "all they do". Then, about two years ago they decided they wanted everyone to have profiles which would be kept on the cloud. As soon as you install the software, before you try to send any message to anyone you're asked to provide a pin to secure you data. Once you set one (or opt out of setting it yourself) it collects a bunch of data from your device (not needed for routing anything - remember you've just installed the app and are not trying to send or receive any message at this time) and having collected that data it encrypts it on your device using the pin, then it uploads that data to their cloud. That data can be recovered by you (or anyone else for that matter) by providing the pin that you set. The data they just collected and stored is not used to transmit, route, or delver messages. This data collection takes place in addition to any information needed temporarily to transmit, route, or delver messages.
> Read their subpoena responses, they publish all of them.
That's incorrect. They publish the ones they are allowed to publish under the law (look up "national security letters" for more info) and their refusal to provide one agency with data says nothing about the requests they are forced to comply with. Their favorite examples involve cases where Signal was unable to hand over the data because they didn't collect it in the first place. Today, because of changes in their data collection practices, they now collect exactly the kinds of data they were not collecting before and were therefore unable to provide.
It's unlikely that Signal would be compelled by a standard subpoena to brute force their users pins to access the encrypted data. It is far more likely that the data is already being collected by an agency on-site, and that the data collection is continuous and ongoing (look up "Room 641A" for an example of on-site data collection by the state).
The fact that it is unlikely that Signal would be compelled by a standard subpoena to brute force their users pins does not mean:
- Signal employees can't do it themselves any time they feel like it.
- State actors can't do it whenever they feel like it
- A hacker couldn't gain access to a server and do it
Because of the sensitive nature of the messages sent over the platform, and because they have explicitly marketed themselves to vulnerable groups like whistleblowers and activists it is critical that Signal be honest about the risks of using their software. They insist they don't collect any data, while in practice they do. They say they secure the data they have, in practice that data is exposed by way of multiple vulnerabilities that could very well endanger the freedom or even the lives of the people using Signal.
The scheme they came up with to store user data in the cloud was described here: https://signal.org/blog/secure-value-recovery/
The code is here: https://github.com/signalapp/SecureValueRecovery
This site does a pretty good job of explaining why this isn't a good design: https://palant.info/2020/06/16/does-signals-secure-value-rec...
I'm sure I've linked to it already, but please review the discussion here as well: https://community.signalusers.org/t/sgx-cacheout-sgaxe-attac...
Even more details here: https://community.signalusers.org/t/wiki-faq-signal-pin-svr-...
Few things:
1. The vulnerabilities in question for SGX have been patched, only one of which affected Signal at all.
2. Signal preemptively combats any future speculative execution vulns by adding "don't speculate about this next branch" instructions before every single branch.
3. nit: SRV is a scheme to store the 256bits of entropy in the cloud, not the actual user data. It's unclear from those links whether Signal has actually deployed the "store encrypted contacts" portion.
4. It is concerning that the security of this entropy is tied to Intel's SGX implementation.
5. If you use a strong password, which security nuts would, none of this matters.
6. If you turn off your pin, none of this happens at all (so it's at least opt out but IIRC setting a pin was optional).
7. I don't find your interpretation particularly charitable to the truth of what's actually happened. It's incredibly reactionary.
I will give you:
1. The trust model for Signal has changed to include a dependence on a piece of Signal cloud to enforce a rate limit on (really access to) escrowed entropy IFF you use a weak pin.
2. There does seem to be unnecessary confusion surrounding this whole thing.
What bothers me reading through this is that it was never made clear to users that the security model would change if you enabled a weak pin, in other words that the strength of your pin/password is now important if you don't/can't/won't trust Signal+Intel. If that was made clear there would be no issues at all and concerned citizens would simply disable their pin and deal with the not-improved UX or choose a strong pin such that the entroy escrow SVR thing is entirely moot.
I don't think they need to update their privacy policy or user agreement to reflect these technical implementation details, though, as I've previously stated.
Moxie blames the poor reception on not having analytics. I'd say they should have known, it's pretty obvious you can't pretend you don't need a password and try to hide it from users if you want to add stuff that needs a password, like usernames. But I also know from first hand experience how difficult it is to just sit there and say "whelp, we can't build this thing that will make many users happy and make the product better because it isn't perfect".
What's sad is actually that this is all in service of enabling username messaging and dropping the phone number requirement which is exactly what everyone is yelling about. So it's like, they listen to feedback from people who want to use Signal without a phone number requirement. Then they build the thing that lets them take a crack at the nut. And then they get reamed by HN for having the audacity to try and build a secure solution to a problem that largely only exists on HN and only for Signal (nobody gives a shit that every other app under the sun just stores your contacts in plaintext). Must really suck to get that kind of response.
I'll probably go turn off my pin. I have no interest in signal managing my contacts.
The strengths and weaknesses of SGX are debatable, I may lean on the pessimistic side, but as you say it impacts the security model of Signal users and to me that means they (and new users) should be clearly informed. The first line of their privacy policy says "Signal is designed to never collect or store any sensitive information." which is demonstrably false.
As for opting out, unless something has changed they still store your data on the cloud, it's just handled differently:
https://old.reddit.com/r/signal/comments/htmzrr/psa_disablin...
I don't know what options someone has after they've already created a pin, if there's a way to remove your data from the cloud, I stopped using signal before they forced the pin (back when you could still just ignore the notice) and getting real answers to these kinds of basic questions is way more difficult than it should be. This is, again, a service targeting very vulnerable people whose lives and freedom may be on the line.
I was one of those Signal users who wanted them to move away from requiring a phone number too. That said, what I was looking for was something more like Jami. They managed to create a system with usernames and passwords but without phone numbers or accounts keeping your data in the cloud.
I'm not shitting on Signal's efforts overall. A lot of great work went into Signal and I'm pissed I still haven't found a good replacement for it, but the changes they made hurt the security and safety of the people who depend on Signal. They are a massive intelligence target and I can't blame them for anything they were forced to do, and if their goal was to subtly drive people away by raising a bunch of red flags I thank them, but if this is their best effort at communication and building trust how charitable can they expect us to be when two years later so many of their users don't have a clear idea of what's being collected and stored or what that means for their safety?
This is the first I've heard of that. And if it's true, it's a big problem.
Is there any documentation of this behavior that you can direct me to?
https://community.signalusers.org/t/proper-secure-value-secu...
https://community.signalusers.org/t/what-contact-info-does-t...
https://community.signalusers.org/t/can-signal-please-update...
https://community.signalusers.org/t/dont-want-pin-dont-want-...
https://community.signalusers.org/t/sgx-cacheout-sgaxe-attac...
Edit: This bit is apparently not the case. And more's the pity.
====Section affected by edit=========
I can't (and wouldn't try to) speak for anyone else, but if you disable the PIN functionality[0], Signal doesn't upload the information you're talking about.
==== End section affected by edit=========
Which isn't a new change (IIUC, PIN disablement was introduced ~2 years ago). I'd say that using the PIN functionality should be opt-in rather than opt-out, so in that respect I agree.
Further, Signal should probably update their policy documents to reflect the current state of affairs.
But I stand by my previous comment[1].
[0] https://support.signal.org/hc/en-us/articles/360007059792#pi...
This is also incorrect. If you opt out of setting a pin, Signal creates a pin for you and uses that to encrypt the data it uploads to their servers. Again, not your fault. Signal has gone out of their way to avoid answering direct questions about this in a plain way.
See: https://old.reddit.com/r/signal/comments/htmzrr/psa_disablin...
See: https://community.signalusers.org/t/can-signal-please-update...
> "This should be updated for the recent changes where contacts are uploaded to Signal’s servers and stored permanently along with Groups V2 and other data, protected by a 4-digit minimum PIN and Intel SGX – there have been concerns 5 raised 2 in these forums, particularly if one of your contacts chooses a brute-forceable PIN which in the context of an Intel SGX vulnerability 1 could leak a lot of contact data if hacked, even if you choose a strong password."
See the two links sited in that comment for more information on why it isn't actually stored in "secure" way.
Using phone numbers allows signal to plug into the existing state of the world and leverage it to upgrade the security of messaging for everyone who uses it. The one compromise is that it treats phone number as a short identifier (importantly, not cryptographic, it uses real crypto for that).
If you don't use phone numbers, your product would look more like Keybase. You have to somehow facilitate key exchange between people in a way that's actually usable. Otherwise all your security benefits go out the window because nobody uses your product. Signal understands this nuance perfectly which is why they're a successful product.
If I subsequently sign-up for Signal, then I have no way to discover which of them use Signal - short of contacting them via some other method and asking for their Signal username, if any.
By making the Signal username the same as the user's phone number, I actually DO have a list of Signal 'usernames' on my phone already. As soon as I sign-up, I can send my list of friends' phone numbers to Signal and they can tell me which of those people have Signal accounts.
And then nobody would use Signal.
It’s very unfashionable today, but they decided to not let perfect be the enemy of good.
But I guess you can just keep moving the goal post.
I suspect it would be rather trivial to cut out the phone parts of Signal and have a UI where you paste in the first 8 characters of pubkeys and it matches those. Why not try building it?
My point was just that there is a simple technical solution that Signal could apply if they wanted to make people happy who have no phone number and its moving the goal post to say 'use some other app'.
Put simply, telling Signal to add usernames is like telling the existing users to "use something else" because that's what Signal must turn itself into to satisfy the "I need usernames right now" crowd.
Meanwhile, someone in my contacts that installs Signal automatically sees my name pop up and can start chatting. Far easier, and helps drive adoption.
Also, when they rolled out their cryptocurrency payment system (after keeping the server-side source code secret for more than a year, during which Moxie, who is a paid advisor to that same cryptocurrency, denied they were working on a payment system), they got KYC for free.