Help people in Iran reconnect to Signal – a request to our community
signal.org
signal.org
https://github.com/signalapp/Signal-TLS-Proxy/blob/main/data...
IMO it would be better if they release a pre-built image in docker hub so people has easier time hosting it on other container platforms instead of just docker compose.
Just like you should have the habbit of checking random bash scripts you download before executing them, I think there is value in knowing the moving parts of the stuff you run.
Having to create an account for open source software isn't reasonable, there's ways around that but not easily for most people.
On windows it's `winget install docker`. Mac is more of the same, just drag and drop docker desktop into your Applications. You can skip the tutorials on first launch for desktop.
> Having to create an account for open source software isn't reasonable, there's ways around that but not easily for most people.
Creating an account is entirely optional, it doesn't even prompt you to sign in.
> there's ways around that but not easily for most people.
Please explain. It never requires an account at any point of the install. It never prompts for a sign in. It's entirely optional. How much easier can "not clicking the sign in button" be?
You don't even need to install docker desktop, you can just use docker CLI. It doesn't even have to be docker, you can use podman.
I believe OP comment is just struggling with adapting to containerized workflows. An account is not a requirement, nor is the install process difficult. If you're still wanting to do it without a container, you can just inspect the image to see what the steps are for configuring your environment yourself. It is more work to not use a container.
My information is outdated but only a few years ago required you to sign up for a docker account on win and macos. Please read the SO link.
I've given up on them anyway, the good faith is burnt, it's only one middle management change away from reverting to the bs of last decade.
https://stackoverflow.com/questions/58133878/direct-download...
First they created the problem with centralized network (and phone numbers required for registration, my ass), then they ask people to run proxies for them. They can also piggyback on TOR and their bridges, they can make registration easier, but no.
Also many people won't be able to run the proxy anyways because they already got something listening on http ports and it seems like this crap doesn't cannot be put behin. a regular web server as a virtual host.
I'm pretty sure you can merge the nginx config with your own existing one, it seems pretty straightforward to me: https://github.com/signalapp/Signal-TLS-Proxy/blob/main/data...
I'm not sure if this is solvable. How would a network tell the difference between an iranian citizen and an iranian police? If you allow iranian citizens to connect to some IP address, how would you prevent iranian police from connecting the same way, and then adding the IP to the blocklist?
The best solution I can think of right now is for major tech companies (like Google, Microsoft, Apple) to host Matrix servers of their own, on their IPs. This way if the iranian police block those IPs, the country also loses access to these major internet services, which will shut off communication with the rest of the world and cripple their technological development (like North Korea).
The problem is similar to finding paths in a wireless mesh network where links may be obstructed. I've spoken to someone in a team that tried hard, he said that the traffic volume for routing updates grew faster than the size of the network and with their algorithms the limit on the size of the network was disappointingly small. ("Limit" being the approximate size at which the network becomes more concerned with routing itself than with delivering payload traffic.)
Now, if Matrix doesn't try to route around blocks, then blocking Matrix is trivial: ① Identify one or a few servers and block them ② check each packet to/from those and assess the likelihood that the peer is another server ③ add to the block list and go to back to step 2. So I assume Matrix does try, and wonder how.
From what little I understand about Matrix, the former is probably the case and the latter might perhaps be but I wouldn't bet on it.
My preference would be to instead use CDN endpoints without any custom names. Akamai, Cloudflare, Cloudfront, BunnyCDN, KeyCDN, Fastly, etc... all using their templated generic DNS names making it look like image sharding requests.
Corrected for you
But only sometimes. Some people grow angry when PRs are rejected, so some maintainers leave PRs "open" forever instead of rejecting them formally.
Not saying that’s a good thing or not
The United States has now partly outsourced their intelligence gathering to BigTech ( https://en.wikipedia.org/wiki/PRISM ) and has also made laws to compel any company to allow US agencies to tap into their network (see Why Lavabit shutdown? - https://it.slashdot.org/story/14/05/20/2143258/why-lavabit-s... ) with whom they don't have an explicit arrangement. So it is important to note that your actions may be helping US / 5-eyes / 9-eyes intelligence agencies.
This is important to keep in mind as you are being asked to take sides in an international conflict and help circumvent the laws of one country. And this may have negative repercussion for you in the future. For example, you don't have any guarantees that Signal will not use these proxies for other countries too, and that could create legal trouble for you in your own country if they have a good relation with the country whose communication network / laws you are helping to circumvent. Or, you may become a person of interest in Iran or other countries for doing this and be a potential target for them which can create legal difficulties for you in the future in which case international travel may become difficult for you. (Yes, I am outlining the worst-case scenarios). Do remember that you will be responsible for the traffic that flows through this proxy and may not have similar legal protections like telecom or or communication platforms run by corporates do.
I write this because I too was once naive about how the Internet would change the world by making information open and accessible to all and bring us all closer with the ability to freely communicate through it. The reality today is a lot more sobering - the internet has been siloed and while information technically is still freely available it's very controlled, it is being used to profile people at a massive scale, experiments are being done through social networks to use them to deliberately create social and political turmoil in many countries, platforms like Wikipedia and Google Maps or Open street maps are being increasingly used to entice naive people to share and make even more information public without understanding the repercussion of how it may be used against their country, and worst of all, attempts are being made to replace your own country's communication network with it ... (Signal is also one of the new controlled silos of the internet and not an open, interconnected or distributed platform like the internet was originally envisioned by some).
So go ahead and do this if you believe it will do political good, but do it it with your eyes open.
When you publicly post a signal.tube link, or if a particular server becomes too popular, it increases the chance that Iranian censors will simply add those IPs to their block list.
authorities can track how the information flows, which can be used to identify you (for e.g. through the proxy IP). With foreign encrypted networks, police / intelligence now focus more on getting the device that sent or received the message, rather than intercepting the message by breaking the encryption, as that is an easier method to get all the communication. (And remember that Signal uses phone numbers as identifiers, which really makes it easy for law enforcement to track someone in any investigation). So if someone has been tagged as suspect "terrorist" by the Iranians, and they determine that your proxy has enabled that suspect to bypass their laws and use Signal, you can be liable for aiding and abetting "terrorism".But am I understanding correctly, that if you used this thing, what is flowing through your network would all be encrypted stuff, basically just noise to anyone who isn't either the sender or signal? (if none of the devices in this has been compromised)
It's true: Adding stuff to Wikipedia or OSM can help bad guys get information, and this can have negative effects for you. But the person you're replying to assumes naïvely that this is perceiptibly worse than the negative effects of bad luck. You're going to have bad luck in your life, that's in the nature of luck.
I added the location of a specialist shop that sells mostly grappa. Someone might find that shop with the information I added, buy and drink too much grappa, drive a car and drive over me. It could happen. But thinking that this is perceptibly worse for me than if I hadn't added that location is naïve.
Similarly, your country could introduce a retroactive law prohibiting proxies or introducing some form of liability, and when the Iranians send a list of IP addresses your country gaols you. It could happen, but is it probable enough to be compared to the effects of bad luck on your future life?
Note that these proxies too can be identified and blocked.
Worse, their IP address could be used to identify you in any investigation. This was the legal risk I was pointing out as you do not know how Signal will use your infrastructure (in ways that may make you liable for something in your own country) or how other countries may become hostile towards you for allowing Signal to circumvent their laws.