I don't trust Signal
blog.dijit.sh
blog.dijit.sh
This article says it's not rehashing DeVault's arguments, and it isn't; it's making an even dumber set of arguments.
The ball is on Signal's control, but they are clearly not caring to improve further, just stagnate so long as they have got control of it
In the unlikely event that a set of vulnerabilities as devastating as those from the Nebuchadnezzar paper were found in Signal, Signal controls the whole platform end-to-end, and can simply publish software updates to fix them. Matrix has to do a coordinated multivendor update of their entire protocol.
(I like Matrix and will always sound like I'm dunking on them because of the implications of Nebuchadnezzar, and, before that, of opt-in E2EE; they're doing mostly the best they can with a tough hand to play.)
- If you use our client you can use our servers - If you don't use our client, you can't use our servers, but you can use any other server
It's like, technically it's sometimes[1] OSS, but they don't care about actually being FOSS in practice. If I can't fork the software, add or remove a feature and keep using the software's other features, it hasn't hit the bare minimum to be called FOSS, IMO.
1 - Most old versions of Signal are OSS, but frequently updates are only shared after a long delay - in some cases over a year out of date, if my memory serves me.
Regardless that particular point stands even if he's not the messiah anymore, that he was heralded as a saint who bestowed on humanity the right to privacy, and that we should trust in him.
From what I can find about the entity that funded Signal from the government it seems to be a lot to do with the CIA and anti-censorship products designed to disrupt other countries... Which, actually fits with the narrative of censorship resistant messaging, at least -- so no reason to think that it betrays the stated mission of Signal
The foundation that funded them used to be called: Radio Free Asia (which on inspection seems to be considered propaganda, though seems to market itself as free media), now called OTF, if you see the list of other software they sponsor it's very much in the same category: https://en.wikipedia.org/wiki/Open_Technology_Fund
So, I recant those statements about NSA, I only know that a number of people in NSA are not using Signal, and I had heard about NSA funding from somewhere, which obviously is not true.
EDIT: It appears the link to the submission has been slightly altered to break it; it should be: https://blog.dijit.sh/i-don-t-trust-signal
The details you're providing about BBG, RFA, and OTF aren't relevant, and just add detail to what I said. In case you were relating them to educate me: there's no need, I have firsthand knowledge of the programs you're slandering (whether you mean to or not).
I mean, the points at the bottom of the article are exactly the same. I would consider your temperement and not indulge flights of fancy that I am attacking you or your institutions.
I am speaking as a citizen, from an outside perspective, on what concerns me; because ultimately I see Signal pushed very hard and only lip service paid to any issues.
> The details you're providing about BBG, RFA, and OTF aren't relevant, and just add detail to what I said. In case you were relating them to educate me: there's no need, I have firsthand knowledge of the programs you're slandering (whether you mean to or not).
I thought it might provide some context, given that I am agreeing that the stated mission of OTF aligns somewhat and does not directly contradict the stated goals of Signal.
What are my "actions" that people can draw conclusions from? This sounds very emotive and slightly threatening.
Given that it makes no material difference to the point being made I don't know why it's being so emotionally driven;
I would correct the article even if it completely invalidated my point.
I would correct the article if you hadn't been emotional too.
It's just good to make sure that if you make a mistake that you own up to it and you ensure that misinformation does not spread.
I think (I hope) you agree with that.
Which is why I'm confused as to why you keep pressing the issue as I had already corrected the article after seeing your comment for the first time (before I even replied, in fact).
The reason you can't understand what I'm arguing about is because I'm... not arguing.
To be fair, as I read it, the criticism was directed at your work and not you. We all make mistakes.
You might want to check again because your post is full of inaccuracies. From signal being on f-droid to their backend being relevant to security, you got almost everything wrong.
Doesn’t necessarily mean it’s cryptographically insecure. I can imagine any NSA employee installing a typical strong-crypto software like Signal, PGP, or TOR on a personal device is a massive red flag worth investigating. If I were in that position I would not want to garner that kind of attention even if the crypto itself is fine
Reports from 2007/2008 had already indicated significant interference and government spying between agencies and with private corporations. Also, at that time it was widely believed but not yet confirmed Dual_EC_DRBG was backdoored via NIST/NSA collaboration.
Many folks equate any US government money with NSA money, and did so especially around this time, which is likely why you made this mistake. Taking any US-backed government money, even at the time Signal took it, was and should be suspect.
IIRC Signal continued to take money even after Snowden. So it is a fair point and not at all idiotic, and the over-reaction after you agreed to correct the article is suspect.
I do think Signal needed that money to survive, and it probably was put to good use, but I would have acted differently and more transparently about how my use of that money was communicated to the public.
I don't think you're doing this person any favors by keeping this debate alive.
So I think it’s at least a mild mischaracterisation that they funded everything.
in fact the only other major popular software they seem to fund is Tor (also from US govt) and noscript.[0]
“How could you possibly get the three letter agency wrong, your argument is entirely invalid” is a bit of a strawman dude, I admitted the mistake and corrected immediately — but you make it sound as if it matters at all which three letter agency it was.
No, it wasn't the one that is charged with spying on everyone, it was the one linked to disrupting everyone. Much better, but not materially different. I am not finding evidence to suggest what you claim either.
[0]: https://www.usagm.gov/wp-content/media/2017/01/OIF-Factsheet...
It's fine not to be super well informed about this stuff. Why would you be? Most subjects that come up on HN, I'm very poorly informed about, too. But it's not fine to be so noisily poorly informed that you spread misinformation, which is literally what you've done here. I've done that, too! But I believe I apologized when that happened, rather than doubling down. I hope I did! Dealing with this thread has made me super self conscious about that, which is I guess a good thing. Your blog post was so bad I experienced personal growth.
You could have asked people before you posted this story; you could have done any kind of research at all, and improved it. But you didn't: instead, you ran a piece that claimed the NSA funded Signal, and that Signal relies on server security, and that advocates of Signal are part of disingenuous conspiracy.
(You and I are the ~only people reading this flagged, buried thread now, so we can leave it here if you like).
There are nevertheless legitimate reasons to not trust Signal and to worry about compromise. I am pleased to see that the author mentions one major but usually overlooked one: the (optional, but encouraged) sharing of people’s contact lists with the server through Intel SGX functionality, which has been repeatedly found to be insecure.
"Based on" meaning they're built from that source but have changes to it? Because given that the published source had known bugs and was not updated for months, either they're not fixing known bugs for months, or they're publishing builds based on unpublished source. (And the article does address the verifiable builds point, pointing out that it doesn't and can't really work).
That's the server code, not the client code.
> the article does address the verifiable builds point, pointing out that it doesn't and can't really work
IIRC (the article is now down for me for some reason), the author was again talking about server code.
- Hardware
- Firmware
- O/S
- app(s)
- ISP
- internet
- Governments (Yours and Others)
Did you answer 'No' to any?
> E2EE is meaningless if the client and the network are the same
Using modern, networked computers does involve a lot of trust.
But as long as it's not one company delivering the whole stack, some attacks require a gradually more unlikely scenario where a lot of parties across the world would have to cooperate, and the cost of an exploit that traverses the software stack becomes so expensive that targeting you is out of scope.
That's textbook black-and-white thinking, and it's bullshit. I agree that network and client being controlled by the same entity raises questions, but that doesn't imply that E2EE "doesn't mean anything".
A very basic argument that shows why you are wrong: It's much easier for the government to compel a company to hand over data from their servers than it is to compel the company to write and publish a backdoored client. The two scenarios are not equivalent in practice, and this is what matters. Threat models that ignore how the real world operates are useless.
Please read up on the concept of "defense in depth", central to modern information security, which is built around the insight that security mechanisms can be valuable even if they don't work perfectly in all circumstances.
There is a very real threat when
- Signal servers operate in the US and clients on app stores run by large US companies
- Signal can becompelled to not release government-imposed backdoors
- Signal stops releasing their open-source version, but patches it arbitrarily in production
I've read an interview that there is code related to anti-spam you can't share if you're a large network, because it's an arms race. But because Signal does not make their operations transparent beyond what's absolutely necessary to keep secret wrt. anti-spam, this creates distrust: It leaves a sense that they care more about uptime than trust, because they got big. So it's not the messenger of choice for political dissidents, where your threat model does involve the government to some degree (passive or active).They might not have the contents of your messages, but they know who you’re talking to, and when
That's not to say you should use US providers! Just that NSLs aren't a good reason to pick a provider. Pick a service that doesn't have information to share about you in the first place as your high order bit.
I do think this matters in a general sense, because state actors targeting individual users is a completely different threat from state actors collecting the communication graph of a major hub.
SIGINT is one half their chartered purpose. The other half is SIGSEC. And I had good reason to know directly.
"Owning you up" is harder (not impossible, but harder) when they can't simply send a letter and bring the force of the law to bear. NSLs are a very good reason to avoid any system that requires you to use a provider that has a presence in the US (and there are analogous concerns about e.g. AU, and obviously any country where legal and practical protections are weak enough that a strongman can just send a team of thugs round is a nonstarter). But really any specific country is beside the point; it should be table stakes for a serious cryptosystem that one can avoid depending on any single point (and make choices based on one's own trust base vs available resources) whether that's for relay servers, app maintenance, or anything else.
> Pick a service that doesn't have information to share about you in the first place as your high order bit.
True enough; obviously trusting your security to a system that requires you to use a phone number identity is laughable in the first place.
But I think it's quite valid to suggest users should carefully think about the tradeoffs between being subject to legal disclosure and being subject to compromise. Basically, do you trust the FISA courts, or do you trust the code?
The answer isn't really obvious! When it's a random anonymous startup based in, like, Panama that claims to have reinvented JavaScript-based encryption or whatever, yeah, I sorta trust the FISA courts more!
Even with their criticism, the author is giving Signal too much credit.
Signal is not on F-Droid. Signal sends their lawyers after open-source app repos for including their app.
I think the only claim they have is their trademark name "Signal". I wonder what's a good name for packagers to use for apps like this. Reminds me of Firefox and IceCat, or Rust Lang and Crab Lang.
Or Beacon.
Or Flare.
Or FOSSE2EEMsgApp.
If you are trying to hide from the NSA or other nation states, you have a LOT of work cut out for you. There are basically two sub threat models: are you trying to hide from the dragnet (in which case, just using any obscure and relatively obfuscated communications mechanism will work) or the scenario in which you’re being actively targeted (in which case you need rock solid security from end to end). Keep in mind that the Security version of https://en.m.wikipedia.org/wiki/Analog_hole means the security of your networked device is just as important as your messaging protocol, and… good luck with that on mobile.
If you are just a small fish trying to avoid something with a court-admissible record (and don’t care about parallel construction) you’re probably fine with Signal, provided you understand that your counterparty can just give you up.
I hate to bring out the “nothing to hide” argument because I disagree with its premise from a moral standpoint, but from a practical standpoint, I recommend avoiding having “directly targeted by the NSA and needing to avoid it” as your threat model to begin with.
Zero Trust Security Model - Trust no One (Internet Security) : https://en.wikipedia.org/wiki/Zero_trust_security_model
Zero trust means verifying everything. Not only has no living person verified the entire technology stack they are using, it is literally impossible to do so for any modern consumer device, since they all contain closed hardware and software that affects the trust model yet cannot be verified in any meaningful sense.
If you need unbreakable encryption and security that even the NSA (or the various vendors it works with to find zero day exploits) can’t hack you need to get off the fucking internet
Not only has no living person verified the entire technology stack they are using,
it is literally impossible to do so for any modern consumer device..
Correct! - So the options are practice good privacy principles or totally disconnect and become a Hermit.
For those who think that’s too far, Crypto AG. A company that actually wasn’t founded by the CIA, but was slowly bought out by intelligence agencies with shell companies. Also they were Swiss by every appearance! Good thing there isn’t a modern Swiss company many people here use and trust because they are Swiss and not US…
Also, paying for VPNs with cash is, in my opinion, overrated when they know your actual IP address. Sure, visit the coffee shop, but if the coffee shop has cameras…
VPN services are such easy targets that even if they weren't honeypots they would effectively be so.
That was a big reason from me to avoid it.
Even if Signal did deploy the publicly available code, there's no way they nor a user can prove it.
We should never assume an open source version of anything is what's actually running on a server - edits could have been made to the code; in fact it could be entirely different software designed to appear similar.
[1] Minor edits for brevity's sake
If Telegram asked about $4 in BTC for anonimity, I would gladly pay for it.
It's interesting that this experiment shows how valuable is knowing your phone number and identity.
[1] https://community.signalusers.org/t/usernames-in-signal/9157
1. your contacts to be stored server-side instead of device-side, where they might end up in the hands of an adversary
2. your contacts to be stored in some other, less-ubuquitous-and-less-likely-to-be-complete format on your device.
Maybe signal could have write access to your contacts so that it could store its own identifiers in the address book, but I could see a lot of wtf moments coming up when privacy-minded folk see that permission request.
Yes, it needs your phone number. Yes, it shares contacts, protected in a (somewhat) secure enclave. Yes, Signal could theoretically distribute a compromised client that would undermine the end to end encryption (which if ever discovered would end their organisation).
If you are afraid of spy agencies or hostile governments, don't use it. If you just want reasonable protection for your chats with friends and family, it's perfectly fine. I trust it more than WhatsApp.
* they have a forum[3] that is not even indexed by search engines[4], which is not community friendly at all.
[1] https://community.signalusers.org/t/could-signal-become-the-...
[2] https://matrix.org/docs/communities/moderation/
[3] https://community.signalusers.org
[4] https://community.signalusers.org/t/google-site-search-doesn...
If telegram says "trust me, we can't read anything" and signal says the same: the only way you know it to be true is if they have never given you any software that has access to the unencrypted content.
OR
you only use another network to communicate (and, obviously, you ensure that your clients aren't sending any messages out to anywhere that's not that network).
If you play around with the EFF's lovely Tor diagram you can get an idea of what I mean: https://www.eff.org/pages/tor-and-https
I thought NRL gave us Tor.
-that you cannot be open source if you do not instantly share every change
-that the nsa funded signal
-that you can bribe the New Yorker magazine to write a profile about you
-that Facebook Messenger is as secure as Signal
I don’t trust dijit.
I run an IRC network (and have for 15 years), and I tell people often to use OTR in DMS primarily because I shouldn't be trusted. I definitely do not tell people to install my client and forsake all other networks.
> -that you can bribe the New Yorker magazine to write a profile about you
Oh that's definitely true; though I wasn't saying bribe; Did you know those "30 under 30" lists, you have to apply to be on those. It helps if you're rich, but you don't technically have to pay. It's like this with a lot of media.
I have been in the room when discussing paying for PR pieces on our senior staff, especially the CEO in top magazines. Truthfully you hire a PR agency and "things happen".
> -that Facebook Messenger is as secure as Signal
Why are they not?
> -that you cannot be open source if you do not instantly share every change
You are not, since nobody can bloody run the software themselves anyway, and the entire point is transparency.
I mean, you wrote, "From everything I personally know about the media, articles like that are usually paid for, though almost never directly by the person being profiled."
This is, frankly, a stupid claim, though I think from your profile you are probably German or Austrian and thus might not really know which news outlets are reliable. As a perhaps helpful analogy, the New Yorker is roughly like Der Spiegel or Die Zeit, only more respected. (That's not to say they don't have misses; Ken Auletta's profile of Elizabeth Holmes comes to mind.)
The prospect that you can pay for coverage--and as an aside, I don't think The New Yorker has ever run "30 under 30" lists--is rather laughable.
> You are not, since nobody can bloody run the software themselves anyway, and the entire point is transparency.
Er, what are you talking about? https://signal.org/blog/reproducible-android/
I don't know how to say this nicely, but your post doesn't have a strong connection to facts.
the 30-under-30 thing is Forbes, I have always considered them reputable, perhaps I am mistaken.
The reproducible builds website; is; as previously mentioned a really nice looking page which basically says: It won't be reproducible even if you follow these steps.
I literally said: "it looks good in a google search, but there is nothing of substance since they say in the article itself that it will not be reproducible", that "please don't send us messages about how it's not reproducible"; they say it's because of the shared libraries and that some parts are actually reproducible.
No, Forbes is a shithole. https://www.entrepreneur.com/growing-a-business/did-someone-...
The New Yorker is not a shithole, and don't take money for articles.
Maybe you want to, like, correct your blog post? Honestly, the claim makes you sound dumb.
> The reproducible builds website; is; as previously mentioned a really nice looking page which basically says: It won't be reproducible even if you follow these steps.
I don't know what you mean. Are you referring to the NDK portions? And if so, does the critical stuff (key verification, encryption) happen in Java or in native code?
> "please don't send us messages about how it's not reproducible"
Huh? Where did they say that?
Even if I take, for absolute fact that you cannot possibly hire a PR firm or spend enough in marketing to get a puff piece about you in a magazine; you are glossing over the entire point I am making.
Someone is telling me to like this guy. Someone is telling me that he's a saint, a hero, a steward of the future. Someone truly want's me to think that.
I'll say it again because you didn't catch it: none of these issues are nails in a coffin, when placed together they paint a particular picture. I can't unsee that picture, and arguing over semantics doesn't change the core argument at all.
I absolutely will not redact that statement because it is true that you can buy your way into magazines, either directly or indirectly. Whether the New Yorker is entirely immune to being convinced to write profiles like this: even if no money directly changes hands, is irrelevant.
-----
> the Signal Android codebase includes some native shared libraries that we employ for voice calls (WebRTC, etc). At the time this native code was added, there was no Gradle NDK support yet, so the shared libraries aren’t compiled with the project build.
> Getting the Gradle NDK support set up and making its output reproducible will likely be more difficult.
> Please don’t freak out
> Just to head off the inevitable deluge of GPG-encrypted emails with dramatic subject lines, we are not doing this in response to any kind of legal threat or pressure. This is just a weekend hack; please don’t make us regret it.
tl;dr: it's not reproducible with shared libraries, or gradle and it was just a hack, please don't make them regret doing it.
Oh, and did you actually run through the steps? Or is it merely enough that having them listed makes you trust them?
By all means, you're not the first person to proudly wave their ignorance on the Internet, nor will you be the last, and yours isn't especially egregious by Internet standards. I am baffled that you would want to write a blog post about how ignorant you are and then submit it to the front page of HN. If I were you, I'd, like, not want people to read that?
But, up to you. Good thing you don't use your real name I guess. ;)
> > Just to head off the inevitable deluge of GPG-encrypted emails with dramatic subject lines, we are not doing this in response to any kind of legal threat or pressure. This is just a weekend hack; please don’t make us regret it.
This doesn't say what you said it says.
> tl;dr: it's not reproducible with shared libraries, or gradle and it was just a hack, please don't make them regret doing it.
As I said, in which codebase does the key verification and encryption live--is it in the native code, or in the Java code? I suspect you don't know, or you don't know why that matters.
> Oh, and did you actually run through the steps? Or is it merely enough that having them listed makes you trust them?
Oh, definitely the latter.
Well, I am ignorant, I don't know the internal workings of every single magazine, but I am aware how the media engine is working since I also work in the entertainment industry.
I am sure you are not genuinely claiming that it's impossible for them to be influenced by PR firms or external marketing spend? That you sincerely believe they are never influenced by external marketing of people? How might you suppose they find people to write profiles on? I personally know that it isn't chance.
> Good thing you don't use your real name I guess. ;)
I do use my real name for whatever it's worth, I have absolutely no problem wearing these statements on my sleeve- if you read the article you would see my real name plastered at the top of the page and a link to my video game credits buried near the bottom of the page in the "Commonly Asked Questions" section.
I'm really happy you took the the time to respond to me though, since you are precisely the type of person I'm writing this for; people who are emotionally pro-signal, when in reality there's no reason to be.
Do you even read how aggressive your tone is? If you actually had anything meaningful to say I would feel terrible.
"PR people pitch profiles to writers" is very different from...oh, what did you write? "From everything I personally know about the media, articles like that are usually paid for..."
The former is normal journalism. The latter is an ethical breach. So, yes, let's talk about tone for a moment: in your post, you accused multiple people of ethical or legal breaches, on the basis of, oh...your feelings?
Very respectful of you! Yes, my "tone" is direct. But I didn't accuse you of anything unethical, did I?
> I do use my real name for whatever it's worth, I have absolutely no problem wearing these statements on my sleeve
Hahah, OK then.
> I'm really happy you took the the time to respond to me though
Oh, but I did. As far as I can tell, you made one, and only one, technical claim: that Signal's reproducible builds aren't useful because they don't cover the NDK code. I asked you, twice now,
"As I said, in which codebase does the key verification and encryption live--is it in the native code, or in the Java code? I suspect you don't know, or you don't know why that matters."
You have twice now failed to reply to that. Care to try for a third time?
Edit: Seems like Signal's reproducible builds now do cover native code, though I haven't tried this myself: https://github.com/signalapp/Signal-Android/blob/main/reprod....
So, like...what was your point again? Other than that you don't know what you're talking about?
Do you think it irrelevant that your phone auto-updates without consent (citation in TFA), do you think it irrelevant that the reproducible builds are -- not, you wouldn't ever need to touch the key to bypass signal. You want me to go into semantics but anyone with half a technical brain knows that RCE, logging, remote screen capture, or anything that can read memory will easily break security and doesn't have to be colocated with the code that actually does the encryption/decryption.
Also I made multiple technical claims:
* "third party clients are a no go"
* "third party networks are a no go"
* "Automatic updates are enabled and forced" (due to "move fast" ;))
* "The code on the server has been provably non-public"
* "Forces the use of a globally unique number that can often be tied to personal identity and will always be tied to physical location"
Care to answer these? ;)
EDIT: seems like Signal has a spotty relationship with reproducible builds but they are trying to keep it and even have an automated job for it, though it seems people are often unable to reproduce: https://community.signalusers.org/t/beta-feedback-for-the-up...
Good luck with that.
The New Yorker is a storied magazine that has never had anything like that. Forbes runs those lists, I believe.
I am not particularly a fan of the New Yorker any longer, and some media ignorance is forgivable. But to make a libelous sloppy claim on this basis is the height of hypocrisy and recklessness.
Do you notice how people have to waste time repeatedly rebutting your pig ignorant claims? I am a free speech advocate but your behavior is the reason libel laws exist.
What about having E2EE traffic for your day-to-day communications? Why not, it seems reasonably protected and no government agency or third party would reasonably put the effort into looking into that.
Always something wrong https://www.securemessagingapps.com/
Other people live in the margins of what either their own, or some aggressor society wants and information from/about them is key. I can understand somebody having a heightened sense of what should be the foundation of "trust" in these circumstances. But that said: simply using signal is probably putting a giant red flag over you in some circumstances. Or, PGP. Any self-installed cryptographic technology you are associated with, puts a marker against you for some problems.
I don't "trust" closed source. I prefer that people have review, and that objective groups of people I trust in a personal sense (because I know them, no matter how vaguely, from online lists, and IETF wg and the like) tell me from their position of contextual knowledge, and I admit some authority, where trust can be well placed. Some of them are American. Some of them work for agencies related to the state, like the FCC and in some cases the NSA. I again have to re-frame "trust" into the sense of what it means when somebody who works for an agency like those tell you something. (others of them are not american, do not work for these agencies, or sister agencies in five eyes or other economies. But I observe, if you are competent to speak about cryptography you almost certainly DO engage with people who work for state enterprises like NIST and the NSA, even if in other economies. Its just the way the world IS: academics who work on cryptography have a circuit of relationships which includes the mathematicians inside these agencies)
I don't "trust" Moxie quite as much as I did, because some of the actions around Signal confused and worried me. And, I saw little to no desire to engage. Well, he doesn't owe me anything, financial or moral. I have no direct relationship, and in the end if he decided trying to assuage a million edge users like me (edge user not edge lord) was a loosing game, I can't fault his logic but the other side of that logic is I don't "trust" him as much as I used to.
I do trust Meredith. I have met her (once or twice) and she seems to me to behave in an open, direct manner, and when she says things I see them reflected in what she does. And, I trust the kinds of statements she has made about signal and the kinds of things I see emerging around governance of something like signal.
In due course I do hope she and the board can say something about source code, and future development, and how we can re-build or build from scratch some reasoned trust in the code, and its cryptography and the trust in systems behind the code.
It is absolutely not the case that cryptography engineers generally interact with NIST employees, and certainly not NSA employees.
Unless and until somebody audits and reviews, I would believe code he wrote remains in the application suite and head-end services? Should I "trust" that implicitly?
> It is absolutely not the case that cryptography engineers generally interact with NIST employees, and certainly not NSA employees.
Day to day? no. Communications are confined to matters of substance between them. But I see NIST people at IETF standards meetings, Mailing to lists. I see engineers who submit algorithms to the NIST beauty contests talking online about who they discussed things with. I knew researchers in Australia who were engaged in NSA related study and it was simply understood no technology entered the building with them, to go and do face to face but the fact they met was not secret, and there are lots of people in bodies like IETF who meet these people on an as-needs basis.
Around the time of IETF being held in Beijing a number of people wound up being asked or told not to take their normal laptop with them into that economy. A lot more than I would have expected simply because of commercial in confidence reasons of risk.
"generally" might be too sweeping. It's not forbidden. It might be unusual.
I don't understand why you believe cryptography engineers generally participate in standards bodies. A comparable percentage of cryptography engineers do that as do software engineers with software standards bodies.
If the ratios are similar then sure, there's hundreds (thousands) who don't. The point of substance is, these people can be asked what they think about software and systems. I haven't asked for a while.
One meeting I went to in Nepal, the attendee from a US company had a personal minder (with gun) and car. That's about as close as I've come to a heightened sense of need facing attendance at standards and policy meetings internationally.
So maybe to YOU this is unremarkable. My anecdata is that it's more said, than done. However some people who work in these fields are placed under specific requirement. Perhaps it goes to your seniority and importance: I am glad I've never been held to that burden in 42 years.
That doesn’t relieve one entirely of fears of betrayal. American 501c3 law allows nonprofits to act like ordinary for-profit corporations in many ways. Such organizations cannot generate a profit (which has a specific legal meaning) but they can amass money to pay as much as they want in salaries to their leadership under employment contracts, or use that money for things that none of the original supporters saw as part of the mission. The community’s insight into finances is limited to peeking into periodic tax filings instead of having insights into (and any oversight over) day-to-day operation.
Signals money comes from two sources:
1. User donations - you can in fact be paying for it,
2. A 50 million dollar initial fund provided by a benevolent sponsor, and probably some other misc funding
It does not come from selling ads or user data, which is the usual meaning of that glib saying.