You are hinting at something important here. Let me strengthen your point: to own an object means to subject it fully to your own will. If the object can act in a way that favors someone else's interests over yours, you do not own it. This is true of pretty much any device running proprietary software.
A litmus test: can you make your device lie to the manufacturer's servers? Regardless of the legality or morality of doing so.
However this article is really about something else: the vulnerability of centralized services in the face of government oppression. Signal only has the ability to log messages because it is a centralized service that controls both the client and the server. The benefits of E2EE is greatly reduced if the client and the server is controlled by the same entity (tomorrow Signal can push out an update that would send a plaintext backup to their servers, and you wouldn't know it until later). Moreover, the non-free distribution mechanisms on mobile phones (stores) limits a company's ability to resist.
(Reproducible builds is a cool technique.)
But to be specific: "open source" claims go out the window when they're;
1. Not reproducible (before anyone links me to the "reproducible steps" please actually read them because they tell you directly that they will not create a reproducible output).
2. Able to hide development of mobilecoin (somehow) from us for nearly a year. To be clear: There were updates to the Signal app on iOS and Play, otherwise there would have been security bugs, but those patches did not make their way into the repositories.
Signal operates on a "trust us bro" mentality, and no matter how trustable they seem to be- something about that doesn't sit right with me and never has.
EDIT: I don't really care if bots or shills downvote me, can you really, with a straight face, say it's NOT "trust us bro" ideology that makes people use Signal?
https://github.com/signalapp/Signal-Android/blob/main/reprod...
A significant improvement.
/s
If you don't like this, you use the non-Play Store build instead (which supposedly doesn't include any binary blobs, but I haven't checked).
Why can't I sha256sum the two apk?
i should have done that.
Now that I asked ChatGPT, it didn't include this reason - perhaps it's too obvious and no-one has written it down before.
As someone who got their whole network to switch to Signal before that happened, it was absolutely disgusting watching that all play out.
The MobileCoin work and the source code not being published on the public repository for nearly a year was an extremely ill thought move. It soured my view of Signal as well.
F-Droid and Debian/etc show how this is done.
With reproducible builds, you don't have to trust the packager or the developer as long as you trust at least one person who reviewed the source code.
It's all based in trust in the packager and only the packager—there are no checks and balances. The only reason why splitting up the responsibilities might help is if you find the F-Droid maintainers to be inherently more trustworthy than the Signal developers, not due to simply separating the concerns.
Not by a long shot. Just a few counterexamples from the top of my head: Destroying currency, altering passports, reproducing copyrighted images.
I'm not saying I'm a fan of even more exceptions of that kind, but I don't think there are any particular inherent rights arising from property ownership beyond from what society agrees on there are (e.g. the first sale doctrine for physical media). That's what makes it even more important to codify these rights.
You can't make your phone lie to an app developer about its location, rooted status, etc. You can't make your HP printer print with unsanctioned ink. Therefore, you do not own them.
Now you could of course say that the difference is somebody having intentionally designed an object in a way that makes it capable of withholding some functionality from me but not others, and I'd agree.
But all in all, I just don't think "property rights" is the right lens to think about computing devices.
These aren't counterexamples, they prove the rule. A US passport literally has the text "this passport is the property of the United States" printed inside of it, and I imagine the same is true in most countries: you are the recipient of a passport, not the owner of one.
The same applies to copyrighted images— when you purchase a book you own the physical copy and can fully subject it to your own will, but you don't own the right to make additional copies of it. You own the copy, not the intellectual property.
As for currency, it may not legally be the property of the US government like a passport, but I would argue that the fact that you can't modify it does in fact mean that you don't own the bill, the bill is a representation of an abstraction of "money" that you do own.
Let’s explore that.
If the law says I can’t ride my motorcycle the wrong way down the street, does that mean I don’t own it?
What about if we add traffic cameras that absolutely guarantee I will be prosecuted?
What about it if we add a black box that reports transgressions automatically to the authorities?
What about if the black box automatically cuts power to the engine?
I don’t think ownership is a binary using your criterion, or perhaps it’s simply that different people will put the dividing line in different places.
You can do what you want with the bike, but your analogy falls flat because it implies that despite you owning the bike you get to drive through your neighbours living room: because your right to own a bike somehow trumps their right to own land and a home.
Which police with a warrant can very much do.
Scalable surveillance is different, just as scalable weapons are different.
Even if there was warrant protection, I’d still be against it. People have traditionally had the right to speak to each other without giving a transcript to the police. I think it’s unreasonable to make that illegal.
Comparing to analog is I think flawed because even if it mapped 1-to-1 it does allow for a level of search that is problematic given the low cost of digital surveillance.
The issue with Apple caving to UK demands regarding encryption, and now Signal being in a similar situation, shows that you can't just focus on technology and ignore policy and politics.
And you'll find out that a ton of people here on HN will care, but most of the public won't.
People should take XKCD 538 really to heart (The 5$ wrench one). It's not the same point, but very similar. https://xkcd.com/538/
It very much can. In a battle between human force and physics, physics win every time. If I send an encrypted email to you, you have the choice to not give up the key, even if you'll be in jail. With physical letters, you don't have this option. Technology gives you the ironclad ability to keep a secret, only limited by the fortitude of your character.
And I hope you understand that 5$ wrench is a euphemism for what would 'really' happen.
All this to say that no, technology does not triumph over politics and policy.
If the second person is somewhere else in a different jurisdiction, how are you going to communicate with each other to get the two halves of the secret together to encrypt/decrypt messages? It's an unworkable situation.
As I see it, you create a fantasy situation that would not work if you just want to communicate with people in a secure way. No amount of technology or encryption is going to work, especially in the real practical world.
This bill is akin to making it illegal to destroy your own correspondence.
We're talking about companies though, not technology. Something like Bitcoin or BitTorrent can be regulated, but not stopped.
And if Apple and Google were forced to remove all wallets from their app stores, it would largely be game over.
Very few people actually care about the principles of Bitcoin and the like. Maybe the core devs and some very early adopters?
I did worry this example would be too political, hence including the BitTorrent example as well.
The actual software and code? Good luck getting that genie back in the bottle now. But, you can certainly hamstring it in other ways, and frankly, that should be good enough. I say this as someone who is absolutely not a fan of the project and find the perverse incentives in PoW especially to be pure garbage, but I am also a realist.
When you have folks like Peter Zeihan declaring that Bitcoin *will* go to zero - that is, I think, the epitome of hubris. We don't know what will happen next, and with our current administration, I'm only seeing Bitcoin become more influential in the interim, much to my chagrin.
> The actual software and code? Good luck getting that genie back in the bottle now. But, you can certainly hamstring it in other ways, and frankly, that should be good enough.
This is my point - the technology is out of the bottle. You can't stop it. You can disincentivize its use in all sorts of social and legal manners, but to go all the way back to my original comment: you can stop Apple (Coinbase) from operating, you can penalize individuals for using encryption (or cryptocurrency in this case), but encryption (and blockchain) still exists and can be self-hosted, and individuals can continue to utilize those tools.
Again, look at torrents. Its primary use case is illegal. What.CD, Oink, even TPB (at various points) have all been taken down. Yet torrenting still enjoys widespread use across the globe.
I'm not a fan of cryptocurrency either, but I do want to note that "hamstringing" it at this point will likely have many negative downstream effects on the overall economy.
This part does terrify me. Too many hedge funds and more common investment vehicles have gotten exposure to this. If there ever is a huge rugpull, regular folks will get nailed. Sad times.
It often only can't in a world of mandatory centralized app stores. That's not the only possible world.
Most 'regular/normal' people won't and most importantly - don't want to - jump through the technical hoops to keep using Signal.
Although the downside of the official app stores is clear, the alternative might result in a swift return to the '90s and '00s where malware and viruses were rampant. Pick your poison.
The answer you're looking for is probably to build more decentralized, FOSS software with better UX. Much easier said than done of course.
Steganography isn't some magic shield to avoid surveillance though. If authorities are already monitoring you for some other reason, then they can burn a zero-day exploit and see anything you do on your device. And if your entire city is covered in cameras with facial recognition, well... you can have your secret messages but I don't know what kind of resistance you're going to be putting up. So to some degree you're right that you can't fully ignore policy and politics.
Not sure how to get most of the public to care though. I get most people have more immediate concerns in there lives, and crime is a legitimate issue, but even a cursory knowledge of history will show the hell life can be under authoritarian governments. I think far too many people think "it can't happen here", which seems insane considering how often it has occurred even in liberal democracies (Spain, Portugal, Germany, Italy, Argentina, Chile, and many more.) In less liberal and less stable democracies, it has happened even more times. I'm not sure why people have some unfounded faith that their government could never become authoritarian and oppressive.
I'm not saying take down every CC camera and get rid of intelligence agencies -- they are important tools for fighting crime. But there's a difference between a few traffic cameras and CC cameras in places people would presumably commit a crime, and burning targeted exploits for surveillance of truly notorious criminals, and just mass surveillance through banning end-to-end encryption. With zero-day exploits, the government is inherently limited in the surveillance they can do, so it's a limiting factor on their potential for abuse, as the more they use it, the more likely they are to be discovered and patched. But with no end-to-end encryption, the potential for abuse is limitless.
Apple "caving" would've looked different; in fact, we probably never would have known, given the insidious nature of the underlying statute in the UK.
Apple is making noise about the fact that they pulled the product, and the tech press is making it clear WHY even though Apple itself is legally prohibited from giving any additional context.
I feel like that was probably the best move available to them given the cards dealt. Fighting in secret courts is unlikely to be fruitful.
And in time, they will also remove the e2e encryption on existing accounts using the e2e feature to comply with UK demands.
They may have sounded the alarm, which I appreciate, but they still have to 'cave' and do as the UK government tells them or they have to cease operations in the UK.
Capitulating would've meant giving the UK government the back door they wanted. They didn't do that. They complied in a loud and public way, which unmistakably shined a light on the insane request.
The only other options for them were withdrawal from the UK market entirely, or a secret court fight they'd probably lose.
To me, their actual response reads more like malicious compliance than "caving," which usually implies giving up completely.
There's definitely a strain of thought which perceives almost everything in society as being outcroppings of the progress of technology (however you define that), and especially in the 1990s imagined/expected everything to fall over under the mantle of "information wants to be free" etc.
I think you're right that this is an intellectual dead-end. Many of us lived through the 90s hype wave and into now, and have watched things take a complete circle. The Internet didn't transform society into utopia, the real-world dystopia transformed the Internet into a high definition image of itself.
Back when Moxie Marlinspike made a thoughtful critique of Web3 (the most thoughtful one I had read, actually), I put together a reply. It’s worth a read for anyone on HN who cares about user freedom and how society is structured:
https://community.intercoin.app/t/web3-moxie-signal-telegram...
A note to the younger HN crowd who may have grown up with locked-down devices: the “hacker ethos” used to mean the freedom to tinker and buuld your own. It wasn’t always the case. The Personal Computer and Apple came about through the Homebrew app. And before that, Steve Jobs and Wozniak were even building blue boxes for “phreakers”:
https://www.youtube.com/watch?v=HFURM8O-oYI
Before he became a corporate golden boy, Mark Zuckerberg built Synapse for regular users and open sourced it instead of selling it to Microsoft and wanted to build Wirehog, but Sean Parker proudly said he and Peter Thiel “put a bullet in that thing”
https://techcrunch.com/2010/05/26/wirehog/
I don’t want to just be the “wake up sheeple” guy or some unkempt Stallman clone. But there is a real culture clash between the hackers and the corporations, and I feel like the HN denizens who knee-jerk downvote of anything decentralized today don’t get the point of open source decentralized hacker ethos and how the people who practice it produce the next big thing. Working for FAAMGA and “the cloud” ain’t it folks. Here’s why “the cloud sucks” by Steve Wozniak: https://gizmodo.com/why-the-cloud-sucks-5932161
In short — read my rejoinder to Moxie Marlinspike, in my first link. It is ironic because all these years later, I end up being right: it is exactly his company that’s getting hit with this, exactly because it is centralized.
And if you are Moxie or Durov and think your centralized company has somewhere to run… here is the bigger picture around the world — governments are coming for you and the war on user freedom is coming through you: https://community.qbix.com/t/the-global-war-on-end-to-end-en...
If there is a free software license, it’s of no direct use to them. Only software developers care about such things. (There is an indirect effect on what software is available.)
> If there is a free software license, it’s of no direct use to them.
It's of indirect use; they could use a modified version of the software that does what they want, created by someone else. This is why you generally don't see user-hostile features in Free Software; someone would just fork the project and edit them out.
[1] https://www.securityweek.com/malware-delivered-via-malicious...
More realistically, you generally don't have to switch to a fork in the first place because the mere threat of a fork is enough to prevent the deployment of user-hostile features. And when a project does get forked it's often a highly publicized affair with a lot of community drama which produces no shortage of information about who's trustworthy and who's not.
There is a long tail of malware in app stores, despite the efforts of app vendors to police such things. Nobody would be bothering to fork them because most technical users don't care about them, but they still attract lots of victims.
Example: malicious Chrome extensions. Authors of Chrome extensions receive enticing offers to sell and sometimes they do.
When I say user-hostile features I'm not talking about malware. Yes, I suppose theoretically you could fork a Free Software malware app and make it not-malware, but that's not what I'm talking about here. I'm talking about things like Samsung putting ads on your TV home screen[1], or BMW charging a monthly subscription to access your car's seat heaters[2], or Sweden trying to install a backdoor in Signal. With Free Software, users get the final say on whether those features are installed on their devices or not.
[1]: https://www.reddit.com/r/samsung/comments/184a1j6/why_do_i_h...
Users don’t get final say in what their devices do unless a software developer is willing and able to help them. Most are actually pretty helpless on their own.
There are lots of ways to figure out what version to install; which is a lot better than having literally no choice because there's only one option available: the one with homescreen ads/government backdoors/seat heater subscriptions.
Will some users make the wrong choice? Yes. Is that a valid justification for treating everyone like children unable to make decisions for themsleves? Absolutely not. Just as there are other ways to prevent real-world crime than by locking everyone in concentration camps, there are other ways to prevent cybercrime than by locking everyone in an inescapable walled garden.
If they were Free, users wouldn't necessarily even need to hire a developer to change their app or OS; those changes would most likely already exist in some form somewhere and the user could simply purchase the modified version.
Having the source code to a printer driver available is a completely different thing than being dependent on a platform, because all your friends and relations are using it.
Personally, I'd only trust a governmental agency to provide such services, which makes the article we're discussing ironic at the least, or complicated.
This is not a knock against private industry in general. Capitalism's greatest strength is precisely that it harnesses corruption toward productive ends through private industry.
Nonetheless, it's unsurprising that people would take a chance at less-corrupt versions of key infrastructure. My preference would be to do this through charity, which worked pretty well for e.g. Mozilla for a while - but I wouldn't call other directions naive.
There are plenty of immature ideas about running human affairs going around. History has shown that a social contract obtained by popular assent is the only viable choice, unless you relish war, insurrection, terrorism, and social collapse [0].
Government is good almost by definition because we grant its existence on that basis of benevolence. Indeed one should be ready to defend good government and lay down ones life to make it good, including overthrowing existing bad government.
This was well established 80 years ago and we seem to have forgotten.
I know there are some around here agitating for tyranny and dictatorship. That in my opinion is the "childish view", a result of too much screen-time and a lack of life experience.
Would you be willing to fight for good government? [1]
You're merely playing word games here. A person keeping another human being against their will is called slavery or abduction instead of prison. Similarly, it's only called war when it's a government doing it, otherwise it's called activism, terrorism, or gang warfare (note the overload of the term).
The main difference between a corporation and a real democratic government is that a government is accountable to all its citizens, instead of its shareholders. I understand that this is a difficult concept to grasp for US citizens, but the rest of us living in actual European democracies don't deserve your childish derision. No system is perfect, but don't make the mistake of thinking that the US government is the best (or even a good) example of democracy out there.
I can't see why you'd say that.
Governments (and private corporations) are not operated to faithfully serve the public, certainly not the public as a set of individuals and small groups of people. It's not that "government services are bad", but rather, than governments, even democratically-elected ones, are practically certain to wiggle out of the straightjacket of strict protection of individual needs and interests for legitimate or illegitimate "greater good"; specifically, they will not resist the desire and the interest to spy on you. And the potential for government abuse of private information is quite high.
"There is only one essential difference between a monarchy and even the most democratic republic—in the former, bureaucrats oppress and plunder the people in the name of the monarch; in the latter, they do it in the name of the people's will." - Statism and Anarchy
The core problem isn’t the form of government, but the concentration of power itself.
I suppose if I needed to make sure there was a public immutable record of something it would be useful. Like "I made this thing no later than this post"
But who would use it?