How Trail of Bits helps verify the integrity of Signal chats(blog.trailofbits.com) |
How Trail of Bits helps verify the integrity of Signal chats(blog.trailofbits.com) |
His interview does not tell us if it was metadata or actual calls that were surveilled which could point to device compromise too.
"What caught him by surprise, he told ThePrint, was the Special Cell officers' access to his calls made via Signal"
https://theprint.in/india/ex-civil-servant-ashish-joshi-reca...
For telegram it's a bit easier yes, but the user can set up an additional password. I have done so of course. Note that telegram is not E2EE so they can give your stuff to the police at any time unlike WhatsApp and signal.
For signal I don't know as I don't really use it but i understand it works the same way as WhatsApp, scan a QR code and authenticate to the phone.
Also, with all 3 systems it's clearly visible when you look at the linked systems.
A messaging service filled with bots and spammers is not usable, and possibly not affordable to Signal (what proportion of resources would be spent on spam/bots). What is a more private, usable solution for filtering them out than using a phone number?
Lots of security geeks want Signal to adopt practices unusable to the public. They've made clear that unsusable security is not in their mission.
That happens when public uses it, en masse, in the first place. And as it is today the "public" has no reason/incentive in switching to it and that naturally keeps the "non-technical public" away from it.
So who is this serving eventually? A very few, mostly "technical public", in complete contrast to what you have said.
I suspect Signal's goal is something entirely else. For them it's just two things:
1. Some sort of shallow ideology (started with the founder and the flame kept alive by the later leaders who often come across ideological groupies; the last bit is a bit strong but whatever)
2. Executing based on that for the sake of executing that because they can
What their intention is not: Signal ever becoming IM app of choice anywhere and possibly they might have their reasons for this. One of those reasons could be affordability as you have said it.
Note: in case this wasn't clear, the moment you attach a "phone number" you make it inherently unsafe for most, like 99.353959353%, of "general non-technical public" to use Signal and remain really unidentifiable. Once they are identified - in most countries (and now even in places like USA it seems) only thing needed after that is being "picked up" and rest will be just sung even without a device. I mean it's so absurd to even not think about it is that it's ridiculous. So no, it is DEFINITELY not "non-technical public can use".
I'd use something that's truly decentralised but signal is just another walled garden like WhatsApp. Just one that promises to behave better. But what's a promise worth these days?
A decentralised network would mean a guarantee that they can't do anything bad. I'll take that over promises and good intentions any day.
I don't care about the masses. If signing up for a matrix account is too annoying for them they don't really care about privacy anyway. After all it's the same they have to do for any online shop. Just create a username and password. Somehow it's not a problem for the masses if they wanna order a phone charger but for matrix it's suddenly 'too complicated'?
Since when is giving out your phone number a "more private" option ?
Replacing the need to register with a phone number with a requirement to pay is a better option how, exactly ?
I know plenty of non-technical users on Signal. Based on news reports, it's used widely by activists. I see journalists advertising their Signal contact information for tips. It's recommended government-wide in the US by CISA and is pre-installed on US intelligence community computers, including in the CIA.
SMS is used to register WhatsApp to a new phone, but that signs the original phone out. Also, you need the pin code that WhatsApp forces you to set. If you don't have it you have to wait a week if you got a recycled number. Also the original account holder is notified you tried it.
So this method cannot be used by the police to snoop unnoticed. I believe signal works the same as WhatsApp here, it also forces you to set a pin now.
For telegram this can be used yes but you can set an optional extra password. And also like I said telegram is not E2EE anyway so it's open to warrants.
Remember how everyone jumped on Google when they promised to do no evil? Now they're one of the most abundant mass surveillance companies in the world and we can't move away because they're too big to fail. The same with WhatsApp. People jumped on it because it was good, then nobody left when meta bought it because all their friends were on it.
Signal is one sale away from being evil too. They might not sell it but we've been conned so many times by big tech that I will only take technical guarantees, not promises that can be broken. We have to avoid getting locked in again.
And really, lots of progress is made in real open communications. Matrix is getting more mature by the day. NATO uses it, the French government and several others. And the good thing is, you can always run your own server and connect to the hive. Nobody can tell you what to do, nobody can tell you to surveil your users like the EU is planning to do.
We need something truly open. Not a WhatsApp light.
For me the difference is in the ownership. Who owns each. Which is BigCorp? That’s why I trust one more than the other.
You are deliberately missing the point.
Signal are gatekeeping these new advanced security features behind a phone number wall (soon to become paywall if some posts here are to be believed).
On a smaller scale, it's clear that Signal believes a functioning address book is necessary for end user adoption. For example, by default Signal notifies you of people in your phone contacts who are on or who later join Signal.
> Presumably the Signal folks can come up with more alternative solutions
I have yet to see a solution better than the one they chose, for their requirements. Notice that there are none in this discussion.
When using payment as proof, they can verify that payment occurred, validate the account and then immediately forget about the transaction. One spammer would still have to pay 10^99 times to create that many accounts.
If they accept monero or something then ok but I doubt they will.
Ideally they accept Monero and do unlinkable payments but I doubt they will accept Monero. Hopefully they accept some crypto.
It's already the case today (and has been for years) that you don't need to give strangers your phone number to chat on Signal. My username is soatok.45; try to get my phone number if you can.
If you want absolutely no info to be collected, ever, and there to be zero cost on the end user too, be prepared to welcome your new spam overlords. Because the people who will benefit the most from a zero cost signup that only requires a username are spammers.
For example:
* Are you absolutely positive signal will never have a bug that let attackers reveal contact phone numbers? I really trust in their secure coding skills, but this class of vulnerabilities (like 2fa leaj) happened to even the biggest players.
* One of the reasons signal collects phone numbers (and asks for a contacts permission) is to check which contracts are already on signal. For some people or in some governments even having a signal account is an opsec problem (to be fair, they have a secure privacy-preserving protocol for this - as you know - and it's possible to avoid this footgun if necessary)
Discord is used by a narrow group of technically literate people. Signal is for everyone. Your grandparents probably don't use Discord, but if they can text then they can use Signal.
That is not the same thing.
You buy a Mullvad scratch card on Amazon and you redeem the token string.
Mullvad also offer the option to put your card number into the Mullvad website, and I'm sure many privacy conscious people would be very reluctant to do that.
Card payments these days leave far too big a trail. The bank knows, the intermediary (e.g. Stripe) knows, and the merchant (e.g. Mullvad) has to keep records for accounting/tax requirements.
Molly is going to add a Monero integration while also having various other advantages.
They don't accept crypto donations directly or accept them for their backups so I assume they wont for registration.
Again, I don't trust promises anymore. Eventually they're going to need more money and that money will come with strings attached. If some org like Matrix would get bought people would just decouple themselves from their network. With Signal we can't do that because they are the only operator.
There are third-party forks and clients. Parts of the US government use one.
https://news.ycombinator.com/item?id=49678919
Also, you can audit the code.
Anonymous messengers have no real choice and have to use some sort of number for identity. See Briar, Session or Tox for examples.
My comments on Signalgate 1.0:
Could you give an example of an actual attack of this kind on Signal? The 'Signalgate' event was someone mistakenly inviting the wrong person to a chat.
A Third Party Breached The Intercept’s Signal Tip Line and Has Been Soliciting Whistleblowers https://www.dropsitenews.com/p/intercept-signal-tip-line-bre...
Twilio Incident: What Signal Users Need to Know https://support.signal.org/hc/en-us/articles/4850133017242-T...
Russian State-Backed Hackers Intensify Attacks on Signal Messenger Accounts https://thecyberexpress.com/signal-attacks-russian-fackers-t...
> Allegedly, Signalgate was caused by Apple helpfully mapping the wrong number to a name.
In what system is Apple mapping numbers to names? The address book is maintained by users. An AppleID? How could that happen? And it would seem to result in many errors before the Signal error.
I thought it was simply caused by someone adding the wrong person to the chat?
> The Intercept
Per that article, the cause is unknown. The speculated cause in the article is that The Intercept somehow lost control of the user id, and Signal recycles user ids. That seems like a bad practice generally and with this predictable consequence, and especially bad for an application people trust with security.
> Twilio
This was Twilio employees caught by a phishing attack. I wonder what more secure, and affordable, options Signal has. Operate their own SMS infrastructure - would that be more secure that Twilio's? Use something besides SMS - would on-boarding become too hard? Stop using phone numbers - they need some spammer and bot filter, so what replaces it?
> Russian State-Backed Hackers
A phishing attack on Signal users, using a QR or link to make the attacker a linked device. That setup seems risky for non-technical users; I wonder how Signal could better secure it.
That and other attacks are described here. The other attacks all require compromising the device on which Signal is installed:
https://cloud.google.com/blog/topics/threat-intelligence/rus...