| ▲ | lrvick 15 hours ago | ||||||||||||||||||||||||||||||||||
This is why as a security engineer and researcher even I do not have a Signal account. My conversation with Moxie about Signal convinced me that Signal cannot be trusted as they are obsessed with centralized control and user tracking, via app store stats. Privacy assurances come from enclaves internet randos can freely manipulate as they chose not to implement full source bootstrapped remote attestation. Also relying on app stores that can, with a court order, ship anyone an extra special fork of signal with compromised encryption, and they will never know. But F-Droid with independent control and reproducible builds? Unacceptable to Signal. Their stance is use proprietary partner platforms with their centralized servers so you can be tracked and backdoored at any time or GTFO. Centralized comms that force you to identify yourself and use proprietary software are an enemy of a free society. I do not understand the true goals of Signal, but their actions are inconsistent with their stated ones. This is not even getting started on their Mobilecoin premine scam that was a blatant conflict of interest and a wildly blatant violation of their non-profit charter given Moxies financial ties to Mobilecoin. | |||||||||||||||||||||||||||||||||||
| ▲ | slopinthebag 11 hours ago | parent | next [-] | ||||||||||||||||||||||||||||||||||
I just want to point out that this comment is almost certainly a false flag “privacy conscious” personality who is attempting to discredit Signal to push people away from reasonable and usable private options towards a nihilist approach to privacy. If the usable solutions aren’t “truly” private you might as well stop caring and just use the more convenient alternatives which freely share all their data with governments. Either that or they’ve been manipulated into believing this, which is actually more powerful in the long term. Either way, people should ignore these types of takes. | |||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||
| ▲ | pstuart 13 hours ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||
Is there an alternative out there that you do trust that is "noob friendly"? | |||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||
| ▲ | fwn 15 hours ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||
> [Signal is] obsessed with [...] user tracking, via app store stats. Not sure about that. You do not need Google Play Store to download or update Signal. I use Obtainium to update directly via signal.org for a very long time now. | |||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||
| ▲ | BuildTheRobots 12 hours ago | parent | prev | next [-] | ||||||||||||||||||||||||||||||||||
> I do not understand the true goals of Signal, but their actions are inconsistent with their stated ones. I've been annoyed and suspicious since they stopped being TextSecure and dropped support for SMS messages, and still don't buy the reasons given. It started as offering opportunistic end-to-end encryption on "direct" (SMS) communications to help privacy. It didn't even need a data connection. People bought into it and as an Android user it was good [1]. Data then got added. First boiling frogs to the side, and then SMS support was removed completely, for what I still think are disingenuous reasons (see [1]), and the summary of it's technically impossible and not worth it. Trust us. So what did we get? Well instead of leaking metadata to my phone provider, I'm now sending even more metadata to signal. They've put themselves in the path of every kex, every message, every group chat, every call, every read-recipt. Moxie Marlinspike is my new Santa; he knows when I'm sleeping and he knows when I'm awake. And for something sold as privacy, what the heck is with their Linkedin-be-proud dark pattern of convincing people to upload their contacts (it's safe - honest!), or announcing proudly that "contact I haven't spoken to in 15 years and for good reason" has joined signal! Would I like to connect with the person I was really hoping had forgot I existed and was only saving the number so I could make sure I never answered it? Yes please - and I hope you told them that as well - FML... I'm also suspicious about the encrypted cloud backups, but that might just be me. They also spent years making it difficult for people on de-googled phones, or to use it on desktop, or to run their own servers, or to run custom clients which seemed at odds with encrypt-all-the-things. I should be happy about the mass adoption of the encryption protocol. I should see WhatsApp adopting it just before they got bought out by Facebook as a win for privacy for the common folk. I should trust it more now that there's so many eyes on it. I should be in no way suspicious of the lack serious objection the lack of LA provision by the authorities, or the fact Spy-on-You INC would continue buying the messaging platform they can no longer look at. Things have felt off for a while and I wouldn't be shocked to see it on a future list alongside EncroChat, or Sky ECC, or Exclu or maybe even ANOM - a honeypot from the start. I can't prove anything, and don't know anything, but it sets _all_ of my "there's something wrong and I don't know what it is" senses tingling. But also I'm pretty bad at feelings. Maybe I just need to wee, or drink more water. My gut feel still insists there's a pattern to my RSA dongle's one time codes, so really you shouldn't believe a single word I've said. [1] There were issues. iirc it didn't work on Apple devices, sms is bad for images and group chats, it broke in a messy but easily bypassed (& fixable) way and it would never work for calls. It also still leaked metadata to the phone network. And SMS is just fundamentally dead and costly - but it absolutely served a purpose. | |||||||||||||||||||||||||||||||||||
| ▲ | Cider9986 12 hours ago | parent | prev [-] | ||||||||||||||||||||||||||||||||||
>This is why as a security engineer and researcher even I do not have a Signal account. Signal is regarded as the best mainstream messenger by many security professionals. >they are obsessed with centralized control and user tracking, via app store stats. Do you have any evidence they are obsessed with user tracking via all store stats? It seems reasonable to use any stats given to try to improve your app. Signal doesn't control the app stores and looking at provided stats doesn't compromise their users privacy. "Obsessed" is a weird way to personify a company. Signal chose centralization because it's best for UX which is clear when they have 100x the users of Matrix while being more private. >Also relying on app stores that can, with a court order What law would legally require Apple or Google to do this? Signal doesn't rely on app stores on android as you can a signed apk download directly from them. Other apps like Element or SimpleX also are distributed on app stores. >ship anyone an extra special fork of signal with compromised encryption, and they will never know. This is wrong. "Anyone" can clearly not do this or it would have happened to a single app in history, and yet it has not. It would be trivially detected through reverse engineering and would only ever happen in an insane targeted attack which is not in the threat model of 99.9⁹% of people. It wouldn't be the easiest attack and authorities would use something like Pegasus instead. >But F-Droid with independent control and reproducible builds? Unacceptable to Signal. Their stance is use proprietary partner platforms with their centralized servers so you can be tracked and backdoored at any time or GTFO. FDroid has had terrible security practices in the past. Not sure their current status but it's not recommended by GrapheneOS. Proprietary software is not less secure by default and can be analyzed. >Centralized comms that force you to identify yourself and use proprietary software are an enemy of a free society. Signal can be used without any proprietary software on GrapheneOS and by downloading Signal from their website. iOS and Android are proprietary anyway so your aren't avoiding it on those OSes. >I do not understand the true goals of Signal, but their actions are inconsistent with their stated ones. Their goal is more privacy for everyone, which they are clearly quite good at achieving with their skyrocketing user counts. >This is not even getting started on their Mobilecoin premine scam that was a blatant conflict of interest and a wildly blatant violation of their non-profit charter given Moxies financial ties to Mobilecoin. This was bad but I respect the intentions. They should have worked on Monero instead. It doesn't compromise their apps privacy, though. | |||||||||||||||||||||||||||||||||||