Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Michał "rysiek" Woźniak · 🇺🇦
Michał "rysiek" Woźniak · 🇺🇦
@rysiek@mstdn.social  ·  activity timestamp 2 weeks ago

Here are the four paragraphs of conclusion from that clickbaity piece ("Is Signal safe?") by @protonprivacy about @signalapp that is doing rounds.

1. "Signal remains widely regarded as the gold standard for secure private messaging for very good reasons. The Signal Protocol is extremely secure, and unlike most other apps that use the Signal Protocol, Signal collects almost no metadata from the Signal app."

1/🧵

#Signal #Privacy #InfoSec

  • Copy link
  • Flag this post
  • Block
J.Sʜᴀʀᴘ🌍🇺🇦Fʀᴇᴇᴅᴏᴍ&Dᴇᴍᴏᴄʀᴀᴄʏ
J.Sʜᴀʀᴘ🌍🇺🇦Fʀᴇᴇᴅᴏᴍ&Dᴇᴍᴏᴄʀᴀᴄʏ
@JSharp1436@mstdn.social replied  ·  activity timestamp 2 weeks ago

@rysiek @protonprivacy @signalapp

I hate to break the news to you that Signal is secure, but ... and it's not just Signal that isn't ... nothing electronic is secure from the NSA - NOTHING.

  • Copy link
  • Flag this comment
  • Block
Samat Sattarov
Samat Sattarov
@SamatSattarov@mastodon.social replied  ·  activity timestamp 2 weeks ago

@rysiek Signal is not perfect, but compared to most apps it is still way ahead, and pretending otherwise just confuses people more than it helps.

  • Copy link
  • Flag this comment
  • Block
David Chisnall (*Now with 50% more sarcasm!*)
David Chisnall (*Now with 50% more sarcasm!*)
@david_chisnall@infosec.exchange replied  ·  activity timestamp 2 weeks ago

@SamatSattarov @rysiek

There are also a bunch of good reasons to criticise Signal, but this kind of piece and the recent marketing nonsense by some DeltaChat folks hides those criticisms.

I don’t recommend Signal because it’s perfect, I recommend Signal because it’s better than the alternatives. But there’s still a lot of room for improvement.

  • Copy link
  • Flag this comment
  • Block
Wayward Sun (yak shaver extraordinaire)
Wayward Sun (yak shaver extraordinaire)
@waywardsun@tech.lgbt replied  ·  activity timestamp 2 weeks ago

@rysiek @protonprivacy @signalapp I accept your point about the unnecessarily click-baity headline, but aren't you doing the same with your intro message? Implying that Proton (which has gotten more than its share of shit on fedi) is up to some underhanded shenanigans? Only to conclude at the end of your chain that this is actually a reasonable article?

Just saying; I guess we all live in an attention economy, for bad and for worse.

  • Copy link
  • Flag this comment
  • Block
RootWyrm 🇺🇦:progress:
RootWyrm 🇺🇦:progress:
@rootwyrm@weird.autos replied  ·  activity timestamp 2 weeks ago

@rysiek and yet people will continue to insist that Proton, whose CEO very actively supports literal Nazis and the surveillance state, is one of the good guys. You know. Because the CEO's personal beliefs have zero influence on any company ever.

  • Copy link
  • Flag this comment
  • Block
Michał "rysiek" Woźniak · 🇺🇦
Michał "rysiek" Woźniak · 🇺🇦
@rysiek@mstdn.social replied  ·  activity timestamp 2 weeks ago

2. "Signal is therefore vastly more private than any of its mainstream competitors, and with easy contact discovery and a wealth of advanced features, you might realistically convince your friends and family to actually use it."

2/🧵

  • Copy link
  • Flag this comment
  • Block
Michał "rysiek" Woźniak · 🇺🇦
Michał "rysiek" Woźniak · 🇺🇦
@rysiek@mstdn.social replied  ·  activity timestamp 2 weeks ago

3. "However, being hosted on AWS servers remains a concern in light of Signal’s reliance on SGX. There are a number of open-source encrypted messaging apps like Threema that try to address this and other perceived issues with Signal — such as its reliance on a centralized server and the need to supply a real phone number— some of which show great promise."

⚠️ Warning, this one is not true – Signal does not actually rely on SGX for its privacy; see: https://hachyderm.io/@dalias/115718139556844218

3/🧵

  • Copy link
  • Flag this comment
  • Block
meejah
meejah
@meejah@mastodon.social replied  ·  activity timestamp 2 weeks ago

@rysiek also "perceived" is doing a lot of work there :(

  • Copy link
  • Flag this comment
  • Block
Orca 🌻 | 🎀 | 🪁 | 🏴🏳️‍⚧️
Orca 🌻 | 🎀 | 🪁 | 🏴🏳️‍⚧️
@Orca@nya.one replied  ·  activity timestamp 2 weeks ago
@rysiek@mstdn.social
It's funny that with all those encrypted msg app they have to pick Threema as an example. I haven't forgot that Threema tried to downplay the encryption vulns a team from ETH Zurich discovered last time. 😅
https://www.securityweek.com/threema-under-fire-after-downplaying-security-research/
  • Copy link
  • Flag this comment
  • Block
Cassandrich
Cassandrich
@dalias@hachyderm.io replied  ·  activity timestamp 2 weeks ago

@rysiek "Reliance on SGX" is a common lie by bad faith parties trying to sell you scam/nazi "secure messenger" products. Signal does not "rely on SGX" for any of its actual promised privacy properties.

  • Copy link
  • Flag this comment
  • Block
S1m
S1m
@S1m@infosec.exchange replied  ·  activity timestamp 2 weeks ago

@dalias @rysiek Signal does rely on SGX, but it seems they are moving away from it.

I've written a blog post on the subject: https://s1m.fr/signal-pin/

About Signal PIN

⁂
More from
S1m
  • Copy link
  • Flag this comment
  • Block
Cassandrich
Cassandrich
@dalias@hachyderm.io replied  ·  activity timestamp 2 weeks ago

@S1m @rysiek No, the *use* it to provide some resilience in areas they cannot provide promises on that are unrelated to the privacy of your message contents.

They do not *rely on* it.

  • Copy link
  • Flag this comment
  • Block
Michał "rysiek" Woźniak · 🇺🇦
Michał "rysiek" Woźniak · 🇺🇦
@rysiek@mstdn.social replied  ·  activity timestamp 2 weeks ago

@dalias oh, thank you for catching that!

  • Copy link
  • Flag this comment
  • Block
Michał "rysiek" Woźniak · 🇺🇦
Michał "rysiek" Woźniak · 🇺🇦
@rysiek@mstdn.social replied  ·  activity timestamp 2 weeks ago

4. "But none of these have undergone the same level of rigorous external scrutiny as Signal, and all of them have tiny user bases by comparison to Signal, which limits their practical usefulness."

4/🧵

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.1-alpha.40 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct