Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents.

If you learn a contact phone number then you can buy their location history. Requiring phone numbers and requiring you share them with everyone you contact is brain dead.

This alone is bad enough to abandon Signal but then consider they have centralized control of client binaries, and metadata protection anchored on centralized SGX they can trivially access. This negligent design makes them vulnerable to coercion or even court orders if any judge realizes they actually -can- decrypt messages and dump metadata.

Matrix supports Signal crypto but in a federated network with no PII requirements like Signal. Also no lock-in or central control of apps.



>I refuse to use or recommend Signal due to blatantly bad design choices that put people that need privacy most at risk like security researchers, journalists, abortion seekers, or dissidents.

I understand your concerns, and if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either.

But, like the vast majority of us, I am not any of those things. As such, for my (and most others) use case, Signal is great.

For those at risk from highly motivated and/or state-level actors, Signal isn't nearly enough. Nor, unless you build and run your own servers and clients (and never screw up your OpSec), is Matrix.

Signal isn't perfect. However, for most people, it's good enough.

Don't make perfect the enemy of the good. Because perfect doesn't exist.


Those of us that do not need high privacy today might need it tomorrow, or maybe someone we frequently communicate with.

We also have a responsibility to favor tools and practices that make those that really need privacy not stand out.

Element or other Matrix clients are easy to use and lack the serious flaws I outlined for Signal.


I'd point out that for most people (I suppose that could change, and I wouldn't be upset if such changes resulted in better privacy), messaging is often phone-based and includes folks who use secure methods like Signal and Matrix as well as those who use iMessage and OEM SMS clients.

When it comes to that sort of messaging ("I'm running a few minutes late and will meet you inside the restaurant," or similar) I don't (and won't) separate those out. I just use Signal for all such messages.

Which makes for inconvenience when (especially iPhone users) install Signal and still use iMessage.

I'd add that if I have something to discuss that I don't want recorded (don't forget that it's not just your device that puts you at risk, anyone who's received such messages do so as well), I'll use encrypted voice calls (with the assumption -- valid or not -- that the other participant(s) aren't recording that conversation) with Signal or Matrix.

In both my personal and professional life, I've always made sure to only put in writing that which I wouldn't care if it was shared with the world.

Which is no different than it's ever been. I'm not sure why anyone thinks this is a new thing or that somehow "technology" obviates the need for good OpSec. It never did and still doesn't.


Matrix bridges support iMessage and SMS and even Signal so you do not need to fragment your communications to multiple apps if you do not want to.


> if I was a security researcher, journalist, abortion seeker or dissident, I wouldn't use Signal either.

I mean that's really bad, right? Supposedly Signal is the go-to alternative to doing things the hard way (e.g. GPG over email), but apparently it's just not good enough for those with the highest security needs. Given that the alternative is that these people go back to using extremely brittle software, shouldn't someone do something about that?

The implication of course is that Signal should do something about that, because they already have the user base and are in a position to adopt user identifiers that are not based on phone numbers.


>I mean that's really bad, right? Supposedly Signal is the go-to alternative to doing things the hard way (e.g. GPG over email), but apparently it's just not good enough for those with the highest security needs.

Is it? If that's what you got from my comment, then I certainly didn't communicate my thoughts clearly.

Signal is great for what it is. And that's as a centralized encrypted messaging platform that's easy to use.

Have some tradeoffs been made (e.g., not strictly p2p, some data is stored, in encrypted form, on their servers, etc.) in making Signal easy to use? Yes.

For the majority of folks, Signal is more than good enough.

AFAICT, Signal has been quite successful in that space.

However, if you're the target of motivated folks and/or state-level actors, any product that relies on third-party interaction of any kind is suspect. For that use case, you need more.

Why is it Signal's responsibility to do that? Should they be held responsible for the (lack of) OpSec[0] of others, whether they're Signal users or not?

I mean, I get it. Why should you (or anyone else) have to do any work (other than download this handy app) to protect yourself, especially if your communications are of interest to motivated hostile adversaries?

The whole "telephone number as identifier" bit, and the network discovery it provides, is the primary reason Signal has had the level of adoption it has. And is something of a red herring in this case, IMHO[1].

And Signal is a centralized service. All messages (stored until they're delivered) and metadata (the stuff that Signal stores for each user) are stored on Signal's servers.

Storing anything on systems accessible to the Internet is risky. Plain text is much worse than encrypted blobs, but there's definitely still a non-zero risk.

That alone makes it unsuitable for those whose life may depend on their ability to maintain secure communications.

There are other tools that folks can use (a bunch of folks have mentioned Matrix, which is great too), but which should be either fully p2p or privately hosted/managed on hardware under one's physical control, again assuming that you might be harassed, imprisoned or killed for your communications.

But for most of us, myself included, Signal is more than good enough.

[0] https://en.wikipedia.org/wiki/Operations_security

[1] Since Signal is a centralized service, they need a mechanism(s) to identify their users. In some respects, using a phone number for that purpose is sub-optimal, but it doesn't really impact the security of messages sent through the service, nor does it attach (other than an optional photo and other information voluntarily provided by the user) any information that could be used to personally identify the user in question. A such, even if the encrypted blobs were to be accessed and decrypted, they wouldn't be all that useful anyway, except as a self-selected list (those who have registered with Signal) of phone numbers. I'm not sure how much of an issue that is for most folks, given that dozens, perhaps hundreds of other organizations (almost all of whom don't give a rat's ass about your security) have your phone number associated with your name, your address, your shopping/browsing/travel habits and a raft of other PII.


> The whole "telephone number as identifier" bit, and the network discovery it provides, is the primary reason Signal has had the level of adoption it has.

I agree. Signal absolutely should not abandon this. Rather, it should add other user identifiers that can be used alongside phone numbers.

> Storing anything on systems accessible to the Internet is risky. Plain text is much worse than encrypted blobs, but there's definitely still a non-zero risk. That alone makes it unsuitable for those whose life may depend on their ability to maintain secure communications.

I strongly disagree. A lot of critical work has been done with email + PGP, and that's about as leaky (in terms of metadata) as it gets. Obviously there are use cases where you do worry about this, but "storing data on the Internet" is not as such always a problem for those who need the highest security guarantees. Signal adopting alternative user identifiers would open it to use in some of these extreme cases, but would not (of course) make it usable in every situation - and that's okay.


>I strongly disagree. A lot of critical work has been done with email + PGP, and that's about as leaky (in terms of metadata) as it gets. Obviously there are use cases where you do worry about this, but "storing data on the Internet" is not as such always a problem for those who need the highest security guarantees. Signal adopting alternative user identifiers would open it to use in some of these extreme cases, but would not (of course) make it usable in every situation - and that's okay.

I'm old school. If it's connected to the Internet, eventually it will be compromised.

Yes, strong encryption can (and does) make data compromise immensely more difficult in terms of time and resources (much longer than our star will exist -- about five billion years -- which isn't really that big a deal, since the Earth will be uninhabitable in a billion years or so), but once that centralized server(s) is compromised, all bets are off.

I don't disagree that strong encryption is a valuable tool for maintaining data privacy and integrity, but it absolutely does not reduce the risk to zero.


With Matrix you can use F-Droid build of the client. And you don't really need to trust the server too much, right? Maybe it's not enough for Snowden, but it's better.

I'm not saying "don't use Signal", in fact I still recommend it to non technical people, since it's just much simpler. But pointing at the flaws is a necessary requirement for them to be fixed


>With Matrix you can use F-Droid build of the client. And you don't really need to trust the server too much, right? Maybe it's not enough for Snowden, but it's better.

And why should I trust F-Droid's build of Matrix over Signal's build of Signal?

Please understand, I agree with your point. Mine was orthogonal: If you are under threat from motivated and/or state-level actors, using someone else's servers (or clients, for that matter) is a bad idea.

And that includes Matrix. I run my own Matrix server and the users of that server can interact (especially via voice/video) without any fear of being intercepted -- even by me.

What's more, I can't decrypt the conversations folks have in Matrix "rooms" that don't include me without a long process of brute-forcing.

No one is coming to my house to confiscate my server. That scenario is much more likely with a public/commercial service hosted at a data center/cloud provider.

So yes, Matrix is likely more secure than Signal if, and only if you build and install your servers and clients from source with a compiler/linker you built yourself using a trusted tool chain on hardware whose components you've personally confirmed to be free of compromise[0].

[0] https://users.ece.cmu.edu/~ganger/712.fall02/papers/p761-tho...


I like Matrix, but I admit its E2 EE rooms seem to leak more metadata (users in th room, reactionss, maybe replies, display names, avatars) than Signal.


They leak metadata to the operators of the server. So does Signal, albeit anchored to SGX nodes they pretend they cannot access. Signal also has phone numbers making even worse.

With matrix at least you can pick a server operator you trust to provide your metadata to, or host a server yourself.


What a terrible argument. You might as well just switch to Telegram


>What a terrible argument. You might as well just switch to Telegram

Should I? What specific features of Telegram make it superior to Signal?


How does signal allow you to learn someone's phone number from message history? As far as I understand the only thing one can learn by inspecting signal's protocol is that:

1. generally, a certain phone number uses signal

(1) happens once, upon registration of your phone number. You don't see history of which phone numbers are communicating, do you?

In other words, you don't need Signal to buy someone's location history. You just need their phone number and Signal doesn't particularly provide that to you.

Per my understanding, Signal provides subpoena/nation-state resistant level security and is in fact used by many people with high security needs.


Sadly the protections you mention are only true if we ignore the last decade of security research and dragnet surveillance activity. Metadata protection in Signal has major asterisks they do not like to talk about which could be activated covertly by warrant, threats, or money.

1. Google, Apple, or Signal could, compile a malicious Signal binary that generates weak keys and deliver it to specific users, or all users, via app stores.

2. Signal sysadmins or third party datacenter techs could use any of a pile of SGX exploits to dump all their centralized metadata in plain text.

3. Signal aggregates all IP metadata to one place making it easy for their cloud providers and ISPs to work out who is talking to who.

4. Carriers see SMS activations and know who uses Signal. They also know all of the cellular data IPs. An entity that buys this along with data from other ISPs would quickly learn the identities of most conversation participants and their current locations. Enrich that with data widely sold from drivers license office and you also get race, home address, etc, etc.

Centralized PII requiring services that claim to be promoting security and privacy should be met with extreme scrutiny.


Okay...

(1) is abstractly possible for any software and always has been. Signal cannot directly send my phone a bespoke binary... I got it through the app store. If that was allowed it would be Apple or Googles breach of the model, not Signal.

(2) there were SGX vulnerabilities, yes, but they've been patched and Signal is no longer vulnerable (in the one instance where they were), no?

(3) citation please, these are IP logs for conversations?

(4) this is not Signal's problem to solve. If you buy into what Signal offers, you're saying it's okay that my carrier knows that I registered with Signal because that's all they know. Being able to inspect IP headers for traffic on the internet is possible regardless of the software you're using. If you don't trust the internet with your communications then you need to take them off the internet... I don't know what else to say.

Further, typically companies can't be compelled to do something like (1) because it represents an undue burden on operation of their business. This is why Apple refused to give the FBI a bespoke build of iOS that bypassed the pin code. Not to mention the loss of business when people find out that a breach of trust had happened. Also I thought Signal had reproducible builds in every instance possible.

Idk, it sounds like you really shouldn't use any software you didn't write yourself and hardware you didn't build yourself and network where you don't trust every single node if your threat model involves IP logs and hardware tampering and targeted malicious software... that is hardly practical by any stretch of the imagination.


I agree that Signal does have several questionable design decisions, but that's not one of them. You can get a sim, register with it, and take it back out. There, no location. Or even better, you can simply get a voip number.

Bottom-line, despite Signal's issues it is still the #1 IM app that I recommend to "normal people" seeking to have private conversations. No, it's not perfect, yes, it's a massive improvement over facebook/instagram/whatsapp/telegram/etc.


You can not buy a sim without KYC in almost all countries. Also most users will not realize these consequences and will just assume the defaults on Signal protect them with their every day phone number and SIM.

Also facebook/instagram/whatsapp/telegram/etc are not trying to advertise themselves for the high risk use cases Signal is actively promoted for. I obviously do not recommend anyone use those either, regardless.

Matrix is all I suggest for most people.


> You can not buy a sim without KYC in almost all countries.

I'd be curious to see stats on this. At least in the US, it is very easy to buy a SIM and sign up for a pre-paid plan with zero KYC.


The US is actually the only exception I am aware of world wide which gives us a distorted view of this problem.


Unless things have changed in the last few years, there are apparently countries in Europe that don't require registration: https://www.reddit.com/r/europe/comments/9ziqfi/european_cou...

And that's a quite high regulation part of the world, I'd be surprised if South American or African countries were stricter.


Requiring SIM registration is nearly universal outside of Europe and NA.

https://www.comparitech.com/blog/vpn-privacy/sim-card-regist...


Great link, thanks. Interesting that my intuition was off, although I suppose it makes sense that regulations are loosest in countries with the strongest speech and privacy protections. Although I'm skeptical of how well the rules on paper are enforced in some of the countries listed as requiring registration. I have seen SIMs for sale at roadside stalls in a couple countries listed as requiring registration, and I don't think they were checking ID...

But it looks like the official answer is 36:

> Those without any SIM-card registration requirements are Bosnia and Herzegovina, Canada, Cabo Verde, Comoros, Croatia, Cyprus, Czech Republic, Denmark, Estonia, Finland, Iceland, Ireland, Israel, Kiribati, Latvia, Liechtenstein, Lithuania, Maldives, Malta, Marshall Islands, Micronesia, Moldova, Namibia, the Netherlands, New Zealand, Nicaragua, the Philippines, Portugal, Romania, Serbia, Slovenia, Sweden, the United Kingdom, the United States, and Vanuatu.


In some places, the sale itself doesn't require anything, but you need to go to the provider and show an ID to activate.


You need a government issued ID to get mobile service many places. You can’t just get a SIM in the same way you get a burner email address.


> still the #1 IM app that I recommend to "normal people"

What app do you recommend to HN types? (I'm getting ready to switch messaging platforms. All my friends use iMessage and I'm so tired of typing on my phone at them. They can be lured over to something else with the promise of encryption.)


Try Element.

Effectively the same crypto as Signal but you can be anonymous as needed. Also decentralized with many app options.


And if Element is not the desired application to use matrix, then there are plenty of others, and available across many device and OS platforms: https://matrix.org/clients/

...Of course, Element remains the oldest and likely still most feature-full app.


I haven't really looked into Matrix. I appreciate the nudge!


Beyond any research that you undertakevaround matrix, i would add: while its not new (having existed for several years now), its popularity has increased quite a bit in the last year or 2. So in my opinion its still early days. Althougj its evolved quite nicely. So some rough edges might be encountered - more so on the client/apps side, less on protocol side - but as the superfan that i am, i really feel it represents the future of distributed messaging, which one use-case is chat. Good luck!


Aren’t the apps reproducible? Meaning, if the open source part does not match the binaries the it could be a canary for compromise.

Mind you, the last time I looked there are not alternate implementations of the signal protocol and even the usage of libsignald was frustrating due to continuous backwards compatibility breakage. I would love for a proper libpurple implementation.


> abortion seekers

Uhhh, not sure what koolaid you've swallowed, but including them in that list is almost laughable.



I agree none of this is laughable.

Irrelevant of your position, please read the entire article that you referenced for facts (pre-RvW overturn, pregnancy at 23~28 (?) weeks, took Pregnot, buried in back yard, Nebraska law was at that time 20 weeks).

The Vice article seems to have quite a lot more facts and references. https://www.vice.com/en/article/n7zevd/this-is-the-data-face...


I did read it.

The point is that the mother is being charged with aiding her daughter to have an abortion due to evidence collected from chats they thought were secure, but which were still susceptible to a warrant.

Now, there are other charges. And the time the abortion happened it occurred while the 20 week ban wasn't being enforced, because the state knew it wouldn't hold up under Roe (and is only illegal and chargeable now, with the court having overturned Roe). So, yes, it's super interesting.

But the point is that police are charging someone for aiding an abortion due to texts the sender thought were secure. That's the entire relevancy. Anything else about this particular incident isn't germane.


I wonder how the people putting "abortion seekers" on such lists would feel if I included "self-defense rights advocates" for people 3d printing guns or smuggling them in from abroad on similar lists.


I'd wonder if it's for self defense why you didn't buy your firearm legally, since, you know, it's legal to do so. I haven't done a deep dive, but as far as I can tell in most cases it's legal to 3d print too, though admittedly that's something that there are some semi-serious efforts to change.

In other words I'd suspect the classification of "self defense advocate" to be a self serving branding effort since there are legal ways to accomplish the same, but I wouldn't doubt the need of this person for a secure messaging platform.


>I'd wonder if it's for self defense why you didn't buy your firearm legally, since, you know, it's legal to do so.

Outside of the United States, that's usually not the case. Even if countries do allow private gun ownership, the restrictions on how to obtain them (and what they can legally be used for, what kinds are available, etc.) are exceptionally onerous.

And even within the United States, there are individual states that have attempted to severely curtail private firearm ownership. Were it not for certain Supreme Court decisions, handgun ownership would be outright illegal in the District of Columbia and likely in several other states.


> Even if countries do allow private gun ownership, the restrictions on how to obtain them (and what they can legally be used for, what kinds are available, etc.) are exceptionally onerous

Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally onerous". And i think most non-Americans would agree that adding some friction to a fringe case (owning a personal firearm for protection or fun is not something most people do, even in the US) is worth it if it nearly eliminates blatant misuses of firearms - either making suicides easier and more terminal, enabling easier revenge murders, or making your average school/public place shooting easier.

What would you consider a just middle ground between "onerous requirements" and "everyone can buy any weapon without any requirements but paying for it"?


>Citation needed. I, and probably the majority of the citizens of those countries do not consider the standard test/psych eval/background check/random checks in the future to make sure you're following the rules to be "exceptionally onerous".

Just because you've accepted the boot on your neck doesn't make it not a boot. When (not if) a currently free and democratic Western nation decides to be not so democratic anymore (whether due to invasion, international pressure from economic partners like Russia and China, or just that the assholes in power decided to seize even more power) the citizens (or rather subjects) of those countries will have no means of fighting back. You can already see it with several countries' response to covid.

>What would you consider a just middle ground between "onerous requirements" and "everyone can buy any weapon without any requirements but paying for it"?

My feelings on gun control can be summed up as "I want mail order rocket launchers delivered to my doorstep." The state should fear its people, not the other way around, and the best way to ensure that is to give the people the means to put a bullet (or several) into any would-be tyrants.

And, regardless of what "the majority of citizens" feel about bootlicking and trampling on their own natural rights, advances in home manufacturing are quickly making any efforts to do so a pipedream.


> want mail order rocket launchers delivered to my doorstep." The state should fear its people, not the other way around, and the best way to ensure that is to give the people the means to put a bullet (or several) into any would-be tyrants.

You should look into France and it's protest culture. When the people are unhappy with the government's action, they go out on the street and protest. Without any weapons, this being a civilized country where violence is only a last resort. And you know what? Governments listen and adapt, even without the fear of direct death.

So i find your premise wrong to begin with. There is no natural right to murder, so i disagree that owning a weapon is a natural right.

And i find it extremely funny that the country that is so proud in their "everyone should be armed so the government is afraid of the people" culture has such shitty dysfunctional governments that act against the people's interests extremely often. Where are the armed uprisings against the Patriot act, civil asset forfeiture, racist abuse, abortion restrictions, failures to combat climate change or wasting money in useless wars abroad? No? When then?


>My feelings on gun control can be summed up as "I want mail order rocket launchers delivered to my doorstep."

I don't know. I'm a believer in extreme gun rights as well, but giving people the power to have rocket launching systems like MANPADS just seems a bit, dangerous.


You already have the legal ability to own a rocket launcher - it's not any different from any other "destructive device". The main barrier to ownership is finding someone willing to sell you one, and the price they would likely ask for it. There are rich collectors in US who own tanks (with active turret), artillery etc - mostly older stuff, but still plenty destructive.


A quick google suggests that if you want your tank to have working guns and/or turret you need a Federal Destructive Device Permit, which includes a background check and ATF approval.


Destructive devices are NFA items, true. If you want to own a DD, you need to pay the $200 federal transfer tax, which is done by submitting a form to the ATF and getting a tax stamp from them.

It's not a "permit", though. And there are no special limits on who can own one - if you can legally own a gun, you can legally own a DD or any other NFA item. One doesn't even need to be a US citizen or a permanent resident for that, even people on student and work visas can do it.


This is the site that I was looking at: https://nationalfirearmsact.com/nfa-regulated-items/destruct..., which seems to spell out the background check as a requirement. It also says you need to be a resident of the US. Am I missing something?


Background check is a requirement for regular gun sales as well, except private person-to-person sales - in practice, this is the vast majority of transfers.

ATF can be more thorough with NFA items because the law doesn't have a limit on how long they can look at you, unlike those regular NICS checks which have a hard limit - but the list of things that makes one ineligible to own is the same.

As far as residency, you have to be a resident somewhere in US, but you don't need to be a permanent resident / green card. A student or a work visa is good enough, combined with proof of current residency (such as utility bill with your name and address).

This isn't quite what OP asked for, of course - you can't have one "shipped to your doorstep" - but this is also true for most regular firearms (there's a collector license that enables this for some old guns).


If it's a choice between wearing a mask at the grocery store and the idiot next door blowing up my house with their mail order rocket launcher, I'll take the mask. If that makes me a bootlicker so be it I suppose.


I have a suspicion that I already know, but why are you jumping to a non-sequitur about masks? I tend to agree with the user to whom you're responding on this particular issue, and I still wear a mask in places such as public transit, enclosed spaces, etc.

So...I guess my point is that you don't _have_ to choose between masks and gun rights. I'm unsure of why you would bring it up.


From the comment I'm replying to:

> You can already see it with several countries' response to covid.

Perhaps the commenter was going for something else, but at least where I'm at we've had two straight years of people insisting they are muzzles, an infringement on our god-given rights, and the beginning of a slippery slope to tyranny. Perhaps the commenter meant something else, but since they didn't spell out what specifically about the "response to Covid" they intended to solve with a mail-order rocket launcher of all things, I was left to interpret for myself.


Fair enough, I suppose. I immediately thought of (what I consider to be) excessive lockdowns and enforcement in countries like Australia, but I can see how you went to masks.


It certainly could be. But even then I'm not sure I consider measures attempting to control a pandemic the height of tyranny. I realize this might sound like I'm pro-lockdown, I'm not, I actually think most countries completely botched their handling with measures both insufficient to have sufficient impact on the actual spread, while limiting enough to ensure significant damage from the measures themselves.

I also take issue with the idea of gun (or rocket launcher ownership) ownership as a means of prevention. I mean look at the top countries for (citizen) gun ownership. Sure you've got the US, Serbia, Canada, Uruguay, Finland up there, not bad, But you've also got Yemen at #3 and Lebanon and #11. If that's the kind of "freedom" private gun ownership ensures, then I'm not buying.

And again I'm not even that pro gun control. I think you should be required to get a background check to get one, I think you should be required to be trained on their use and safety, and I think you should be required to take reasonable measures to protect your firearms against theft. I'd say that's it, but I suppose I'm also against mail order rocket launchers. But for the most part, having met those requirements I think you should be able to buy what you want (within reason, again let's skip the rocket launcher). But as protection against government tyranny? Doubt.


> Outside of the United States, that's usually not the case.

A good and fair point. I'd fallen into the trap of being too US centric on HN.

> Were it not for certain Supreme Court decisions, handgun ownership would be outright illegal in the District of Columbia and likely in several other states.

Sure, were it not for the Supreme Court. But as there remains plenty of ways to legally obtain guns in the US, I'm still going to doubt that you've resorted to gun smuggling for "self defense"


I would have no problem seeing that included on such lists either. I have friends who hunt and I myself enjoy shooting on a range once in a while. I also know single parents that live alone in sketchy areas that are well trained and level headed enough to trust with firearms for home self defense.

There are almost always reasonable uses of many services and tools we tend to have knee-jerk-ban reactions to as a society.


How do you figure? Several states had abortion laws that were never repealed and others have trigger laws on the books that have gone into effect or will shortly, so yes you can be prosecuted for abortion now. Hence the need for privacy.




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: