←back to thread

295 points mdhb | 1 comments | | HN request time: 0.409s | source
Show context
bsimpson ◴[] No.43560742[source]

One nice side effect of Signal's importance for governmental/military use is that it helps keep it free for civilian use. They can't mandate a backdoor for something other parts of the government rely on to be secure.

I once heard a great anecdote to that effect, and to my embarrassment I can't recall the details to repeat here.

(And yes, I understand that there are limits on what is appropriate to share with civilian hardware on a civilian network, but the truth stands that part of the reason there's not a push to breach encryption in the US like there is in the UK is because Signal is relied upon even by the government when they need a private channel on civilian hardware.)

replies(9): >>43560773 #>>43560780 #>>43560782 #>>43560939 #>>43560995 #>>43561150 #>>43561233 #>>43561254 #>>43561325 #
kelipso ◴[] No.43560782[source]

> They can't mandate a backdoor for something other parts of the government rely on to be secure.

This is a strong assumption.. A government is a collection of people. While there might not exactly be warring factions in the US government, there are certainly numerous agencies and organizations that operate under varying degrees of independence.

replies(2): >>43561272 #>>43561339 #
_the_inflator ◴[] No.43561339[source]

Even more sinister is the false hope bias. The Signal app can be used as a honeypot to plant a pseudo-secure messenger, a sophisticated device around a backdoor, or even a trojan-like capability.

The Tor network was deemed the culprit of anonymity and secure connections not long ago. We all know how it went.

replies(1): >>43562330 #
jerheinze ◴[] No.43562330[source]

> The Signal app can be used as a honeypot to plant a pseudo-secure messenger

Given its open source nature that would be exceedingly difficult.

> The Tor network was deemed the culprit of anonymity and secure connections not long ago. We all know how it went.

What are you talking about? Tor is still the uncontested king of low-latency anonymity networks.

replies(1): >>43562626 #
arccy ◴[] No.43562626[source]

is it really open source when you have to use the binary builds from signal through the app stores? it could be like the xz attack: clean source, bad binaries.

replies(1): >>43562662 #
1. jerheinze ◴[] No.43562662[source]

This has been a solved problem since 2016: https://signal.org/blog/reproducible-android/