Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Signal's non-phone-number-keeping competition keeps a plaintext database of every pair of users that has ever communicated. The reason Signal uses phone numbers is the same as it has always been: to avoid having that database at all, or features that depend on it.


What features depend on the use of a phone number? Sign up and contact discovery? I don’t understand why a plaintext database is the alternative.


Your Signal contact list is your device's contact list, keyed by phone numbers.


For clarity, this assumes you allow Signal access to the device’s contact list, which is not required.


For clarity, you allow the open source client app (which you can audit and compile yourself) to securely share your contact list with a secure enclave (which is open source so you can audit it as well).


The client-side contact list is one of two lists: (a) device’s contact list if Signal is given access — or (b) list of numbers that have manually been add to the App and Signal is not given access to device’s contact list because user declined providing it access.

Also, might be wrong, but appears Signal’s secure enclave, which is based on Intel’s SGX technology, is known to be vulnerable to side-channel attacks and Intel’s SGX code & hardware is not open source:

https://medium.com/@maniacbolts/signal-increases-their-relia...


Yep, you have to trust the secure enclave for this to work!


No, you have to trust anyone with access to the server; secure enclave provides no security given it appears it is vulnerable to side channel attacks; see comment you just replied to for related link.

Basically all it does is given Signal plausible deniability for public search warrants:

https://signal.org/bigbrother/

It would do nothing to stop national security letters. Basically, you should assume the functionality provided by the secure enclave is only in name; given the NSA ATT national security letters enabled both physical access and system modifications, see no reason to believe others would not be required to do so as well:

https://en.m.wikipedia.org/wiki/Room_641A

Again, average person does not have a threat model that makes this relevant, but to say Signal does not have access to the SGX data is purely based on trust, not mathematical proofs.


At that point, your phone is vulnerable. As is your computer, and your connected fridge.

If your threat model does not allow it, use manual e2ee with pigeons. Otherwise, well secure enclave will get better with time, which will make Signal better too.


> secure enclave will get better with time

Intel already dropped SGX from their new line up of CPUs (11th gen +).

https://news.ycombinator.com/item?id=29932630


Does that mean that the secure enclave technology will die? Feels like:

1. SGX is just an implementation, could be replaced by something else. 2. SGX still works on CPUs that have it.


Signal should make threats clear to users, just as they should have notified all users that multiple 3rd parties downloaded all the phone numbers in Signal. Offering federated servers would also allow users to secure their own servers.


Most of Signal's "competitors" don't just keep a plaintext database of every pair of users that have communicated, they keep a plaintext database of every conversation. (GChat is at least good about making expiring conversations visible and easy.)

There's not necessarily "alternatives" most of the competitors offer a much richer feature set and Signal has stripped away those features down to what they see as the bare minimum.


It would be more accurate to say that Signal has stripped its features down to those it can implement safely without keeping serverside databases of communications metadata. It's surprisingly hard to do that, and so Signal has noticeably fewer features than things like Matrix, which suffered calamitous security vulnerabilities as a result.


Didn't moxie explicitly say Signal needed to now keep your contacts list in their servers via PINs/SVR? It is encrypted of course, and they feel they had to do that to enable identifiers not based on phone numbers. Some people disagreed on that last point.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: