> This is basically an indirect validation that most non listed messaging apps supposedly offering e2e encryption such as Whatsapp or Signal have backdoors with access from any government asking for access.
Not really. At least, I'm not convinced. Signal for instance does not have public channels like Matrix has, maybe that's the big difference. Signal's code can also be audited if in doubt (well, actually, Signal could always provide altered binaries on the App Store and Google Play Store, you'd have to build it yourself to be sure - though they do have reproducible builds for Android [1]).
How many people are:
- auditing signal source code
- recompiling the signal client to make sure they haven't tampered binaries.
I remember a blog post from signal showing how to build a compilation environment to validate the source but it was itself relying on docker images that you should first rebuild yourself to make sure the compiler and any other dependencies are the same as the upstream ones.
There was this statement that what's happening more or less proves that Signal & co has backdoors.
That's a guess but the good thing is that we can check.
It takes one person to do it. Not everybody has to do it.
If I remember correctly, binaries sent to the Play Store are signed by the developer so Google can't really temper with the binary themselves, or they would need to modify Android so it ignores the problem. But at this point, this means Android itself is backdoored.
(Which I don't exclude, btw - we need to trust a whole host of binaries for the phone drivers, and the hardware itself. At this point the issue is deeper than just signal though)
I believe Google now can do the app signing. They seem to encourage developers to upload keys [0]. The stated reason is to generate dynamic packages based on device details.
I don't remember the details but I believe it is their intention to eventually remove the ability for developers to sign their own packages.
Also, if that were true, there wouldn't be a reason to ban Element or these other apps in the first place.
Reproducible builds, combined with Android's developer-signed binaries, means that you don't _need_ to be super-vigilant to detect backdoors. You can investigate binaries after the fact (especially since virtually every version of popular apps is archived on third-party apk sites), and see that the signed build is not reproducible and at that point you can very easily dig into the binary to see which changes were made.
audited for what? what is this signal fanboyism online when there are competing products doing the same thing? if whatsapp is using signal protocol then by effect isn't it as secure as signal? if whatsapp is introducing attack vectors, then they are not as secure as signal.
But all that is a moot point. Indian government wants a representative in india for all the apps which they can throw in the jail or fine or arrest or beat up if their app is used to disseminate information the ruling party finds unpalatable. There is no terrorism threat. If whatsapp is e2ee, why aren't criminals using it? one would argue that it is being monitored and anyone doing any terrorist activity gets auto reported so where is e2ee in this? what happened to that?
the government wants element/threema/telegram/whatsapp/signal to have a rep who will give them backdoor access and dance to their tune or they will cut off their money supply viz a viz, ban from the huge indian market. Telegram and whatsapp have bowed down to the supreme clown so they are after the rest of the apps now.
reproducibility is nothing if the government can't push down on someone's neck. They want a totalitarian state where any dissent is seen as a criminal offense and people are today in jails for doing that.
public channels is nonsense argument. the boogeyman terrorists wont use public channels will they?
second thing, there is no requirement of using a mobile number with matrix. That is an amazing tool with the indian government. They just need the account holders' mobile which whatsapp and telegram are happy to share to save their asses and it takes a matter of seconds to find the person. They then employ the "xkcd $5 wrench attack" and the game is over.
These apps don't mandate the use of a mobile number so that is what they are after.
> what is this signal fanboyism online when there are competing products doing the same thing?
You are completely misreading me. I actually prefer Element/Matrix than Signal (and I use both). But that does not matter one bit, so I hadn't mentioned it so far.
I'm a fanboy of nothing, that's not how I work. Take it easy.
> if whatsapp is using signal protocol then by effect isn't it as secure as signal?
WhatsApp is closed source. We only have Facebook's words for trusting it. Which is a bit weak if ask me.
i am currently being blocked from accessing element.io because this ban is directly affecting me. That is why i am able to speak on it.
my matrix access has not stopped but i guess it probably will in the next few days. There are thousands of matrix servers so being connected isn't an issue.
The issue is specifically making the government understand that e2ee is necessary for the very reason they do not want it in the first place.
terrorism is never an issue. the target, like china is on dissent and these are just propaganda
It is not banned since years where I live and you can say whatever you want to anyone strange you are behaving like every one in entire country is facing same issues . You should ask someone to visit there and feel the terror. Who can be killed anytime. First learn to stay with others.
> Few years who when India unilaterally changed the status of Kashmir
You must not know how laws work. Kashmir agreed to join India in 1948. It was given a special status, enshrined in Article 370 of the Constitution of India.
Now, that "special status" has always bothered a lot of Indians; what's so special about Kashmir? Why not any of the other 537 states that formed India in 1947?
There were certain conditions on which Article 370 could be removed. Those conditions were met in 2019 and the Central Government took the decision to remove Article 370 to much rejoicing in areas like Ladakh and Jammu. This was challenged in the Indian Supreme Court (the final arbiter of things Constitutional) and found to be valid.
What you are saying seems to be factual true, but for context one should probably add, that the only other option would have been Pakistan. Whose troops were already inside Kashmir.
Independence, which is what most Kashmiris likely would have preferred, was not on the table offered to them, by any of the bigger empires around them. And the Kashmir independence movement in its whole, seems to be considered terrorism by india since day one.
There were many other independent to semi independent nations in India then who agreed to join India due to various forms of pressure. E.g. south Kerala Travancore was a princely state where the king gave up the throne and joined India, Bhutan was a princely state and became an independent kingdom. What makes Kashmir special. It could've stayed independent and gotten destroyed I guess. Who knows, speculative history.
Depends on your definition of destroyed I guess, point was various events and conditions led to nations joining India and Kashmir shouldn't have special status because of whatever conditions at the time. About independence etc, I'm not diving into fantasy territory lol.
This was a very controversial and shady decision.
While legally the conditions were met, according to the Supreme Court, I understood it was only possible because there was no elected government in Kashmir at that moment, and it has been put under direct supervision of the central government. But correct me if I misremembered or misinterpreted of course.
Legally it was defensible. That's what matters. Was it controversial? Sure.
But India has several "union territories". Kashmir is not unique.
On the other hand, citizens of Jammu and Ladakh were overjoyed, so there lots of people who supported it.
Now Kashmir is getting tons of investment. They'll be spending nearly a billion dollars on building metros in Srinagar. Such progress would not have been possible under the old regime.
> People have been arrested for posting dissent, for having VPN apps on their phones.
This is only going to get worse, and spread to other countries.
We need a real, reliable, decentralized solution, but we also need a solution that allows plausible deniability.
So if some cop looks at a phone, they can't see anything that would arouse suspicion.
A custom rom masquerading as an official Android release, with some kind of secret set of actions to launch an app, and a way to instantly hide all traces of it like a boss key.
Did you know TikTok was forced to form a company in America so it could comply with American rules?
And BTW: the reason America does not care as much about these apps is because they have deeper hooks into phones and can get the data without worrying about encryption. They get their hands on the messages before they're even encrypted.
I know, magic, right?
Signal is e2ee. The point of e2ee is that you can not trust the backend code (except for clear data it actually manipulates - which is still an issue indeed - Message contents are encrypted though)
This is the case for any e2ee solutions. For instance my company develops CryptPad [1], which is a full open source office suite with e2ee. The server admins can't access your content and you don't need to trust the backend, which just passes messages and store encrypted messages. This is the whole point. e2ee has drawbacks: it's very difficult, if not impossible, to provide indexed search for encrypted content on the server, the client needs to do it which might be impractical.
That still does not change anything though. The backend is unverifiable, that's a fact. Why talk about E2EE, I wasn't really talking about that.
Signal for a whole year was running a different server code and nobody even could tell that they added some cryptocoin stuff. On top of that, metadata, server connection and anything other than the message content is all at the mercy of the server owner.
Of course it does. Just like PGP works fine over untrusted channels - like if I posted a gnupg ascii-armored message here.
e2ee makes all the difference - if two trusted and mutually authenticated clients are communicating with proper e2ee - the best an attacker can do is traffic analysis and denial of service...?
"the best an attacker can do is traffic analysis and denial of service...? "
That's already a lot. If the evil secret police knows when and with whom you texted, then they don't even need to know the text of the messages, to link you to the opposition. And then just extract you and then the password with force to get the rest.
It certainly is a lot. It's enough for a drone strike.
But almost by definition, if you have a back-end, there will be meta-data.
There's been a few attempts at getting around it, with "one-to-many" (eg opaque PGP posts to Usenet groups), Mixmasters (remailers) or onion routing. None are AFAIK truly practical with a state-level adversary.
e2ee is a good start, that doesn't mean you don't need to analyse the risks.
That's the interesting thing about being E2EE. You don't need to verify the backend. This is a private key and ETH wallet with a separator that is obvious on decryption: YSBwcml2YXRlIGtleSBhbmQgRVRIIHdhbGxldCB3aXRoIGEgc2VwYXJhdG9yIHRoYXQgaXMgb2J2aW91cyBvbiBkZWNyeXB0aW9uCg==
For a while I did run a fork of the Signal Server. Beyond the sheer difficulty getting it to run without the server being updated for a year during the mobilecoin launch, it was extremely disconcerting to see PHONE NUMBERS spread throughout the log messages. It doesn't take much imagination to see how you can build a network of who you are talking to (etc.) from this log information.
While it is quite possible that they had some non-default log configuration (and hopefully the metadata leaking in the logs is fixed), if you can't run the server you can't check what data is being leaked.
Take the E2EE claim with a grain of salt if it is difficult to run a server.
> ...it was extremely disconcerting to see PHONE NUMBERS spread throughout the log messages. It doesn't take much imagination to see how you can build a network of who you are talking to (etc.) from this log information.
The intent of Signal is to provide confidentiality of message content, not any sort of anonymity. This covers like 90+% of user's threat models and it's focusing on one problem makes it very effective at solving that problem. If one also needs anonymity then communication should happen over something like Tor or I2P.
If, as we are saying, the client code is public and one can theoretically analyze the code and prove that messages that go out are indeed only going out encrypted, then that must change something here? At that point at least, you can only be suspicious of the cryptography itself, but I believe that is public too.
Not really. At least, I'm not convinced. Signal for instance does not have public channels like Matrix has, maybe that's the big difference. Signal's code can also be audited if in doubt (well, actually, Signal could always provide altered binaries on the App Store and Google Play Store, you'd have to build it yourself to be sure - though they do have reproducible builds for Android [1]).
[1] https://signal.org/blog/reproducible-android/