← Back to context

Comment by purpleidea

1 day ago

Signal needs to release all the infra automation code behind their backend. How they setup and manage it all should not be secret. It also makes it easy to rebuild if for some reason they are compromised. They've ghosted multiple people about this question. There's no reason a 501(c)(3) shouldn't release it.

Signal is there for power and control, not for its users, otherwise they would welcome the usage of third party clients, and generally, encourage decentralisation measures like self hosting, federation and account portability. Yep, they have nice engineering blog posts, they are also US-incorporated, extensively centralised in AWS and subject to the cloud act, which together negates, or largely diminishes claims about being privacy conscious.

  • "Federation freezes the technology" https://signal.org/blog/the-ecosystem-is-moving/

    • That's a defeatist take that's been vastly debunked, someone linked the Matrix version and here is the XMPP one: https://gultsch.de/posts/objection/

      In short, yes, building a standard takes some effort, but that serves your users and to future-proof your solution. Moxie's post boils down to "1- I know better than my users and I don't need input to protocol-design, 2- I'm not willing to put in the effort to standardize and document, 3- I reserve the right to change the deal for whatever reason if I ever feel the need" which is not a good look

      6 replies →

    • I've attended the eponymous CCC talk and I've never seen any other talk there where the Q&A section has just immediately turned into nearly everyone almost dunking on the presented ideas. It's a rather poor take (or at least "controversial" if you will).

  • "...otherwise they would welcome third party clients..."

    Signal app can update itself at any time

    The app is constantly phoning home to Signal servers checking for updates even when it has not been launched and is not being used

    That means the client could change at any time, for any reason, unbeknownst to the user

    If the advanced user is free to write, edit and compile source code for a Signal client, software developers might call this a "third party client" because there is allegedly some "business transaction" between Signal Corporation and the user where Signal Corporation and the user are first or second parties (although, curiously, the Signal app and service are free)

    But it's arguable the more important use of the term "third party" in this context, i.e., "secure" communications, is to indicate a party that is not a first or second party to the communication, a potential eavesdropper

    Signal Corporation is a third party to the communication

    Because it forces users to use its closed source client software that can be updated at all times for any reasons when it's installed on a user's computer, there exists the potential for remote code execution and, for example, eavesdropping

    For example, a US corporation subject to US law could be legally forced to eavesdrop on a particular user. This could be done with an "update"

    • Are you a LLM? In this context, a third party client clearly refers to "a Signal app/client software that's not distributed by Signal",

      The point I was making is that this goes against Signal's terms of service, and can get your user account terminated. That's a very oppressive clause in practice, you may want to use a non-signal client for all kinds of legitimate reasons (porting to a non supported platform, to adapt for accessibility needs, for privacy, for compliance, to remove nagging and dark patterns, etc). Signal don't want that, they want to control your user experience, even if this makes it worse for their user.

  • Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?

    • Realistically nothing is ever perfect, but XMPP comes very close. You've got Signal-introduced double-ratchet encryption if forward secrecy is your jam (so it's as "E2E-secure" in practical terms) and you've got a healthy ecosystem of independent client and server implementers, and service providers to choose from.

    • XMPP. Run your own (federated) server, chat with anyone outside it, with e2e encryption.

    • Is there a messenger that allows anonymous group chats, i.e. for union organizing in a company?

      As far as I can see, you can invote people to a group chat using QR flyers, but your Signal profile is visible to everyone in a chat, so everyone knows what Tina in marketing thinks about it.

      Because nobody is going to have a burner phone with a data plan for a separate Signal identitiy.

      4 replies →

    • Depending on your needs, XMPP or Matrix are probably your best bet. Both have different clients of varying usability and quality on different platforms, so you have to pick your poison. If E2EE is important, you also need to determine how encrypted you want your messages to be (as both XMPP and Matrix carry quite a bit of identifying metadata in its unencrypted headers).

      For most people and use cases, either will probably do, but if you're a human rights activist or journalist in an oppressive country, I'd stick to Signal.

      7 replies →

    • > Does the perfect messaging tool exist (100% e2ee encrypted and decentralized and open)?

      (Note that I don't care about cryptocurrencies except for the cryptography behind it)

      There are fully anonymous cryptocurrencies using ZKP where it's not possible to tell if a transaction sent is a transfer of the cryptocurrency itself or a message. It's decentralized and it's also impossible to tell who the transaction is made for (anyone with a copy of the chain can potentially be the recipient of either the money transfer or the encrypted message).

      If people were really serious about privacy and secure messaging they'd look into this instead of constantly attacking the concept.

      But then of course there are entire armies of shills who have a vested interest in pushing a narrative explaining that services, at best, collecting metadata and, at worst, being backdoored are offering "secure messaging".

      I'm only using Telegram and I don't believe for a second it's secure and private (it's got, supposedly, "one on one" E2EE but not for groups). But at least they're not posturing as the most secure and private messenger on earth.

      1 reply →

Signal ghosts people or gets very evasive on other questions to. They've also refused to update their privacy police since they started permanently keeping sensitive user data in the cloud. They can only scream "Don't trust us" so loud.

When news leaked that federal agents and contractors had access to WhatsApp "end-to-end encrypted" messages using the "Signal Protocol", WhatsApp users sued Meta

Faced with mounting statutory damages per violation for wiretapping claims under CIPA and Pennsylvania's wiretap act, Meta forced arbitration

https://ia801900.us.archive.org/6/items/gov.uscourts.cand.46...

"48. After Meta acquired WhatsApp in 2014, WhatsApp partnered with Open Whisper Systems to integrate the Signal Protocol, which is an end-to-end encryption cryptographic protocol, into the WhatsApp platform.26 The integration of the Signal Protocol onto the WhatsApp platform was completed by April 5, 2016.27

58. Recent reporting has confirmed that WhatsApps numerous promises that no one other than intended recipients has access to users communications is false. Indeed, contrary to WhatsApps repeated assurances otherwise, Meta, WhatsApp, their employees, contractors, and/or third-parties personnel have access to users WhatsApp messages.32

59. According to whistleblower accounts reported to federal investigators, employees of Meta and WhatsApp and third-party contractors employed by Accenture are able to access the contents of users messages, contrary to the privacy representations made by the company.33

60. Former Meta contractors reported to special agents with the U.S. Department of Commerces Bureau of Industry and Security that they and some of their colleagues had broad access to the substance of WhatsApp messages that were supposed to be encrypted and inaccessible.34 The two sources confirmed that they had employees within their physical work locations who had unfettered access to WhatsApp, and one stated that she spoke with a Facebook team employee and confirmed that they could go back always into WhatsApp (encrypted) messages.35

61. Moreover, these whistleblowers have outlined much broader access by Meta employees and third-party contractors than the limited access described in WhatsApps Privacy Policy and website.36

32. Jake Bleiberg, US Has Investigated Claims WhatsApp Chats Arent Private, Bloomberg (Jan. 29, 2026, at 16:22 ET), https://www.bloomberg.com/news/articles/2026-01-29/us-has-in....

33 Id.

34 Id.

35 Id.

36 Id."

Unless users control the client software, "end-to-end encryption" is just marketing

Closed source apps and backends by US companies means communications can be monitored if US law requires it

A "backdoor" in the client app can be easily installed remotely by the company through an "automatic update"

OpenAI is 501c3, should they also be required to release everything?

  • Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.

    • Perhaps it shouldn't necessitate it, but I can't think of a good reason why not.

      If it were expensive to release it, that would be a reason. But it costs roughly zero dollars to create a public repo on GitHub and a cron job to push to it once a day.

      Making the system public potentially increases the likelihood of a hack, which would be bad for Signal users. But relying on this argument to keep the source secret is, I think, a confession that your security is below par. Or to put it the other way round: A secure software system remains secure even if its source code is public, so making your source public is a strong signal that you are confident in your security measures. Security isn't something I expect all non-profits to focus on, but I think it would be telling for Signal to hide behind this reason.

      What other reasons are there?

      2 replies →

    • > Non profit doesn't necessitate open sourcing their whole product. If you don't like that, don't donate. As long as they are transparent about their decisions that is the only obligation they have.

      Actually you're mistaken. Under the 501(c)(3) tax code rules, they are required to act in the public good. Nobody has sued them to enforce this though, but I'd at least like them to acknowledge the game they're playing by ghosting us all on this.

      1 reply →

  • OpenAI is a 501c4 not a 501c3. Also the structure is much more complicated for OpenAI.

    Nevertheless the point stands - I don’t see what relationship company organizational mission has with their technical responsibilities. Indeed, if the open sourced everything, standing up a clone would be easier which creates funding risk due to a race to the bottom of people who didn’t invest into the R&D investing very little additional to compete.

    •     > OpenAI is a 501c4 not a 501c3
      

      This is incorrect. OpenAI is actually registered as a 501(c)(3) public charity, not a 501(c)(4) social welfare organization. (Source: Bloomberg Law)

          > Also the structure is much more complicated for OpenAI.
      

      However, this is correct. Their corporate structure is very complex. Here is a screenshot from OpenAI's corporate structure explanation page (now taken down): https://images.axios.com/fbMDxci4KDAoYxM_v61sPi9jSVs=/0x0:19...

  • "open" is literally in the name, so yes

    • '"open" is literally in the name, so yes'

      Just because someone calls themselves something doesn't mean it is.

      "Open" is a name that George Soros uses for a lot of the things he puts his billions into e.g. the Open Democracy blog.

      I'll leave you to decide whether Soros' enterprises are really open.

Not only that. I also question how they pick new features to implement. For example usernames - I am not going to trust another "private" IM app username feature same as what Telegram and WhatsApp questionably chose. Compromise on this? Well, then even WhatsApp and Telegram are good enough with compromises.

Separate usernames completely from phone numbers. Period.

There's a reason Signal is still "US based". No, I am not talking about some CIA/NSA/DoD/tom/jerry funding conspiracy, just good old human obstinacy and hubris. They don't give a f about who uses it, it's about who makes and maintains it all.