| 00:02:00 | | dm4v quits [Read error: Connection reset by peer] |
| 00:02:13 | | dm4v joins |
| 00:02:16 | | dm4v is now authenticated as dm4v |
| 00:02:16 | | dm4v quits [Changing host] |
| 00:02:16 | | dm4v (dm4v) joins |
| 00:10:55 | | tzt quits [Ping timeout: 252 seconds] |
| 00:15:32 | | maxfan8 quits [Ping timeout: 265 seconds] |
| 00:16:32 | | maxfan8 (maxfan8) joins |
| 00:18:15 | | tzt (tzt) joins |
| 00:18:20 | | AlsoHP_Archivist quits [Ping timeout: 258 seconds] |
| 00:19:02 | | AlsoHP_Archivist joins |
| 00:35:34 | | Stiletto quits [Read error: Connection reset by peer] |
| 00:35:35 | | Meli quits [Ping timeout: 258 seconds] |
| 00:35:46 | | Stiletto joins |
| 00:40:49 | | Meli (Meli) joins |
| 00:43:57 | | igloo22225 (igloo22225) joins |
| 00:59:52 | | AlsoHP_Archivist quits [Ping timeout: 252 seconds] |
| 01:00:31 | | AlsoHP_Archivist joins |
| 01:02:58 | | dm4v_ joins |
| 01:03:10 | | dm4v quits [Ping timeout: 252 seconds] |
| 01:03:10 | | dm4v_ is now known as dm4v |
| 01:03:12 | | dm4v is now authenticated as dm4v |
| 01:03:12 | | dm4v quits [Changing host] |
| 01:03:12 | | dm4v (dm4v) joins |
| 01:36:10 | | Meli quits [Ping timeout: 252 seconds] |
| 01:38:57 | | benjins quits [Read error: Connection reset by peer] |
| 01:40:29 | | benjins joins |
| 01:43:40 | <gazorpazorp> | yano: Sorry for the wall of text: |
| 01:43:46 | <gazorpazorp> | Lots of stuff is government funded (Open Technology fund lists Tor, WireGuard, Tails, NoScript, Subgraph OS, Qubes OS in https://www.opentech.fund/results/supported-projects). I'm a user of all of the listed software and I wouldn't stop using them just because The Open Technology Fund is linked to the US government (OTF-RFA-CUA). The US government does a lot of shady stuff, but also funds legitimate things because the goverment, |
| 01:43:46 | <gazorpazorp> | CIA and NSA in particular, have contradictory goals to both provide security for their citizens or for citizens of countries they have an interest in and to also undermine the security of enemies, whoever that may be - they have to play both defense and offense (although it has long been suggested that such functions be separated into different departments/agencies). |
| 01:43:51 | <gazorpazorp> | Signal is FOSS (as per the article "going a whole year without publishing their server code updates.", which is actually weird to me). So it can be audited and it can even be run on your own server (which the article says it cannot), but cannot be federated, for which Moxie has strong arguments with which I can't say I disagree with, even though I prefer federated systems like Matrix. Most of the cryptographic protocols and |
| 01:43:51 | <gazorpazorp> | systems are developed by or chosen or otherwise endorsed by the NSA, NIST, etc.. We shouldn't trust them because they're endorsed by the government, but because they are popular and widely scrutinized by the public compared to the alternatives. |
| 01:43:56 | <gazorpazorp> | I'd love to my contacts to Matrix, but it was extremely painful moving them to Signal alone, so for my threat model regarding my communication with them Signal is fine. I'm not sure how much visibility they have into the metadata - if anyone can shed some light on that... The article recommends XMPP, but says it suffers from fragmentation, which is one of the reasons Moxie decided not to federate Signal. It recommends Briar, in |
| 01:44:02 | <gazorpazorp> | which "apps communicate directly with each other over the TOR network on the Internet, the same wifi, or through bluetooth", but Tor was developed by the United States Naval Research Laboratory and is funded by The Open Technology Fund. |
| 01:44:52 | | gazorpazorp is now known as zorpy |
| 01:45:29 | | benjins is now authenticated as benjins |
| 02:05:31 | | Meli (Meli) joins |
| 02:37:38 | | ThreeHM quits [Ping timeout: 265 seconds] |
| 02:39:17 | | ThreeHM (ThreeHeadedMonkey) joins |
| 03:06:27 | | @dxrt quits [Quit: ZNC - http://znc.sourceforge.net] |
| 03:06:45 | | dxrt joins |
| 03:06:48 | | dxrt is now authenticated as dxrt |
| 03:06:48 | | dxrt quits [Changing host] |
| 03:06:48 | | dxrt (dxrt) joins |
| 03:06:48 | | @ChanServ sets mode: +o dxrt |
| 03:07:23 | | Jake quits [Ping timeout: 258 seconds] |
| 03:09:41 | | AlsoHP_Archivist quits [Ping timeout: 258 seconds] |
| 03:18:15 | | qw3rty__ joins |
| 03:22:06 | | qw3rty_ quits [Ping timeout: 265 seconds] |
| 03:30:38 | | kiska5 quits [Quit: Ping timeout (120 seconds)] |
| 03:30:52 | | kiska5 joins |
| 03:52:57 | | @dxrt quits [Client Quit] |
| 03:53:15 | | dxrt joins |
| 03:53:17 | | dxrt is now authenticated as dxrt |
| 03:53:17 | | dxrt quits [Changing host] |
| 03:53:17 | | dxrt (dxrt) joins |
| 03:53:17 | | @ChanServ sets mode: +o dxrt |
| 05:06:13 | | systwi quits [Ping timeout: 258 seconds] |
| 05:54:12 | | BlueMaxima quits [Read error: Connection reset by peer] |
| 06:09:25 | | Nay (JeDa) joins |
| 06:24:42 | | Jake (Jake) joins |
| 07:11:40 | | wizards_ quits [Ping timeout: 252 seconds] |
| 07:12:20 | | wizards_ joins |
| 08:20:09 | | Mateon1 quits [Remote host closed the connection] |
| 08:20:21 | | Mateon1 joins |
| 08:46:26 | | qwertyasdfuiopghjkl quits [Ping timeout: 244 seconds] |
| 08:59:35 | | systwi (systwi) joins |
| 09:05:28 | | systwi quits [Read error: Connection reset by peer] |
| 09:06:00 | | systwi (systwi) joins |
| 09:57:51 | | cheesy joins |
| 10:04:58 | | cheesy quits [Ping timeout: 244 seconds] |
| 10:31:45 | | sec^nd quits [Remote host closed the connection] |
| 10:32:22 | | sec^nd (second) joins |
| 10:40:00 | | Mateon2 joins |
| 10:41:38 | | Mateon1 quits [Ping timeout: 258 seconds] |
| 10:41:41 | | Mateon2 is now known as Mateon1 |
| 10:49:45 | | driib8 (driib) joins |
| 10:53:32 | | driib quits [Ping timeout: 265 seconds] |
| 10:53:32 | | driib8 is now known as driib |
| 11:37:18 | | AlsoHP_Archivist joins |
| 12:16:25 | | AlsoHP_Archivist quits [Client Quit] |
| 12:16:44 | | HP_Archivist (HP_Archivist) joins |
| 13:59:46 | | Arcorann quits [Ping timeout: 252 seconds] |
| 14:09:28 | | sonick quits [Quit: Connection closed for inactivity] |
| 14:26:14 | | AlsoHP_Archivist joins |
| 14:28:00 | | sonick (sonick) joins |
| 14:29:20 | | HP_Archivist quits [Ping timeout: 258 seconds] |
| 14:31:07 | | AlsoHP_Archivist quits [Ping timeout: 252 seconds] |
| 14:31:17 | | AlsoHP_Archivist joins |
| 14:39:53 | | qwertyasdfuiopghjkl joins |
| 14:40:27 | | AlsoHP_Archivist quits [Ping timeout: 258 seconds] |
| 14:41:16 | | AlsoHP_Archivist joins |
| 14:48:45 | | Hackerpcs quits [Client Quit] |
| 14:50:02 | | AlsoHP_Archivist quits [Ping timeout: 258 seconds] |
| 14:50:11 | | Hackerpcs (Hackerpcs) joins |
| 14:50:45 | | AlsoHP_Archivist joins |
| 15:04:02 | | AlsoHP_Archivist quits [Client Quit] |
| 15:04:20 | | HP_Archivist (HP_Archivist) joins |
| 15:25:21 | | AlsoHP_Archivist joins |
| 15:28:33 | | HP_Archivist quits [Ping timeout: 265 seconds] |
| 15:42:04 | | AlsoHP_Archivist quits [Ping timeout: 252 seconds] |
| 15:42:55 | | qwertyasdfuiopghjkl8 joins |
| 15:45:27 | | qwertyasdfuiopghjkl quits [Ping timeout: 244 seconds] |
| 15:59:14 | | qwertyasdfuiopghjkl8 is now known as qwertyasdfuiopghjkl |
| 16:06:04 | | Wingy quits [Remote host closed the connection] |
| 16:07:03 | | Wingy (Wingy) joins |
| 17:06:00 | | IDK (IDK) joins |
| 18:38:45 | | Matthww quits [Quit: Ping timeout (120 seconds)] |
| 18:39:04 | | Matthww joins |
| 18:40:02 | | qwertyasdfuiopghjkl79 joins |
| 18:42:09 | | qwertyasdfuiopghjkl quits [Ping timeout: 244 seconds] |
| 19:54:24 | | Wingy quits [Ping timeout: 258 seconds] |
| 20:01:09 | | Wingy (Wingy) joins |
| 20:09:41 | <@JAA> | gazorpazorp: Signal is FOSS except not really for practical purposes. Cf. why it isn't in F-Droid, for example. It's a very 'fun' rabbit hole there... |
| 20:18:43 | | Wingy quits [Read error: Connection reset by peer] |
| 20:19:36 | | Wingy (Wingy) joins |
| 20:26:35 | | Wingy quits [Read error: Connection reset by peer] |
| 20:27:50 | | Wingy (Wingy) joins |
| 21:14:50 | <zorpy> | JAA: (I changed my nick to be shorter) Yup, and the (heavily downvoted) reasons given on github are the same "we don't want different versions/forks connecting to our servers", which is kinda BS. At least they have apk from their website that detects lack of FCM during registration and uses a permanent notification websocket instead (but AFAIK the FCM code is still there). |
| 21:15:42 | <zorpy> | But I wouldn't say that makes it more likely for it to be a backdoored CIA/NSA project |
| 21:16:15 | <@JAA> | I agree, but there are some good points in that essay. |
| 21:17:08 | <@JAA> | And yeah, the APK plus reproducible builds are somewhat decent at least. |
| 21:17:32 | <zorpy> | Is Signal reproducibly built yet? |
| 21:17:50 | <@JAA> | Yeah |
| 21:17:55 | <@JAA> | https://github.com/signalapp/Signal-Android/tree/343aadcd9af23ebe5be25e3ce722d017d77868cd/reproducible-builds |
| 21:18:26 | <@JAA> | I wonder if this 'don't run modified code' is compatible with GPLv3 though, which the code is released under. |
| 21:20:36 | <zorpy> | Do they just don't want modified code to use their servers? That was my impression so far. That seems OK, compared to "don't modify Signal and use it with your own servers" |
| 21:21:00 | <@JAA> | Well, they didn't want F-Droid to build the repo and then distribute that APK. |
| 21:21:52 | <@JAA> | Not sure whether the code had a Google check at the time, but they basically said 'fuck no' regardless. |
| 21:22:28 | <zorpy> | Did they ask or demand? If I was F-Droid and Signal didn't want to be on F-Droid, I'd probably not bother even if it was within my rights to distribute it |
| 21:22:32 | <@JAA> | They didn't even want their own signed APK distributed through F-Droid as I understand it. Which is beyond ridiculous. |
| 21:23:11 | <zorpy> | Not trying to be a Signal apologist here, btw. Widespread adoption of Matrix would be awesome and I'd prefer it to Signal |
| 21:24:05 | <zorpy> | ridiculous indeed |
| 21:25:10 | <@JAA> | Oh yeah, their other reason was 'to use F-Droid, you need to enable third-party APKs, which we consider a security risk'. Since they offer the APK on the website, that point is moot now though. |
| 21:26:06 | <zorpy> | That reason is very condescending to users |
| 21:28:11 | <@JAA> | Yep |
| 21:28:23 | <@JAA> | This is the original discussion: https://github.com/signalapp/Signal-Android/issues/127 |
| 21:37:40 | <zorpy> | Even with all its faults (F-Droid, requiring a phone number to register, etc.), it still seems like the best secure-by-default messenger to recommend to the masses. Most people (especially older people) want me to install it for them from Google Play so creating an account with a password for Matrix would be an even bigger challenge for them. And at least Signal has some network effect - after I've recommended it to others, they say |
| 21:37:40 | <zorpy> | they saw a few people from their contacts already on Signal |
| 21:40:10 | <zorpy> | So for these technically illiterate people (who are sadly the vast majority of people) it's either going to be Signal or Telegram (which is not E2EE by default) or some proprietary surveillance tool disguised as a messenger |
| 21:55:53 | | BlueMaxima joins |
| 22:03:03 | | qwertyasdfuiopghjkl79 is now known as qwertyasdfuiopghjkl |
| 22:32:22 | | Arcorann (Arcorann) joins |
| 22:41:10 | | BlueMaxima quits [Read error: Connection reset by peer] |
| 22:41:44 | | BlueMaxima joins |
| 22:42:09 | | ave quits [Quit: Ping timeout (120 seconds)] |
| 22:42:32 | | ave (ave) joins |
| 22:42:45 | | Ryz quits [Quit: Ping timeout (120 seconds)] |
| 22:42:47 | | kiska5 quits [Client Quit] |
| 22:43:16 | | @dxrt quits [Client Quit] |
| 22:44:35 | | kiska5 joins |
| 22:44:50 | | dxrt joins |
| 22:44:52 | | dxrt is now authenticated as dxrt |
| 22:44:52 | | dxrt quits [Changing host] |
| 22:44:52 | | dxrt (dxrt) joins |
| 22:44:52 | | @ChanServ sets mode: +o dxrt |
| 22:47:06 | | Ryz (Ryz) joins |
| 22:47:13 | <kpcyrd> | I remember fdroid was also behaving fairly debian-esque regarding patching for political reasons. But still, I'd wonder how this discussion would look like 8 years later. |
| 22:47:46 | <kpcyrd> | I'm redistributing signal-desktop for Arch Linux and signal is cool with it |
| 22:51:55 | <kpcyrd> | regarding "no 3rd party clients" - I kinda get that, I wouldn't want to deal with buggy unmaintained clients either. "but my client wouldn't become unmaintained" - I had to contribute sealed sender support to signal-cli myself because nobody else was doing it. |
| 22:53:04 | <@hook54321> | i doubt that it's incompatible with the license, i hate it though. |
| 22:53:21 | <kpcyrd> | it's not the license, it's the trademark |
| 22:54:25 | <@hook54321> | iirc they didn't care if the client used the term "Signal", they just didn't want third-party clients connecting to their servers period. |
| 22:54:25 | <@JAA> | LibreSignal would've changed the name to not include Signal if that would've been the blocker. |
| 22:54:38 | <@JAA> | Yup, that. |
| 22:57:36 | <@JAA> | I also loved his argument that went 'not using Google Play Store for installing the apps is an illusion of privacy because the other Google services on your phone will phone home anyway'. As if AOSP-based OS without Google's proprietary stuff didn't exist. |
| 22:59:08 | <@hook54321> | some even come with f-droid as a system app, so enabling third-party APKs probably isn't even neccesary then |
| 22:59:45 | <kpcyrd> | the "3rd party apk" setting is not really a thing anymore as far as I know |
| 23:00:19 | <kpcyrd> | it's kinda complicated to lock down to "playstore only" these days |
| 23:00:51 | <@JAA> | Yeah, because all the phone manufacturers have their own shitty stores as well. |