HN user

rahrahrah

193 karma
Posts8
Comments206
View on HN

Sorry, my intention wasn't to move the goalposts, I actually misspoke the second time. Obviously I don't care where the evidence comes from. I did mean "no public evidence" and then the parent made it political, somehow.

I did read the RPT-APT28 report by FireEye on APT28 (all fifty-something pages, surprise!). It did convince me that APT28 has political motivations. What's the connection between that and DNC/Podesta? I don't know, because there's no public evidence on that (that I know of).

Ok, so I just want to be absolutely clear:

They are signed by the same process as all other APK's on the store; using the play store developer keys that OWS received. Google can backdoor it because they control the distribution source and verification scheme.

If I verify the signature, I can determine whether or not the APK has been tampered with by Google, yes or no?

It would be too easy to say "don't try to teach moxie how to do crypto" but this won't be interesting to either of us, I'm really curious what is your threat model that you would like additional signature specifically by OWS and what do you want them to sign.

Well, obviously I'm not trying to teach anyone crypto as I don't know enough myself to begin with. My threat model is don't trust anyone that has a bad track record. In my book Google has a bad track record but not moxie.

Because it depends on how you want to use email. eg I have emails which are sent to my address+subs@gmail.com being put to a label "subscriptions", but obviously not everyone wants to use it like this, in which case why make it default?

Most people have similar needs, and most people's job is to actually do their job, not mess with their email config

This is such an obvious excuse. You get the config right once and you've solved a problem forever. It is, how do you say, very "scalable" in time.

You said that the play sore APK is signed. Signed by whom? By OWS, right? So Google can't backdoor it. Again, what am I missing? Help me out. I might be making a reasoning mistake due to not thoroughly understading how these things work (I mean APK distribution)

Guys.... This is obviously NOT an attempt to SQL inject. This is a full fledged company incorporation. A marketing move if you will.

Although a risky one. If that had worked that guy would end up in court.

I probably don't know enough to be talking about these things, but it seems to me that the Qubes OS approach is more complex and less battle tested. User permissions in Linux have been around forever.

If Apple/Google want to backdoor Signal they can do so, they can also backdoor your device in this case the signature check is irrelevant if you consider them an adversary.

What? No...

Assuming you trust OWS you can check the APK signature.

A) Nuke everything

B) Install ASOP or other OS that you prefer.

C) Download and manually checked Signal's signature.

D) Transfer it to your device.

No need to trust Google. Am I missing something?

Listen, you always need to trust SOMETHING. If you don't trust Google or OWS you can read their code yourself, but then you're trusting the compiler, the OS, the hardware, etc. But I submit that of the above some are inherently more trustworthy than others, given their track record.

Something related happened to me. Some of the photos on my google photos are just completely black. It's not exactly the same because this guy's photos are "corrupted". Mine are just literally black. Not all of them, just around 20, all in the same day, all in sequence.

Curating IS their business. When you type in "public key pinning", for example, google understands that you want to learn about public key pinning and so it curates OUT results about kim kardashian for example and instead shows you factual truths about public key pinning. Why should the holocaust be different?

AGAIN, google's goal is to organise all knowledge and that's exactly what it's doing. That holocaust denial is a thing is also knowledge, and so you can find it by typing "holocaust denial".

he is generally in favour of ephemerality over verifiability

That's not an absolute law in a vacuum. What does "ephemerality" even mean in the context of the question "how can I verify that the software that's being pushed to my phone comes from where it says it comes?"