Basically Signal doesn’t clarify to users that their keyboard is quite possibly spying on them, rendering all of Signals security moot if you’re trying to steer clear of spying governments. In practice this means that Signal is completely owned for most users in China if they use their phone as Chinese users normally do.
I keep hearing people say “use signal, it’s secure” and very few people also say “and the keyboard may render all of that security useless”. Thoughts? Naomi Wu has expressed recently that she feels totally ignored in this issue. Almost as if Signal doesn’t want to discuss it.
On the one hand, there is nothing on a technical level that Signal can do beyond what they’ve already done (linked in the twitter thread, set a flag that the installed keyboard may or may not respect). Anything beyond this is venturing into providing a general computer security 101 course and/or telling you how your mobile OS permissions work and/or region-specific opsec advice. I’m not sure they’re equipped to do that or if they are even the right people to do that. They are a small team and they most definitely do not have somebody embedded in activism of any kind in the sinosphere, which I think is what it would take for them to actually responsibly give region specific opsec advice.
On the other hand, I think it may be quite reasonable for them to say, very clearly, “use your system IME to input text”. It’s a very simple guideline with reasoning that I think can be understood easily by most people. They have a privacy/security section in the FAQ on their site; something like this could go there.
But of course if they did that, they would have to keep managing expectations around how much to delve into the security model of every platform they run on, and how many resources they can reasonably dedicate to usage scenario support. Their mission and product and user requirements are really unique; I’d love to be a fly on the wall of a signal product management meeting lol
I’m basic and use my iOS system IME to text in chinese, but also I’m a basic overseas chinese. Maybe I’ll have to survey my friends and family for what keyboard they use...
Yes. I think at this point Naomi is seeking official recognition from Moxie that this is a flaw in the overall system. I think she feels that she has been unfairly ignored, and she also knows people who she believes have been kidnapped by her government because of this flaw. So it’s a very real and visceral issue for her and she is also a very high profile person so it seems wrong to ignore her. I believe her recent Twitter frustrations started when she noticed that Signal responded to questions from some very small Twitter account, but still hasn’t responded directly to her.
If, due to factors outside of their control, Signal cannot actually guarantee that your conversations are secure, it may be irresponsible of Signal not to make that more clear. But one can understand why they might prefer to avoid the issue...
I think it's completely unrelated to Signal, to be frank.
> Naomi Wu has expressed recently that she feels totally ignored in this issue.
Yeah; I'd ignore it too if it was reported in a bug bounty programme. It'd obviously be out of scope.
It reminds me of the "but users might be running malicious WebExtensions!" argument (one of many!) I keep seeing in the Signal community for not implementing a proper web client (along with "but the PKI might be compromised and the JavaScript might be backdoored!"). They might be running a compromised OS too! Hell, their phone might have an entire ARM-based listening device inside the case. Security is always relative, and if someone reading "Use Signal, it's secure" doesn't understand that then they have bigger problems.
It basically boils down to "your fancy lock doesn't fix the person-sized hole in my door". She seems to be expecting the Signal devs to develop an entire Chinese IME. Why should the lock company have to also make doors?
Somewhere in the middle there she gets rather rude and starts accusing Signal devs of only caring about western users, as if there is a double standard. But there isn't: Signal doesn't provide a keyboard and keylogger detector for "western" users, why should it for Chinese?
I think this is the core part where Signal decides what it wants to really be:
* A messenger for activists, whistleblowers and other people that might be hunted by governments.
* A decently secure messenger for everyone that provides an alternative to WhatsApp, Facebook Messenger and other major corporate platforms.
Because in these cases those two goals are opposite - IME is the most fundamental way how people interact with a messaging app. Switchin it is very hard because users have muscle memory connected to an IME and IMEs vary wildly in their language support and typing experience,. Messing with it (blocking it, forcing people to use another) will make a lot of people refuse to use the app. Not messing with it will make activists mad and result in bunch of "Signal is crap for proper security" posts.
They need to choose. And sitting on both goalposts is the worst option here.
It doesn't have to force it. One of the proposed things has been making one of the on-boarding prompts give on-boarding prompts and point this out to the user - giving people who expect security of the first level based on how it has been presented to them the chance to realize they don't have it, and react.
Seems more like a core OS issue than something Signal specific. iOS at least disables keyboard apps' network access by default, Android users seem to be screwed (as usual) unless they root the phone and install a firewall..
I think the issue is that Naomi is seeking official recognition of this system flaw but signal and moxie have not done so in response to her questions. I think “signal creator acknowledges that signal is not always secure” would be a headline that would help non technical people understand this system flaw.
Why do you say that. You are free to block any app on Android from accessing the internet, including keyboards, from the standard Android settings, no root or anything.
Because what GP points out is that in China everyone uses Baidu's third party keyboard. So Signal alone enough is not enough to ensure safe communication.
This isnt a signal problem, its an android problem. I don't see how Signal could fix it, short of developing their own keyboard for their own app only but that would break a shitton of android accessibility features.
https://twitter.com/realsexycyborg/status/134916717100428902...
Basically Signal doesn’t clarify to users that their keyboard is quite possibly spying on them, rendering all of Signals security moot if you’re trying to steer clear of spying governments. In practice this means that Signal is completely owned for most users in China if they use their phone as Chinese users normally do.
I keep hearing people say “use signal, it’s secure” and very few people also say “and the keyboard may render all of that security useless”. Thoughts? Naomi Wu has expressed recently that she feels totally ignored in this issue. Almost as if Signal doesn’t want to discuss it.
* Input Method Editor