Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Unfortunately a country is looking out for their own best interests instead of relying on questionable technology out of their control?


Countries should in-house their critical technology, jobs, and infrastructure true as much as possible. Sure, you can save a few bucks by using that huawei router or Russian developed secure message app. And maybe it’s cheaper to pay people in China to handle all of your advanced fabrication. And foreign investment money seems to flow a lot more freely than domestic. But I think we’ve seen over and over again how countries that control investments and supply chain are more than willing to use their influence as a political lever when it suits them.


There is a slight issue: French officials likely often exchange with their colleagues from other EU countries (or the EU itself in Brussels).

Using what then? will they go back to using pigeons or will President Macron force Olvid upon all European administrations?


We could say that this is another case where the European Union has failed to act united in pursuit of a common goal.


Obviously the latter. EU will mandate installation of this app.


Why would you not use diplomatic cables or encrypted e-mail?


How is Signal a questionable technology? I do understand whatsapp and telegram though.


Hypothesis yet plausible scenario: Signal is actually a NSA/CIA-run honeypot.

As far as I know, nobody knows (for sure) what software runs on the official Signal servers. Only the official client app can be used to communicate with ONLY the Signal server.

US law (as far as I know) forces ALL US-based organizations (including non-profits) to cooperate with any and all government agencies, without being legally allowed to publicly admit or disclose that they're doing so. Thanks to Snowden we know that this has happened A LOT in the past. After Snowden, when exactly did the NSA stop illegally spying on everybody? ... Exactly...

With the above in mind it is possible that all Signal traffic is not actually e2e encrypted and is instead decrypted and re-encrypted at the server.

A less "far fetched" version of the above would be that there are simply known vulnerabilities in the Signal client app (and/or Android and/or iOS and/or other apps) that governments are exploiting to see all decrypted Signal communications.

IMO it would be extremely dumb for an EU country to voluntarily use software made in the US or in any other country if it isn't FULLY open source and FULLY audited (and compiled from source) by the EU country itself.

Just like it is extremely dumb that EU-based companies are PAYING to upload their own trade secrets to their direct competitors in the US through OneDrive.

If you think that the above is far-fetched, read this: https://www.swissinfo.ch/eng/politics/switzerland-closes-inv...


Signal Facing Collapse After CIA Cuts Funding [0]

[0] https://kitklarenberg.substack.com/p/signal-facing-collapse-...


It's a US based organisation isn't it?

So all the standard US problems (national security letters, etc) would seem to apply.


Signal claims to only have the phone number and, IIRC, last connection time. But being American they seem at least somewhat vulnerable to pressure by the US government.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: