This is the best rebuttal. I might change my opinion a little bit on this. But as a service that still passes data through someones centralized network, there is no real guarantee for full privacy. But it does look to be ran by a rockstar with a descent view on privacy first. So I will yield to signal.
The problem with proton is that centralized service. Proton has given up user data before and ideally if your trusting a platform for privacy reasons then you dont want them to have a mechanism for handing over your data. So proton is still a platform that needs work before it can be what it promises to be. That said it is probably still better than using non privacy centric services like gmail and so on.
Yeah, I trust Whittaker’s conviction on this because she’s been tested multiple times by the governments of multiple countries at this point. When pushed, her response is “OK, we just won’t support your country, bye”… and then the government ends up using Signal internally anyway. She is more than just talk, and so far she’s been unwilling to sell out or compromise Signal for anyone. At the moment, there’s no other secure communication project that I know of that is similarly effective, well audited by third parties, and has trustworthy leadership.
Proton is more complicated. There are more tradeoffs and compromises, but it is also more complex and offers more functionality than just a messaging platform. I recommend this video by Reject Convenience: https://www.youtube.com/watch?v=xFKSKjyBVDU He used Proton services for awhile and has made some different choices since, so he has some useful criticism from experience (not knee-jerk reactionary stuff).
At some point you have to make decisions about what your risk tolerance is, how much manual effort you can reasonably put in to sustain your tools, and how much money you’re willing to spend on it. Proton is the right choice for many people not because it’s a perfect company, but because providing equivalent functionality for yourself is a full-time job.
In order to provide a globally accessible, reliable, and high-performance communications service for the many millions of people around the world who depend on Signal, it’s necessary for Signal’s servers to be globally distributed. Having a geographically distributed network of servers is particularly important for end-to-end encrypted voice and video calls, because latency can result in audio delays or degraded video connections that quickly make the app unusable for real-time communication.
Because everything in Signal is end-to-end encrypted, we can rent server infrastructure from a variety of providers like Amazon AWS, Google Compute Engine, Microsoft Azure, and others while ensuring that your messages and calls remain private and secure. We can’t access them, and neither can the companies that provide any of the infrastructure we rent. As a small nonprofit organization, we cannot afford to purchase all of the physical computers that are necessary to support everyone who relies on Signal while also placing them in independent data centers around the world. Only a select few of the very largest companies globally are still capable of doing this, which is a hallmark of a troublingly concentrated industry.
Signal’s servers are distributed globally, but yes rented primarily from American companies. I think they would diversify this if they could, but there aren’t really other options with global presence. The only other host providers with comparable scale are Chinese ( like Tencent), but Signal is banned in China as of 2021 ( https://www.vice.com/en/article/signal-blocked-in-china/ ) because the PRC does not allow its citizens to have privacy from government surveillance at all.
There is no evidence that having Signal infrastructure hosted on US company servers provides any capacity for the US government to bypass Signal’s encryption.
There is no evidence that having Signal infrastructure hosted on US company servers provides any capacity for the US government to bypass Signal’s encryption.
I didn’t say that. A foreign government being able to disable your communication whenever they want to is already a threat to national security
A foreign government being able to disable your communication whenever they want to is already a threat to national security
Well… yes it would be, but even though we’re talking about US-based companies, the servers aren’t all located within US borders, they’re spread around the globe. Maybe the US government could force Amazon data centers within the US to stop carrying Signal data… though that in itself would be a logistical mess and I’m not sure how they would justify it legally. Even the current administration loses court battles and their actions get reversed, and at that point they’d be contending with the legal teams of both Signal and Amazon, plus probably the ACLU and EFF. Considering how few competent lawyers are left in the Trump administration, I doubt they would win that court battle.
For the servers outside the US, not only would it be a logistical and legal nightmare but I’m also not sure how it would be done in a technical sense, at least not all at once or in a time frame of less than a month. It would be very difficult to accomplish actually shutting down Signal’s operations in any practical way. You would have to exercise legal authority or physical force over more than half the data centers on the planet (AWS, Google, Microsoft).
This is the best rebuttal. I might change my opinion a little bit on this. But as a service that still passes data through someones centralized network, there is no real guarantee for full privacy. But it does look to be ran by a rockstar with a descent view on privacy first. So I will yield to signal.
The problem with proton is that centralized service. Proton has given up user data before and ideally if your trusting a platform for privacy reasons then you dont want them to have a mechanism for handing over your data. So proton is still a platform that needs work before it can be what it promises to be. That said it is probably still better than using non privacy centric services like gmail and so on.
Yeah, I trust Whittaker’s conviction on this because she’s been tested multiple times by the governments of multiple countries at this point. When pushed, her response is “OK, we just won’t support your country, bye”… and then the government ends up using Signal internally anyway. She is more than just talk, and so far she’s been unwilling to sell out or compromise Signal for anyone. At the moment, there’s no other secure communication project that I know of that is similarly effective, well audited by third parties, and has trustworthy leadership.
Proton is more complicated. There are more tradeoffs and compromises, but it is also more complex and offers more functionality than just a messaging platform. I recommend this video by Reject Convenience: https://www.youtube.com/watch?v=xFKSKjyBVDU He used Proton services for awhile and has made some different choices since, so he has some useful criticism from experience (not knee-jerk reactionary stuff).
At some point you have to make decisions about what your risk tolerance is, how much manual effort you can reasonably put in to sustain your tools, and how much money you’re willing to spend on it. Proton is the right choice for many people not because it’s a perfect company, but because providing equivalent functionality for yourself is a full-time job.
Which is terrible for national security because everything is hosted on centralized American servers
https://signal.org/blog/signal-is-expensive/
Signal’s servers are distributed globally, but yes rented primarily from American companies. I think they would diversify this if they could, but there aren’t really other options with global presence. The only other host providers with comparable scale are Chinese ( like Tencent), but Signal is banned in China as of 2021 ( https://www.vice.com/en/article/signal-blocked-in-china/ ) because the PRC does not allow its citizens to have privacy from government surveillance at all.
There is no evidence that having Signal infrastructure hosted on US company servers provides any capacity for the US government to bypass Signal’s encryption.
I didn’t say that. A foreign government being able to disable your communication whenever they want to is already a threat to national security
Well… yes it would be, but even though we’re talking about US-based companies, the servers aren’t all located within US borders, they’re spread around the globe. Maybe the US government could force Amazon data centers within the US to stop carrying Signal data… though that in itself would be a logistical mess and I’m not sure how they would justify it legally. Even the current administration loses court battles and their actions get reversed, and at that point they’d be contending with the legal teams of both Signal and Amazon, plus probably the ACLU and EFF. Considering how few competent lawyers are left in the Trump administration, I doubt they would win that court battle.
For the servers outside the US, not only would it be a logistical and legal nightmare but I’m also not sure how it would be done in a technical sense, at least not all at once or in a time frame of less than a month. It would be very difficult to accomplish actually shutting down Signal’s operations in any practical way. You would have to exercise legal authority or physical force over more than half the data centers on the planet (AWS, Google, Microsoft).
The US servers are required (see us-west outage crashing Signal globally)