Self hosting Signal server
litchralee @ litchralee @sh.itjust.works 帖子 121评论 1,128加入于 2 yr. ago
litchralee @ litchralee @sh.itjust.works
帖子
121
评论
1,128
加入于
2 yr. ago
Micromobility Products-Related Deaths, Injuries, and Hazard Patterns: 2017–2022
Tahoe area trail network will connect Truckee to Nevada City
Buy/DIY? Seeking advice: 29er wheelset, 150/197mm thru-axle, ~23mm inner rim, for ebike
Help me remember a "back-to-back chaise longue" from TV or film. What would you call this?
Walgreens: free 8x10 print. Use code NY-PRINT. Exp 1 January. Now works on desktop!
Walgreens: free 8x10 print. Use code NY-PRINT. Exp 1 January. In app only.
How big and heavy until it's no longer a form of micromobility?
This doesn't answer OP's question, but is more of a PSA for anyone that seeks to self-host the backend of an E2EE messaging app: only proceed if you're willing and able to upkeep your end of the bargain to your users. In the case of Signal, the server cannot decrypt messages when they're relayed. But this doesn't mean we can totally ignore where the server is physically located, nor how users connect to it.
As Soatok rightly wrote, the legal jurisdiction of the Signal servers is almost entirely irrelevant when the security model is premised on cryptographic keys that only the end devices have. But also:
So if you're going to be self-hosting from a country where superinjunctions exist or the right against unreasonable searches is being eroded, consider that well before an agent with a wiretap warrant demands that you attach a logger for "suspicious" IP addresses.
If you do host your Signal server and it's only accessible through Tor, this is certainly an improvement. But still, you must adequately inform your users about what they're getting into, because even Tor is not fully resistant to deanonymization, and then by the very nature of using a non-standard Signal server, your users would be under immediate suspicion and subject to IRL side-channel attacks.
I don't disagree with the idea of wanting to self-host something which is presently centralized. But also recognize that the network effect with Signal is the same as with Tor: more people using it for mundane, everyday purposes provides "herd immunity" to the most vulnerable users. Best place to hide a tree is in a forest, after all.
If you do proceed, don't oversell what you cannot provide, and make sure your users are fully abreast of this arrangement and they fully consent. This is not targeted at OP, but anyone that hasn't considered the things above needs to pause before proceeding.