Live data from Hacker News

MEGAChat now includes end-to-end encryption

mega.nz

91–98 of 98 posts

Re: MEGAChat now includes end-to-end encryption

#91
post #88
post #86

Earlier quoted context omitted.

That's not what that message says, but maybe you could email your auditors and ask if they'd stand by the assertion you're making that native apps aren't safer for cryptography than browser apps. As for the rest of it: I'm sorry you feel that way, but I've reached a point in my message-boarding career where, after many, many years of fighting the good (then marginal then tedious then bad) fight, I'm just not going to…

> I think you should port to a browser extension Chrome extensions are HTML5/JS... which wouldn't stand to your own argument. > Unfortunately, the 10 years since 2005 have made browsers less hospitable to cryptography. You're saying IE6 and Firefox 1.0 were better for cryptography than our environment today? We've got effective standards like CSP and CSP2 for restricting code execution client side, SRI for validating…

No, I'm saying that web standards were more hospitable for crypto.

The mic drop at the end of your comment would have been more dramatic had you been replying to a comment addressed to you.

Re: MEGAChat now includes end-to-end encryption

#92
post #61
post #43

Earlier quoted context omitted.

Recent updates also show disconcerting "Joe is on Signal!" messages for everyone in your contacts (who is registered with Signal) regardless of whether or not you've had any contact with them. They've stated that this is not a security issue (I don't recall the specifics) but it was pretty disturbing nonetheless. I'll definitely be paying closer attention and consider switching to an alternative if this trend continu…

Why specifically are you worried about that?

I've recommended Signal (then TextSecure) to a number of non-technically savvy friends as a trustworthy app that takes security seriously. Moxie is somewhat unique in this respect, among the sea of proprietary apps put out by larger shops. Upon seeing these "X is on Signal" messages, I had a number of people contacting me with concerns. At least the outward appearance is that Signal is somehow leaking contact data to their servers. Presumably it is also alerting people to the fact that "Joe" is a Signal user, despite no communication with that user having taken place.

I realize that phone numbers are probably hashed before being sent, with only local contact data being displayed, but it has people concerned nonetheless. It starts to err more towards convenience, ease of use, and network building above security.

Re: MEGAChat now includes end-to-end encryption

#93
post #78
post #76

Earlier quoted context omitted.

Am I understanding correctly that you consider your adversary to be the National Security Agency, the world's best funded, best equipped, best staffed SIGINT agency, and that you think they're limited to passive observation? No, you aren't; the example was to illustrate an entirely different point. Again: I just think this is a bad idea. I'm sure you're great people, but cryptographic security is hard enough for nati…

There are very specific concerns I have about implementing secure cryptography in a browser runtime. I wrote an article about this a while back. I don't love that article and never did, but one complaint I've heard about it is that it's "dated". In fact: I think the last few years have made it harder to securely deploy crypto in a browser. So one short answer is, for a bunch of fiddly reasons, I think you're building…

> But the broader concern is, in fact, that by offering people a secure messenger, you're accepting some responsibility for securing traffic that can jeopardize lives if you're compromised. You have, I think, a moral responsibility to be as conservative as you possibly can be. When someone gets hurt because this system is flawed --- assuming you ever learn about it --- I think you're going to be surprised by where it happened. People with causes you've never even considered will use this thing in ways that, if you knew about, you'd say "fuck! stop! i like my application but i can't let you bet your life on it!".

I agree with you about web crypto, but I disagree with this point. A point that Roger Dingledine (of Tor fame) made a few years ago was that people who are going to say something which their government doesn't want them to say are going to say it anyway. If they can't communicate using the internet, they are willing to make protests in the streets, to shout and scream to try to improve their world. The job of people making cryptosystems to try to keep such activists safe is to minimise risk and do the best they can. You shouldn't think that you're responsible for what happens to those people, you're doing the best you can for them. But at the end of the day, they are willing to die for their goals and it is disrespectful to ignore that fact.

But yes, I agree that the service in question probably needs much more work. And it should probably say "this is still Alpha".

Re: MEGAChat now includes end-to-end encryption

#94
post #92
post #61

Earlier quoted context omitted.

Why specifically are you worried about that?

I've recommended Signal (then TextSecure) to a number of non-technically savvy friends as a trustworthy app that takes security seriously. Moxie is somewhat unique in this respect, among the sea of proprietary apps put out by larger shops. Upon seeing these "X is on Signal" messages, I had a number of people contacting me with concerns. At least the outward appearance is that Signal is somehow leaking contact data to…

I think we should push for Axolotl (the cryptosystem used by Signal, which is an improvement on OTR) support in Ricochet and get a Ricochet phone app.

Ricochet uses Tor hidden services to anonymise your social graph, which is something you don't do with Signal (not to mention that Signal does identity key lookups with phone numbers). I'm not sure there's a low-latency way to do VOIP anonymously. The best method I know of is to literally record and send audio files, which have a few seconds of latency.

Re: MEGAChat now includes end-to-end encryption

#95
post #93
post #78

Earlier quoted context omitted.

There are very specific concerns I have about implementing secure cryptography in a browser runtime. I wrote an article about this a while back. I don't love that article and never did, but one complaint I've heard about it is that it's "dated". In fact: I think the last few years have made it harder to securely deploy crypto in a browser. So one short answer is, for a bunch of fiddly reasons, I think you're building…

> But the broader concern is, in fact, that by offering people a secure messenger, you're accepting some responsibility for securing traffic that can jeopardize lives if you're compromised. You have, I think, a moral responsibility to be as conservative as you possibly can be. When someone gets hurt because this system is flawed --- assuming you ever learn about it --- I think you're going to be surprised by where it…

I felt that that was a perfectly fair statement on Thomas's part. It's fine if people are willing to risk their lives for a cause, but they shouldn't be misled into outright sacrificing their lives because someone irresponsibly marketed a tool as being suitable for a particular purpose.

I'm also not sure where you get the impression that Cyph is currently at an "alpha" stage, but I'm going to have to disagree with you there too. Do you have more specific feedback, and/or did you run into a bug while using it?

Re: MEGAChat now includes end-to-end encryption

#96
post #89
post #86

Earlier quoted context omitted.

That's not what that message says, but maybe you could email your auditors and ask if they'd stand by the assertion you're making that native apps aren't safer for cryptography than browser apps. As for the rest of it: I'm sorry you feel that way, but I've reached a point in my message-boarding career where, after many, many years of fighting the good (then marginal then tedious then bad) fight, I'm just not going to…

I'm just not sure how you expect me to take your position seriously and blindly follow it, when your reaction to the information I've presented is to pretend that there's literally no difference between WebSign/Cyph and something like MEGAChat. I felt that the "HPKP suicide" hack (which is something enabled only by recent Web standards) was a stroke of genius on Cure53's part; in the very least generous interpretatio…

So, if you're still reading this thread, I have one last question: what advantage do you think a browser extension has over WebSign as I've described it?

I'm asking explicitly because, since you still maintain that the extension model is objectively more secure, at least one of us is clearly missing something very important.

Re: MEGAChat now includes end-to-end encryption

#97
post #92
post #61

Earlier quoted context omitted.

Why specifically are you worried about that?

I've recommended Signal (then TextSecure) to a number of non-technically savvy friends as a trustworthy app that takes security seriously. Moxie is somewhat unique in this respect, among the sea of proprietary apps put out by larger shops. Upon seeing these "X is on Signal" messages, I had a number of people contacting me with concerns. At least the outward appearance is that Signal is somehow leaking contact data to…

you can easily enumerate this data anyway, though. Just go through your contact list and try to add people. You could come up with an elaborate system where the other person has to confirm you, but everyone knows that's rubbish and users hate it. Sorry for the late response, I forgot I made this comment.

Re: MEGAChat now includes end-to-end encryption

#98
post #97
post #92

Earlier quoted context omitted.

I've recommended Signal (then TextSecure) to a number of non-technically savvy friends as a trustworthy app that takes security seriously. Moxie is somewhat unique in this respect, among the sea of proprietary apps put out by larger shops. Upon seeing these "X is on Signal" messages, I had a number of people contacting me with concerns. At least the outward appearance is that Signal is somehow leaking contact data to…

you can easily enumerate this data anyway, though. Just go through your contact list and try to add people. You could come up with an elaborate system where the other person has to confirm you, but everyone knows that's rubbish and users hate it. Sorry for the late response, I forgot I made this comment.

Yes I'm well aware at the ease in which someone could build a client that would provide such a feature had it not been included. Moxie takes great care not to provide mere illusions of security (or in this case obscurity) such as self-destructing messages or other features of that ilk. I appreciate it, and it's a big part of why I use and recommend projects affiliated with Open Whisper. Still don't believe it was the right decision to blast users with a notification from every Signal user in your contacts. Let Telegram or Whatsapp or some other crap play that game.
Post reply on HN