Live data from Hacker News

Moxie Marlinspike Makes Encryption for Everyone

popsci.com

101–110 of 144 posts

Re: Moxie Marlinspike Makes Encryption for Everyone

#101

Earlier quoted context omitted.

No, that's not how it works. The GCM message is empty, it just wakes up your device which then fetches the actual message from the Signal servers.

You don't think Google could correlate the two? Google knows device A got messages at times X, Y, and Z, and device B got messages at times X+1, Y+2, and Z+1.5. I'd be willing to bet with some statistical analysis over time, some pretty interesting data could be mined from that raw knowledge.

More worried about NSA correlating the two after getting the data from Google, but the one good thing about their centralization model probably is that with millions of users to a central server (and something you do as often as texting) this makes timing analysis extremely difficult.

Re: Moxie Marlinspike Makes Encryption for Everyone

#102

Watch his documentary "Hold Fast" to get a glimpse of just how unique and interesting a character he is. Anarchists yachting? Yes, more, please

If that's his autobiographical documentary, I'll pass. Never seen a more narcissistic piece of trash in my life. He won't stop talking in his monotonous voice the whole time--made it to the first scene where he films a conversation, but had to cut it off because even that he had to overdub--guy loooooves the sound of his own voice.

Re: Moxie Marlinspike Makes Encryption for Everyone

#103
post #91

Earlier quoted context omitted.

Why don't they know that anyways from basic traffic analysis?

This topic was about GCM specifically, which, since it goes through Google servers (unlike, say, my arbitrary browsing, or the network profile of my arbitrary apps), is directly available to Google. Speculating that Google may have access to my full network profile is a little off-topic, but yeah, if they did have that data, they could certainly do similar analysis on it. Did anyone say they couldn't?

So is the answer "there is nothing that GCM is revealing that NSA doesn't already get from simple traffic analysis"?

Re: Moxie Marlinspike Makes Encryption for Everyone

#104
post #6
post #3

Not for everyone, their crypto is GPL only and GPL can't be deployed everywhere.

> Not for everyone, their crypto is GPL only and GPL can't be deployed everywhere. GPL code can be used anywhere; GPL code cannot be made proprietary.

Not on Apple's app store.

Re: Moxie Marlinspike Makes Encryption for Everyone

#105

Earlier quoted context omitted.

This topic was about GCM specifically, which, since it goes through Google servers (unlike, say, my arbitrary browsing, or the network profile of my arbitrary apps), is directly available to Google. Speculating that Google may have access to my full network profile is a little off-topic, but yeah, if they did have that data, they could certainly do similar analysis on it. Did anyone say they couldn't?

So is the answer "there is nothing that GCM is revealing that NSA doesn't already get from simple traffic analysis"?

The answer is "GCM may reveal more to Google than one would expect from using an E2E encryption application (like metadata, and more than one would initially assume)".

The person I initially replied to was talking about Google, GCM, E2E encryption, and that metadata won't reveal anything to Google except time/date of a single message and the message size. I pointed out there may be more information there.

I have no doubt that the NSA can do traffic analysis, or may have some of this data already... I'm not sure why that is in the replies to my comments in this thread.

Re: Moxie Marlinspike Makes Encryption for Everyone

#106

Earlier quoted context omitted.

So is the answer "there is nothing that GCM is revealing that NSA doesn't already get from simple traffic analysis"?

The answer is "GCM may reveal more to Google than one would expect from using an E2E encryption application (like metadata, and more than one would initially assume)". The person I initially replied to was talking about Google, GCM, E2E encryption, and that metadata won't reveal anything to Google except time/date of a single message and the message size. I pointed out there may be more information there. I have no d…

That's only a meaningful answer if simple traffic behavior wasn't already revealing the same information. Was it, or wasn't it? I feel like I'm having a hard time getting a straight answer.

Re: Moxie Marlinspike Makes Encryption for Everyone

#107
post #82

Earlier quoted context omitted.

Here I copy the "dead" message from "uola": "Yes, phone numbers are public enough that they are shared everywhere, but unique enough to lead to a single person not to speak of that persons movements. And "just use twilio" isn't a motivation for using phone numbers in the first place. If he had said "the benefits of finding friends are greater than the privacy implications" or something like that there would at least…

> If he had said "the benefits of finding friends are greater than the privacy implications" or something like that there would at least been a case for a discussion This has already been discussed at length many times. Perhaps uola hasn't seen this blog post yet: https://whispersystems.org/blog/contact-discovery/

[deleted]

Re: Moxie Marlinspike Makes Encryption for Everyone

#108

Earlier quoted context omitted.

> It is your assumption that the perceived threat is a 'nation-state'... ... That was the opening sentence of my paragraph that demonstrated that there is no such thing as "guaranteed security". If you think that there is such a thing, then you're going to be confused about many things when you think about security matters. To the rest of your comment: You need to keep things in perspective. [0] * On Windows, Mac, an…

At issue further up the thread was whether insisting on using Google Play to distribute Signal for security reasons was sound logic, right? Forgive me if I missed the point but I thought that's what we were debating. That's why I provided the specific example above which showed malware distributed via the Google Play store. this advanced my position that an app insisting on distribution via Google Play store exclusiv…

So your point is that the Play store isn't perfect at stopping malware and that negates all benefits over just installing random unsigned APKs?

Besides, Moxie's point is that the store installs what he signs and nothing else. Perhaps the system wouldn't catch malware but if it prevents people from running builds he didn't make it sure lessens the window of opportunity.

Re: Moxie Marlinspike Makes Encryption for Everyone

#109
post #44

I've respected Moxie Marlinspike ever since he made sslstrip, a simple illustration of the fundamental insecurity of browser-based HTTPS. However I do question his premise that criminals already have the wherewithal to opt in to "clunky" strong encryption before engaging in criminal activity. In fact there are many scenarios where criminals simply go with the default security configuration in consumer devices, either…

Right, not all criminals can choose secure defaults. But those who can't are unlikely to be all that secure in other ways either meaning that it won't change the threat landscape much.

Besides, it wouldn't kill our LEOs to work for their supper. This reliance on dragnet tactics means that'll soon be all they're able to do.

Re: Moxie Marlinspike Makes Encryption for Everyone

#110
post #6

Earlier quoted context omitted.

> Not for everyone, their crypto is GPL only and GPL can't be deployed everywhere. GPL code can be used anywhere; GPL code cannot be made proprietary.

Not on Apple's app store.

File a bug report. The store is clearly broken as GPLed code has no impact on the store selling the app.

Apple clearly doesn't understand Copyright law. (or, are trying to poison their competitors with unfair business practices...)

Post reply on HN