Earlier quoted context omitted.
No, that's not how it works. The GCM message is empty, it just wakes up your device which then fetches the actual message from the Signal servers.
You don't think Google could correlate the two? Google knows device A got messages at times X, Y, and Z, and device B got messages at times X+1, Y+2, and Z+1.5. I'd be willing to bet with some statistical analysis over time, some pretty interesting data could be mined from that raw knowledge.
Moxie Marlinspike Makes Encryption for Everyone
101–110 of 144 posts
Re: Moxie Marlinspike Makes Encryption for Everyone
#102Watch his documentary "Hold Fast" to get a glimpse of just how unique and interesting a character he is. Anarchists yachting? Yes, more, please
Re: Moxie Marlinspike Makes Encryption for Everyone
#103Earlier quoted context omitted.
Why don't they know that anyways from basic traffic analysis?
This topic was about GCM specifically, which, since it goes through Google servers (unlike, say, my arbitrary browsing, or the network profile of my arbitrary apps), is directly available to Google. Speculating that Google may have access to my full network profile is a little off-topic, but yeah, if they did have that data, they could certainly do similar analysis on it. Did anyone say they couldn't?
Re: Moxie Marlinspike Makes Encryption for Everyone
#104Re: Moxie Marlinspike Makes Encryption for Everyone
#105Earlier quoted context omitted.
This topic was about GCM specifically, which, since it goes through Google servers (unlike, say, my arbitrary browsing, or the network profile of my arbitrary apps), is directly available to Google. Speculating that Google may have access to my full network profile is a little off-topic, but yeah, if they did have that data, they could certainly do similar analysis on it. Did anyone say they couldn't?
So is the answer "there is nothing that GCM is revealing that NSA doesn't already get from simple traffic analysis"?
The person I initially replied to was talking about Google, GCM, E2E encryption, and that metadata won't reveal anything to Google except time/date of a single message and the message size. I pointed out there may be more information there.
I have no doubt that the NSA can do traffic analysis, or may have some of this data already... I'm not sure why that is in the replies to my comments in this thread.
Re: Moxie Marlinspike Makes Encryption for Everyone
#106Earlier quoted context omitted.
So is the answer "there is nothing that GCM is revealing that NSA doesn't already get from simple traffic analysis"?
The answer is "GCM may reveal more to Google than one would expect from using an E2E encryption application (like metadata, and more than one would initially assume)". The person I initially replied to was talking about Google, GCM, E2E encryption, and that metadata won't reveal anything to Google except time/date of a single message and the message size. I pointed out there may be more information there. I have no d…
Re: Moxie Marlinspike Makes Encryption for Everyone
#107Earlier quoted context omitted.
Here I copy the "dead" message from "uola": "Yes, phone numbers are public enough that they are shared everywhere, but unique enough to lead to a single person not to speak of that persons movements. And "just use twilio" isn't a motivation for using phone numbers in the first place. If he had said "the benefits of finding friends are greater than the privacy implications" or something like that there would at least…
> If he had said "the benefits of finding friends are greater than the privacy implications" or something like that there would at least been a case for a discussion This has already been discussed at length many times. Perhaps uola hasn't seen this blog post yet: https://whispersystems.org/blog/contact-discovery/
Re: Moxie Marlinspike Makes Encryption for Everyone
#108Earlier quoted context omitted.
> It is your assumption that the perceived threat is a 'nation-state'... ... That was the opening sentence of my paragraph that demonstrated that there is no such thing as "guaranteed security". If you think that there is such a thing, then you're going to be confused about many things when you think about security matters. To the rest of your comment: You need to keep things in perspective. [0] * On Windows, Mac, an…
At issue further up the thread was whether insisting on using Google Play to distribute Signal for security reasons was sound logic, right? Forgive me if I missed the point but I thought that's what we were debating. That's why I provided the specific example above which showed malware distributed via the Google Play store. this advanced my position that an app insisting on distribution via Google Play store exclusiv…
Besides, Moxie's point is that the store installs what he signs and nothing else. Perhaps the system wouldn't catch malware but if it prevents people from running builds he didn't make it sure lessens the window of opportunity.
Re: Moxie Marlinspike Makes Encryption for Everyone
#109I've respected Moxie Marlinspike ever since he made sslstrip, a simple illustration of the fundamental insecurity of browser-based HTTPS. However I do question his premise that criminals already have the wherewithal to opt in to "clunky" strong encryption before engaging in criminal activity. In fact there are many scenarios where criminals simply go with the default security configuration in consumer devices, either…
Besides, it wouldn't kill our LEOs to work for their supper. This reliance on dragnet tactics means that'll soon be all they're able to do.
Re: Moxie Marlinspike Makes Encryption for Everyone
#110Earlier quoted context omitted.
> Not for everyone, their crypto is GPL only and GPL can't be deployed everywhere. GPL code can be used anywhere; GPL code cannot be made proprietary.
Not on Apple's app store.
Apple clearly doesn't understand Copyright law. (or, are trying to poison their competitors with unfair business practices...)