Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

251–260 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#251

Earlier quoted context omitted.

You can totally run your own server for yourself and your friends: https://github.com/WhisperSystems/TextSecure-Server (you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy) What you won't be able to do is federate with the official servers. Oh, and there's also a WebSocket transport (used by the Desktop client) that doesn't involve Google. That just do…

> you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy I'm sorry, but is this a joke? "To not use a centralized server that you can neither audit nor trust, you have to recompile the client, but that's easy ?" This smacks of "oh, PGP for email is fiiiiiine." To say nothing of the silliness of the inability to federate.

>silliness of the inability to federate

The moment you open the door for federation, the protocol is written in stone forever. All it takes is one server in the federation network with a substantial user base that chooses not to update. (See SMTP).

OWS decided that relinquishing the ability to force updates (i.e. away from a broken cryptosystem) would sacrifice too much in the way of security to be consistent with the project's goals.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#252

Earlier quoted context omitted.

> you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy I'm sorry, but is this a joke? "To not use a centralized server that you can neither audit nor trust, you have to recompile the client, but that's easy ?" This smacks of "oh, PGP for email is fiiiiiine." To say nothing of the silliness of the inability to federate.

>silliness of the inability to federate The moment you open the door for federation, the protocol is written in stone forever. All it takes is one server in the federation network with a substantial user base that chooses not to update. (See SMTP). OWS decided that relinquishing the ability to force updates (i.e. away from a broken cryptosystem) would sacrifice too much in the way of security to be consistent with th…

I understand that. I don't think it's a malicious decision. I think it's a wrong one. I'm not criticizing Whisper Systems, I'm criticizing the tech-priesty stuff out of the post I replied to.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#253
post #186

Earlier quoted context omitted.

You can't run your own signal server. All accounts use phone numbers in the same namespace as ID, and all messages go from the phone to opensystems.org, further on to google, and from google to the destination phone (with lots of encryption being added and removed at various points). This has advantages (it's difficult for the Man distinguish a received signal message from other android notifications) but also disadv…

You can totally run your own server for yourself and your friends: https://github.com/WhisperSystems/TextSecure-Server (you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy) What you won't be able to do is federate with the official servers. Oh, and there's also a WebSocket transport (used by the Desktop client) that doesn't involve Google. That just do…

Distributing a modified client is non-trivial, especially if any of your friends use iOS.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#255

Earlier quoted context omitted.

You can totally run your own server for yourself and your friends: https://github.com/WhisperSystems/TextSecure-Server (you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy) What you won't be able to do is federate with the official servers. Oh, and there's also a WebSocket transport (used by the Desktop client) that doesn't involve Google. That just do…

> you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy I'm sorry, but is this a joke? "To not use a centralized server that you can neither audit nor trust, you have to recompile the client, but that's easy ?" This smacks of "oh, PGP for email is fiiiiiine." To say nothing of the silliness of the inability to federate.

uh... do you even know what the PG in PGP stands for?

"fiiiiiine" is better than they claim to offer.

idiot.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#257
post #104
post #78

Earlier quoted context omitted.

I'd argue that WhatsApp and FBM adopting signal have been some of the highest-impact movements toward resistance of mass surveillance, largely due to sheer numbers and accessibility. Sure, there is room for improvement, but having 0.000001% of t he population using an ultra-secure messenger doesn't have the same impact. And hopefully those improvements will happen in time.

The point is that metadata is more valuable for mass surveillance purposes than content. WhatsApp and FBM do nothing to protect metadata.

Er, no.

Mass surveillance wants both metadata and content. Metadata happens to be a bit easier to analyse, but often they are only analysing metadata to lead them to the content in the first place.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#258

Earlier quoted context omitted.

Rogue browser plugins can be discounted as that's tantamount to a compromised device in the context of a downloaded E2EE app. MITM, well it's E2EE with trust-on-first-use for the crypto logic and implements the works when it comes to web security protocols, such as HPKP. There's enough mitigation there. TOFU in this context would mean once you visit once, the logic that's pinned in the browser then performs signature…

This is a weird response. The comment you replied to suggested (very accurately) that there are lots of different ways that browsers leak information, and gave the example of rogue plugins. You (accurately) dismiss rogue plugins, and then go on to write as if that were the only, or even the most important, vector for leaks. But, obviously, no. Can you cite some other ways browsers leak information besides browser plu…

Why not. Replying via email.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#259
post #204

Earlier quoted context omitted.

You can totally run your own server for yourself and your friends: https://github.com/WhisperSystems/TextSecure-Server (you'll have to change the server's URL in the client's source as well and compile it yourself, but that's really easy) What you won't be able to do is federate with the official servers. Oh, and there's also a WebSocket transport (used by the Desktop client) that doesn't involve Google. That just do…

Yeah, so instead of being in Whisper Systems' walled garden, I can set up my own and ask people to install Rvense's Magical Messenger App. Sit there in my treehouse with a bucket on my head and a NO DUMMIES sign or something.

Seems like you want the advantages of both centralization and federation without any of the disadvantages.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#260
post #204

Earlier quoted context omitted.

Yeah, so instead of being in Whisper Systems' walled garden, I can set up my own and ask people to install Rvense's Magical Messenger App. Sit there in my treehouse with a bucket on my head and a NO DUMMIES sign or something.

Seems like you want the advantages of both centralization and federation without any of the disadvantages.

[deleted]
Post reply on HN