Live data from Hacker News

Facebook Messenger begins testing end-to-end encryption using Signal Protocol

whispersystems.org

291–300 of 312 posts

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#291
post #144

Earlier quoted context omitted.

One would hope that the founder of the company trying to bring that weird secure caching attempt to market would believe that it wasn't very complicated. :) Of course, if you've filed for patents on this, as was suggested upthread, that somewhat cuts against that argument, doesn't it?

lol, I'm definitely biased given that I'm long since familiar with the idea and wrote the implementation, but I think it's more conceptually counterintuitive/clever/weird than it is actually complicated in terms of having many moving parts. WebSign does have a patent pending on it (I think it's fair enough to say that the whole system of accomplishing in-browser code signing this way was non-obvious), but HPKP Suicid…

> WebSign does have a patent pending on it (I think it's fair enough to say that the whole system of accomplishing in-browser code signing this way was non-obvious),

Yay, another technology to boycott entirely.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#292
post #83

Earlier quoted context omitted.

There's no way for a site to securely store keys in the browser. The server can't put them there because then the server would have them too. A client-side script could generate them, but it can't store them without extensions (or the server via some JS it sends) also having access to them. This is why Signal and WhatsApp require the client to run on the phone - the phones are doing the decryption for the web apps. T…

Server would have the keys _because_ the client-side code can send it to the server. That's also possible in the native app, isn't it?

The apps are updated relatively infrequently, and you can put off updating to see if problems are found with each release. In the browser, you'd have to analyze every script Facebook ever sends you to see if it's exfiltrating your key.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#293

Earlier quoted context omitted.

Hundreds of millions use Messenger from a web browser. No secure way to verify code or store keys without routing through mobile. I wouldn't use the web version if they had not disabled Jabber access... and then I could use OTR. This trend makes me very sad... IM networks are getting more centralized as ever. I don't feel thankful for this kind of development. End-to-end encryption should not be a feature of the serv…

Enabling interoperable chat to non-nerdy friends is basically Matrix's raison d'être. We're not there yet (see https://matrix.org/blog/2016/07/04/the-matrix-summer-special... for the current status), but if we don't provide it we will have failed in the whole mission to defragment these silos, letting users choose which service to trust without losing interoperability. The good news is that the Olm end-to-end cryptog…

Sorry if this is a stupid question, can I store chat logs of all (even encrypted) conversations locally?

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#294
post #159
post #89

Now that the Signal Protocol is deployed in so many different places, is there a proper specification of the (current) protocol? (The old axolotl spec and the GPL implementation don't qualify) What are the licensing conditions / restrictions for using the protocol?

https://github.com/whispersystems/libsignal-protocol-c#licen...

Sorry, but an implementation is not a specification. It is not only much harder to read, but it is also a moving target. It is borderline impossible to make an independent implementation of the protocol this way.

Besides, the fact that it is licensed under the GPL might mean that somebody porting the protocol to a different platform / language might be creating a "derived work" which also must be licensed under the GPL.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#295

Earlier quoted context omitted.

It's also one hell of a loaded term with things like Heavens Gate and Jim Jones having existed. To my knowledge, Facebook has yet to cause a mass suicide by people worshiping Zuckerberg.

Facebook has convinced millions of people to give up vast amounts of private information to an apparatus that would make the Stasi or KGB drool. Part of cult indoctrination is giving up personal and private information, documents, secrets and property to participate and become part of the whole. Meanwhile, leaders profit from the property and information given up and use secrets to blackmail or breakdown an individua…

Yes yes yes, make your descriptors fuzzy enough and you can compare anything with anything else.

Here's a list of actual cult characteristics [1]. The comparison is an idiotic one to make.

[1]: http://www.anandainfo.com/cult_checklist.html

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#296
post #293

Earlier quoted context omitted.

Enabling interoperable chat to non-nerdy friends is basically Matrix's raison d'être. We're not there yet (see https://matrix.org/blog/2016/07/04/the-matrix-summer-special... for the current status), but if we don't provide it we will have failed in the whole mission to defragment these silos, letting users choose which service to trust without losing interoperability. The good news is that the Olm end-to-end cryptog…

Sorry if this is a stupid question, can I store chat logs of all (even encrypted) conversations locally?

On the serverside (which may be "local" depending on where your server is running), the history for the rooms you participate in is stored as a matter of course. Matrix operates by replicating that history between the servers participating in the conversation. If that history is e2e encrypted, any device with the necessary cryptographic ratchet state can decrypt it. (Note that rooms may be configured to change ratchet frequently to deliberately stop history being decrypted multiple times, providing a form of PFS).

On the client side, it depends on the client you're using. Many native Matrix clients and many bridged clients give the option to store local history (whether it was originally encypted or not). Smarter clients will store it encrypted at rest by whatever mechanisms the OS and hardware provides.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#298
post #256

How susceptible is this Signal Protocol to a man-in-the-middle attack? Because if Facebook is going to be the man in the middle, then this feature is pointless.

Here Facebook isn't even a man-in-the-middle. They are a 'man-on-the-box'. They get to generate the nonces, keys, etc.

It's pointless to add encryption if Facebook is your root of trust.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#299
post #133

Earlier quoted context omitted.

> I am not usually one for paranoia, but is anyone else becoming more suspicious about Facebooks motivations and involvement with gov? I worked for Facebook; I am friends with the people who developed this: I would like to reassure you strongly (well, as much as an Internet stranger can) on their motives. They are the good guys, and this was develop with people being spied on by abusive governments in mind — because…

This might sound offensive, but please don't take it that way, I just don't know how else to phrase it: I have no reason to trust you, or them. Just because you think people have good motives, doesn't mean it's true. I'm sure there are great people working there, but I'm also sure there are shady people working there. Just like at any big org. "Even though you don't know me, trust me, these guys are cool" arguments d…

Of course I won’t be offended — that’s why I wrote, if that mattered to you, to reach out to them. Although, as someone pointed out, that feature was developed by a team mostly in London.

Re: Facebook Messenger begins testing end-to-end encryption using Signal Protocol

#300

Earlier quoted context omitted.

What if he's scored as a threat and reported to the FBI? A human can understand sarcasm, jokes, or hyperbole. An algorithm is going to see scary words and add them to the 'dangerous' score.

> What if he's scored as a threat and reported to the FBI? Then he'll be referred to a human, who may or may not understand sarcasm, jokes, or hyperbole?

'May not' seems likely, we are talking about the FBI after all ;)
Post reply on HN