Live data from Hacker News

Technology preview: Private contact discovery for Signal

signal.org

131–140 of 169 posts

Re: Technology preview: Private contact discovery for Signal

#131

While they are at it, Signal should improve SMS integration capabilities as well. If Signal is used as default SMS client (Which IMO is a good use case), the search implementation is by far the worst search implementation ever on the application. Searching local SMS DB shouldn’t be security concern, Android’s SearchView should basically do it by itself. I haven’t looked through their code yet, there’s minor possibili…

> Searching local SMS DB shouldn’t be security concern

Actually, it is, since Signal encrypts your messages and only decrypts them when the app is "open". See http://esl.cs.brown.edu/blog/signal/ and See https://github.com/WhisperSystems/Signal-Android/issues/1232...

Re: Technology preview: Private contact discovery for Signal

#132
Wait, but the Signal Server does not need to store the contact graph, it stores only (some of) its vertices. Moxie wants to make it hard for somebody to learn about the edges from the way clients ask whether a vertex is in signal's subgraph of the social graph.

Why don't the clients simply use Tor to retrieve information about the numbers they're interested in? To avoid the server from using the time of the requests to correlate them, you could let the clients sleep a random amount of time in between requests, and sometimes request information they already have. Maybe you could even ask volunteers to spam the server with nonsense requests, so that the genuine requests are drowned in this noise.

Re: Technology preview: Private contact discovery for Signal

#133

Earlier quoted context omitted.

In case someone from Open WhisperSystems is reading: please do NOT add stickers and junk to your clean and pretty system. I know a lot of people that would leave the service if it turned into WeChat (including me). Stick to the fundamental engineering of privacy as you are doing, and forget the gimmicks.

I don't understand your motivation here. Every time I advocate using Signal I run into a wall of "but it doesn't have stickers"; for those users, all the privacy engineering is moot if the app doesn't fill their needs. Adding another attachment type would do nothing to degrade your experience, nor would it turn Signal into WeChat.

What do you imagine is the point of proselytizing the use of secure apps to people for whom this is a concern that would override security? They aren't likely to adhere to secure practices anyways, so it's moot.

Re: Technology preview: Private contact discovery for Signal

#134

Earlier quoted context omitted.

In case someone from Open WhisperSystems is reading: please do NOT add stickers and junk to your clean and pretty system. I know a lot of people that would leave the service if it turned into WeChat (including me). Stick to the fundamental engineering of privacy as you are doing, and forget the gimmicks.

> I know a lot of people that would leave the service if it turned into WeChat (including me). Where will they go? To some less secure alternative simply because of stickers?

To some equally secure alternative not bloated down by useless cruft, I'd imagine

Re: Technology preview: Private contact discovery for Signal

#136
post #18

I don't really understand why this is an improvement on the existing architecture. In the current contact discovery implementation you need to fully trust the server, namely the open source component that is the contact discovery service. In this proposed new implementation, you still have to trust the server; you need to trust closed source processor hardware offering the Software Guard Extensions. Those extensions…

And you still need to trust the client. There is nothing stoppting them from slipping you a compromized client via Android Play Store update.

The only way around this would be to have many implementations - but AFAIK they don't allow third party clients to connect.

Re: Technology preview: Private contact discovery for Signal

#137
post #47
post #38

Earlier quoted context omitted.

Well, it is a major step – but Moxie always sells his solutions, even if they’re just a puppy, as solutions for world hunger. As I mentioned, advertising with Snowden leads to a promise that Signal can not fulfill. Not even with this. But, you know, there is already a solution for all the issues here: Don’t use phone numbers, use usernames! As it turns out, that is far more private and secure.

> Don’t use phone numbers, use usernames! As it turns out, that is far more private and secure. It is. But it's not convenient. Everyone has contact list with numbers and people want to talk to their friends immediately not call them for their ID for service X.

Everyone?

I've got basically no phone numbers of many of my friends, or they've switched them so often that the ones I have are long wrong. Half the numbers in my contacts list don't exist anymore.

I certainly prefer usernames.

Re: Technology preview: Private contact discovery for Signal

#138
Why don't they just use hashed pairs of telefone numbers for discovery? I'm more worried that they have my whole telefone contact list, than that they know with whom I am chatting. They could probably find out the latter by manipulating the client anyway.

Also, don't they neccessarily have a mapping of telefone number -> IP address? They could just show all contacts, and attempt to send if you write to somebody. If they want to only show mutuals, use the hashed pairs to get the IP address (or ID, or status, or whatever they need).

I don't want to be too negative, but this seems to me like an unnecessary complex solution to a problem I don't have. I'd rather have the option to register anonymously, or to use alternative clients and servers.

Also, as a layperson, they could be making all of this up and I would never be able to tell. Somebody could have bought or coerced a couple of security experts that I know and trust, and I would never be able to find out. So, in a sense, a dumber and less secure solution might actually be better...

Re: Technology preview: Private contact discovery for Signal

#139
I cringed in anticipation of the HN comments on this one.

Cue the inevitable HN complaints that it's not perfect security, that you still have to trust your CPU manufacturer, that the app permissions are too invasive, that it uses phone numbers as identifiers, and that it runs on Google play services.

Pull your head out of the trees and look at the forest: humanity desperately needs privacy herd immunity, and you are taking the part of digital anti-vaxxer.

Signal is one of the best options available for privacy: thoughtfully architected by a leader in the field, reliable, with a good UI and reasonable adoption, and genuinely open source. People NEED an alternative to Facebook messenger, Facebook WhatsApp, closed source Viber and Telegram, and carrier SMS. By refusing to recommend this extremely good, strong contender, you are actively hurting the causes of privacy and open source. Stop being a digital anti-vaxxer.

If you have complaints, submit a PR or make a compatible fork. But stop discouraging people from protecting themselves.

Or alternatively: if you're going to be a digital anti-vaxxer, hit up Facebook, Google, or the NSA to see if they'll send you a paycheck for it. Because doing their jobs for free is just dumb.

Re: Technology preview: Private contact discovery for Signal

#140

I cringed in anticipation of the HN comments on this one. Cue the inevitable HN complaints that it's not perfect security, that you still have to trust your CPU manufacturer, that the app permissions are too invasive, that it uses phone numbers as identifiers, and that it runs on Google play services. Pull your head out of the trees and look at the forest: humanity desperately needs privacy herd immunity, and you are…

I agree with your message but you're way too harsh. At least these guys, unlike antivaxxers, have genuine concerns. Maybe they're not considering the even worse alternatives in their comments, but then again, that's not really their business. Signal isn't losing users because a couple of nerds are pointing out weaknesses in its security.
Post reply on HN