Live data from Hacker News

Technology preview: Private contact discovery for Signal

signal.org

151–160 of 169 posts

Re: Technology preview: Private contact discovery for Signal

#151
post #145

I cringed in anticipation of the HN comments on this one. Cue the inevitable HN complaints that it's not perfect security, that you still have to trust your CPU manufacturer, that the app permissions are too invasive, that it uses phone numbers as identifiers, and that it runs on Google play services. Pull your head out of the trees and look at the forest: humanity desperately needs privacy herd immunity, and you are…

> People NEED an alternative to Facebook messenger, Facebook WhatsApp, closed source Viber and Telegram In a broad sense, they don't actually - being pretty much happy with all these messengers.

Telegram is not closed source. Unless they mean the server.

And in terms of server, Signals is "open source" but you can't run one yourself so how can you be sure really. :\

Re: Technology preview: Private contact discovery for Signal

#152
post #151
post #145

Earlier quoted context omitted.

> People NEED an alternative to Facebook messenger, Facebook WhatsApp, closed source Viber and Telegram In a broad sense, they don't actually - being pretty much happy with all these messengers.

Telegram is not closed source. Unless they mean the server. And in terms of server, Signals is "open source" but you can't run one yourself so how can you be sure really. :\

You're right, but I mean there's no messenger problem at all for vast majority of the people, and privacy and security aren't features people tend to choose over any other feature.

Re: Technology preview: Private contact discovery for Signal

#153
post #51
post #50

Earlier quoted context omitted.

The two users are two folks who wish to communicate who hold their phones back-to-back and let NFC validate who they each are. Both parties are now able to perform a private set intersection to find people whom they know in common who also use Signal, and are able to then use private set intersection with each of those people to find more. The idea is that users bootstrap via the social graph of folks they physically…

So you want to completely punt on the "open the app to an empty contact list" problem and force people to perform what's effectively a GPG keysigning party... Call me crazy, but I think that'd be a bad user experience of the sort that held back encrypted messaging for decades.

> So you want to completely punt on the "open the app to an empty contact list" problem and force people to perform what's effectively a GPG keysigning party...

I want to protect people's contact lists.

What's more, Signal's current solution doesn't actually address the problem: the vast majority of people who install Signal will open up the app and see … an empty contact list. Why? Because the vast majority of the human race doesn't use Signal. So what do folks who use Signal have to do? Ask their friends to install it, and register it. Which isn't appreciably different from asking a friend to install Signal, and text/email/NFC one his contact information.

Yes, once a cluster of people have installed it, the contact-sharing functionality becomes useful. So, too, would friend-of-a-friend contact sharing.

> Call me crazy, but I think that'd be a bad user experience of the sort that held back encrypted messaging for decades.

Since that's still the user experience of Signal, and Signal is pretty popular, I don't really think it's a problem.

I use Signal. I like Signal, a lot. I respect Moxie Marlinspike's crypto chops. But I wish he had more respect for privacy, and didn't require us all to trust in his good intentions.

Re: Technology preview: Private contact discovery for Signal

#154
post #86
post #50

Earlier quoted context omitted.

The two users are two folks who wish to communicate who hold their phones back-to-back and let NFC validate who they each are. Both parties are now able to perform a private set intersection to find people whom they know in common who also use Signal, and are able to then use private set intersection with each of those people to find more. The idea is that users bootstrap via the social graph of folks they physically…

The whole point is finding out which of your contacts are already on Signal. What benefit do you get out of performing set intersection on the contacts lists of 2 users? That sort of thing is done to find your "mutual friends", but I don't see why a messaging service like Signal cares about mutual friends.

> I don't see why a messaging service like Signal cares about mutual friends.

Signal doesn't care; users care about mutual friends.

Here's an example:

- Alice installs Signal². She has many contacts, and doesn't know which contacts also use Signal². Notably, she doesn't want to give the Signal² servers all of her contacts.

- Alice asks Bob to install Signal². He does, and they trade key information (e.g. via SMS, email, NFC — whatever) and their phones use private set intersection to discover that they have Charlie, Diana & Ed in common. None of those guys has Signal² installed yet, so far as Alice or Bob know.

- Alice asks Charlie to install Signal². He does, they trade key information, and they see that they have Bob, Frank & Gene in common. Charlie gets (what Alice says is) Bob's public key, without contacting Bob directly.

- Charlie's phone contacts Bob's phone, and discovers that they have Alice in common; Charlie's phone validates that Bob's claim of Alice's key matches what he verified himself.

- Bob asks Diana to install Signal². She already has it, so all they need to do is exchange keys and discover mutual contacts. They both know Alice & Ed — and Diana is able to give Bob Ed's public key (it turns out that, unbeknownst to Alice or Bob, he's been using Signal² for months). Bob's phone can then share Ed's public key with Alice in another round of set intersection.

- Diana's phone can also share Ed's public key with Alice, now that she knows Alice's contact information. Alice's phone now has two different people attesting to Ed's public key; if they agree, that's good and if they disagree then her phone can give her a warning. She can contact Ed out-of-band if she chooses. This is an improvement on the current Signal protocol, since Alice has a chance to detect a malicious attestation without having to manually compare keys with Ed.

Note the user experience: as each user starts using Signal², his social network is used to share the contact information of his circles of friends. Users are incented to be truthful, since lying will be easily detected. The Signal² servers never see users' contacts; they don't even need to know users' real-world identities.

Just as in current Signal, each Signal² user is introduced to the program by a friend. Just as in the current Signal, users discover contacts who use Signal². Now, it's not identical: users won't see contacts who use Signal but have no mutual friends in common. This is indeed a cost — but it comes with the benefit of not needing to trust OWS.

Re: Technology preview: Private contact discovery for Signal

#155

I cringed in anticipation of the HN comments on this one. Cue the inevitable HN complaints that it's not perfect security, that you still have to trust your CPU manufacturer, that the app permissions are too invasive, that it uses phone numbers as identifiers, and that it runs on Google play services. Pull your head out of the trees and look at the forest: humanity desperately needs privacy herd immunity, and you are…

This particular change on private contact discovery looks like a great initiative, like many others by Signal.

I'm all for privacy and security. That said, I like the idea of Signal, but don't use it at all. The reasons are straightforward. It's not as good as Telegram in UX/UI/features. It is not multi-platform (I don't like installing Chrome/Chromium just to add Signal). Worst of all, it doesn't have multi-device message sync (like Wire does, even with end-to-end encryption).

Ok, fine, I could learn to live with those limitations and quirkiness. But far worse than all of the above is the fact that if you change devices (at least on iOS), you start with a blank slate [1] because Signal's developers refuse to allow data backups and restores (encrypted ones through iTunes on a computer or plain backups on iCloud). [2] The application does not allow backups of the data because the developers have actively restricted it! Not everyone is capable of creating a PR or forking it. The people who did take the time to file it as an issue or a request have been told it won't be done or the issues left unresponded to or locked for further commenting. Anyone interested in what's been happening on this particular issue can visit https://github.com/WhisperSystems/Signal-iOS/issues , search for "backup" and look at the open and closed issues over the past few years.

I feel bad to say this, but without a minimally decent UX, which Signal does not provide IMO, I can't recommend it to anyone. People don't expect to lose all previous chats and conversations when they buy a new phone. Quoting a line from the blog post, albeit out of context, that's not "We want to enable online social interactions that are rich and expressive in all the ways that people desire" means - not to me personally.

[1]: https://support.signal.org/hc/en-us/articles/212476798

[2]: https://github.com/WhisperSystems/Signal-iOS/issues/2290

Re: Technology preview: Private contact discovery for Signal

#156
post #149

Earlier quoted context omitted.

Everyone? I've got basically no phone numbers of many of my friends, or they've switched them so often that the ones I have are long wrong. Half the numbers in my contacts list don't exist anymore. I certainly prefer usernames.

Clearly you're not the target market for Signal but there are many encrypted messangers out there for you.

I'm not so sure about that. Matrix is the closest thing, and that has a code quality that makes me want to puke.

EDIT: Before I get complaints from the Matrix devs again that I’m bad-mouthing their app: ObjectOutputStream is NOT a suitable implementation for a "database": https://github.com/matrix-org/matrix-android-sdk/blob/736643...

Re: Technology preview: Private contact discovery for Signal

#157
post #7
post #3

> clients will be able to efficiently and scalably determine whether the contacts in their address book are Signal users without revealing the contacts in their address book to the Signal service. This should be the fucking defacto standard! We really need Privacy-as-a-service and security-as-a-service

> We really need Privacy-as-a-service and security-as-a-service We can provide food-as-a-service, but we can't provide digestion-as-a-service. Which is to say, we can provide many useful services but privacy and security are things that can't be outsourced, just like you can't hire someone to digest your food for you. They require deep integration and planning, and they're difficult to pull off in the best of cases.…

hmm... I like your insight - thank you.

Re: Technology preview: Private contact discovery for Signal

#158
post #154
post #86

Earlier quoted context omitted.

The whole point is finding out which of your contacts are already on Signal. What benefit do you get out of performing set intersection on the contacts lists of 2 users? That sort of thing is done to find your "mutual friends", but I don't see why a messaging service like Signal cares about mutual friends.

> I don't see why a messaging service like Signal cares about mutual friends. Signal doesn't care; users care about mutual friends. Here's an example: - Alice installs Signal². She has many contacts, and doesn't know which contacts also use Signal². Notably, she doesn't want to give the Signal² servers all of her contacts. - Alice asks Bob to install Signal². He does, and they trade key information (e.g. via SMS, ema…

Users also won't see contacts who use Signal and do have mutual friends in common, but who simply haven't used Signal to talk to those mutual friends.

Your solution is certainly better than nothing, but it relies on people having actually used Signal to talk to each other in the past. It also appears to involve a lot of P2P coordination. And while it may not share contacts with the Signal servers, it does leak your address book to all of your friends, with potentially serious consequences ("hey, why does Alice have my therapist in her address book?", "Bob told me he erased Carol from his life! Why does he have Carol's key?", etc).

Re: Technology preview: Private contact discovery for Signal

#159

Earlier quoted context omitted.

I don't understand your motivation here. Every time I advocate using Signal I run into a wall of "but it doesn't have stickers"; for those users, all the privacy engineering is moot if the app doesn't fill their needs. Adding another attachment type would do nothing to degrade your experience, nor would it turn Signal into WeChat.

What do you imagine is the point of proselytizing the use of secure apps to people for whom this is a concern that would override security? They aren't likely to adhere to secure practices anyways, so it's moot.

Moxie has stated in the past that the goal of Signal is not to cater to "security people" but to "make mass surveillance impossible".

Re: Technology preview: Private contact discovery for Signal

#160
post #151
post #145

Earlier quoted context omitted.

> People NEED an alternative to Facebook messenger, Facebook WhatsApp, closed source Viber and Telegram In a broad sense, they don't actually - being pretty much happy with all these messengers.

Telegram is not closed source. Unless they mean the server. And in terms of server, Signals is "open source" but you can't run one yourself so how can you be sure really. :\

[deleted]
Post reply on HN