Live data from Hacker News

Keybase Exploding Messages

keybase.io

31–40 of 155 posts

Re: Keybase Exploding Messages

#33
post #20
post #9

Earlier quoted context omitted.

It is impossible to implement this feature "safely" even with trusted clients -- worst case I take a screenshot or even a photograph of the device displaying the message before it explodes. If you don't trust the person at the other end, this is never going to work. It's more useful for "we both agree that we don't want a paper trail" kind of thing.

A dead simple way to thwart the “screenshot” attack is to release a tool for accurately falsifying a screenshot. I’ve never seen this employed in practice though.

Photo, audio, and video evidence should already be dismissed until one is able to verify the integrity and source. All of these can already be believably faked - it's just a matter of educating people that a layperson can easily create fake things by using tools developed by research teams.

Fake text is the easiest to fake if you can identify the font used - any image editor will work. HN uses 9pt Verdana, even without using dev tools I could fake your post to say anything I wanted it to say since it would just be 9pt Verdana on a solid background set to text wrap every 1050px.

See: https://www.youtube.com/watch?v=ohmajJTcpNk & https://www.youtube.com/watch?v=AmUC4m6w1wo

Re: Keybase Exploding Messages

#34
post #20
post #9

Earlier quoted context omitted.

It is impossible to implement this feature "safely" even with trusted clients -- worst case I take a screenshot or even a photograph of the device displaying the message before it explodes. If you don't trust the person at the other end, this is never going to work. It's more useful for "we both agree that we don't want a paper trail" kind of thing.

A dead simple way to thwart the “screenshot” attack is to release a tool for accurately falsifying a screenshot. I’ve never seen this employed in practice though.

Apps do screenshot detection but again nothing beat the old Polaroid.

Any DLP or DRM can be circumvented using analog means.

Re: Keybase Exploding Messages

#35
post #20

Earlier quoted context omitted.

A dead simple way to thwart the “screenshot” attack is to release a tool for accurately falsifying a screenshot. I’ve never seen this employed in practice though.

How is any bitmap editor not such a tool?

I think they're talking more along the lines of those online meme editors. Yea i could download the lion king and clip the frame with simba and then pull it into photo shop and then add text and then upload it to imgur. Or I could go one of those online meme editors in click the photo and enter my text and then get a link to the meme I made.

The whole point is to totally lower the bar for anyone to make a passable copy, thus removing all confidence that any screen shot is genuine.

Re: Keybase Exploding Messages

#38
Author here. I'm seeing the same comment in 4 different places on here, worded with various amounts of hostility. I now wish I had addressed this in the FAQ on the post.

There's the suggestion that an exploding feature is worthless, given your partner can just take a screenshot or video of what you sent.

This suggestion is missing (1) that your relationship with a partner is disproportionately okay at the time you sent something (i.e., you trust them THEN) and (2) there's a whole different class of adversary who compromises your or your partners' devices in the future.

SnapChat, as far as I know, has none of the cryptographic implementation of Keybase. And yet it has likely protected hundreds of thousands of kids from severe bullying. Consider the teen girl who sends the goofy sexy pic to her boyfriend. Before the advent of exploding messages, he might've iMessaged or emailed that to a friend, just one friend, his best friend, out of pride. And that friend sent it to a few more, and so on. Not out of malice, but suddenly the whole school has seen her pic of god knows what and she literally wants to die. But with Snapchat, taking a screenshot is knowingly violating a social agreement. It's also violating the trust of his current girlfriend - everyone knows it's not okay to screenshot that shit. And the number of people who would do that is much tinier. Second, consider the far worse scenario: she dumps him a month later and until then he has been NiceGuy. But then he becomes r/niceguy, the guy who will look through the old pictures and spread them around.

Finally, let's not forget that your device can be compromised by loss, theft, or hackers, at any time. Exploding messages are gone when that happens.

People can be tricked, compelled, coerced, blackmailed, and hacked. Or just turn evil. All in the future. Which is what a timed message protects against. This is why Keybase is doing this. Paired with encryption it's quite powerful.

Re: Keybase Exploding Messages

#39
post #21
post #9

Earlier quoted context omitted.

It is impossible to implement this feature "safely" even with trusted clients -- worst case I take a screenshot or even a photograph of the device displaying the message before it explodes. If you don't trust the person at the other end, this is never going to work. It's more useful for "we both agree that we don't want a paper trail" kind of thing.

Absolutely - That's my understanding as well. There are ways to mitigate (snapchat detects screenshots, etc) but no way to fully prevent - Someone could always use an external camera, etc. I was just really hoping that they had come up with some sort of cool technical way to stop the ability to decode messages after XYZ time, even if they couldn't prevent it from being copied once decoded. For example, imagine if a m…

I think the solution is pretty simple: encrypt with a one-time pad and then store the pad in a box that will burn that pad at your desired time; make sure no one can ever see the pad and your secret will be pretty safe.

Re: Keybase Exploding Messages

#40

This is like snapchat, they're offering something that they can't actually guarantee. Of course keybase users are going to be generally more knowledgeable than snapchat users and most will understand the limitations.

It's still better to delete the message than to leave it there "because you can't guarantee it 100% either way". Defense in depth.
Post reply on HN