Live data from Hacker News

Messenger systems compared by security, privacy, compatibility, and features

docs.google.com

231–240 of 242 posts

Re: Messenger systems compared by security, privacy, compatibility, and features

#231
post #169

I would like to use Riot/Matrix but its UI (at least on Android) is terrible. I can't convince non-technical friends & family to switch. Part of the problem is the inability to assign nicknames to contacts, so you have to remember everyone's Matrix ID.

Why not use Signal? Better privacy guarantees and the same underlying protocol.

Had the same UI problems.

Also Signal isn't federated and doesn't use the Matrix protocol.

Re: Messenger systems compared by security, privacy, compatibility, and features

#232
post #224

Earlier quoted context omitted.

I don't know that I made any extrodinary claims. You published a spreadsheet listing messaging apps 'ordered by security' in which Signal, Whatsapp and iMessage are shown as way less secure than IRC. It also still says, and you've repeatedly argued here, that things like whether, say, WhatsApp uses E2E encryption is essentially unknowable.

The apps listed in the spreadsheet are clearly sorted by number of features supported (with weights). I don't think OP is necessarily claiming IRC is more secure than Signal.

You are correct. I generalized this as "roughly sorted by security". Some in the list, like Tox, have notable design flaws, but this list is binary and does not account for implementation quality.

This is mostly for discovery of options to consider diving into.

Re: Messenger systems compared by security, privacy, compatibility, and features

#233
post #224
post #219

Earlier quoted context omitted.

I don't know that I made any extrodinary claims. You did ask me if I audited things before and I answered honestly. I frequently report vulnerabilities in a range of open and closed systems and read a lot about those others find. I also don't consider myself an expert and generally distrust people that claim they are in this space because it is, as you say, really hard. I initially started a spreadsheet to document t…

I don't know that I made any extrodinary claims. You published a spreadsheet listing messaging apps 'ordered by security' in which Signal, Whatsapp and iMessage are shown as way less secure than IRC. It also still says, and you've repeatedly argued here, that things like whether, say, WhatsApp uses E2E encryption is essentially unknowable.

IRC is lacking in features but setup correctly with modern OTR I stand by it having easy to reason about security advantages Whatsapp and iMessage do not. (Usability is another story)

Notably if there was a blackbox audit of Whatsapp or iMessage 6 months ago you have no path to easily check if a blatant backdoor was introduced in the build you installed last night. You also can't know if there were obvious flaws in the code the whole time that would be very hard spot in blackbox testing if you didn't know what to look for. Maybe the app build from last night leaks its key intentionally via very subtle steganography in metadata?

Compare to a binary I installed via F-Droid that I can confirm was built reproducibly from a given git head I can go see the code review for.

To use a simple analogy: I can see the exact ingredients of what went into -my- meal instead of what went into the meal of the food inspector.

This allows much deeper release accountability and -is- a major security feature iMessage and Whatsapp lack worth flagging.

Verifying security with source code is hard enough. Without source code it is substantially harder and I for one have no interest in using or recommending security tools that fail to be 100% transparent about how they work.

Without source code all we have are claims that can never be thoroughly verified.

Re: Messenger systems compared by security, privacy, compatibility, and features

#234
post #233
post #224

Earlier quoted context omitted.

I don't know that I made any extrodinary claims. You published a spreadsheet listing messaging apps 'ordered by security' in which Signal, Whatsapp and iMessage are shown as way less secure than IRC. It also still says, and you've repeatedly argued here, that things like whether, say, WhatsApp uses E2E encryption is essentially unknowable.

IRC is lacking in features but setup correctly with modern OTR I stand by it having easy to reason about security advantages Whatsapp and iMessage do not. (Usability is another story) Notably if there was a blackbox audit of Whatsapp or iMessage 6 months ago you have no path to easily check if a blatant backdoor was introduced in the build you installed last night. You also can't know if there were obvious flaws in t…

You keep making this argument and ignoring experts who tell you it is bogus. The whole thread is there for everyone to read; you can pretend you haven't read the rebuttals, but you can't pretend for everyone else. The idea that "without source code we can't thoroughly verify things" is false, and at odds with basically all of modern software security.

Re: Messenger systems compared by security, privacy, compatibility, and features

#235
post #232

Earlier quoted context omitted.

The apps listed in the spreadsheet are clearly sorted by number of features supported (with weights). I don't think OP is necessarily claiming IRC is more secure than Signal.

You are correct. I generalized this as "roughly sorted by security". Some in the list, like Tox, have notable design flaws, but this list is binary and does not account for implementation quality. This is mostly for discovery of options to consider diving into.

He's not correct (as he has since acknowledged!), and you did, and still do, suggest that placement on the chart implies greater or lesser security. You literally included instructions on how to read and use the chart that make that point. "Usability is subjective and people can work down the list to the most secure tool they feel they can comfortably use."

Re: Messenger systems compared by security, privacy, compatibility, and features

#236
post #233
post #224

Earlier quoted context omitted.

I don't know that I made any extrodinary claims. You published a spreadsheet listing messaging apps 'ordered by security' in which Signal, Whatsapp and iMessage are shown as way less secure than IRC. It also still says, and you've repeatedly argued here, that things like whether, say, WhatsApp uses E2E encryption is essentially unknowable.

IRC is lacking in features but setup correctly with modern OTR I stand by it having easy to reason about security advantages Whatsapp and iMessage do not. (Usability is another story) Notably if there was a blackbox audit of Whatsapp or iMessage 6 months ago you have no path to easily check if a blatant backdoor was introduced in the build you installed last night. You also can't know if there were obvious flaws in t…

IRC is lacking in features but setup correctly with modern OTR I stand by it having easy to reason about security advantages Whatsapp and iMessage do not. (Usability is another story)

The fact that you can replace OTR with OTP in this sort of statement and it becomes even truer should tell you what a lousy argument for the practical security of anything it is.

Re: Messenger systems compared by security, privacy, compatibility, and features

#237

Earlier quoted context omitted.

You just said the same thing LVH did, just with more emphasis. It's tough to reason about on a message board. Signal does some important privacy things better than anyone else does; for instance, Signal cares more about metadata that I think any mainstream messenger does. On the other hand, Signal made a conscious, deliberate choice to ensure that it works for ordinary users. It is not a goal of Signal's to mollify t…

You are way out of touch here. Disclosing a phone number is absolutely not a nerd problem and very much a normal people problem. Particularly women or vulnerable people. I don’t even need to warn people about it, they already don’t want to share their phone number with strangers. That’s in spite of them not even knowing a fraction of what a dangerous person can do with your phone number. Journalists and nerds know ho…

The goal is to make messaging secure for everybody who is messaging now. The most popular messaging application in the world already uses phone numbers as identifiers. I understand what a phone number is and why people find them sensitive, but I'm not the person who's out of touch in this debate.

Re: Messenger systems compared by security, privacy, compatibility, and features

#238
post #233

Earlier quoted context omitted.

IRC is lacking in features but setup correctly with modern OTR I stand by it having easy to reason about security advantages Whatsapp and iMessage do not. (Usability is another story) Notably if there was a blackbox audit of Whatsapp or iMessage 6 months ago you have no path to easily check if a blatant backdoor was introduced in the build you installed last night. You also can't know if there were obvious flaws in t…

You keep making this argument and ignoring experts who tell you it is bogus. The whole thread is there for everyone to read; you can pretend you haven't read the rebuttals, but you can't pretend for everyone else. The idea that "without source code we can't thoroughly verify things" is false, and at odds with basically all of modern software security.

Oh, I read them. I simply firmly disagree with them and my personal experience of 15+ years finding and fixing security issues flys in the face of your statements. We clearly test software for bugs very differently.

I made specific arguments and use cases to justify my position and you have simply told me I am wrong without directly addressing them.

Once again, I find the term "expert" overrated. I for one admit I am not an expert on security, a field that is already hard enough on auditors like myself without withheld source code.

I have also worked with a half dozen or so security auditing firms all of which stated source code access would make their job much easier.

It didn't take me hours of blackbox testing for me to find CVE-2018-9057. It took me 20 minutes of reading code on Github half asleep at 4am because I was curious about an unrelated bug.

I remain convinced blackbox testing would of very probably never found that vuln, and even if it did, not in as short of a time period. I trust Terraform over closed alternatives because it was patched within a couple hours of me mentioning it on IRC by a peer who submitted the bug report and patch in one shot. I could verify the source code fix easily and compile the new binary myself to take advantage of the patch before Hashicorp even merged it.

I can also easily verify there are no regressions in future releases.

Tell me how you go about solving for this or other subtle cases like stego exfiltration more easily -without- source code. Also how you or your team could of patched the issue yourself without source code.

If I really solved this the hard way then I will by all means move my security engineering career to focus more on blackbox testing as you seem to be advocating for.

Re: Messenger systems compared by security, privacy, compatibility, and features

#239
post #155
post #147

Earlier quoted context omitted.

The care Signal puts in that actually makes it a better, more secure messenger is primarily about metadata management. Consider how long it took for them to implement profiles, how much time they took to explain how their contact discovery works, et cetera. These are not trivial matters: they got subpoenaed and had nothing to respond with, because they're tried extraordinarily hard not to.

These are problems other tools have solved, without having to resort to a walled garden network or having a SPOF. Sure, maybe Signal has done some useful technicality -legal- protections for now for US citizens, but what happens when a state actor threatens to kill the family of a Signal employee if they don't ship a very subtle compromise in how their binaries source random numbers, or if they don't sell the metadat…

> Also why would people outside the US trust the legal protections afforded to a US company to protect US citizens?

Oh, hello there. The short answer is, of course we don't.

It's a very obvious attack surface that Signal and Whatsapp could avoid if they wanted to. For Whatsapp, being tied to Facebook, I kind of get why they don't (it's mainly that I don't expect them to be better).

But for Signal there aren't any good reasons. I've read various threads (on github and HN?) with Moxie being asked questions about this and I've not heard reasons that satisfied me. On occasion he was even evasive. Now, when the reasons given aren't good enough to explain why to take such a major security affecting decision when there is an obvious better alternative, and Signal seems to be very meticulous about doing the right thing in almost every other area of the protocol and systems around it, then there MUST be another motivation behind the decision that is not stated openly. Maybe it's just something benign left unsaid, who knows?

But even then, the only reasons I can imagine for choosing becoming this huge target, are reasons that are just good for Signal/Whispersystems but meaningless risk to its users.

Re: Messenger systems compared by security, privacy, compatibility, and features

#240
post #238

Earlier quoted context omitted.

You keep making this argument and ignoring experts who tell you it is bogus. The whole thread is there for everyone to read; you can pretend you haven't read the rebuttals, but you can't pretend for everyone else. The idea that "without source code we can't thoroughly verify things" is false, and at odds with basically all of modern software security.

Oh, I read them. I simply firmly disagree with them and my personal experience of 15+ years finding and fixing security issues flys in the face of your statements. We clearly test software for bugs very differently. I made specific arguments and use cases to justify my position and you have simply told me I am wrong without directly addressing them. Once again, I find the term "expert" overrated. I for one admit I am…

It sounds like you're arguing that you'd require source code to see whether something was using math/rand vs. crypto/rand, something that is literally evident in the control flow graph of a program. I do not doubt that source code makes it easier to review code when you're half-asleep at 4 in the morning.

For your particular example: go download a copy of radare and pull up any go build artifact and see for yourself how hard it is understand what's going on.

I don't know about your security engineering career, but if you intend to get serious about vulnerability research, yes, you should learn more about how researchers test shrink-wrap software. I spent years at a single stodgy midwest financial client doing IDA assessments to find vulnerabilities in everything from Windows management tools to storage appliances. It wasn't my IDA license; I was augmenting their in-house security team, which had 4 other licenses. This was in 2005.

Post reply on HN