Live data from Hacker News

Technology preview: Sealed sender for Signal

signal.org

11–20 of 162 posts

Re: Technology preview: Sealed sender for Signal

#12
How does signal do media messages? All the time i'll open signal and see someone sent a picture but I have to download it. If signal doesn't store anything on it's own servers but ip and timestamp, where is this media message stored after it's sent but before I received? Am I just downloading it from the device that sent it to me? That would explain why it's so unreliable.

Re: Technology preview: Sealed sender for Signal

#13
I'm not sure I understand the feature. It protects the sender's identity from their servers, or from the recipient? What's the use case / threat model?

I think it prevents their servers from correlating my identity and my IP address etc., but since I want replies and I'm asking the server about replies, doesn't that operation tell the server what my identity is anyway?

(There are some comments here talking about anonymous messages, but that doesn't sound right since the phone number is apparently kept in the encrypted, inner envelope, and also how would you route replies if you didn't have an identity of some sort for the sender?)

Re: Technology preview: Sealed sender for Signal

#14

Here's an idea, Signal, how about removing the requirement that everything be tied to phone numbers? BBM back in the day worked great with their unique "PINs", that could be shared by QR code, and I could reject an "add" request.

Second this. A phone number is tied to an individual. Even though the conversation is secure,it makes targeting easier since the attackers know who is talking to whom(comments on pgp usage and why the NSA loves pgp: https://www.theregister.co.uk/2016/01/27/nsa_loves_it_when_y... ,former NSA chief hayden also made similar remarks).

Let'a say a journalist is targeted by a sophisticated attacker. The attackers want everything on the phone,why just calls and messaging? They won't even attack the protocol,they'll first try putting a RAT in place which will have access to everything. Signal does not promise to protect your communication after your phone is compromised(which only makes sense) but now the attackers don't just have access to your messages but also to your contacts. They now know the journalists sources and contacts by the phone number they used.

Re: Technology preview: Sealed sender for Signal

#15

How does signal do media messages? All the time i'll open signal and see someone sent a picture but I have to download it. If signal doesn't store anything on it's own servers but ip and timestamp, where is this media message stored after it's sent but before I received? Am I just downloading it from the device that sent it to me? That would explain why it's so unreliable.

Signal does store encrypted media on their servers until your client downloads it (and for some time after).

Re: Technology preview: Sealed sender for Signal

#16
post #6

How to fight spam if sender identity is not known? Currently I get at least a few marketing calls a week and don't know how to make them stop other than blocking the numbers.

From the Signal blog post:

> To prevent abuse, clients derive a 96-bit delivery token from their profile key and register it with the service. The service requires clients to prove knowledge of the delivery token for a user in order to transmit “sealed sender” messages to that user.

Re: Technology preview: Sealed sender for Signal

#17

Here's an idea, Signal, how about removing the requirement that everything be tied to phone numbers? BBM back in the day worked great with their unique "PINs", that could be shared by QR code, and I could reject an "add" request.

Wire supports email-only registration at https://app.wire.com (from a desktop web browser). The account can then be used to login from mobile or web.

This approach enables "easy" mode for casual users who prefer phone number registration, while supporting additional privacy for others.

Re: Technology preview: Sealed sender for Signal

#18

Here's an idea, Signal, how about removing the requirement that everything be tied to phone numbers? BBM back in the day worked great with their unique "PINs", that could be shared by QR code, and I could reject an "add" request.

Wire supports email-only registration at https://app.wire.com (from a desktop web browser). The account can then be used to login from mobile or web. This approach enables "easy" mode for casual users who prefer phone number registration, while supporting additional privacy for others.

Yep, Wire is better even just because of this possibility, but even this project is interesting :)

https://briarproject.org/

Re: Technology preview: Sealed sender for Signal

#19
post #13

I'm not sure I understand the feature. It protects the sender's identity from their servers , or from the recipient ? What's the use case / threat model? I think it prevents their servers from correlating my identity and my IP address etc., but since I want replies and I'm asking the server about replies, doesn't that operation tell the server what my identity is anyway? (There are some comments here talking about an…

I think their servers.

(This is my imagination and it might be completely wrong so please feel free to correct me)

they mentioned spam problem which leads me to believe that if enabled, the sending client will encrypt the whole message using the recipient's public key and put all metadata other than recipient's identifier inside this bigger encrypted envelope. The receiver opens this envelope with its key and opens the smaller box inside which contains the sender's metadata.

What we lose now with this is the server does not have much insight into who is sending messages (by design). This means if you allow sealed sender from everyone, someone could send you a lot of messages which you may not like.

Re: Technology preview: Sealed sender for Signal

#20

How does signal do media messages? All the time i'll open signal and see someone sent a picture but I have to download it. If signal doesn't store anything on it's own servers but ip and timestamp, where is this media message stored after it's sent but before I received? Am I just downloading it from the device that sent it to me? That would explain why it's so unreliable.

"Unreliable" - It's not. I've been using it since the early RedPhone and TextSecure days. The only times it's been remotely unreliable is because of my connectivity. I can say I've never had either a lost picture or file sent to me that I can recall. My family and circle of friends (~40 people) use it daily. I just transferred my backup from my old phone to a new one (which by the way thank you for implementing real backups Signal devs!) and I was surprised that my backup sat at over 300 thousand messages. I do leverage many group chats that are repositories of pictures, but I was actually surprised at the volume.

To say Signal is "unreliable" is bull shi*. It's a fantastic product and service that I would gladly pay for but am glad it's free. In the meantime I'll continue to donate as Signal has been very reliable in my years of use.

Post reply on HN