Live data from Hacker News

Technology preview: Sealed sender for Signal

signal.org

151–160 of 162 posts

Re: Technology preview: Sealed sender for Signal

#151

Without cover traffic, its not clear to me that this would prevent a correlation attack from an adversary with resources.

I feel like the bar is constantly being raised. Which messengers provide cover traffic? To my knowledge it is only pond, which has been discontinued. Pond was limited to text at about 5kB/s. Sustained connections is not suitable for mobile phones, and unless you sustain a data flow or introduce random delays correlation attacks will always be possible.

Signal could probably force TOR connectivity (forcing websockets for those connections), which would conceal the sender even more, but would not stop correlation attacks.

This also wasn't made to stop correlation attacks. This is a measure to reduce metadata being stored on the server. Messages stored on the server won't have a "from" label that can be read by the server.

Re: Technology preview: Sealed sender for Signal

#152
post #25

Earlier quoted context omitted.

No mainstream messenger has ever done a better job with metadata than Signal. It took Signal several years after launch just to get user profiles with names and stuff, purely because of privacy concerns. Read the blog post they wrote about GIF sharing to get a sense of how seriously they take this, then compare how their features work to other mainstream messengers. There is one privacy issue people put pressure on S…

Briar is leading the field on privacy issues today, unlike Signal. There is no metadata leaking who you are sending messages to or from, just a connection to the Tor Network. This problem is still unsolved in Signal, with only partial protection of some messages looking to be added in the future, while mitigation tactics like running your own server are unsupported & discouraged by Open Whisper Systems. The post abou…

I have been trying to understand some things about briar. Their threat model document states that an attacker on the same network can actually see the to/from metadata. How does this work in relationship to tor?

I want to use it, but I haven't been able to get it to work reliably, so I haven't started trying to convert people.

Re: Technology preview: Sealed sender for Signal

#153
post #98

Earlier quoted context omitted.

As a previous user of a program that uses phone numbers as identification you stopped using Signal because you discovered that it uses phone numbers as identification?

Yes. More precisely, I stopped when I discovered that I couldn't decouple the signal user from my phone number. More importantly, I'm still very interested in seeing the data behind your vocal-minority assertion.

The survey data you are looking for is WhatsApp.

Re: Technology preview: Sealed sender for Signal

#154

Earlier quoted context omitted.

I think this issue is more complicated than people realize. There are really only three options here: 1. Use the device's address book (phone numbers). 2. Use Facebook Connect (FB id). 3. Store the entire social graph on the server (custom identifiers). I think #3 is what every messenger that offers non-phone identifiers does (Snapchat, Twitter, Telegram, Wire, Viber, etc). The reason is simple: if someone does manag…

It can be stored on the server, and encrypted by the users' private key. Like a message to himself.

That doesn't solve the case for when you get a new device or reinstall the app. Any keys you had are lost.

Re: Technology preview: Sealed sender for Signal

#155

Earlier quoted context omitted.

I don’t buy the UI for discovery thing. Email is fine without discovery. So are.. phone numbers. I don’t want to be discovered. I want to give you my pseudonymous pointer and you can ping me to connect. Using phone numbers to ‘discover’ doesn’t solve the problem you say prevented encrypted email adoption, that’s a next step in the dance.

What exactly do you not buy? I think you might be missing the point on what is meant by discovery here. This is not about random strangers talking to you, but about the issue that you have signal, your friend has signal, but even though you're already in each others phone books you can't talk to each other because you haven't exchanged pseudonymous pointers. There are exactly two pseudonymous identifiers that have "m…

> I think you might be missing the point on what is meant by discovery here. This is not about random strangers talking to you, but about the issue that you have signal, your friend has signal, but even though you're already in each others phone books you can't talk to each other because you haven't exchanged pseudonymous pointers.

On the contrary, this is precisely the discovery many users do not want. 1. Someone you know can discover you’re using this channel. 2. You can’t use the same channel both overtly and with deniability. I should be able to have as many faces for speech as I choose.

Re: Technology preview: Sealed sender for Signal

#156
post #153

Earlier quoted context omitted.

Yes. More precisely, I stopped when I discovered that I couldn't decouple the signal user from my phone number. More importantly, I'm still very interested in seeing the data behind your vocal-minority assertion.

The survey data you are looking for is WhatsApp.

I don't see how. Could you explain?

Re: Technology preview: Sealed sender for Signal

#157
post #23

Two observations: 1. You should look into what other messengers do with sender/receiver pairs information. One very popular competing messenger logs pairs permanently, serverside, in order to make UI features work. 2. One of the least popular attributes of Signal (on Hacker News, at least) is its lack of federation and ability to interoperate with third-party clients. This feature is a pretty crystalline example of t…

> 1. You should look into what other messengers do with sender/receiver pairs information. One very popular competing messenger logs pairs permanently, serverside, in order to make UI features work.

I wish you'd name things and explained what exactly they are doing.

Re: Technology preview: Sealed sender for Signal

#158

Earlier quoted context omitted.

What exactly do you not buy? I think you might be missing the point on what is meant by discovery here. This is not about random strangers talking to you, but about the issue that you have signal, your friend has signal, but even though you're already in each others phone books you can't talk to each other because you haven't exchanged pseudonymous pointers. There are exactly two pseudonymous identifiers that have "m…

> I think you might be missing the point on what is meant by discovery here. This is not about random strangers talking to you, but about the issue that you have signal, your friend has signal, but even though you're already in each others phone books you can't talk to each other because you haven't exchanged pseudonymous pointers. On the contrary, this is precisely the discovery many users do not want. 1. Someone yo…

If everybody is using encrypted technology 1. isn't a discovery anymore. Your entire argument is built on assuming that encryption for everyone will never happen. And that is factually incorrect.

If you need deniable encryption today use WhatsApp. Done.

Re: Technology preview: Sealed sender for Signal

#159
post #153

Earlier quoted context omitted.

The survey data you are looking for is WhatsApp.

I don't see how. Could you explain?

The biggest messaging platform on the planet uses phone numbers as user ids. It seems very unlikely a majority of users see this as a showstopper.

Re: Technology preview: Sealed sender for Signal

#160
post #159

Earlier quoted context omitted.

I don't see how. Could you explain?

The biggest messaging platform on the planet uses phone numbers as user ids. It seems very unlikely a majority of users see this as a showstopper.

Those users do not use it a secure messaging platform. The see it as a way to get around SMS fees. The majority of Signal users are likely privacy- and security-focused, and chose to use signal because of the features it provides on those fronts.

Comparing those two userbases doesn't make much sense to me.

Post reply on HN