Live data from Hacker News

On Ghost Users and Messaging Backdoors

blog.cryptographyengineering.com

11–20 of 57 posts

Re: On Ghost Users and Messaging Backdoors

#11

With the spread of misinformation and rage using messaging apps that have literally resulted in people getting killed by mobs (see for example https://www.nytimes.com/interactive/2018/07/18/technology/wh... ) maybe we should re-evaluate our belief that making it impossible for governments to see what is spreading through messaging apps is an unmitigated good?

So we should just go ahead and put Orwell's Telescreens in everyone's house so the governments can see what we're plot^h^hannng all the time?

(Looks around the office and sees the Echo and Google Home, remembers how many friends have those and/or Samsung "Smart TVs" in their home, or who have their phones constantly listening for "OK Google" or "Hey Siri". Right. As you were...)

Re: On Ghost Users and Messaging Backdoors

#13
post #10

With the spread of misinformation and rage using messaging apps that have literally resulted in people getting killed by mobs (see for example https://www.nytimes.com/interactive/2018/07/18/technology/wh... ) maybe we should re-evaluate our belief that making it impossible for governments to see what is spreading through messaging apps is an unmitigated good?

What makes you think these "mobs" used WhatsApp for its security reasons? I'd expect it's far more likely they use WhatsApp because it's the most popular messenger in that part of the world.

People aren’t dumb.

Remember Nextel direct connect? It was known that those communications weren’t tappable initially, and for a time every street level drug salesman had them.

Re: On Ghost Users and Messaging Backdoors

#14
post #11

With the spread of misinformation and rage using messaging apps that have literally resulted in people getting killed by mobs (see for example https://www.nytimes.com/interactive/2018/07/18/technology/wh... ) maybe we should re-evaluate our belief that making it impossible for governments to see what is spreading through messaging apps is an unmitigated good?

So we should just go ahead and put Orwell's Telescreens in everyone's house so the governments can see what we're plot^h^hannng all the time? (Looks around the office and sees the Echo and Google Home, remembers how many friends have those and/or Samsung "Smart TVs" in their home, or who have their phones constantly listening for "OK Google" or "Hey Siri". Right. As you were...)

No.

The state should be able to get a warrant to intercept communications for reasonable cause, and the accused should be able to litigate the validity of the search.

Re: On Ghost Users and Messaging Backdoors

#15
post #7
post #6

Earlier quoted context omitted.

What does that mean, “manage centrally in a manner”... and how does Signal not manage it centrally?

Signal groups are managed by the client devices. The details are quite complicated, but some are documented here: https://signal.org/blog/private-groups/ Perhaps another user with stronger familiarity on the subject can expand on this (ELI5 would be great!).

Interesting. Compare https://safenetworkprimer.com/ by the way

Re: On Ghost Users and Messaging Backdoors

#16
post #7
post #6

Earlier quoted context omitted.

What does that mean, “manage centrally in a manner”... and how does Signal not manage it centrally?

Signal groups are managed by the client devices. The details are quite complicated, but some are documented here: https://signal.org/blog/private-groups/ Perhaps another user with stronger familiarity on the subject can expand on this (ELI5 would be great!).

Signal client is centrally managed and can be updated for every user. And it's quite ridiculous claim that Signal can't implement a backdoor in the client because of some arbitrary design choice.

Re: On Ghost Users and Messaging Backdoors

#17
post #12
post #8

Instead of creating a ghost user account and attempt to join a chat, why not just copy they key of one of the participants?

In a "properly designed system", the service only ever sees public keys not private keys.

If the point of a law is to circumvent encryption you shouldn't be surprised that it doesn't satisfy anyone who wants the encryption to be safe.

Either the backdoor works and the system is bad. Or the backoor doesn't work and the system is illegal. At least if the law doesn't have a loophole.

So not sure why the article complains about the design whereas the intent and goal are the real issue. Seems like the design works as intended.

Re: On Ghost Users and Messaging Backdoors

#18
post #5

Earlier quoted context omitted.

Maybe we should consider that goods can still be worthwhile despite their mitigations.

I agree, but when you do that, you need to actually make an accounting of the costs/benefits. If you look among programmers and security specialists on say HN there is not even a debate or discussion about this, but rather an absolutist position that this is good and that the only reason to think this is bad is if you are a totalitarian government wanting to oppress your people.

I think you're conflating two different positions, which do admittedly co-occur in many people: 1. The technical, that any such "backdoor" is necessarily a backdoor, with all that implies, and thus to be eschewed on a "fundamental principles of good security" basis, and 2. The moral, that any such backdoor is crime against humanity, or whatever, because some of the people who have the technical capability will be leveraging it in order to oppress, and all of them will be doing so in order to act in a manner contrary to the user's interests.

Who do our tools serve? Is it just that they should be made to serve someone else, against us? Where, exactly, is the line on one side of which it's justified, but on the other it's abuse? How do you build a system that prevents abusive uses, but allows appropriate ones?

Decrying absolutist positions is all well and good, but it is a nigh-on tautology-level truth that a system with a flaw or backdoor, will be exploited — usually in multiple ways, and well beyond any potentially intended such.

Re: On Ghost Users and Messaging Backdoors

#19
post #11

Earlier quoted context omitted.

So we should just go ahead and put Orwell's Telescreens in everyone's house so the governments can see what we're plot^h^hannng all the time? (Looks around the office and sees the Echo and Google Home, remembers how many friends have those and/or Samsung "Smart TVs" in their home, or who have their phones constantly listening for "OK Google" or "Hey Siri". Right. As you were...)

No. The state should be able to get a warrant to intercept communications for reasonable cause, and the accused should be able to litigate the validity of the search.

That's a little hard to do in a world where this kind of thing is done by National Security Letter.

Re: On Ghost Users and Messaging Backdoors

#20

Apparently some researchers from the GCHQ in the UK are proposing that "secure" messaging systems like iMessage and WhatsApp which manage group chats centrally in a manner that bypasses the end to end encryption should: - Add "ghost" users/devices to existing chats - Suppress notifications of these additions to users This would perpetuate a currently known bug in secure communication protocols, effectively turning it…

Keybase Teams—also featuring e2e-encrypted group chat—appears to be proof against the ghost-user-based attack.

It would be interesting to compare its implementation to how Signal does group messaging in TextSecure v2.

[0] https://keybase.io/blog/introducing-keybase-teams#anyway-tea...

Post reply on HN