Live data from Hacker News

On Privacy versus Freedom

matrix.org

161–170 of 209 posts

Re: On Privacy versus Freedom

#161
First off, I have to say this about matrix: they have by far the best foss community I have seen. Excellent work on managing the community, others should take note.

Second, both signal and matrix collect too much metadata. signal means you're completely screwed by their dependency on phone numbers. I expect little metadata privacy from signal because to me, it is practically the same as using my SSN or fingerprint as my user name,same for all my contacts, this key field is used by everyone and their mother to track everything we do like 1984 was target practice. For matrix, it's the defaults and how easy it is for others to fingerprint you using your specific device (equivalent of a user-agent seen by everyone iirc?) and other profile details ,but none of this is easy to correlate and answer questions like "which social network demographic micro-group does this user belong to so we can perform targeted infiltration of their device?" or "Hey, let's use this phone number to look perform the equivalent of a background check on this person who is sending us a message because we now have their phone number". Oh and the best part is, you can't just get a burner to use for registration, and to link a signal desktop,you need the mobile app. Matrix has none of these issues.

Third, consider your threat models carefully. As an individual, is it better if you have infrasructure diversity and protocol interoperability or is it better to put all your eggs in signal's basket. I never liked their use of google infra at the begining for example because I consider google more of a threat to me than most other parties. I can see the argument both ways. I personally consider the set of parties that have the most to benefit from targeting me as an individual plus those who have the most to benefit from dragnet surveillance where I reside. To me, matrix is more flexible to adopt to various threat models by for example self hosting compared to using a popular matrix server. Signal is better than the competition, if your fear is being exposed to unpatched vulnerabilities and/or if you are worried about metadata snooping (but you trust signal's infra provider, still google??) Then Signal makes more sense. For dragnet, I think matrix is better for me because implementation vulns only apply to a few users,making reliable dragnet attacks less likely. For anyone that might target me, my mobile phone is completely defenseless, so my concern is someone identifying my specific device for targeted attacks, with matrix they need to compromise the matrix server and even then they might need to do a lot more work to correlate which matrix user is me (real life "target worthy" identity). Where as with signal,they can easily micro target a group ,find out everyone's phone numbers (e.g.: hk protesters) and target their device for further exploitation via signal or any other pwnable app that is known to present on a device associated with that phone number.Practically, I am more worried about how each app fits in with everything else I do and matrix wins the security round for me.

Last but not least, I use signal for 98% of my comms because the phone number usage by Signal means I can easily connect to and invite people who don't have signal. If there is a Matrix client app that can be used as an sms client and can discover contacts' matrix account/server over sms without communicating or collecting phone number/name details of the contact, I think i might jump ship. The way I envision this to work is: the matrix client would have an invite button for non-matrix contacts and it will have an option to initiate discovery of contacts. Both options would do a challenge-response with each contact and instead of associating with a phone number they would ask to create a new martrix only contact.

Re: On Privacy versus Freedom

#162

Earlier quoted context omitted.

We tend to be pretty conservative on maturity estimates on Matrix (and bad at keeping the website updated). IRC, Slack, Gitter bridges are all considered stable these days. XMPP, Discord, Telegram, WhatsApp work usably too. The UX for managing them is not always great or consistent (we’re working on that currently), but “yet another protocol with its own chatrooms” is untrue. You can certainly access the entirety of…

I only have experience with the IRC one, which is ok, but I think it deserves to still be considered Beta (see https://news.ycombinator.com/item?id=21944035 ) Regarding Bifrost, it's the first time I hear about it. I'm glad it exists. Is there an hosted instance that allows me to access Matrix rooms without installing anything other than an XMPP client? I can't find any info about it other than the code repo.

The IRC bridge shouldn’t restart that frequently (and we’re in the process of decoupling the irc connectors from the bridge itself so we can fix bugs in the bridge without bouncing all its connections). Membership should categorically be synced correctly - if you ban a Matrix user on IRC their Matrix side should be kicked out too. If not, it’s a bug and we need to know the details asap. The only scenario I can think of here is if the matrix server was lagging on handling traffic, but that shouldn’t cause a desync like this either.

For bifrost; we used to run one on matrix.org but temporarily stopped due to lack of ops bandwidth. There’s a community one somewhere though - come ask in #bridges:matrix.org about it

Re: On Privacy versus Freedom

#163
post #159
post #154

Earlier quoted context omitted.

A 'chat' client in the style of eg WhatsApp, but based on S/MIME over SMTP/IMAP, seems perfectly doable, and appropriate for most people's needs, with the obvious advantage of being supported by traditional email clients as a fallback. Additionally, message threading is the feature I most appreciate in a messaging system, but which is painfully lacking in most products (and no, Slack doesn't cut it). SMTP has built-i…

There's an open source (GPL) client app (last updated last week) on F-Droid called Dib2Qm for exactly this, and it's apparently e2e as well. I haven't used it, I just happened across it yesterday out of sheer coincidence. Link: https://f-droid.org/en/packages/net.sourceforge.dibdib.andro...

This too

https://delta.chat/en/

Re: On Privacy versus Freedom

#164
post #148

Signal really tries hard to not be trustworthy. The way they defend WhatsApp is heart-breaking. It's cute to see them saying there is no backdoor when it can't be proven to be the case, since it's all proprietary. They can't show the server side wasn't tampered with. Same with Skype.

The constant repetition of this ignorant claim is starting to be annoying. Think there is a client backdoor? Go find it. It is not like the binary is not available to you. It is not like there are not emulators in which you can step through the code. Please, show us the backdoor. Server side tampering? Show us how it can be done. Create a server that can tamper with a patched client. Demonstrate your chops.

I see you're formerly from FB.

It's not up to us to reverse engineer a binary every update to guess if it's secure...

It's up to Facebook, which has time and again proven that it is absolutely not trustworthy, to open its code and make builds auditable, inspectable, and reproducible.

This is what ANY secure software does. That's the cost of entry. Imagine if OpenSSH were closed and its devs issued the same response you just did. "Just reverse engineer the binary and prove that it's not secure!"

Rediculous.

Re: On Privacy versus Freedom

#165

"Democracy and republics are hard, so we should all just give up and have autocratic governments" It may sound flippant or unrelated, but I think this extreme projection of his argument makes it evident how silly it is. This is one of the reasons I switched away from using Signal, as much as I'd like better privacy on my text messages it's not worth handing that much control over to someone I shouldn't have to put my…

How about that being in an atocracy might be much better when you have a population of 51% wolves and 49% sheep.

Re: On Privacy versus Freedom

#166
post #98

Earlier quoted context omitted.

Talking about privacy of a system that requires you to sign up with a phone number, that in my country (and in most other European countries as far as I know, and without talking about non democratic regimes) is required to be associated with your ID (it's illegal to buy a SIM without registration) is nonsense. And you know another thing? Email works great to me, and it's decentralized. I have my email server, with m…

>I need a chat application where I can have a client that I can use in my terminal, and Signal doesn't do that Have you looked at signald or Signal-CLI? https://gitlab.com/thefinn93/signald https://github.com/AsamK/signal-cli

weechat-matrix is really nice

Re: On Privacy versus Freedom

#167

I think the timing makes Moxie's point very well without him saying a thing. All these years later Matrix only has... The ambition to some day try to offer the core privacy features Signal already delivered back then. Some of the most basic stuff is, you believe, almost kinda sorta done. This is, to be clear, much better than just sitting back insisting you were right but not lifting a finger. But for an actual user…

>All these years later Matrix only has... The ambition to some day try to offer the core privacy features Signal already delivered back then. E2E on Matrix works, plus key verification is easier than on Signal. Managing metadata is hard, but my Matrix homeserver doesn't have my phone number (unlike Signal) and does not require Google Cloud Messaging. I can even run it on a PinePhone or Pocket CHIP! >But for an actual…

> Tell that to the people getting imprisoned due to Signal's metadata leaks:

Please explain how Signal leaks metadata given:

- everything behind the client and the server goes over TLS

- all Signal messages are end to end encrypted with the Signal protocol

- the Signal server doesn't even know who is messaging whom in the majority of cases: https://signal.org/blog/sealed-sender/

Re: On Privacy versus Freedom

#168

I think the timing makes Moxie's point very well without him saying a thing. All these years later Matrix only has... The ambition to some day try to offer the core privacy features Signal already delivered back then. Some of the most basic stuff is, you believe, almost kinda sorta done. This is, to be clear, much better than just sitting back insisting you were right but not lifting a finger. But for an actual user…

Talking about privacy of a system that requires you to sign up with a phone number, that in my country (and in most other European countries as far as I know, and without talking about non democratic regimes) is required to be associated with your ID (it's illegal to buy a SIM without registration) is nonsense. And you know another thing? Email works great to me, and it's decentralized. I have my email server, with m…

> And you know another thing? Email works great to me, and it's decentralized. I have my email server, with my domain, so I don't depend on anyone to provide me a service. I have full control of my data that is on my server. I can even send encrypted emails with GnuPG without any problem

OK, and how many non-technical people do you email that have GPG keys? If they don't have GPG, how do you have end to end encrypted communications with them?

This is where Signal won and GPG lost, with the Signal protocol integration into WhatsApp, one billion people instantly got secure comms without even having to know what a key is.

> it's as secure as Signal, if not better.

Signal uses a new key for every single message you send, so it could be argued that actually Signal is better than GPG.

Re: On Privacy versus Freedom

#169
post #159

Earlier quoted context omitted.

There's an open source (GPL) client app (last updated last week) on F-Droid called Dib2Qm for exactly this, and it's apparently e2e as well. I haven't used it, I just happened across it yesterday out of sheer coincidence. Link: https://f-droid.org/en/packages/net.sourceforge.dibdib.andro...

This too https://delta.chat/en/

Hmm, interesting. I might have a play.

Re: On Privacy versus Freedom

#170
post #148

Earlier quoted context omitted.

The constant repetition of this ignorant claim is starting to be annoying. Think there is a client backdoor? Go find it. It is not like the binary is not available to you. It is not like there are not emulators in which you can step through the code. Please, show us the backdoor. Server side tampering? Show us how it can be done. Create a server that can tamper with a patched client. Demonstrate your chops.

I see you're formerly from FB. It's not up to us to reverse engineer a binary every update to guess if it's secure... It's up to Facebook, which has time and again proven that it is absolutely not trustworthy, to open its code and make builds auditable, inspectable, and reproducible. This is what ANY secure software does. That's the cost of entry. Imagine if OpenSSH were closed and its devs issued the same response y…

Actually it _is_ up to you; put up or shut up is a fairly well-known principle. Find the backdoor and make yourself famous, or continue to whine and listen to everyone laugh.

I left FB because it was getting too creepy and I would not trust 99% of FB dev with a single shred of my personal info, but the code is right there for you and people who actually have skills to disassemble and examine. They are under no obligation to do your work for you and the people who can actually do the work make good money so maybe you will learn a useful skill or two.

Post reply on HN