Live data from Hacker News

Moxie Marlinspike has a plan to reclaim our privacy

newyorker.com

21–30 of 237 posts

Re: Moxie Marlinspike has a plan to reclaim our privacy

#21
post #12
post #9

Why is it, whenever Signal is brought up on Hacker News, we get inundated with the people who object to the core decisions of the Signal Project? Would Signal really be better if, instead of having a secure messenger available to the masses, it spent massive amounts of time implementing the things these people want? No. I would be comfortable recommending Signal (or WhatsApp) to a nontechnical friend and communicatin…

A great deal of human communication is dedicated to signalling high rank/superiority, or demonstrating familiarity/intimacy.[1] In the case of HN, very few people know much about Moxie, so the only useful signal they can convey is expertise. Many people come here because of their technical or product development background/interests, and the way they show expertise is by second-guessing technical, user interface, and…

> signalling high rank/superiority

Please leave this social darwinism propaganda out of HN.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#22
post #13

Earlier quoted context omitted.

You can't coherently be alarmed by Signal's use of SGX while at the same time endorsing systems that use no cryptography whatsoever to protect the metadata Signal uses SGX for.

I’m not sure that that’s the only conclusion you can draw. Some systems choose to not handle that metadata, which often makes them a worse service but they make that choice by looking at the landscape and choosing to not use SGX. The other plausible argument is that Signal uses SGX, which is better than nothing, but in selling it as more secure than it is they do more harm than good.

Some people choose not to turn their servers on at all. It makes for a worse server, but it's very secure.

Security is always about tradeoffs and compromises. A system that is very, very good, but not perfect and widely used is far preferable to a system that is perfect but used by no one.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#23
post #13

Earlier quoted context omitted.

You can't coherently be alarmed by Signal's use of SGX while at the same time endorsing systems that use no cryptography whatsoever to protect the metadata Signal uses SGX for.

I’m not sure that that’s the only conclusion you can draw. Some systems choose to not handle that metadata, which often makes them a worse service but they make that choice by looking at the landscape and choosing to not use SGX. The other plausible argument is that Signal uses SGX, which is better than nothing, but in selling it as more secure than it is they do more harm than good.

What’s an example of a system in this space which chooses not to handle that metadata?

Re: Moxie Marlinspike has a plan to reclaim our privacy

#24

Earlier quoted context omitted.

I’m not sure that that’s the only conclusion you can draw. Some systems choose to not handle that metadata, which often makes them a worse service but they make that choice by looking at the landscape and choosing to not use SGX. The other plausible argument is that Signal uses SGX, which is better than nothing, but in selling it as more secure than it is they do more harm than good.

Some people choose not to turn their servers on at all. It makes for a worse server, but it's very secure. Security is always about tradeoffs and compromises. A system that is very, very good, but not perfect and widely used is far preferable to a system that is perfect but used by no one.

Right, but in this case the choice is "should I be able to discover contacts" and some people just don't desire that feature enough.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#25
post #11
post #2

I was vouching for Signal for all my friends for years, supported them with donations, and was really rooting for them. However, I regrettably can't trust in moxie having the best intentions with Signal anymore. Lost count of the number of times this has been recycled on HN so I'm not taking the time to formulate this extremely well but: * For the longest time, requires phone number as identifier. When asked to remov…

There is a reason why signal is relatively mainstream succesful (by crypto product standards) and PGP wasn't. Its because its willing to make tradeoffs in the name of usability (while still emphasizing security). A secure messenger product nobody uses helps nobody's security.

Many of the security design flaws in signal have had little to no direct impact on usability.

For example, for years we asked for a simple mechanism which could be used to view a users key and mark it as identified, to prevent MITM -- even one buried in a menu for advanced users (who could at least act as canaries against widespread interception). Not only was the request turned down but usually responded to with vigorous personal attacks against the requesters.

Subsequently once a fingerprint validation method was added it was gratuitously bound to be pair-wise, making it largely unusuable -- e.g. post a pgp signed signal fingerprint that any of your contacts could use to transfer trust from an existing key. Requests for a non-pairwise version, even as just some advanced thing that grandma never sees ... again, hostility.

The constant logic-bombed auto-expiring software that make signal effectively open-source-in-name-only. etc.

I think signal is fine as an insecure messanger: Unencrypted communications protocols should have no place in on the internet today. But to advance it as a security tool almost certainly puts people's lives and freedom at risk.

Common usage of signal has zero security against MITM: users aren't effectively notified that the contacts keys have changed-- and given how often users lose/wipe phones perhaps that's really the best that can be done for normy friendly software.

If that's how it is, that's how it is. Some resistance against passive monitoring is still a critical upgrade. But don't call it secure: if you do people will do and say things using it that they wouldn't otherwise.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#26
post #13
post #3

Earlier quoted context omitted.

These are all exact reasons I have never used Signal. Additionally I find concerning the choice to bet the farm on SGX which has been repeatedly broken with repeated opportunities to extract the keys, at which point cracking small numeric pins is trivial. Moxie simply promised they always patch right away and never take the keys when they have such opportunities to do so. I do believe him, today, but I don't believe…

You can't coherently be alarmed by Signal's use of SGX while at the same time endorsing systems that use no cryptography whatsoever to protect the metadata Signal uses SGX for.

> You can't coherently be alarmed by Signal's use of SGX while at the same time endorsing systems that use no cryptography whatsoever to protect the metadata Signal uses SGX for.

You can be: It isn't difficult to argue that signal overstates the security properties of their solution.

It's not an incoherent position to say that it's more important to be conservative (or at least accurate) about the claimed properties than it is to provide epsilon more security.

If it were the case that signal claimed that this metadata had no privacy towards them (and the hosts running their systems), but when you dig into the protocol or detailed tech docs you find that they're using SGX to minimize risk-- then I think there would be nothing to fault about the addition of SGX. In that case it would be purely additive security.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#27

It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…

> When tech nerds nit pick Signal's implementation, they ignore that the unfederated nature of Signal limits the damage these decisions can cause.

It limits the damage that some decisions can cause, but exacerbates others. Signal only allows the first-party client to connect to its network; if the developers were legally compelled to add a backdoor into that client, users would have few options.

Its security depends on a single company being perpetually trustworthy, free of influence, and supported. Having used many chat platforms that have been shut down/acquired/etc in the past, that’s not a bet I’m willing to take.

I’d also contest the idea that Matrix can never have a client as usable as Signal, but I’ll agree that there isn’t one yet.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#28

Earlier quoted context omitted.

Some people choose not to turn their servers on at all. It makes for a worse server, but it's very secure. Security is always about tradeoffs and compromises. A system that is very, very good, but not perfect and widely used is far preferable to a system that is perfect but used by no one.

Right, but in this case the choice is "should I be able to discover contacts" and some people just don't desire that feature enough.

Who, though? Matrix has contact discovery, doesn't it?

Re: Moxie Marlinspike has a plan to reclaim our privacy

#29

It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…

>Like the key agility that makes the Axolotl Ratchet so superior to GPG,

I am not sure how you can usefully compare a thing originally intended to secure email to a thing intended to secure IM.

The ratchet only provides forward secrecy anyway. My take on that is that it is a pointless thing for something like email and pointless in practice for most IM applications. Most IM users keep their old messages and practically all email users keep their old messages...

There is nothing particularly wrong with Signal. Some of the criticism might a reaction to the constant promotion of it over all other things, even when (as in this case) the things are fundamentally different.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#30

It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…

> update agility makes Signal infinitely superior to every existing or proposed federated network.

Translation: Signals ability to forcefully change the software and protocol out for users without any consent (much less informed consent) renders it functionally immune to any criticism or review because any aspect of the protocol could be changed ('improved') at a moments notice.

I think signal is a fine insecure messenger. If you mistake it for a cryptographic security product you are making a significant mistake. The fact that is uses cryptographic techniques internally just means that it isn't grossly incompetently constructed, but that doesn't make it achieve any particularly strong notion of security against any particular attack model.

I strongly recommend people us it (at least on devices which are already compromised by mystery meat binary updates that could be remotely backdoored at any time)... just don't think it's going to provide you with substantial security against active attackers (much less state level attackers or from Signal themselves).

Post reply on HN