Live data from Hacker News

Moxie Marlinspike has a plan to reclaim our privacy

newyorker.com

111–120 of 237 posts

Re: Moxie Marlinspike has a plan to reclaim our privacy

#111
post #12

Earlier quoted context omitted.

A great deal of human communication is dedicated to signalling high rank/superiority, or demonstrating familiarity/intimacy.[1] In the case of HN, very few people know much about Moxie, so the only useful signal they can convey is expertise. Many people come here because of their technical or product development background/interests, and the way they show expertise is by second-guessing technical, user interface, and…

He's got a master mariners license, which to me is way more cool than any of the computer stuff. Legally captain a merchant ship of any size, of any type, operating anywhere in the world.

Also made a neat documentary about getting a sailboat and gunk-holing in the Caribbean.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#112

It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…

[deleted]

Re: Moxie Marlinspike has a plan to reclaim our privacy

#113
post #46

Earlier quoted context omitted.

Matrix lets people host their own servers and in doing so put the metadata anywhere they are comfortable. One can have metadata for sensitive internal corporate channels stay on a network they own in whatever country they want while still being able to chat with outside parties on matrix.org or other servers. Several friends host their own servers and more recently matrix p2p is rapidly maturing to dump the need for…

Here's something I've never understood about federated approaches to secure messaging: With a centralized approach like Signal, I have to trust one single provider, i.e. the Signal Foundation running the servers, with my (meta)data. Sure, in an ideal world I'd rather not trust anyone. Fair enough. With a federated network, however, I generally have to trust every single host that any of my contacts has decided to sig…

> With a federated network, however, I generally have to trust every single host that any of my contacts has decided to sign up with

I can see why, at first glance, this seems strictly worse because there are more entities to trust, but this is not a static system.

As an analogy, think about Facebook. Let's say that your friends all hate Facebook, but continue to use it, because for them the inconvenience and switching costs of moving to a different social network (perhaps one you are offering to host for them) is higher than the cost of continuing to use Facebook.

With a federated network, not only can you encourage (or demand) your friends to use a host that you approve of, but also, the very fact that people can move from one host to another (and there isn't a single basket containing all the eggs) means that these hosts are less likely to risk their reputation or be attacked in the first place.

> even in federated networks like email, some hosts will become bigger than others and will eventually take over most of the users and traffic

It seems you are arguing both that federated systems lead to there being too many nodes to trust, and also that in practice only a few big nodes will be trusted. I may be over-simplifying your points there, and I do think there are challenges with federated networks (particularly when federation is deliberately broken due to spamming/abuse/politics) but it's worth having a clear SWOT analysis here.

Anyway, my point, as before, is that a network coalescing around a few big nodes is not a problem as long as there is portability of accounts between them. I would rather trust 3 big providers who fear losing users to a more secure platform, than 1 monopolistic provider that's too big to fail.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#114
post #46

Earlier quoted context omitted.

Matrix lets people host their own servers and in doing so put the metadata anywhere they are comfortable. One can have metadata for sensitive internal corporate channels stay on a network they own in whatever country they want while still being able to chat with outside parties on matrix.org or other servers. Several friends host their own servers and more recently matrix p2p is rapidly maturing to dump the need for…

Here's something I've never understood about federated approaches to secure messaging: With a centralized approach like Signal, I have to trust one single provider, i.e. the Signal Foundation running the servers, with my (meta)data. Sure, in an ideal world I'd rather not trust anyone. Fair enough. With a federated network, however, I generally have to trust every single host that any of my contacts has decided to sig…

I think perfect really is the enemy of good in this case. Attack vectors will presumably always exist. I look upon any argument against openness - be it software licensing, protocol federation, data export, binary blob usage, or anything else - with _extreme_ skepticism.

> ... I generally have to trust every single host that any of my contacts has decided to sign up with ...

In general, you should only have to trust a particular host with communications going to the specific contact that uses it.

> Am I the exception here? Does everyone here only have friends who are IT security experts ...

No, I think you're just looking at the problem the wrong way.

With a centralized model, you generally have to unconditionally trust the central authority.

A federated system offers much more flexibility. Metadata is likely to be spread piecemeal across multiple hosts and network paths, making it much more difficult for an adversary to analyze in the general case. Instead of a blanket trust decision, you make a per-contact decision based on the nature of the interaction you intend to have with them. If you feel the need, you can even self host and insist that a particular contact register with _your_ server to communicate with you.

If you absolutely can't trust someone to make good decisions with security critical information, it's unlikely Signal can do much to change the threat they pose to you in a real world scenario anyway. At the end of the day you're ultimately choosing how much trust to place in the person you're communicating with regardless of which system you use to do so.

> ... there will eventually appear "supernodes" which have a disproportionally high number of edges/connections to other nodes ...

That's certainly an interesting dynamic but it's hardly an argument against federation. Centralization is literally the worst case in that model (ie a single node and nothing else). In a federated network you have a choice of whether to make use of such supernodes. If it really matters, I can (for example) refuse to communicate with a particular contact regarding some sensitive topic via (say) gmail. A centralized system doesn't provide that option at all.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#115

Other than matrix, what are some other alternatives or upcomers in the messaging field I should try. Matrix still has a high burden of me setting up my own server and maintaining it. Till their P2P solution doesnt release, they have their own metadata problem.

Take a look at some of the metadata-hiding ones:

https://vuvuzela.io/ https://petsymposium.org/2015/papers/vandenhooff-vuvuzela-ho... https://katzenpost.mixnetworks.org/ https://leap.se/en/about-us/news/2017/katzenpost http://web.archive.org/web/20151101081526/https://pond.imper...

Re: Moxie Marlinspike has a plan to reclaim our privacy

#116

Earlier quoted context omitted.

> The Signal group has an uncompromising commitment to user privacy Would you say that outing people who are signal users and putting them in signal contact lists without their permission is 'uncompromising commitment to user privacy?'

Far from "compromise", Signal implements the only privacy conscious possibility here. Without automatic contact discovery "Signal private messenger" would be forced to default to not-private for all contacts until manual confirmation could occur. Adding UX friction to the primary use case would hinder adoption among non security-enthusiasts. With protection for the casual user eliminated, the truly sensitive communic…

I think a reply that simply dismisses phone number outing as something unimportant is fairly offensive, and does not advance the case you are making.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#117

Other than matrix, what are some other alternatives or upcomers in the messaging field I should try. Matrix still has a high burden of me setting up my own server and maintaining it. Till their P2P solution doesnt release, they have their own metadata problem.

ScuttleButt is pretty interesting, even if it uses an utterly flawed data encoding system.

https://scuttlebutt.nz/ https://librelounge.org/episodes/episode-14-secure-scuttlebu...

Re: Moxie Marlinspike has a plan to reclaim our privacy

#118

Earlier quoted context omitted.

Here's something I've never understood about federated approaches to secure messaging: With a centralized approach like Signal, I have to trust one single provider, i.e. the Signal Foundation running the servers, with my (meta)data. Sure, in an ideal world I'd rather not trust anyone. Fair enough. With a federated network, however, I generally have to trust every single host that any of my contacts has decided to sig…

> With a federated network, however, I generally have to trust every single host that any of my contacts has decided to sign up with I can see why, at first glance, this seems strictly worse because there are more entities to trust, but this is not a static system. As an analogy, think about Facebook. Let's say that your friends all hate Facebook, but continue to use it, because for them the inconvenience and switchi…

> ... the very fact that people can move from one host to another ...

I think it's worth explicitly spelling out that federation reduces the cost to switch hosts to near zero in many cases. There's no technical reason you can't use a different host on your end per contact in Matrix (for one to one messaging at least). It would be absurd, but you could do it provided that your client supported it.

If it's really needed, federation combined with open source software means that tooling can be adapted to facilitate your particular security and workflow requirements. (Not that you should need it generally, but the freedom is always there if you do.)

Re: Moxie Marlinspike has a plan to reclaim our privacy

#119
post #28

Earlier quoted context omitted.

Right, but in this case the choice is "should I be able to discover contacts" and some people just don't desire that feature enough.

Who, though? Matrix has contact discovery, doesn't it?

If and only if you opt in to it. It's difficult to understate how important that is.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#120
post #46

Earlier quoted context omitted.

Matrix lets people host their own servers and in doing so put the metadata anywhere they are comfortable. One can have metadata for sensitive internal corporate channels stay on a network they own in whatever country they want while still being able to chat with outside parties on matrix.org or other servers. Several friends host their own servers and more recently matrix p2p is rapidly maturing to dump the need for…

not the _identity_ servers currently though.

Yes, but it should be noted identity servers are only used for associating phone numbers and email addresses to Matrix IDs. Matrix IDs themselves are federated just like email addresses (@cyphar:cyphar.com is mine, and it's hosted on my own homeserver at cyphar.com).

If you don't register your phone number or email address (which last I checked is not part of the default account creation flow) then it really makes no difference. I agree they should be federated (and they have been working on that among many other things) but it's not like every user's identity is centralised.

Post reply on HN