Live data from Hacker News

Moxie Marlinspike has a plan to reclaim our privacy

newyorker.com

171–180 of 237 posts

Re: Moxie Marlinspike has a plan to reclaim our privacy

#171

Earlier quoted context omitted.

> the developers of the reference server have gone on record saying that they don't expect anyone else to be able to successfully implement. Despite this, there are multiple alternative server implementations. Dendrite is the next gen server from the same core team, though Construct and Conduit are fledgling servers from different groups.

Neither Construct nor Conduit are complete implementations, and may never be. The protocol developers were actively discouraging them at one point too.

Got a source for the latter statement? It’s contrary to everything I’ve seen and heard.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#172

This old post from Moxie Marlinspike in 2012 about having the worst material possessions made a huge impact on me for some unclear reason. Fun read. https://moxie.org/2012/11/27/the-worst.html

He's a great writer, his post on privacy and privacy abuse was eye opening for me

https://moxie.org/2013/06/12/we-should-all-have-something-to...

Re: Moxie Marlinspike has a plan to reclaim our privacy

#173

Earlier quoted context omitted.

OTOH, Telegram's crypto is... suspect. https://security.stackexchange.com/a/49802

Sigh . That Stack Exchange answer is incredibly old and points to the flaws everyone knew in MTProto 1, which has been superseded by MTProto 2 for years . MTProto 2 is based on standard crypto primitives that not a single human being has found fault in. Please do your research before putting this stuff out there in the future: it spreads unnecessary fear, uncertainty and doubt.

Using standard crypto primitives isn’t enough. I tried to find a review of the security of telegrams new protocol a few months ago and came up empty.

So asking the parent to “ do their research” isn’t helpful. And it isn’t FUD to treat an unknown system as insecure.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#174
post #68

The fundamental point is that he's doing this for good reasons, beyond the trivial in issues lists of a git backed repo: he believes in what he is doing. And, he's doing it in ways which cryptographers I respect relate to: its visible work and its open to critique. I have my own kibbitz about stuff down in the weeds, I think the decision to make a cellphone/SMS identity key in the recruitment and to have one device p…

Cryptography is a black, and white field. Either crypto algorithm is deemed 99.9999999999+% physically unbreakable, or anything less, and it doesn't work.

Except that it's not true. Even proven mathematical algorithms can be breaked if not implemented correctly, or some side channels might be discovered along the way.

It's not just black and white.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#175
post #25

Earlier quoted context omitted.

Many of the security design flaws in signal have had little to no direct impact on usability. For example, for years we asked for a simple mechanism which could be used to view a users key and mark it as identified, to prevent MITM -- even one buried in a menu for advanced users (who could at least act as canaries against widespread interception). Not only was the request turned down but usually responded to with vig…

Can the downvoters please respond to the post with the reasons why they are downvoting?

You claim that MitM attacks are possible because keys can change without being notified.

Can you provide more details on that? I’ve been using signal for years and often get key change notices.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#176

Earlier quoted context omitted.

Cryptography is a black, and white field. Either crypto algorithm is deemed 99.9999999999+% physically unbreakable, or anything less, and it doesn't work.

Except that it's not true. Even proven mathematical algorithms can be breaked if not implemented correctly, or some side channels might be discovered along the way. It's not just black and white.

This put an even more extreme emphasis on being on the paranoid side, and not leaving anything to the chance, not less.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#177
post #118

Earlier quoted context omitted.

> With a federated network, however, I generally have to trust every single host that any of my contacts has decided to sign up with I can see why, at first glance, this seems strictly worse because there are more entities to trust, but this is not a static system. As an analogy, think about Facebook. Let's say that your friends all hate Facebook, but continue to use it, because for them the inconvenience and switchi…

> ... the very fact that people can move from one host to another ... I think it's worth explicitly spelling out that federation reduces the cost to switch hosts to near zero in many cases. There's no technical reason you can't use a different host on your end per contact in Matrix (for one to one messaging at least). It would be absurd, but you could do it provided that your client supported it. If it's really neede…

> federation combined with open source software means that tooling can be adapted to facilitate your particular security and workflow requirements

In theory, yes. In practice, however, it gets very complicated. (See e.g. Jabber.) You end up with a situation where only experts are able to set up a secure system for themselves, whereas the average user can't even accurately assess how well her/his privacy is currently protected.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#178
post #59

Earlier quoted context omitted.

> Thanks to Signal's security posture, global protection from weak ciphers, buffer overflows, and even SGX, is just one software update away. Conversely, thanks to Signal's centralized model, implementations of backdoors are also one software update away. By the time the "nerds" find out, it'd probably be far too late and lives could be at stake. It's unfortunately such the nature of the beast that being half-hearted…

reputation and community trust sometimes counts for something? i get it but i also know that if the nerds find out no one would use Signal...

If Signal's security boils down to reputation and community trust, why not just use WhatsApp or Facebook Messenger or really any chat product where the makers claim it's secure and private?

Re: Moxie Marlinspike has a plan to reclaim our privacy

#179
post #68

The fundamental point is that he's doing this for good reasons, beyond the trivial in issues lists of a git backed repo: he believes in what he is doing. And, he's doing it in ways which cryptographers I respect relate to: its visible work and its open to critique. I have my own kibbitz about stuff down in the weeds, I think the decision to make a cellphone/SMS identity key in the recruitment and to have one device p…

Cryptography is a black, and white field. Either crypto algorithm is deemed 99.9999999999+% physically unbreakable, or anything less, and it doesn't work.

That's what you'd think.

Read some advanced cryptography papers and you'll discover it's not quite that simple. There are the exotic hardness assumptions: are those mathematical problems really hard to solve or not? They aren't classical, natural problems like discrete log. Then there are the odd threat models, e.g. plenty of algorithms out there claim to be proven secure in the honest-but-curious model. Although this threat model isn't entirely naive, in the real business world "honest but curious" adversaries do appear in the imaginations of business leaders at least, but most people assume the point of cryptography is to keep you secure against arbitrarily malicious adversaries.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#180
post #132

Earlier quoted context omitted.

Alternatively, users could be given the option to opt-out of automated contact discovery so that most users have the current behaviour but people who don't want others to find out they've started using Signal (there are dozens of fairly serious situations where this could be very bad -- dismissing them like you did by calling them "elite" betrays you don't actually care about the issue being described). I mean, the f…

I imagine that getting caught using Signal could be dangerous, whether to an "elite user" planning a one way trip from Hawaii to Russia with a layover in HK, or even to a minor with an abusive parent-over-shoulder. In some countries, a single boolean of metadata could put you in jail or worse. A future Signal update (usernames?) may address this use case. But update or no, it's irresponsible to proffer these scenario…

> But update or no, it's irresponsible to proffer these scenarios as relevant to the typical westerner, especially given the abysmal privacy of the popular alternatives.

Have you considered the (sadly) common case of an abusive partner who is likely to see your sudden usage of Signal as an indication that you are speaking to other people about their abuse, or at the least asking others for help?

I don't think these scenarios are nearly as rare as you think they are. These cases do definitely happen in English-speaking countries -- not that I understand your argument here in the first place (Signal is available world-wide and has been translated to many other languages, what does language have to do with anything?). Not to mention that Signal themselves don't warn you about this behaviour at all.

(Yes, you could argue that an abusive partner has many other avenues through which to discover that you're asking for help -- but that isn't a defense of providing more avenues for an abuser to discover you're asking for help. Again, Signal actively notifies all of your contacts that you've started using Signal -- which is above and beyond the transparent upgrade from SMS to Signal messages you mentioned.)

Post reply on HN