Live data from Hacker News

Moxie Marlinspike has a plan to reclaim our privacy

newyorker.com

181–190 of 237 posts

Re: Moxie Marlinspike has a plan to reclaim our privacy

#182
post #114

Earlier quoted context omitted.

Here's something I've never understood about federated approaches to secure messaging: With a centralized approach like Signal, I have to trust one single provider, i.e. the Signal Foundation running the servers, with my (meta)data. Sure, in an ideal world I'd rather not trust anyone. Fair enough. With a federated network, however, I generally have to trust every single host that any of my contacts has decided to sig…

I think perfect really is the enemy of good in this case. Attack vectors will presumably always exist. I look upon any argument against openness - be it software licensing, protocol federation, data export, binary blob usage, or anything else - with _extreme_ skepticism. > ... I generally have to trust every single host that any of my contacts has decided to sign up with ... In general, you should only have to trust…

I think we need to agree on a common threat model because right now I'm getting the impression that you and I are assessing things from very different angles. If any of the 3-letter agencies decide to target John Doe specifically and expend significant resources on this task, I think we can agree that chances are they will succeed. Neither a centralized or a federated approach will protect John from that because, unless John is a security expert and very paranoid and careful in everything he does online, there will be many other attack vectors.

Signal's goal, however, is to protect the masses and, thus, society as a whole, by protecting as many people's privacy as possible. The things that are at stake here are not the data and the social graph of a handful of individuals, but the data and social graph of society as a whole. (I'm sure I don't have to mention the implications for democracy and social order.)

My perspective, therefore, was that of an average user. The reason I mentioned my personal situation and the fact that I myself spend quite a bit of time on making sure my systems are safe, was to emphasize that if the situation is already overly complicated for me, it will be much worse for the average user.

> In general, you should only have to trust a particular host with communications going to the specific contact that uses it.

I don't think the word "only" is appropriate here. Let's say John Doe has roughly ~1000 contacts. This means that, in the worst case, he would have to research ~1000 hosts and their privacy policies. Now the "accumulation effect" I mentioned previously will reduce that number quite a bit but there are still going to be dozens of different hosts. I doubt we could expect John to look into each and everyone of them before he gets in touch with his contacts. (Note that this gets even worse when people can freely switch between hosts, as suggested e.g. by other replies to my comment, as John will then have to repeatedly do the checking.) Therefore, I think it is reasonable to expect that a significant number (millions, if not billions) of users will end up residing on insecure and untrustworthy hosts and their social graph and metadata – and possibly even their data (see below) – won't be protected at all.

> With a centralized model, you generally have to unconditionally trust the central authority.

In the federated model, John has to do that, too. Sure, he can self-host but how many people are actually going to do that? Put differently, the vast majority of all acts of communication in the network is going to get routed not through self-hosted nodes but through the servers of providers whose trustworthiness is at least questionable. I hope you will agree that, for society as a whole, this exacerbates the trust problem you mentioned.

> A federated system offers much more flexibility. Metadata is likely to be spread piecemeal across multiple hosts and network paths, making it much more difficult for an adversary to analyze in the general case.

A federated system also makes it much easier for adversaries to enter the game, as they don't have to compromise a well-known provider like Signal that is under the close scrutiny of the public. Instead, they can just create new hosts (just like they do in the case of the Tor network). What's worse, in this case they won't just be able to access their user's social graphs but very likely also the content of their messages, as the key discovery problem is usually solved by hosts distributing their users' public keys.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#183

Earlier quoted context omitted.

I think you intended to link the sources but you didn't. Could you still provide them please? I'd be very interested in where those numbers come from.

Here's the foundation's Form 990 from 2018: https://projects.propublica.org/nonprofits/display_990/82450...

Very cool, thank you!

Re: Moxie Marlinspike has a plan to reclaim our privacy

#184
post #98
post #94

Requiring a mobile phone number to use Signal is a NOGO.

You can use a voip number that forwards sms (ex: voip.ms). You don't need to setup VoIP, just setup SMS forwarding to email. That's what I did initially for my kid on an android tablet, and always did for my data-only phone.

So instead of giving a phone number I should register my Name, Address, Phone Number?

Sounds worse than buying a prepaid SIM if you ask me.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#186

Earlier quoted context omitted.

Sigh . That Stack Exchange answer is incredibly old and points to the flaws everyone knew in MTProto 1, which has been superseded by MTProto 2 for years . MTProto 2 is based on standard crypto primitives that not a single human being has found fault in. Please do your research before putting this stuff out there in the future: it spreads unnecessary fear, uncertainty and doubt.

Using standard crypto primitives isn’t enough. I tried to find a review of the security of telegrams new protocol a few months ago and came up empty. So asking the parent to “ do their research” isn’t helpful. And it isn’t FUD to treat an unknown system as insecure.

You are welcome to develop your argument and point out where in MTProto 2 you find fault or why using standard crypto primitives isn't enough and what you'd like to see from MTProto 2 to secure it in your mind.

The gp comment literally just posted a link to a deprecated comment that painted MTProto 1 as (rightfully) insecure.

That was not thorough research and it attaches the FUD associated with an unused protocol to MTProto 2, which I'd again like to remind you and everyone, not a single security researcher or otherwise has found fault in.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#187

It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…

I agree that an emphasis on usability is required, and that is why Zoom now rules. My elderly relatives use Zoom exclusively, partly because that is what they are invited to use for the 80th birthday celebrations that seem to happen every week. But also because they don't have smart phones; they are somewhat comfortable with a desktop computer, but smart phones are just unusable due to lack of dexterity, poorer eyesight and worse user interfaces. I can't see a mobile-only solution winning family use cases. Maybe it will do better with business.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#188

I won’t bother reading this, it seems to be a standard time waster. Coincidentally I saw this yesterday https://youtu.be/IWMZ17Iyu3o “What’s wrong with Signal etc. “

You haven't even glanced at the article, which tells us a lot about the fascinating life of a very interesting person, and to add insult to injury, you then link to a video that does nothing but state the obvious (with much melodrama) for 17 minutes. Frankly, this is the laziest dismissal I've ever seen.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#189

I won’t bother reading this, it seems to be a standard time waster. Coincidentally I saw this yesterday https://youtu.be/IWMZ17Iyu3o “What’s wrong with Signal etc. “

If you have time to watch a long, low-information video you have time to read the article so you can comment knowledgeably.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#190

This old post from Moxie Marlinspike in 2012 about having the worst material possessions made a huge impact on me for some unclear reason. Fun read. https://moxie.org/2012/11/27/the-worst.html

I think after reading that...

Do the right thing poorly instead of the wrong thing correctly.

Post reply on HN