Moxie Marlinspike has a plan to reclaim our privacy
181–190 of 237 posts
Re: Moxie Marlinspike has a plan to reclaim our privacy
#182Earlier quoted context omitted.
Here's something I've never understood about federated approaches to secure messaging: With a centralized approach like Signal, I have to trust one single provider, i.e. the Signal Foundation running the servers, with my (meta)data. Sure, in an ideal world I'd rather not trust anyone. Fair enough. With a federated network, however, I generally have to trust every single host that any of my contacts has decided to sig…
I think perfect really is the enemy of good in this case. Attack vectors will presumably always exist. I look upon any argument against openness - be it software licensing, protocol federation, data export, binary blob usage, or anything else - with _extreme_ skepticism. > ... I generally have to trust every single host that any of my contacts has decided to sign up with ... In general, you should only have to trust…
Signal's goal, however, is to protect the masses and, thus, society as a whole, by protecting as many people's privacy as possible. The things that are at stake here are not the data and the social graph of a handful of individuals, but the data and social graph of society as a whole. (I'm sure I don't have to mention the implications for democracy and social order.)
My perspective, therefore, was that of an average user. The reason I mentioned my personal situation and the fact that I myself spend quite a bit of time on making sure my systems are safe, was to emphasize that if the situation is already overly complicated for me, it will be much worse for the average user.
> In general, you should only have to trust a particular host with communications going to the specific contact that uses it.
I don't think the word "only" is appropriate here. Let's say John Doe has roughly ~1000 contacts. This means that, in the worst case, he would have to research ~1000 hosts and their privacy policies. Now the "accumulation effect" I mentioned previously will reduce that number quite a bit but there are still going to be dozens of different hosts. I doubt we could expect John to look into each and everyone of them before he gets in touch with his contacts. (Note that this gets even worse when people can freely switch between hosts, as suggested e.g. by other replies to my comment, as John will then have to repeatedly do the checking.) Therefore, I think it is reasonable to expect that a significant number (millions, if not billions) of users will end up residing on insecure and untrustworthy hosts and their social graph and metadata – and possibly even their data (see below) – won't be protected at all.
> With a centralized model, you generally have to unconditionally trust the central authority.
In the federated model, John has to do that, too. Sure, he can self-host but how many people are actually going to do that? Put differently, the vast majority of all acts of communication in the network is going to get routed not through self-hosted nodes but through the servers of providers whose trustworthiness is at least questionable. I hope you will agree that, for society as a whole, this exacerbates the trust problem you mentioned.
> A federated system offers much more flexibility. Metadata is likely to be spread piecemeal across multiple hosts and network paths, making it much more difficult for an adversary to analyze in the general case.
A federated system also makes it much easier for adversaries to enter the game, as they don't have to compromise a well-known provider like Signal that is under the close scrutiny of the public. Instead, they can just create new hosts (just like they do in the case of the Tor network). What's worse, in this case they won't just be able to access their user's social graphs but very likely also the content of their messages, as the key discovery problem is usually solved by hosts distributing their users' public keys.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#183Earlier quoted context omitted.
I think you intended to link the sources but you didn't. Could you still provide them please? I'd be very interested in where those numbers come from.
Here's the foundation's Form 990 from 2018: https://projects.propublica.org/nonprofits/display_990/82450...
Re: Moxie Marlinspike has a plan to reclaim our privacy
#184Requiring a mobile phone number to use Signal is a NOGO.
You can use a voip number that forwards sms (ex: voip.ms). You don't need to setup VoIP, just setup SMS forwarding to email. That's what I did initially for my kid on an android tablet, and always did for my data-only phone.
Sounds worse than buying a prepaid SIM if you ask me.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#185Re: Moxie Marlinspike has a plan to reclaim our privacy
#186Earlier quoted context omitted.
Sigh . That Stack Exchange answer is incredibly old and points to the flaws everyone knew in MTProto 1, which has been superseded by MTProto 2 for years . MTProto 2 is based on standard crypto primitives that not a single human being has found fault in. Please do your research before putting this stuff out there in the future: it spreads unnecessary fear, uncertainty and doubt.
Using standard crypto primitives isn’t enough. I tried to find a review of the security of telegrams new protocol a few months ago and came up empty. So asking the parent to “ do their research” isn’t helpful. And it isn’t FUD to treat an unknown system as insecure.
The gp comment literally just posted a link to a deprecated comment that painted MTProto 1 as (rightfully) insecure.
That was not thorough research and it attaches the FUD associated with an unused protocol to MTProto 2, which I'd again like to remind you and everyone, not a single security researcher or otherwise has found fault in.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#187It's frustrating to see Signal's reputation undermined in technical circles by the shortsighted zeitgeist. Signal's constitutional emphasis on usability supports user demographics that no other security product can attract. My elderly relatives use Signal now instead of Skype. This drew in other family members who just wanted to video chat with grandma and grandpa. Matrix will never win markets like this. When tech n…
Re: Moxie Marlinspike has a plan to reclaim our privacy
#188I won’t bother reading this, it seems to be a standard time waster. Coincidentally I saw this yesterday https://youtu.be/IWMZ17Iyu3o “What’s wrong with Signal etc. “
Re: Moxie Marlinspike has a plan to reclaim our privacy
#189I won’t bother reading this, it seems to be a standard time waster. Coincidentally I saw this yesterday https://youtu.be/IWMZ17Iyu3o “What’s wrong with Signal etc. “
Re: Moxie Marlinspike has a plan to reclaim our privacy
#190This old post from Moxie Marlinspike in 2012 about having the worst material possessions made a huge impact on me for some unclear reason. Fun read. https://moxie.org/2012/11/27/the-worst.html
Do the right thing poorly instead of the wrong thing correctly.