Live data from Hacker News

Moxie Marlinspike has a plan to reclaim our privacy

newyorker.com

191–200 of 237 posts

Re: Moxie Marlinspike has a plan to reclaim our privacy

#191

This old post from Moxie Marlinspike in 2012 about having the worst material possessions made a huge impact on me for some unclear reason. Fun read. https://moxie.org/2012/11/27/the-worst.html

I get real 'Zen and the Art of Motorcycle Maintenance' vibes from reading that. An excellent post that resonates a lot.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#192
post #149
post #147

Earlier quoted context omitted.

My biggest annoyance with Signal is that when I send an SMS, people with Signal on an Android will not reply back with an SMS but with a Signal message. It doesn’t make any sense that I don’t get replies on the same channel as I send. This is a big usability no-go for me an the reason I’m not using Signal anymore. Don’t interfere with other messaging systems like SMS.

The only way to avoid this seems to be delete your Signal account, if you just uninstall the app these contacts will still try to reach me (reply to my messages), but the messages will not be delivered as SMS as long as my account exists.

Users can explicitly send SMS messages (long press the send button and select "insecure SMS"), but this option isn't sticky -- I think if the app restarts it will again default to Signal messages. As you say, unregistering your Signal account[1] is the only permanent solution.

[1]: https://signal.org/signal/unregister/

Re: Moxie Marlinspike has a plan to reclaim our privacy

#193

This old post from Moxie Marlinspike in 2012 about having the worst material possessions made a huge impact on me for some unclear reason. Fun read. https://moxie.org/2012/11/27/the-worst.html

This was an entertaining read. I'm probably more of an adherent of the worst than then best. The ideal is probably somewhere in the middle as it usually is. I bought my kid a cheap bike and it fell apart while he was riding it. So then I bought him a more expensive bike.

I've bought a lot of junk and I've spent more time trying to fix the junk or replace it than I'd like to admit and I'd rather spend the upfront time finding the stuff that's not junk in the future so I can spend more time with my family and less time running to the store for a new toaster after mine blows up. just my 2 cents.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#196
post #136
post #72

Earlier quoted context omitted.

It provides forward secrecy and deniability. Your chat database doesn't prove that I said what your database says I said.

It should be noted that (while cool from a cryptographic perspective), this security primitive is practically useless in any scenario where you might think it would be useful: * The burden of evidence to introduce chat logs in legal proceedings is much lower than you would think. Often screenshots of Facebook messages are used, or SMS records (which are also easily spoofed). A judge or jury will likely not entertain…

> The burden of evidence to introduce chat logs in legal proceedings is much lower than you would think. Often screenshots of Facebook messages are used, or SMS records (which are also easily spoofed). A judge or jury will likely not entertain the possibility the messages were fabricated unless you have substantial evidence to the contrary.

This is true for now. It seems likely that fabrication of screenshots etc will start to appear in legal cases, and as soon as it does, the burden of proof will shift.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#197
post #180

Earlier quoted context omitted.

I imagine that getting caught using Signal could be dangerous, whether to an "elite user" planning a one way trip from Hawaii to Russia with a layover in HK, or even to a minor with an abusive parent-over-shoulder. In some countries, a single boolean of metadata could put you in jail or worse. A future Signal update (usernames?) may address this use case. But update or no, it's irresponsible to proffer these scenario…

> But update or no, it's irresponsible to proffer these scenarios as relevant to the typical westerner, especially given the abysmal privacy of the popular alternatives. Have you considered the (sadly) common case of an abusive partner who is likely to see your sudden usage of Signal as an indication that you are speaking to other people about their abuse, or at the least asking others for help? I don't think these s…

Signal isn’t optimized for the use case where you need to use it to ask for help in an abuse scenario.

But isn’t that scenario a weak one? How would you know to install signal and reach out to a specific person for help if you hadn’t already asked for help?

Re: Moxie Marlinspike has a plan to reclaim our privacy

#198

Earlier quoted context omitted.

Using standard crypto primitives isn’t enough. I tried to find a review of the security of telegrams new protocol a few months ago and came up empty. So asking the parent to “ do their research” isn’t helpful. And it isn’t FUD to treat an unknown system as insecure.

You are welcome to develop your argument and point out where in MTProto 2 you find fault or why using standard crypto primitives isn't enough and what you'd like to see from MTProto 2 to secure it in your mind. The gp comment literally just posted a link to a deprecated comment that painted MTProto 1 as (rightfully) insecure. That was not thorough research and it attaches the FUD associated with an unused protocol to…

Crypto primitives aside, Telegram doesn't do E2E by default.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#199

Earlier quoted context omitted.

Using standard crypto primitives isn’t enough. I tried to find a review of the security of telegrams new protocol a few months ago and came up empty. So asking the parent to “ do their research” isn’t helpful. And it isn’t FUD to treat an unknown system as insecure.

You are welcome to develop your argument and point out where in MTProto 2 you find fault or why using standard crypto primitives isn't enough and what you'd like to see from MTProto 2 to secure it in your mind. The gp comment literally just posted a link to a deprecated comment that painted MTProto 1 as (rightfully) insecure. That was not thorough research and it attaches the FUD associated with an unused protocol to…

The point the parent is making is that ‘not a single researcher has found fault’ is not actually a valid baseline for considering cryptographic protocol to be secure.

We have to assume that all protocols are insecure by default. That is standard practice.

Only protocols which have withstood serious scrutiny and incentivized adversaries can be considered to have a level of security.

So if you want to claim MTProto 2 to be secure, it isn’t enough to say ‘it uses standard primitives’. It also isn’t enough to say ‘nobody has found any bugs yet’.

You need to demonstrate that received sufficient attention from motivated attackers before you can claim it is secure. That’s just how it is with crypto.

Re: Moxie Marlinspike has a plan to reclaim our privacy

#200

Earlier quoted context omitted.

In general, I agree. However, their decision to force PINs broke Signal for one of my non-technical contacts, to this day (despite them supposedly offering an opt-out now). This person opens Signal, gets some weird confusing modal dialog, and is now stuck. There is supposed to be a way to opt out without having to set and remember a PIN now, but I was unable to guide this person to find it, and I can't exactly travel…

OK, this is shit. I was not under the impression that this PIN was used to encrypt user data for storage somewhere else. That was not made clear to me.

It would have been more clear if you had clicked the link to their web page and spent time reading a whole long document while you had other things to do.

If I'm not mistaken, this PIN also allows people to hijack your account. That's kind of the point; you export here and you import on your next phone.

But I'm not sure, because the whole thing is so badly explained!

Post reply on HN