Earlier quoted context omitted.
I can't even convince my contacts to use signal.
My approach is to use Signal for organizing surprise birthday parties. (or at least I did before the world went to shit.) "We need SUPER SECURITY to make sure Rob doesn't find out what's up! So we're all using Signal to plan... Join up!"
Moxie Marlinspike has a plan to reclaim our privacy
221–230 of 237 posts
Re: Moxie Marlinspike has a plan to reclaim our privacy
#222Earlier quoted context omitted.
You're really missing the point here. The core Matrix protocol doesn't handle contact discovery at all. An entirely separate system exists to facilitate contact discovery. You have to explicitly choose to publish an identifier to it. You choose the server you want to publish to. You choose if, which, and when to query such servers. You choose what to query them with. A server implementation can (in theory) support wh…
In the interest of being an informed member of this discussion, I went to try out Matrix. Per the top recommendation from matrix.org, I downloaded the Elements app for iOS. When I opened it, the very first thing it did was ask me if it could access my contacts for sharing them with my (as yet unchosen?) identity server. Then, I registered an account and clicked the “People” tab. I was immediately prompted to enable c…
You are looking at only a single implementation here. The point is that this is a set of federated protocols that has been specifically designed to provide freedom of implementation in this regard.
> But if we can’t agree that the flow recommended on the website is the one that the vast majority of users are going to follow, there’s not much room for a productive discussion.
I never claimed otherwise? We seem to be talking past each other.
You say you followed the top recommendation provided to you and that the end result was essentially equivalent to Signal. Since you appear to approve of how Signal handles things, that hardly seems like a complaint to me?
The key difference, of course, is that for Signal that's the only option. If the central authority changes it tomorrow, then tough. Matrix, on the other hand, provides you the freedom to select (or build, or patch, or whatever) a client that meets your needs. It's providing a superset of what Signal is offering.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#223Earlier quoted context omitted.
In the interest of being an informed member of this discussion, I went to try out Matrix. Per the top recommendation from matrix.org, I downloaded the Elements app for iOS. When I opened it, the very first thing it did was ask me if it could access my contacts for sharing them with my (as yet unchosen?) identity server. Then, I registered an account and clicked the “People” tab. I was immediately prompted to enable c…
> If “contact discovery” isn’t part of the core offering, it certainly makes a great attempt to look like it is. You are looking at only a single implementation here. The point is that this is a set of federated protocols that has been specifically designed to provide freedom of implementation in this regard. > But if we can’t agree that the flow recommended on the website is the one that the vast majority of users a…
My initial question, earlier up the chain, was in regards to this dilemma: Signal didn’t upload contact metadata to their servers for years, until they implemented SGX to allow them to do so securely. By contrast, every other messaging platform (Matrix included) just wrote up a spec for contact metadata storage that doesn’t address protections from the server operator.
We’ve got back and forth about the upsides of federation and open source clients and such, but as I’ve tried to point out, none of that is relevant to the actual question I asked, or the upstream point in the thread: that Signal’s spec didn’t include contact uploads at all until there was a way they could store them securely, and other message platforms just skipped straight to storing them.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#224Earlier quoted context omitted.
> If “contact discovery” isn’t part of the core offering, it certainly makes a great attempt to look like it is. You are looking at only a single implementation here. The point is that this is a set of federated protocols that has been specifically designed to provide freedom of implementation in this regard. > But if we can’t agree that the flow recommended on the website is the one that the vast majority of users a…
Except this isn’t the same as how Signal handles things. Signal uses SGX specifically so that they can store metadata without exposing it to the server. Matrix’s contact discovery spec doesn’t. My initial question, earlier up the chain, was in regards to this dilemma: Signal didn’t upload contact metadata to their servers for years, until they implemented SGX to allow them to do so securely. By contrast, every other…
In practice I have no way of preventing Signal from turning off SGX any time they feel like it because they aren't open and federated. They could push a software update and I'd be none the wiser until a security researcher noticed and pointed it out!
I guess it would be nice if Matrix integrated some sort of remote attestation support into the identity server protocol. Maybe they should have done so from the start, maybe not. At this point I don't see their offering as being less secure than Signal's though, just slightly different.
It's also worth noting that SGX (and AMD's competitive offering) has been broken an embarrassing number of times at this point. From my perspective, secure storage by the server is more or less orthogonal to any given spec or implementation. You either provide data to a server as cleartext or ciphertext. The server does with it what it will - you as the user have effectively no control over that.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#225Earlier quoted context omitted.
Can the downvoters please respond to the post with the reasons why they are downvoting?
You claim that MitM attacks are possible because keys can change without being notified. Can you provide more details on that? I’ve been using signal for years and often get key change notices.
And even there, if I send a message to you and on receipt the software finds that your key has changed, my client sends it again to the new key. Which means that even if I was savvy enough to catch the message, it's tool late and potentially a critical secret has already been disclosed to a MITM by the time I see it.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#226Earlier quoted context omitted.
I think perfect really is the enemy of good in this case. Attack vectors will presumably always exist. I look upon any argument against openness - be it software licensing, protocol federation, data export, binary blob usage, or anything else - with _extreme_ skepticism. > ... I generally have to trust every single host that any of my contacts has decided to sign up with ... In general, you should only have to trust…
I think we need to agree on a common threat model because right now I'm getting the impression that you and I are assessing things from very different angles. If any of the 3-letter agencies decide to target John Doe specifically and expend significant resources on this task, I think we can agree that chances are they will succeed. Neither a centralized or a federated approach will protect John from that because, unl…
> Signal's goal, however, is to protect the masses and, thus, society as a whole, by protecting as many people's privacy as possible.
Sure, by positioning themselves as the only node, which you are then forced to trust. That hardly seems like an acceptable solution to me.
The chance of a given mainstream node being actively malicious seems unlikely to me. Maybe that's misguided, but at least (as you point out) there will be relatively few big ones to research. Non-mainstream nodes don't pose a significant threat by virtue of having little to no use (and so seeing little to none of your traffic and contact graph).
> ... the vast majority of all acts of communication in the network is going to get routed not through self-hosted nodes ... I hope you will agree that, for society as a whole, this exacerbates the trust problem you mentioned.
Actually, it seems to diminish the problem to me. Instead of everything going through one central authority it's now being split across multiple actors. No single entity has access to the complete picture anymore. Moreover, you as the user have the freedom to avoid such supernodes if you feel the need. Yes, that will likely introduce usability hurdles, but at least you have the freedom to do so (as compared to a strictly centralized model).
> Instead, they can just create new hosts (just like they do in the case of the Tor network).
Doesn't this attack model fail to account for how users go about selecting and using servers? If I join the Mozilla instance to chat with them, that wasn't an arbitrary choice - I selected the instance that the organization I want to communicate with is using. So the other party, which I'm going to communicate with one way or another, is the real threat here.
As far as MITM attacks go, that scenario seems to get a bit out into the weeds cryptographically. I'm not sure how viable a large scale attack would be here - presumably at some point odd traffic patterns would become noticeable? And you still have the issue of a malicious node that actively attacks all traffic needing to somehow manage to grow its user base to a significant degree.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#227This old post from Moxie Marlinspike in 2012 about having the worst material possessions made a huge impact on me for some unclear reason. Fun read. https://moxie.org/2012/11/27/the-worst.html
Ahh, I'm from the camp of "the worst". My girlfriend is from that "the best" camp, but doesn't have too much money. So we can't use that little more expensive aluminum foil, because it's for "special occasions". She got upset because I've slightly damaged cheapest workshop vacuum (it's cheapest, but happened to be rather good quality) using it for heavy duty tasks (and saved 50x it's price by doing those tasks myself…
There's a middle way for a lot of product categories: find an enthusiast community and get their recommendation for a low-cost and beginner-friendly product. It's often listed in their FAQ. The gap between enthusiast-grade and mass-market products in some categories is huge, while the gap in price may not be.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#228Earlier quoted context omitted.
Great. Go ahead and demonstrate that Signal Protocol has received sufficient attention from motivated hackers to your satisfaction. Telegram has an open invitation to crack their protocol for 100k USD. Nobody's collecting. I guess those high-value targets using Telegram must be worth more than 100k. I don't need to demonstrate anything other than what I have already: when would we know a protocol has received signifi…
You claimed that the reason to trust MTProto 2 because it is based on standard primitives and because no security research had yet found a bug. I was responding to that, and only that, because it an invalid security argument, and irrelevant to the ‘admonishment’ of the other commenter. The 100k bounty is a somewhat better argument. It would have been far more helpful to lead with that.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#229Earlier quoted context omitted.
Great. Go ahead and demonstrate that Signal Protocol has received sufficient attention from motivated hackers to your satisfaction. Telegram has an open invitation to crack their protocol for 100k USD. Nobody's collecting. I guess those high-value targets using Telegram must be worth more than 100k. I don't need to demonstrate anything other than what I have already: when would we know a protocol has received signifi…
Eh, thanks for the info on MTProto2. They made poor decisions initially, and doubled down on them, and thus I didn't (and still don't) think it worth my time to follow their changelog. The contests are not remotely sufficient. Here's a good article: https://www.cryptofails.com/post/70546720222/telegrams-crypt... "I’ll repeat it again: If you want to show that a system is secure, give the adversary as much power as po…
> and thus I didn't (and still don't) think it worth my time to follow their changelog.
I strongly advise you not to comment on topics you don't find worth following. You directly harm a project that has done a lot of good (for protestors in Hong Kong, Belarus, and Russia) with your ignorance.
Re: Moxie Marlinspike has a plan to reclaim our privacy
#230Earlier quoted context omitted.
Great. Go ahead and demonstrate that Signal Protocol has received sufficient attention from motivated hackers to your satisfaction. Telegram has an open invitation to crack their protocol for 100k USD. Nobody's collecting. I guess those high-value targets using Telegram must be worth more than 100k. I don't need to demonstrate anything other than what I have already: when would we know a protocol has received signifi…
Bug bounties alone don't prove anything. https://www.schneier.com/blog/archives/2005/12/bug_bounties_...
> Paying people rewards for finding security flaws is not the same as hiring your own analysts and testers. It’s a reasonable addition to a software security program, but no substitute.
Sounds like a reasonable addition to me!